Security

Phishing and Impersonation

Hosting accounts are a high value target, so people will try to impersonate Kapsule to get your password. This page tells you exactly what a genuine message from us looks like, what we will never ask for, and what to do if you have already handed something over.

The One Rule

Kapsule will never ask you for your KPanel password. Not by email, not by phone, not in a chat window, not in a support ticket reply, not ever.

Your password is only ever typed into the sign-in form at kpanel.kapsulehost.com and into the panel's own confirmation prompts when you are already signed in. Anywhere else, by anyone, for any stated reason, it is an attack.

There is no situation in which a support agent needs your Kapsule password. Support can already see and act on your account without it. A request for it is proof the message is not from us.

Which Addresses and Domains We Actually Use

The Addresses We Send From

Every automated message from Kapsule is sent from a subdomain, send.kapsulehost.com, with replies directed to kapsulehost.com.

Sender nameSending addressUsed for
Kapsulenoreply@send.kapsulehost.comSign-in and security messages
Kapsulehello@send.kapsulehost.comWelcome, tips, product news
Kapsule Billingbilling@send.kapsulehost.comInvoices, receipts, renewals, payment problems
Kapsule Provisioningprovisioning@send.kapsulehost.comServices becoming ready
Kapsule Supportsupport@send.kapsulehost.comTicket replies
Kapsule Opsops@send.kapsulehost.comInfrastructure notices
Kapsule Alertsalerts@send.kapsulehost.comAlerting

A reply to a support ticket carries a reply address of the form ticket+KC-0000@kapsulehost.com, where the number is your ticket reference.

A display name is trivially forged. "Kapsule Billing" in your inbox proves nothing on its own. Expand the header and read the actual address. Anything that is not @send.kapsulehost.com, or a lookalike domain such as kapsule-cloud.com or kapsulecloud.co, is not us.

The Only Domains We Use

DomainWhat it is
kpanel.kapsulehost.comThe control panel, and the only place you sign in
kapsulehost.comThe main website
support.kapsulehost.comThis help centre

If a link claims to be a Kapsule login page and the address bar says anything else, close it. Hover a link before clicking it and read where it actually goes, not what it says.

There Is No Secret Code Between Us

Some providers give you an anti-phishing passphrase that they quote back to prove a message is genuine. Kapsule does not have one. Do not accept a "verification code", "security passphrase", or "support PIN" from anyone claiming to be us as proof of anything, because no such mechanism exists to be quoted.

Your Support Key, the code beginning KSK- on the Support page and on Settings, then Account, works the other way round. It identifies you to us, so that a ticket can be matched to your account quickly. It is not a secret, it is visible to anyone who can already see your panel, and it proves nothing about who sent you a message.

The One Place a Credential Is Ever Collected

There is exactly one exception, and it is worth understanding so that it does not confuse you later.

The support ticket form, at Support inside the panel when you are already signed in, offers an optional field labelled Login Credential (Optional). It is for a third-party credential you are choosing to share so that we can work on something for you: a mailbox password, or an application administrator password on your own site.

  • It is never your Kapsule password.
  • It is optional. Leaving it blank does not stop a ticket being answered.
  • It is encrypted, readable only by support staff, and is never shown to the AI assistant.
  • It is wiped automatically 30 days after the ticket is raised, and 7 days after the ticket is resolved or closed.
  • It only ever appears inside the signed-in panel. It is never requested by email, phone, or chat.

Even so, treat any shared credential as burned. Create a temporary account or a temporary password for the work, and change or remove it once the ticket is resolved.

How to Check a Suspicious Message

Never act on the message itself. Go to the source instead.

  1. Do not click the link. Open a new tab and type kpanel.kapsulehost.com yourself.
  2. Sign in normally and look for the thing the message claimed. A genuine failed payment appears on the Billing page. A genuine ticket reply appears under Support. A genuine suspension shows a banner.
  3. Check the audit log at Settings, then Account, then View log, for anything you did not do. See Reading Your Account Audit Log.
  4. If it is not there, it did not happen. Delete the message.

Active sessions and login history on the KPanel security settings page

Classic pretexts: a card that has supposedly expired, a domain about to be deleted today, an invoice attached as a document, an account "verification" request, and a threat of suspension within minutes. Our real suspension process gives you a week of warnings, not an hour.

If You Have Already Entered Your Password

Move quickly and in this order.

  1. Change your password immediately at kpanel.kapsulehost.com. If you cannot sign in, use the forgot-password link on the login page.
  2. Turn on two-factor authentication if it is not already on, so a stolen password alone is no longer enough. See Account Security.
  3. Sign out everywhere from Settings, then Security, to kill any session the attacker has.
  4. Review your active sessions and login history on the same page for devices and locations you do not recognise.
  5. Revoke every API key you did not create. Keys survive a password change and a sign-out, so this step is not optional. See API Keys and Developer Access.
  6. Check the audit log for changes: new sites, DNS edits, an email change, a new team member.
  7. Check your email address is still yours. An attacker who reaches the account will try to move it. See Changing the Email Address on Your Account.
  8. Change the same password anywhere else you used it. If it was reused, every one of those accounts is now exposed.
  9. Open a support ticket and say what happened, so the account can be watched.

If your site rather than your account was affected, see What to Do If Your Site Is Hacked.

If Someone Is Impersonating You

Phishing that uses your domain is a problem you can reduce technically.

Publish correct SPF, DKIM, and DMARC records so that receiving mail servers can tell your real mail from a forgery, and so that forgeries are rejected rather than delivered. See SPF, DKIM and DMARC.

If a fake version of your site is hosted on Kapsule, report it. See Reporting Abuse for what to send and where.

Reporting a Phishing Message That Claims to Be Us

Forward it to abuse@kapsulehost.com, as an attachment where your mail client allows it so the original headers survive. Include the URL of any page it linked to.

Do not reply to the message, and do not enter anything into the page to "see what happens". A phishing site logs everything you type.

Troubleshooting

The email looks perfect but I am still unsure. Sign in directly and check. That is always conclusive.

I got a two-factor code I did not request. Someone has your password and is trying to get past your second factor. Do not enter the code anywhere. Change your password immediately and work through the compromise checklist above.

I received an email change alert I did not request. Someone is in your account right now. Act on the checklist immediately. See Lost Access to Your Account Email.

Someone rang claiming to be Kapsule support. We do not make unsolicited calls asking for credentials or payment details. Hang up and raise a ticket instead.

A message asks me to pay an invoice by bank transfer to a new account. Invoice redirection fraud. Only ever pay through the Billing page in the panel. See Payment Options and Saved Cards.

Still need help?

Email us at support@kapsulehost.com or open a chat in KPanel.

Open KPanel