Evite Scam: The Fake Invitation That Wants Your Password
The invitation looks right. It has the layout you’ve seen a hundred times, the RSVP button in the usual place, and at the top, the name of someone you actually know. Then you tap it and a login box appears asking for your email address and password before it will show you the party details.
That’s the scam. Not the design, not the sender name, not the wording. The login box.
The FTC put out an alert about this in May 2026, and the phrasing was blunter than the agency usually gets. Asked to enter your email address and password to open a party invite? That’s a scam. They wanted one sentence people could remember, and it’s the right sentence, because everything else about these messages is designed to survive inspection.
I spent a long time on the product side of identity protection, and this is one of the better-built consumer phishing campaigns I’ve seen. Not because the technology is clever. Because the psychology is.
Why This One Gets Past People Who Know Better
Almost every phishing message you’ve been trained to spot runs on fear. Your account has been suspended. Suspicious activity detected. Final notice before your package is returned. Fear makes people click, but it also makes them suspicious, which is why plenty of those messages fail.
An invitation runs on the opposite emotion. You’re not alarmed, you’re curious. Somebody thought of you. There’s a party. The part of your brain that scans for threats never engages, because nothing here reads as a threat.
Then there’s the name at the top. It’s a real person you know, and that isn’t a coincidence or good guesswork. It’s evidence the scam already worked on them. Once an attacker has someone’s email login, the contact list comes with it, and the next batch of invitations goes out from that account to everyone in it. The FTC describes this directly, noting that once scammers get into an email account they may send the same scam to the victim’s contacts.
So the most convincing detail in the message is also the clearest sign of what’s happening. Your friend didn’t send it. Your friend is the previous stop.
The Tell Is Structural, Not Visual
Most advice about these invitations tells you to hunt for the signs of a fake. Blurry logo, odd spacing, a typo in the footer.
Don’t build your defense on that. The platforms themselves say the fakes look remarkably like the real thing, and any visual flaw you learn to spot is one the next version will fix. Design is the part attackers can iterate on cheaply.
What they can’t change is the structure of the ask. A real digital invitation is a web page. You click, the page opens, you see the event. There’s no locked door, because there’s nothing to lock. Paperless Post says this outright in its own help center, that no login or download is required and you can always open an invitation directly. The Identity Theft Resource Center puts it the same way. A legitimate invitation site will not ask for your email password just to let you view a card or RSVP.
Paperless Post is equally direct about attachments. It never sends executable files, PDFs, installers, or anything else you’d download, only images embedded in the message. An invitation that arrives with a file to open is fake, and the file is the payload.
The rule worth memorizing.
No invitation company needs the password to your email account. Not to show you the event, not to let you RSVP, not to verify you’re really you. If a page asks for it, close the page. That single check catches this entire category regardless of how good the design gets.
The Two Versions, and the One That’s Worse
Which version you get depends mostly on what you’re holding.
On a Phone
You get a sign-in screen. Often it’s built to look like the Google or Microsoft login you’ve typed your password into a thousand times, which is exactly why it works. Muscle memory does the rest.
Whatever you type goes straight to the attacker. There’s no party, and there never was.
On a Computer
You get pushed toward a download instead. One version making the rounds puts an antivirus company’s logo on the page next to an official-looking RSVP code, which is a nice touch, since a security logo is the last thing anyone expects on a malicious page.
The Version That Should Worry You Most
The FTC alert mentions a third variant, and it’s the one I’d flag hardest. Some of these messages ask for your phone number and then ask you to share a special code to RSVP.
There is no such thing as an RSVP code. The University of Michigan’s security team documented this exact sequence in a phishing alert covering a fake invitation, and their description is worth repeating. The page asks for your password, then your phone number, then a one-time passcode that gets created when the attacker uses the password you just gave them.
Read that order again. The code arriving on your phone is real. It was generated by the real service, because the attacker triggered it seconds earlier. You type it in because you just did something and a code showed up, which is exactly the reflex the sequence is built to exploit.
At that point the second factor is gone too, and it was handed over voluntarily.
This is why I get uneasy when people treat two-factor codes as harmless little numbers. A code is a key. If anything ever asks you to read one out or type it somewhere other than the app or site that issued it, stop.
Why They Want Your Email and Not Your Credit Card
People are often puzzled that the goal is an email password rather than card details. From the attacker’s side it isn’t close.
A stolen card gets canceled. You notice a charge, you call, the number changes, and the window closes in days. Your email doesn’t work that way. It’s the recovery address for everything else you own, so whoever controls it can reset your bank, your brokerage, and your social profiles one at a time, at their own pace.
Account takeover, if you haven’t run across the term, just means someone gets control of an account you already have rather than opening a new one in your name. It’s quieter than new-account fraud and it tends to run longer before anyone notices.
