An email claims important messages have stopped arriving because of a DNS problem. The button says the account owner can fix it in moments.
That sounds technical enough to be urgent and vague enough to leave you guessing. Before touching the button, separate the real technology from this particular notice.

Overview
The message claims DNS is blocking your mail
The “DNS Activation Required” email tells recipients that administrator policy has prevented delivery and that ownership must be confirmed to restore messages.
Its reported subject includes the recipient’s address followed by “Please confirm to continue.” The body offers a prominent “Confirm Now” button.
This is a credential-phishing lure. The reported destination presents a fake Google-style sign-in dialog, not an authenticated DNS administration page.
A recipient need not run a diagnostic tool or change a domain record to be exposed. Typing a working email password into the fraudulent form is the danger.
DNS is real, but this repair request does not fit it
DNS records help direct email for a domain. For example, an MX record tells other systems which mail server receives messages.
Cloudflare’s MX record explanation describes that routing role. A mailbox password entered on an unrelated page does not modify the record.
Domain administrators may need to verify ownership in legitimate setup workflows. Those processes happen through the provider’s established dashboard, with specific records or instructions.
The reported email instead asks a broad recipient to confirm ownership through a generic link. It does not identify an actual record requiring change.
Recognize the specific handoff
- The message attributes missing mail to an administrator policy without an independently verifiable incident.
- It uses DNS terminology but supplies no domain record, provider ticket, or technical error.
- Its “Confirm Now” control opens a website selected by the sender.
- The destination requests mailbox credentials inside a copied login design.
- Google branding and cloud hosting do not authenticate the sender.
If mail is genuinely failing, involve the actual host or domain administrator. Do not let the unsolicited email choose your support route.
Why the DNS Claim Can Sound Plausible
Email delivery does depend on domain settings
When someone sends a message to your domain, their system looks up where to deliver it. The domain’s DNS records are part of that process.
A wrong MX record can cause delivery problems. Other records, such as SPF, DKIM, and DMARC, help receiving services evaluate whether mail is authorized.
Those functions are technical, but they are not mysterious. A real support investigation can identify the affected domain, record, service, and observable error.
The scam email skips those facts. It announces a diagnosis and supplies one generic button to people who may not even manage their domain.
Many recipients use free webmail and have no DNS console at all. Asking them to “activate DNS” for their individual mailbox is especially incoherent.
Missing messages are difficult to disprove instantly
You know which emails arrived. You rarely know every email that someone attempted to send but could not deliver.
That uncertainty is useful to a phisher. A quiet afternoon can feel like evidence of a problem once the warning supplies an explanation.
For a business, the concern may be sharper. Lost quotations, customer questions, or password resets can have immediate consequences.
The right response is to test delivery through trusted systems and ask a known administrator. It is not to reveal a password to a surprise page.
If a sender reports a bounce, request the actual error details from that sender through an existing conversation. Compare them with your host’s records.
A familiar cloud host can camouflage an unfamiliar page
The reported phishing page was hosted using Google Cloud Storage infrastructure. That service is legitimate, but a hosted page is not automatically a Google account service.
A cloud storage address may look less suspicious than a newly registered stand-alone domain. It still can contain content controlled by an unrelated party.
The page reportedly displays a Google-style “Sign in to continue” dialog, with the recipient’s address already filled in.
Prefilling is not proof of account access. The sender knows which address received the message and can place it in a link or browser form.
Never decide who owns a login by the logo alone. Confirm the precise address and open the real service directly when authentication is necessary.
How the DNS Activation Required Scam Works
Step 1: The sender makes delivery sound already broken
The email says important messages have been prevented by an administrator’s policy. That claim turns a possible technical issue into an immediate personal concern.
It does not identify which messages failed, who sent them, or what server recorded the refusal. The reader is expected to supply those missing details mentally.
A rough line in the reported specimen reads “Administrator,s police has prevented.” The wording is suspicious, but the mechanism does not depend on poor grammar.
Another version could correct every typo and remain the same phishing scheme. The central issue is the unsupported diagnosis and the linked credential request.
If you manage a domain, check server or provider records before accepting an emailed failure claim. If you do not, ask the person who does.
Step 2: DNS language makes a password request seem technical
“Please confirm your ownership with DNS” sounds like a legitimate verification process. It borrows vocabulary used when connecting domains to mail services.
In real setup, an administrator may add a TXT record or configure MX records through a DNS provider. A user typically does not fix that by re-entering webmail credentials.
That mismatch is the lever. The reader might know enough to recognize DNS as important, but not enough to see that the proposed action does not match the problem.
Ask what exactly will change after confirmation. The email provides no record value, domain dashboard, or authenticated support ticket to answer.
A genuine provider can explain how it determined an error. It should not require trust in a generic message whose authority cannot be independently checked.
Step 3: “Confirm Now” moves the reader to a chosen page
The button is the transition from story to control. Clicking it leaves the familiar inbox and opens a location specified by the sender.
In the reported case, the page used a cloud-hosted location. The hostname may change quickly as abusive pages are reported or replaced.
That means a future copy may not match one documented URL. The robust warning sign is the instruction to authenticate outside the normal provider workflow.
Before any account action, open a fresh tab and enter the host’s known address yourself. Do not navigate from the email, even if the label looks routine.
For a managed workplace domain, use the organization’s approved help desk. The mail recipient should not improvise DNS changes through an unsolicited button.
Step 4: A copied sign-in dialog asks for the mailbox password
The page reportedly places a Google-style login prompt over a generic setting screen. Its purpose is to collect email credentials.
The form may already display the recipient’s address. That small detail can make it feel as if the page has recognized an existing account session.
But an address is not an authentication secret. A criminal can put it into the URL or page text after mailing the same recipient.
Entering the password does not confirm domain ownership, activate an MX record, or release a queue of mail. It gives the form operator a reusable credential.
Do not approve any unexpected multifactor prompt or supply a code afterward. The attacker may attempt a real login while the victim remains on the fake page.
Step 5: The stolen identity can be used beyond mail delivery
A successful mailbox login may expose conversations, attachments, contacts, and password-reset messages for other services.
An intruder might create forwarding rules, grant an app access, or send messages as the account holder. Those actions can remain unnoticed if no password alert appears.
In a business setting, one compromised mailbox can make later invoice or supplier fraud more believable. The original DNS story may disappear from view.
These are risks following credential exposure, not confirmed outcomes for every recipient. Receiving the email alone does not demonstrate that any account was accessed.
Keep the response tied to your actual actions: did you view the page, submit a password, approve a prompt, or download anything?
How to Investigate a Real Email Delivery Problem
Start with symptoms, not the scammer’s diagnosis
Ask a known contact to send a harmless test message. If it does not arrive, have that person preserve the exact bounce or error report.
Check spam, quarantine, and service-status information from your provider. Determine whether one sender, one mailbox, or the entire domain is affected.
Those differences matter. A single mistyped address is not the same incident as a bad MX record or an organization-wide outage.
If mail is delayed, record timestamps and sender domains. Specific evidence helps support more than the scam email’s claim about “important messages.”
Let the person with DNS access examine records
Domain DNS may be managed by a registrar, hosting company, Cloudflare account, IT contractor, or internal administrator. Identify who has authorized control.
That person can review MX, SPF, DKIM, and DMARC records in the actual dashboard and compare them with the mail provider’s published requirements.
Do not change records simply to satisfy a suspicious notice. A mistaken MX update can cause a genuine outage or route new mail incorrectly.
