So, I got an e-mail from Netflix. It caught my attention for two reasons; 1) I don't have Netflix, 2) the sender was actually Nettflixx (2 t's, 2 x's) I got interested in who would send such a tacky e-mail, and why would they send it? Are they making money on it? Kidnapping computers?


This is what the e-mail said:

From: Netflix (
Sent: 2013-09-25 08:10:25
1 attached file (63,0 kB) NETFLIX.html
Dear Netflix customer, You have received this email because you or someone had used your account from different locations. In order to safeguard your account, we require that you confirm your Netflix account details. We have limited access to your Netflix account in order to protect against future unauthorized transactions. If this is not completed by October 30, 2013, we will be forced to close your account. Download the attached file and follow the instructions. We thank you for your prompt attention to this matter, Netflix Customer Service. Copyright © 2013 Netflix. All rights reserved.

They used proper English, as far as I can tell anyway. :-) This is not as common as one would think though, not for the spam e-mail that I usually get anyway. For some reason they used "" as sender. I thought this would be the easy bit to spoof. This domain seems to be available if you are interested. Although DomainTools says it has quite the history, so maybe they were in the possession of this domain once.

Most of it seems legit, it probably got copied from the real site. It even has validation and everything! Except that most images seem to be hosted at tinypic... What doesn't seem to be so legit is the following though:

form action="
If you try to surf to the IP FireFox reports this as "web forgery". Even if you ignore the warning you can't surf to it anymore. According to Project Honey Pot it is legit though. According to DomainTools it seems to be hosted by a normal company, and today the IP is used by this site (under construction?).

Googling for either "Nettflixx" or "" doesn't reveal much. Should that be interpreted as nobody got fooled by this? Even though it has been reported as "web forgery" in both FireFox and Chrome. Maybe the safety systems are very good these days and it got shut down quickly. Pity (well, I mean for me ;) ). But I am guessing it was meant to gather credit card info. Hopefully nobody fell for it.

Some helpful links to check the safety of a site:

