A hosted mailbox that stops taking incoming mail is the kind of ticket people open before they finish coffee, because invoices still have to land and a client who thinks you vanished will not wait. The subject sitting in this inbox is a cPanel service notification that the mail delivery daemon is currently blocked, with an affected node labeled server1, which is enough of a host-sounding ticket to survive the few seconds between the list and the reading pane.
The card writes in the calm voice of a monitor that already runs the server, and it says immediate action is required because mail storage is fully exhausted. The system-monitor, the letter claims, detected that the email account has used its allocated disk quota, and the file system is now preventing the mail delivery daemon from writing new messages to the inbox. One orange control sits under that warning, labeled Manage Email Disk Usage, and a second line offers Adjust Alert Settings if you want the notices to stop. The footer signs as an automated system that needs no reply, then copies a 2026 copyright line for cPanel, L.L.C., with a stub 4JTzgsm as if a panel desk had already closed the ticket.
If incoming mail actually stopped, you check it from the panel you already open, or from the webmail you already use, rather than from a surprise storage button that arrived with the warning. Leave this card where it is while you look at the mailbox the way you always look at it. A quota alert that cannot wait for a page you type is asking you to hurry for a reason that is not on the card.

Overview
Manage Email Disk Usage looks like a storage page a host would already keep, yet the click does not open a quota bar you can print, raise, or compare with last month’s hosting invoice. The next screen is a sign-in form that copies the inbox you already use, so a Gmail address is shown a Gmail Portal. Other addresses get the colors and labels their own provider already uses every morning on a real login page. There is no disk tool waiting behind that orange control, because the page is collecting the password for the mailbox you are already sitting in.
What they take first is that password, and after that they take the mailbox itself, including the threads with clients and the invoices that still have to land. Reset codes that arrive an hour later go to the same inbox, which is why a copied password becomes a way into other accounts. A blocked mail delivery daemon is useful costume for that harvest, because a full disk sounds like operations rather than like a stranger asking for a secret. A bar painted at 100% makes the errand feel like a chore you already meant to finish before lunch. Once the copied portal has the password, the people who wrote the notice can read the real mail, impersonate the address, and reset other logins that all send their recovery mail to the same place.
cPanel, L.L.C. is a real company, and hosts around the world use its control panel to run mail, sites, and DNS, which is exactly why that name is useful on a cold letter. Anyone can type cPanel Service Monitor into a display name and paste a 2026 copyright line plus a stub like 4JTzgsm onto a footer. A tidy heading on that card does not prove that a panel exhausted your quota for you. The company does not collect a mailbox password through a surprise Manage Email Disk Usage button in a cold storage alert. A real vendor does not need you to prove you own a box that just received mail. If you need the real control-panel company, type cpanel.net yourself in a new tab, then look at mail from a page you already trust.
The next page copies the inbox rather than copying a storage dashboard, which is why Gmail users often see a Gmail Portal asking for the address and the password. Other mailboxes get the layout they already see every morning, which is how the copied page pretends it belongs to the host. Your address may already be sitting in the username field, and the portal will say storage cannot be cleared until you sign in. That is a polite way of asking for the same password you used to open Outlook. One copy of that next page has sat on EdgeOne, which is not a host you type for webmail, and which is not a reason to go hunting the address after you close the tab.
The Federal Trade Commission writes the same rule in ordinary consumer language in How To Recognize and Avoid Phishing Scams. The FTC says criminals use email to steal passwords, account numbers, or Social Security numbers. A common story is that there is a problem with your account when there is no problem, and another common story is that you must confirm personal information right now when you do not. The Commission’s advice is to contact the company with a phone number or website you already know is real, not the information in the email. A Manage Email Disk Usage button inside an unexpected quota notice is a poor place to start.
CISA says the same thing from the systems side on Avoiding Social Engineering and Phishing Attacks. It tells people not to reveal personal or financial information in email, and not to follow links in a message that asks for that information. On Teach Employees to Avoid Phishing, CISA tells staff that if a message feels off, they should verify it without using any phone number or link in the message. That means a number you already have and a site you already type, which is the opposite of finishing a storage repair through a button the letter provided.
A real quota problem can exist, because hosts do cap mailboxes, and a panel you already pay can show you a storage bar without asking you to retype the password on a stranger’s portal. That check still lives on a page you reach the way you always reach the account, by opening the webmail you already use or by typing the host you already pay. It does not live on a cold orange button that chooses the next screen for you. The letter already arrived in the mailbox it claims is too full to accept mail, which is a contradiction you can sit with for a moment longer than the quota bar wants you to. The same card also writes that the system system-monitor detected the problem, and that at no cost space is depleted. That doubled and broken English is not what a real panel desk would ship under its own copyright.
