Bravo VIP Club

Anti-phishing

Is this message really from bravovipclub.com?

Three checks, in order of how hard they are to fake. The third one — the cryptographic signature — is the one that settles it, and your mail app will show it to you in about twenty seconds.

Check 1 — the domain, read character by character

There is no mailbox to memorise here. What you compare against is the domain: the part of the sender's address after the @, which on a genuine message is bravovipclub.com and nothing else.

The display name — the friendly name your inbox shows in the list — is typed by whoever sent the message. Anyone can type a friendly label like “VIP Manager” there. Tap or click it to reveal the real address underneath, then read the part after the @ from right to left.

The last two labels must be exactly bravovipclub then com, with nothing between them and nothing after. Everything else is a different domain, however similar it looks:

The trick is always in the part after the @. These are illustrations, not addresses seen in the wild.
What you see after the @The real domain (read right to left)Why it fails
bravovipclub.combravovipclub.comThis is the domain.
bravovipclub.com.rewards-mail.netrewards-mail.netOur name is used as a subdomain of someone else’s domain. Read the end, not the start.
bravo-vipclub.combravo-vipclub.comAn added hyphen makes it a completely separate domain.
bravovipclub.netbravovipclub.netDifferent ending, different owner.
bravovipclubs.combravovipclubs.comOne extra letter. Easy to miss at a glance, trivial for someone else to buy.

This check is necessary but not sufficient: a sender's domain can be forged outright. That is what checks 2 and 3 are for.

Check 2 — what this domain publishes

Email from this domain is protected by three standard mechanisms. You do not have to take that on trust: they are published in public DNS records, and any receiving mail provider reads them automatically on every message.

SPF
A published record naming the servers allowed to send mail for bravovipclub.com. Mail from anywhere else fails this check.
DKIM
Outbound mail is cryptographically signed. The signature is bound to the message and to the domain, and it cannot be produced by anyone without the private key.
DMARC
A published policy that ties the two checks above to the domain you actually see, and asks receiving providers to treat a message that fails as suspicious rather than delivering it normally.

Why the check on your own message matters most

SPF, DKIM and DMARC are applied by the receiving mail provider to every message. A summary in one inbox can occasionally look wrong when nothing is wrong — most often because a message was forwarded and rewritten in transit. That is why the check that settles it is the one you run on the message in your own hands, next.

Check 3 — read the result on your own message

Every mail provider records what it found when it applied those checks, and stores it with the message. Here is where to look.

Where the raw message is

  • Gmail (web): open the message, then the three-dot menu at the top right of the message → Show original.
  • Outlook.com / Outlook on the web: three-dot menu → View → View message source.
  • Outlook desktop: open the message in its own window, then File → Properties, and read the internet headers box.
  • Apple Mail: View → Message → All Headers, or press Shift-Command-H.
  • Yahoo Mail: the three-dot menu on the message → View raw message.
  • Proton Mail: the three-dot menu → View headers.

What a genuine message looks like

Search that text for the word dkim=. You are looking for a line in this shape — the exact wording differs a little between providers:

Authentication-Results: mx.google.com;
       dkim=pass header.d=bravovipclub.com;
       spf=pass smtp.mailfrom=bravovipclub.com;
       dmarc=pass header.from=bravovipclub.com

Three things have to be true together:

  • dkim=pass and the signing domain is bravovipclub.com. Depending on the provider this appears as header.d=bravovipclub.com or d=bravovipclub.com.
  • spf=pass.
  • dmarc=pass with header.from=bravovipclub.com. This is the line that ties the signature to the address you were shown.

A dkim=pass on its own proves nothing if the domain next to it is somebody else’s: a fraudulent message can be perfectly well signed — by the fraudster’s own domain. The domain beside the pass is the whole point.

One thing not to rely on

Gmail shows a short “mailed-by” and “signed-by” summary above the message. Do not use “mailed-by” as your test. On mail sent through a hosting provider, that line frequently shows the provider’s own domain rather than ours, which looks wrong when nothing is wrong. Go to the raw message and read the DKIM signing domain and the DMARC result instead.

What should make you stop regardless

These are worth acting on whoever the message appears to be from, and whatever the headers say:

  • Any request for a password, a full card number, a card PIN, or a one-time code. Nothing about a VIP account requires you to hand those over in an email. Never share them, and never enter them on a page you reached from a link in a message.
  • Spelling and grammar that are slightly off, or a greeting and sign-off that do not match how the desk has written to you before.
  • A link to a domain you do not recognise. Hover over it, or press and hold on a phone, and read where it actually goes before you decide.
  • An attachment you did not expect, particularly a document that wants you to enable content or a file that opens a login page.
  • Pressure and a deadline. “Confirm within one hour or lose your status” is a technique, not an administrative process.
  • A push to move the conversation to a messaging app, a chat channel or a different address in order to “continue” something about your account.
  • A request to send money, buy vouchers, or accept a transfer in connection with a reward.

Passing the technical checks means the message came from this domain. It does not mean you have to act on it immediately, and taking an hour to check costs nothing.

If you are still not sure

  1. Do not reply to the message itself. If it is fake, the reply goes to whoever sent it — and a reply confirms your address is live.
  2. Reach the desk through a route you open yourself — sign in to your account, or use the official support of the site where you play — rather than by replying to the message or following a link in it.
  3. Describe or forward the message you received, including the raw headers if you can get them. That is what makes it possible to tell you what you are looking at.
  4. Do not include your password or any one-time code in that message, or anywhere else. Nothing about answering this question needs them.

If you have already clicked something and entered details, change the password on the account concerned first, then reach the desk through your account area or the official support of the site where you play and say what happened. Speed matters more than tidiness.