The first thing a competent attacker does after getting in isn’t to send anything. It’s to set up a forwarding rule or a filter so copies of your mail route to them and certain messages get archived before you see them. Then the invitations go out to your contacts, and by the time somebody texts you asking whether you really sent a party invite, the useful work is already done. I’ve walked through the full recovery sequence for a hacked email account separately, and the order of those steps matters more than people expect.
Checking an Invitation Takes About Fifteen Seconds
You don’t need to become an expert. You need four habits.
- Look at the sender’s address, not the display name. The display name is free to fake. The address is harder. Evite calls this the single most reliable indicator, and all three major platforms publish the exact addresses they send from. They’re in the table below.
- Hover or long-press the button before you tap it. Real links go to the platform’s actual site. Fakes go to a lookalike domain that reads plausibly at a glance and falls apart when you actually look at it.
- Notice if there’s a file attached. There shouldn’t be one. If there is, the message is fake.
- Ask the host through a channel you already use. Text them. Call them. Do not reply to the invitation to ask whether the invitation is real, because if their account is compromised, you’re asking the attacker.
What a Real Invitation Actually Comes From
Each platform publishes this itself. Worth a bookmark, since it turns a judgment call into a lookup.
| Platform | Invitations come from | Real links start with |
|---|---|---|
| Evite | evite.com and verified subdomains of it, including mailva.evite.com | evite.com or evite.me |
| Paperless Post | paperless@email.paperlesspost.com, paperlesspost@paperlesspost.com, or paperlesspost@accounts.paperlesspost.com | paperlesspost.com, pp.events, or links.paperlesspost.com |
| Punchbowl | mail@mail.punchbowl.com | www.punchbowl.com |
That Evite subdomain trips people up. An address ending in mailva.evite.com looks made up, and enough people go looking to find out whether it’s safe that it’s worth saying plainly. It’s legitimate. The part that matters is what sits at the end, immediately before the .com.
Paperless Post and Punchbowl both note that major email providers show a blue verified checkmark beside their sender name. Useful when it appears, but it doesn’t render in every email client, so treat its absence as inconclusive rather than damning.
If You Want the Definitive Check
Evite points to one, and it works for any sender. In Gmail, open the message, click the three-dot menu, and choose Show original. You’ll see lines for SPF, DKIM, and DMARC, the three standards that let a receiving server confirm a message really came from the domain it claims. A legitimate Evite passes all three. A spoof usually fails at least one. Most people will never need this, but it’s the right tool for a message you can’t just text a friend about.
If You Already Entered Your Password
Move in this order. The sequence matters, because doing it out of order can undo your own work.
- Change the email password first, before anything else. If the attacker still has the inbox, every reset notification you generate elsewhere lands in front of them. Lock the email down and everything downstream gets easier. Use a different device if you have one available.
- Turn on two-factor authentication on that email account if it isn’t already on, and use an authenticator app rather than text messages where you have the option.
- Check for forwarding rules and filters you didn’t create. This is the step most guides skip and the one that lets an attacker keep reading your mail long after you’ve changed the password. Also check the recovery email address and recovery phone number, since changing those is a common way to keep a foothold.
- Change the password anywhere else you used that same one. If you’re reusing passwords, this is the moment to stop, and a password manager makes that practical rather than theoretical.
- Tell your contacts. Not because it’s embarrassing, but because they’re the next targets and a heads-up breaks the chain.
If you clicked the link but didn’t type anything in, you’re in much better shape. My guide on what to do after clicking a phishing link covers how to tell the difference between a visit and a compromise.
If you downloaded and ran a file, treat that device as untrusted until a full scan with up-to-date security software comes back clean, and change your passwords from a different device.
Where to Report It
Reporting takes a minute and it feeds real enforcement work.
Forward phishing emails to the Anti-Phishing Working Group at reportphishing@apwg.org, and forward scam texts to SPAM, which is 7726 on the keypad. Then file the report with the FTC at ReportFraud.ftc.gov. If you gave up account information, IdentityTheft.gov will walk you through steps based on what specifically was exposed.
Report it to the platform being impersonated too. Paperless Post takes reports at phishing@paperlesspost.com, and the platforms are the ones who can get lookalike domains taken down.
The Honest Bottom Line
This scam keeps working because it’s built on a good instinct rather than a bad one. Wanting to see what your friend invited you to is not a security failure.
So don’t try to out-inspect it. Keep one rule instead. A real invitation never needs your email password, and no legitimate service will ever ask you to share a verification code with a third party. Everything else about these messages is negotiable. That part isn’t.
If you want to shore up the account this scam is actually after, start with how to recognize a hacked email account and get it back. And since the same crews run this by text as well as email, my breakdown of text message scams and how they’re built covers the mobile side of the same playbook.
Tom Reardon spent over 20 years in product and operations at major identity protection providers. He writes at MyScamGuide.com to give consumers the honest picture the industry’s marketing never did.
Recommended resources:
- FTC: How to Recognize and Avoid Phishing Scams: the agency’s plain-language reference
- ReportFraud.ftc.gov: where to file the report
- IdentityTheft.gov: the FTC’s step-by-step recovery tool