Unfortunately, we're dealing with an increasing number of malicious entities who attempt to deceive our customers by posing as Webador. They do this through fraudulent emails, known as phishing, in which they attempt to steal your login credentials or other information.
In this article we'll explain how to identify these fake emails and what action you should take if you receive one.
When in doubt, don't use the link in the email. Open your browser and go directly to webador.com to log in. Any genuine account, subscription, or payment issue that requires your attention can then be checked from your account.
How to spot a fake phishing email?
Four key indicators can help you recognize a fake email impersonating Webador:
1. The sender's email address
Always check the full email address of the sender — on mobile, tap or click the sender's name to reveal the actual address, don't trust the name shown by default.
Genuine / from Webador: Our emails are always sent from an official Webador or JouwWeb domain for your market, for example @webador.com, @webador.de, @webador.fr, @webador.it, @webador.nl, or @jouwweb.nl — never anything else, even if the sender's display name says "Webador".
Fraudulent senders: Often use addresses that look similar to ours but contain small errors. Or they'll use a totally different email address, so be sure to check the sender! Scammers have also been seen using invisible or lookalike characters inside a display name that still visually reads "Webador". The display name is never proof that an email is genuine, only the actual address after the @ counts. Always check the complete sender's email address and make sure the domain exactly matches our official domain.
2. The link in the email
Hover your mouse over the link in the email without clicking on it to see the actual destination URL.
Genuine links: Lead to our official website, Editor, or help center. Our official website is webador.com, and our official help center link is help.webador.com (or the matching domain for your country, e.g. webador.de, webador.fr).
Fake links: Lead to suspicious, unknown, or misspelled websites. Always ensure the URL begins with https:// and not http://. However, a website using https:// is not automatically trustworthy, as phishing websites can also use HTTPS, so check the actual domain carefully.
3. The request for sensitive information
Webador will NEVER ask you via email for:
Your password or full login credentials.
Your bank account details or full credit card number via an unsolicited or automated message. Our support team will only ask for this information after you have contacted us yourself regarding a payment issue (for example, a double charge or unrecognized payment).
- You to call a phone number about a security or payment problem.
Phishing emails often request this information under false pretenses, such as:
"Your payment has failed, click here to update your details."
"Your account has been blocked, log in to reactivate."
"You are entitled to a refund, please enter your bank details."
- "Please transfer a small activation fee to [a bank account], citing our real company name (JouwWeb B.V.) or address" — citing our real, publicly-registered company details is not proof that a request is genuine.
Tip: A genuine Webador invoice number always starts with the year, e.g. 2026-123456. If a "reminder" or "unpaid invoice" email quotes a number that doesn't follow this pattern (or no number at all), that's a strong sign it's fake. If you're unsure, log in directly via webador.com and check your invoice overview to verify whether there is actually an outstanding invoice.
4. Language and formatting
Fraudulent emails often contain clear warning signs:
Grammatical errors: Numerous spelling mistakes or strange sentence structures.
Generic salutation: They are often addressed impersonally ("Dear Valued Customer" or "Dear Webador user") instead of using your personal name. This is just an indication of a possible scam attempt, so please always check your invoice overview as well.
Unnecessary urgency: They create a sense of panic or emergency ("Do this within 24 hours, or your website will be deleted!").
What should I do if I receive a phishing email?
- Do not click! Don't click on any links, don't open attachments, and don't reply to the email.
- Report and delete the email: If your email provider offers a "Report phishing" or "Report spam" option, use it before moving the email to your trash or junk folder.
- Still unsure? (optional): If you've checked the points mentioned in this article and you're still uncertain about the email's authenticity, you can forward it to our support team for verification. If the email clearly matches the phishing indicators described, you can safely delete it.
- Did you click on a suspicious link? Close the page and don't enter or download anything.
- Did you enter your Webador login details? Immediately change your Webador password via your secured dashboard — log in directly via webador.com, never via a link from the suspicious email. If you use the same password elsewhere, change it there too.
- Did you enter your payment or banking information? Contact your bank or card provider to let them know that you may have entered your payment details on a phishing website. They can advise you if any further action is needed.
How to protect your account?
Use a unique password: Ensure you use a strong and unique password that you don't use for any other service. Consider using a password manager to create and securely store unique passwords. You can use the password management features integrated into your device or browser, such as Apple Passwords or Google Password Manager, or a third-party password manager such as Bitwarden or 1Password.
Stay alert: Never trust an email that asks for your login credentials or financial information. Always log in via the official Webador homepage to check your account status.