How The Scam Works
1. A quota alert lands
The message arrives in the same Outlook or hosted webmail you already trust, with a subject that says the mail delivery daemon is currently blocked. The display name says cPanel Service Monitor as if a panel already had a queue. There is no long pitch and no attachment you have to open, and the whole card fits on a phone screen on purpose. A short storage notice is easier to believe than a letter that asks for a Social Security number in the first line. If you are already signed in to webmail, the folders on the left and the search bar on the top make the fake note feel native. You are not visiting a strange site yet, because you are still sitting inside the mail you already opened.
The letter only has to survive the few seconds between the subject and Manage Email Disk Usage. People who would ignore a lottery note will still open a quota alert that looks like the host they already pay. Invoices live on that kind of dread, and so does anyone whose job is to keep a client from thinking the shop vanished, because a blocked inbox is a Monday that will not wait. An affected node labeled server1 is enough to invent the rest of the afternoon, whether that is a missing invoice or a client who will not wait. The costume only has to last until the orange button, which is all the glance needs.
2. The name copies cPanel
cPanel is not a made-up control panel invented for one inbox, which is the load-bearing detail of the costume. That name already lives in the muscle memory of people who keep a domain mailbox. You do not need a long story when the letterhead already sounds like the window a host uses to run mail. The footer already copies a 2026 copyright line for cPanel, L.L.C., plus a stub 4JTzgsm as if a ticket had closed. The people who wrote the letter are not the cPanel company, even though they borrowed the name so a five-second glance would survive. An orange bar plus Immediate Action Required do the rest of that glance, which is why the costume does not need a long pitch.
A real desk would not need that costume, because a real desk already has a panel you can open without a surprise button. A thief does need it, because the thief is not inside the product and is not inside your host. Display names are cheap, and anyone can set From to cPanel Service Monitor, which Microsoft’s guide to spotting phishing treats as a reason to slow down rather than as a badge you can trust. The names are there so you will skip the check, and a support desk you already pay does not need a cold portal to prove you own the mailbox it just delivered mail into.
3. Blocked incoming mail is the hurry
The body does not threaten arrest or dangle a prize, and instead it says mail storage is fully exhausted. It also says the file system is now preventing the mail delivery daemon from writing new messages to your inbox. Immediate Action Required sits in orange over that claim, and a bar painted at 100% makes the hurry look measured rather than theatrical. That is a quieter scare than a lockout clock, and therefore easier to finish on a phone. No new incoming messages will be received until storage is cleared is the second beat of the same hurry, because a silent inbox is a client who thinks you vanished. It turns a maybe later into a now, which is the feeling the orange bar is built to produce.
Urgency is the point of the blocked-daemon claim, not evidence of a real storage bar that a host would enforce through a button in a cold email. A real quota problem, when a host actually has one, is visible inside the panel you already open, and it usually comes with a path you can walk without proving your password to a stranger. A fake one cannot wait, because the people who wrote it need you to press Manage Email Disk Usage before you read the address bar. They also need you to miss that the same mailbox just received the warning it claims it could not accept. The awkward warning that at no cost space is depleted is doing the same job in broken English, pushing you toward the orange control before you notice the sentence does not quite parse.
4. Manage Disk Usage is the handoff
You click Manage Email Disk Usage because that is what a storage control is for, and the click is the moment the quota costume can drop. The next page is not a disk tool with folders you can empty, and it is not a log of oversized messages you can match against last week’s mail. It is a door to a page the letter already picked, and there is no honest reason for a quota repair to live on a surprise site you reached from an unexpected email. You are already sitting inside the mailbox that supposedly could not take new mail, which is the contradiction the orange button hopes you will not sit with.
A real storage page would open inside the webmail you already use, or it would sit as a banner on the panel your host already gave you. It would not ask you to prove you are you so invoices can finish landing. It would not need a fresh login to show you a quota bar for an account that just received this letter. CISA tells people not to follow a link in a message that then asks for that kind of information. Manage Email Disk Usage is the detour from a letter you trust to a page you should not finish. The button is written as a disk tool you can open, and what it actually does is hand you off to a page the letter already chose. Adjust Alert Settings is the same handoff in quieter clothes, offering to stop the notices if you would rather not see them. That quieter line is still a trip to a page you did not type, which is the same handoff with softer wording.
