Suspicious email about iNaturalist donation payment method change

Got an email suggesting I cancel my monthly (small) donation through PayPal and then restart it by clicking on the link in the email.

3 Likes

It appears that is a legitimate email, check this thread:
https://forum.inaturalist.org/t/is-the-email-about-changing-paypal-donation-for-some-other-system-valid/75135/4

3 Likes

Thanks very much!

1 Like

This does seem to be a genuine email, and I’m sure no-one at iNat thought it would be a problem to include a link for a user to set up a new payment. But it doesn’t really follow good cybersecurity practices. It would have been a lot better to simply tell users to “Go to iNaturalist. Click Donate at the bottom of the page and select the monthly option.”

What’s wrong with providing a link? Well consider a scammer who obtained a list of email addresses for iNat donors. On its own, a long list of email addresses is not especially valuable. But all of these people have already proven willing to give money over the Internet with no expectation of receiving anything in return. It’s not difficult for a scammer to register a domain very similar to inaturalist.org and scrape several pages from the real site to make it look superficially plausible. Then the scammer sends all of the targets an email with a link to a fake donation page on the fake iNat site. Their goal is to fool enough people for long enough to steal a bunch of well-intentioned iNat users’ contributions and then disappear.

That scam is still entirely possible even if iNat stops including donation links in emails, but the more that organizations avoid this practice the more suspicious people will be in general about requests that say “Click here to give me your money”.

6 Likes

You can also check the headers. I am not currently donating, but I get an update email every day; here’s a header from one of those:

Received: from o1.ptr9832.inaturalist.org (o1.ptr9832.inaturalist.org
[198.37.153.128]) by (Postfix) with ESMTPS id
C70435FD00 for ; Sat, 14 Feb 2026 07:40:07 -0500 (EST)

1 Like