Cloudflare’s email-record setup guidance shows that the exact values depend on the email provider.
There is no universal “Confirm Now” button that activates DNS for every recipient. Technical fixes require the right domain and authenticated administrative context.
Separate account security from delivery repair
If you entered a password on the false page, secure the mailbox even if test messages still arrive. Normal delivery does not rule out unauthorized reading.
If you did not submit anything, you may still have a real delivery issue. Investigate it independently rather than concluding that the scam email caused it.
A browser may show a padlock on the fake page. That indicates transport encryption, not permission to ask for your credentials or change your domain.
Similarly, a cloud-hosted page may have a trustworthy infrastructure owner but untrustworthy content. Check who authored the page and why it relates to your account.
What to Do if You Have Fallen Victim to This Scam
Leave the page and document your actions. Record whether you only opened it, entered a password, supplied a code, approved a prompt, or downloaded a file.
Save the email, visible address, and approximate times. Do not revisit the destination to see whether it still works.
Replace any submitted password immediately. Open the actual provider from a known address and create a unique password from a clean browser session.
Change the same password on other services if it was reused. If this is a work account, notify IT before making uncoordinated changes.
Remove lingering access. Sign out active sessions where possible, review recent sign-ins, and remove unknown devices, recovery details, delegated users, and app permissions.
Enable strong multifactor authentication. Reject prompts you did not initiate and reset compromised recovery codes if they were shared.
Inspect the mailbox for abuse. Check forwarding rules, filters, sent messages, deleted items, and password-reset mail.
Ask administrators to preserve logs for a workplace account. A quiet mailbox can still be copied through a hidden forwarding rule.
Check the actual DNS and mail service separately. Ask the verified host or domain administrator whether any records changed or delivery failed.
Do not change DNS because the scam email said to. Restore only changes confirmed as unauthorized or incorrect through the real administrative process.
Scan if software exposure occurred. A message or webpage alone does not prove device infection. If a file downloaded or ran, use Malwarebytes and approved security tools.
AdGuard can block some malicious destinations later, but it does not revoke a password already disclosed to a fraudulent form.
Report and warn appropriate people. Use the provider’s phishing-report control and share the incident with organizational security when applicable.
If the account sent suspicious messages, warn contacts through another channel. Do not forward the live phishing button as a demonstration.
Is Your Device Infected? Run a Free Malware Scan
Slow performance, constant pop-ups, or strange behavior? These are classic signs of a malware infection. The fastest way to find out is to scan your device with Malwarebytes Free — one of the most trusted malware removal tools available.
The free version detects and removes the most common threats, including:
- Adware — the cause of those annoying pop-ups
- Browser hijackers — unwanted redirects and changed homepages
- Trojans and spyware — hidden programs stealing your data
- Potentially unwanted programs (PUPs) — software you never asked for
👉 Select your device below — Windows, Mac, or Android — then follow the simple steps to download Malwarebytes, scan your system, and remove any threats it finds. The scan usually takes 5 to 20 minutes.
Run a Malware Scan with Malwarebytes for Windows
Malwarebytes is one of the most popular and trusted anti-malware tools for Windows — and it’s completely free for removing infections. It catches threats that many antivirus programs miss, including adware, browser hijackers, and trojans. Follow the steps below to scan and clean your PC in just a few minutes.
Download Malwarebytes
Click the button below to download the latest version of Malwarebytes for Windows from the official source. The free version is all you need — it will scan your computer and remove adware, browser hijackers, and other malicious software at no cost.
Download MalwarebytesOfficial installer for Windows 11 and 10. Your download starts right away.Want real-time protection? See Malwarebytes Premium
Malwarebytes Free for WindowsScans and removes malware at no cost-
Install Malwarebytes
When the download finishes, open your Downloads folder and double-click the MBSetup file. If Windows shows a User Account Control pop-up, click “Yes” to allow the installation.