5. The page copies the inbox provider
When the destination loads, the screen often looks like the inbox you already use, which is a useful stage set. A familiar portal feels like a system talking rather than like a stranger asking for a key. The page identifies the provider from the address it already has, so a Gmail mailbox is shown a Gmail Portal that asks for the address and the password. Other mailboxes get the colors and labels they already see every morning, so the portal feels like a continuation of the quota story. That is how a quota alert turns into a copied inbox without changing the story on the button, and it is why the portal feels like a continuation rather than like a new request.
Padlock icons and HTTPS do not establish that the portal belongs to the host it imitates, because they only mean the connection to that particular page is encrypted. Your address sitting in the box can feel like recognition even though the address was taken from the message, the link, or the bulk list that received the same quota alert. Do not finish that form to see whether the quota bar then drops, because a copied login does not become safer when you only wanted to free a little disk. The address in that tab is a door you should stop using rather than a clue you need to collect. A screenshot with the link unclicked is enough if you need a second pair of eyes.
6. They want the mailbox password
If you type the password they have the first key, and if a text, an authenticator prompt, or an email code arrives while that portal is still open they want the second key too. The story will sound helpful, asking you to confirm so storage can be cleared, or to approve so the mail delivery daemon can write again. It may also ask you to enter a code to verify your work account, and each line is the same request for access to the mailbox you were already sitting in. The exhausted quota was never sitting behind that box, because the mailbox was, and the people who wrote the letter designed the 100% bar so you would not notice the swap.
Microsoft’s phishing page tells you to change the password on every affected account if you think you typed it on the wrong site. It also tells you to turn on multifactor authentication if it is not already on, which is the same advice the FTC gives in consumer language. Treat the password as burned and treat the code as burned, and do not reuse either one on the next page that promises to clear storage. You should not type the same password into the host, the bank, or payroll as a courtesy refresh, because a copied portal does not get to supervise those other accounts either. Change those passwords on sites you open yourself, one at a time, after the fake tab is gone, because a copied Gmail Portal does not get to supervise the cleanup.
Once they can open the account they are not hunting for a folder that exceeded a quota, because they are reading the last invoice you sent and the last invoice you received. They also read the thread with a client who pays by wire, and then they write the next message in your voice, which is how a storage alert becomes a payment problem. A bill that looks like last month’s bill is enough, and a new-account, same-firm line is enough. If they add a forwarding rule they can keep a copy after you change the password until someone deletes the rule. A compromised mailbox is not a nuisance in that setting, because it is a way to move a payment without ever calling you again. That is why a quota alert that asked for a password was never about disk.
7. A second crew sells recovery
The last move is often social, and it may not even be the same people. A day later you can get a call, a text, or a fresh email that already knows you opened a cPanel disk quota notice. They will offer to raise the quota, unblock the mail delivery daemon, or recover invoices you never received. Then they will ask for a code, a remote-access session, a second password, or a cleanup fee. Hang up, because a stranger who found you after a quota alert is not your incident responder and does not work for the panel. A cPanel desk that called you after Manage Email Disk Usage is not the product whose name was printed on the card.
That is why a quiet admission that you already clicked, even if you did not pay anyone, is not the end of the story. You may not have paid, while the person who trusts you might still send money. Tell the people who send you money and the people you pay, and tell a real coworker if you actually share the mailbox. Use a number you already have rather than a number that arrived after Manage Email Disk Usage. A 30-second call from you is cheaper than a week of wires that look like your week. The second crew is counting on shame to keep you quiet long enough for the first crew’s mail to land.
What To Do If You Have Fallen Victim to This Scam
If you only opened the email and closed it without following the button, you are not finished with the message, but you are not looking at a device infection from reading alone. If you pressed Manage Email Disk Usage and then typed a password, a code, or personal information, treat the account as touched. Move through the steps below, because speed matters more than naming the exact kit they used on the portal. The goal is to take the mailbox back before someone else sends the next invoice or client note in your name.
- Write down what you typed, including the time and the subject about the blocked mail delivery daemon, then stop using that tab. Note whether the card showed a 100% quota bar, whether you entered a password on a Gmail Portal or another copied inbox, and whether you approved a code or an app prompt. Close the portal and do not keep checking it to see if storage clears, and do not forward the live button to a friend so they can look. Send a screenshot with the link unclicked, or send the raw message as an attachment to a person you already know.
- Open your real mail yourself in a new tab you type, then change the password to one you have not used anywhere else. Use the official site or the app you already trust, and do not return to the quota alert for a reset link. If this is a Microsoft account, follow Microsoft’s steps to recover a hacked or compromised Microsoft account. If you cannot sign in, use the official reset path, not a link from the storage notice. If this is Gmail or a workplace portal, open that product the same way from an address you typed.
