About this tool
Check an Apple ID account-locked email, text or call against Apple's real domains and the things Apple never asks for.
Account-locked messages are judged on two things: the registrable domain the link actually goes to, and whether the message asks for something Apple never asks for. This page checks both — sender and link domains against apple.com and icloud.com, and the wording against Apple's published position that it does not request passwords, verification codes or security answers by email, message or phone. It also covers the SMS, iMessage and cold-call versions of the same script, and the anatomy of the email itself, from the fake case number to the 24-hour deadline.
Open Apple ID Locked Phishing Anatomy on AltFTool — it loads instantly in your browser.
Add your input to the workspace.
Adjust the options until the result looks right.
Copy or download the output and put it to work.
A pixel-perfect copy of an Apple page is trivial; the registrable domain is the part that cannot be faked.
SMS sender IDs are forgeable and cold calls have no header at all, so the tool weights those channels differently.
Every finding points to checking your account from Settings or a hand-typed address instead of any link.
Almost always no. A genuine Apple ID hold is cleared from your own device or at iforgot.apple.com, and Apple's account mail comes from apple.com or icloud.com domains. Check the link's registrable domain — the part immediately before the first single slash — and if it is anything other than apple.com or icloud.com, delete the message.
Apple sends account and receipt mail from hosts under its own domains, such as email.apple.com and icloud.com. The From header can still be forged, so treat a matching sender as one weak signal and judge the link and the request instead. When in doubt, open Settings, tap your name, and check Purchase History and Sign-In and Security there.
No. Apple states it does not ask for passwords, verification codes or security answers by email, message or phone. A request for a two-factor code is the most serious version of this scam, because it means the caller already has your password and needs only the code to complete a sign-in.
Change your Apple Account password immediately from Settings on your device or by typing appleid.apple.com yourself, then review the trusted devices and trusted phone numbers listed there and remove anything you do not recognise. Check Purchase History for unfamiliar charges, and forward the phishing email to reportphishing@apple.com. If money has moved, contact your bank the same day.