Follow the On-Screen Prompts to Install Malwarebytes
The setup wizard will walk you through a few quick screens:
-
Choose where you’re installing the program — “Personal Computer” or “Work Computer” — then click Next.
-
Malwarebytes will now install on your device. This usually takes under a minute.
-
When installation is complete, the “Welcome to Malwarebytes” screen will open automatically.
-
On the final screen, click Open Malwarebytes to launch the program.
-
Enable “Scan for Rootkits”
Before scanning, turn on rootkit detection so Malwarebytes can find even the most hidden threats. Click the Settings gear icon on the left side of the screen.

In the settings menu, find “Scan for rootkits” and click the toggle so it turns blue.

Done? Click “Dashboard” in the left pane to return to the main screen.
Start the Scan
Click the blue Scan button. Malwarebytes will automatically update its virus database and start checking your computer for malware.

-
Wait for the Scan to Finish
The scan checks your entire system for browser hijackers and other malicious programs, so it can take 5 to 20 minutes depending on your computer. Feel free to do something else — just check back occasionally to see the progress.

-
Quarantine the Detected Threats
When the scan is done, you’ll see a list of everything Malwarebytes found — malware, adware, and potentially unwanted programs. Click the “Quarantine” button to remove all of them at once.

Malwarebytes will now remove the malicious files and registry entries and move them safely into quarantine.

-
Restart Your Computer
Some threats can only be fully removed after a reboot. If Malwarebytes asks you to restart, click Yes. Once you’re logged back in, Malwarebytes has finished removing the threats it found.

That’s it — your Windows PC is now clean of trojans, adware, and other malware, and should be back to running smoothly.
If you are still having problems with your computer after completing these instructions, then please follow one of the steps:
- Run a computer scan with ESET Online Scanner
- Ask for help in our Windows Malware Removal Help & Support forum.
Run a Malware Scan with Malwarebytes for Mac
Malwarebytes for Mac is a free on-demand scanner that removes the malware other security software tends to miss — adware, browser hijackers, and unwanted programs included. Cleaning an infected Mac with Malwarebytes has always been completely free, and it’s our go-to recommendation. Follow the steps below to scan and clean your Mac in just a few minutes.
-
Download Malwarebytes for Mac
Click the button below to download the latest version of Malwarebytes for Mac.
Download MalwarebytesOfficial installer for macOS. Your download starts right away.Want real-time protection? See Malwarebytes Premium
Malwarebytes Free for MacScans and removes malware at no cost -
Open the Malwarebytes setup file
When the download finishes, open your Downloads folder and double-click the setup file to begin the installation.

-
Follow the On-Screen Prompts to Install Malwarebytes
The Malwarebytes for Mac Installer will guide you through a few quick screens. Click “Continue” and keep following the prompts until the installation completes.



When the installation is complete, Malwarebytes opens to the Welcome to Malwarebytes screen. Click “Get started“.
-
Select “Personal Computer” or “Work Computer”
Malwarebytes will ask what type of computer you’re installing it on. Click either Personal Computer or Work Computer, whichever applies.

-
Start the Scan
Click the “Scan” button. Malwarebytes will automatically update its detection database and begin checking your Mac for malware.

-
Wait for the Scan to Finish
Malwarebytes will scan your Mac for adware, browser hijackers, and other malicious programs. This can take a few minutes, so feel free to do something else — just check back occasionally to see the progress.

-
Quarantine the Detected Threats
When the scan is done, you’ll see a list of everything Malwarebytes found. Click the “Quarantine” button to remove all the threats at once.

-
Restart Your Mac
Malwarebytes will now remove all the malicious files it found. Some threats can only be fully removed after a reboot — if Malwarebytes asks you to restart, allow it. Once you’re logged back in, your Mac is clean.

That’s it — your Mac is now free of adware, rogue browser extensions, and other potentially harmful software.
If you are still experiencing problems while trying to remove a malicious program from your computer, please ask for help in our Mac Malware Removal Help & Support forum.
Run a Malware Scan with Malwarebytes for Android
Malwarebytes for Android automatically detects and removes dangerous threats like malware and ransomware so you don’t have to worry about your most-used device being compromised. Aggressive detection of adware and potentially unwanted programs keeps your Android phone or tablet running smooth.
-
Download Malwarebytes for Android.
You can download Malwarebytes for Android by clicking the link below.
Get Malwarebytes for AndroidOpens Google Play in a new tab.Want real-time protection? See Malwarebytes Premium for Android
Malwarebytes for AndroidScans your phone and removes malware at no cost -
Install Malwarebytes for Android on your phone.
In the Google Play Store, tap “Install” to install Malwarebytes for Android on your device.