- Sign out of other sessions everywhere you can, then turn multifactor authentication back on before you do anything else with the mailbox. Review recent activity and sign out of sessions you did not start, then confirm the extra lock is on. Prefer an authenticator app, a passkey, or a security key rather than a text message alone. If you approved a prompt you did not start, assume that session is not yours until you kill it, and remove recovery phones and recovery addresses you did not add. A password change that leaves an old session running is only half a change and will not finish the cleanup. If you reused that password on banking, payroll, or the hosting panel, change those on their own sites after you type those sites yourself.
- Look for inbox rules, automatic forwarding, and mail that left without you, because those are the quiet ways a stolen mailbox keeps working after a password change. Check the Sent folder and look for a new mailbox delegate, a new app that can read mail, or a filter that hides replies. Delete what you did not create, and search for other disk quota notices you did not expect. If this is a work account, call IT before you spend an hour hunting, because they can dump sessions and pull the audit faster than you can. Also look at Deleted, Junk, and custom folders, because an attacker who is already inside often hides the security alerts that would have told you they were there.
- Protect every account that shares the inbox, starting with banking, cloud storage, shopping, social media, payroll, and the hosting panel that sends reset mail to the same address. Replace reused passwords while you revoke suspicious sessions on those sites too, after you type those sites yourself rather than following anything in the quota alert. If personal, financial, or identity information went into the portal, contact the relevant bank or provider directly. Use a number from a statement or a card in the drawer, not a number that appeared after Manage Email Disk Usage. United States victims can use IdentityTheft.gov to build a recovery plan based on the information that was stolen. That plan is more useful than waiting to see whether a client already paid on a fake invoice.
- Tell the people who might get the next copy of this letter, including contacts who already received messages from your account this week. Warn them not to open unexpected quota or storage links that appeared to come from you, and tell them to call you on a number they already have. If you handle invoices, payroll, or vendor payments at work, tell your administrator the same day, because a hijacked mailbox can change payment instructions in a thread that already looks like yours. A 30-second call on a number you already have is cheaper than a week of wires that look like your week, and shame is the delay the second shift is counting on.
- Report the email through the controls your mail product already publishes, then scan the device if Manage Email Disk Usage saved a file or pushed a viewer. In Outlook, use Report and then Report phishing, the path Microsoft publishes on its phishing help page, and in Gmail use Google’s reporting control from the same phishing help page they publish for this. Forward a copy to the Anti-Phishing Working Group at reportphishing@apwg.org, file at the FTC’s ReportFraud site, and send a cyber report to the FBI’s IC3 if money or identity data moved. If Manage Email Disk Usage saved a file or pushed a viewer, run a full scan with Malwarebytes or the antivirus you already keep updated. The scan does not get a password back, and the password change is the step that actually closes that door.
If someone forwarded you the notice, send them this page instead of the Manage Email Disk Usage button, because these quota alerts travel in office threads when they look like a host talking. Do not install a new cleaner you just searched for because a follow-up email recommended it. Do not approve a remote-access session for a person who already knows the subject line and offers to unblock the daemon. A stranger who found you after a blocked mail delivery notice is not your incident responder. A recovery desk that called you after a Gmail Portal is not the product whose name was printed on the orange bar.
If you actually keep mail on a host that uses cPanel, treat this letter as a reminder to open that product from a bookmark you already keep, not from mail. Then look at the real storage bar and the real inbox, and if the panel shows no exhausted quota, then no quota is waiting. If a real mailbox is actually full, it will still be sitting in a page you can open without typing a password into a copied portal. A fake quota alert does not become real because you were waiting on an invoice, and waiting is the opening they wrote the subject for.
The Bottom Line
A note that says the mail delivery daemon is currently blocked, arrives as cPanel Service Monitor, and paints a 100% quota bar is a login hunt wearing a storage page. It claims mail storage is fully exhausted, writes that the system system-monitor detected the problem, and warns that at no cost space is depleted. It offers Manage Email Disk Usage as if a disk tool were waiting behind a button. The product whose name was borrowed is real, and it is not the sender of this mail. It does not ask you to sign in on a copied Gmail Portal from an unsolicited inbox notice just to free a little disk. Manage Email Disk Usage is how they get you onto that portal, and the provider-matching page is how they collect the password. The mailbox is what they use next, including the contacts, the reset codes, and the client threads that already trust your name.
Open the mail service you already pay by typing it yourself if you need to know whether anything is wrong with the account. Open the host panel the same way if you need to know whether a real quota bar is red. If you already typed the password, change it on the provider’s own page, kill the other sessions, and inspect forwarding rules. Tell the people who send you money before the next email goes out as you. The exhausted disk was only costume for a password harvest, and Manage Email Disk Usage was how they asked you to hand the inbox over.