A fake Reddit modmail / suspension scam uses messages that look like they came from subreddit moderators or Reddit Admin. The script claims your account is banned, shadowbanned, or under review for spam, vote manipulation, or “ToS violations,” then pushes a link to “appeal,” “verify,” or “unlock” the account. The page clones Reddit login or asks for gift-card PINs, crypto, or remote-access software. Real Reddit does not unlock accounts with Apple, Google Play, or Steam codes read to a stranger in chat.
This guide is modmail- and suspension-specific. Broader patterns: Phishing and account takeover. Chat-app cousins: Fake Discord Nitro scams. Landscape: Credit and debt scams.
How fake modmail plays work
| What you see | What is actually happening |
|---|---|
| Modmail: “Your post violated rules—appeal here” with a bit.ly or reddit-help lookalike | Credential / session phishing page |
| Chat or DM from “u/reddit” or “Admin Support” with a ban countdown | Impersonation; Reddit staff usernames and official channels are limited |
| “Pay a $49–$200 unlock / appeal fee” via gift cards or crypto | Payment extract (Gift cards and prepaid debit risks) |
| “Install AnyDesk so we can clear the suspension” | Remote-access theft (Fake tech-support refund scams) |
| Compromised mod or helper account mass-messages the same appeal link | Account takeover of a trusted identity |
Reddit’s real Modmail lives inside the official Reddit app or reddit.com when you are already signed in. Cold links that ask you to sign in again on a third-party domain are hostile until proven otherwise.
Common scripts
- Suspension + appeal portal. Message says your account will be deleted in 24 hours unless you open an “appeal form.” The form clones Reddit login and steals password + 2FA.
- Fake mod “helper.” Someone claiming to be a moderator offers to reverse a ban if you “verify ownership” on an external site or share a password reset code.
- Gift-card unlock fee. After the phish, a chat demands iTunes or Google Play PINs “to clear the automated hold.”
- Crypto / P2P follow-on. Attackers push wallet drains or Zelle / P2P “refunds” after claiming they overpaid an appeal fee.
- Hijacked community voices. Compromised accounts of known mods or power users paste the same lure into chats and comment replies.
Worked example
Casey gets a Reddit chat from “r/personalfinance_mod_team”: “Account flagged for vote brigading. Appeal before permanent ban: https://reddit-appeal-center.net/case/…”. Casey enters username, password, and the email one-time code. Within an hour the account posts crypto spam, and a follow-up chat demands three $100 Apple gift cards to “restore karma and flair.” Healthy version: Casey ignores the link, opens Reddit from the bookmarked app, checks official notifications and reddit.com/settings, and uses Reddit’s documented appeal paths only from pages reached inside the logged-in site—never from a cold URL. No gift cards, no AnyDesk.
Hard rules that prevent most losses
- Never sign in to Reddit from a link in modmail, chat, DM, email, or a comment.
- Reddit does not collect gift-card PINs, wire, or crypto to reverse bans.
- Real mods will not ask for your password, 2FA codes, or remote-access software.
- Type reddit.com yourself or use the official iOS/Android app; check the domain carefully.
- If a trusted mod account suddenly sends appeal links, verify on another channel or assume compromise.
If you already clicked, logged in, or paid
- On a clean device, change your Reddit password; enable or rotate 2FA; review connected apps and email/phone.
- Check sent messages, posts, and linked payment methods for activity you did not start.
- Contact your card issuer for unauthorized charges; document gift-card numbers and report to FTC (ReportFraud.ftc.gov).
- Report the impersonation accounts and phishing URLs with Reddit’s in-product Report tools.
- Reject “recovery helpers” who charge a second fee.
Checklist
- Treat cold suspension / appeal links as hostile.
- Open Reddit only via official apps or URLs you type.
- Never pay unlock fees with gift cards, crypto, or P2P.
- Never share passwords, 2FA codes, or AnyDesk/TeamViewer for a “ban review.”
- Verify surprise modmail with known mods off that thread when stakes are high.
- After any credential entry, reset the password and audit the account.
Educational only. Not legal, security, or fraud-recovery advice. Reddit policies and scam scripts change; verify through official Reddit Help / in-app channels.