When the installation process has finished, tap “Open” to begin using Malwarebytes for Android. You can also open Malwarebytes by tapping on its icon in your phone menu or home screen.

-
Follow the on-screen prompts to complete the setup process
When Malwarebytes will open, you will see the Malwarebytes Setup Wizard which will guide you through a series of permissions and other setup options.
This is the first of two screens that explain the difference between the Premium and Free versions. Swipe this screen to continue.
Tap on “Got it” to proceed to the next step.
Malwarebytes for Android will now ask for a set of permissions that are required to scan your device and protect it from malware. Tap on “Give permission” to continue.
Tap on “Allow” to permit Malwarebytes to access the files on your phone.
-
Update database and run a scan with Malwarebytes for Android
You will now be prompted to update the Malwarebytes database and run a full system scan.

Click on “Update database” to update the Malwarebytes for Android definitions to the latest version, then click on “Run full scan” to perform a system scan.

-
Wait for the Malwarebytes scan to complete.
Malwarebytes will now start scanning your phone for adware and other malicious apps. This process can take a few minutes, so we suggest you do something else and periodically check on the status of the scan to see when it is finished.

-
Click on “Remove Selected”.
When the scan has been completed, you will be presented with a screen showing the malware infections that Malwarebytes for Android has detected. To remove the malicious apps that Malwarebytes has found, tap on the “Remove Selected” button.

-
Restart your phone.
Malwarebytes for Android will now remove all the malicious apps that it has found. To complete the malware removal process, Malwarebytes may ask you to restart your device.
That’s it — your Android phone is now clean — no more malicious apps, adware, or browser redirects.
If you are still having problems with your phone after completing these instructions, then please follow one of the steps:
- Restore your phone to factory settings by going to Settings > General management > Reset > Factory data reset.
- Ask for help in our Mobile Malware Removal Help & Support forum.
Stay Protected: Block Ads and Malicious Sites
Now that your device is clean, keep it that way. Most infections start with a malicious ad or a fake download button — so blocking them at the source is your best defense.
We recommend AdGuard, which blocks malicious ads, phishing pages, and dangerous redirects before they can reach you.
👉 Download AdGuard and browse safely
What We Can and Cannot Confirm About This Campaign
The reported specimen shows a DNS activation pretext, a “Confirm Now” link, and a copied Google-style credential prompt on cloud-hosted infrastructure.
We have not established that any individual reader’s domain was misconfigured, that messages were actually blocked, or that every click led to the same active page.
The campaign’s hosted page can disappear or be replaced. A failed link today does not make the original message legitimate or prove what an earlier visitor saw.
Our lead image is a fictional, nonfunctional email interface illustrating the reported pretext. It is not a capture from a victim’s mailbox.
Frequently Asked Questions
What does “DNS Activation Required” mean in this email?
It is the phrase used to push an unverified account-confirmation link. The message does not demonstrate a real DNS change needed for your mailbox.
Could my domain genuinely have a DNS problem?
Yes. Real mail routing can fail because of incorrect records. Verify through your domain administrator, provider dashboard, and delivery errors, not the unsolicited button.
Why was the phishing page on Google Cloud Storage?
Cloud storage can host webpages or files. Using that legitimate infrastructure does not mean Google created or approved the fraudulent sign-in prompt.
Does a prefilled email address prove the page knows my account?
No. The sender already knows the delivery address and can insert it into a link or form without accessing your mailbox.
Will typing my password fix an MX record?
No. MX records are managed through authorized DNS settings. A password entered on a random page can expose the account without changing mail routing.
What if I clicked “Confirm Now” but entered nothing?
Close the page and check for downloads or permissions. A click alone does not establish credential theft; investigate any other action you took.
The Bottom Line
The DNS Activation Required email uses a real technical term to justify a fake sign-in. A cloud-hosted page and copied Google styling do not make the request authentic.
Check delivery with your actual host or domain administrator. If you submitted a password, secure the mailbox and inspect existing access before troubleshooting DNS.