How to tell it’s us

Four things every real AuraClout email has

Anyone can send an email that looks like ours. So every email we send you carries a test you can run in two seconds, without knowing anything about security.

  1. Your phrase. A phrase you chose opens every email we send you. If it isn’t there, or it isn’t yours, the email isn’t from us.
  2. Your name. We write to you by the name on your account, not “Dear customer.”
  3. Links to auraclout.com only. Every link in our email starts with https://auraclout.com. Nowhere else, ever.
  4. We never ask for your password or your two-step code — not by email, not by phone. Nobody from AuraClout will ever call you to ask for a code.

If an email fails the test

Don’t click anything in it. Forward it to security@auraclout.com so we can act, and to the Anti-Phishing Working Group at reportphishing@apwg.org, which the FTC recommends. Then delete it.

The site is always https://auraclout.com

Type it into your browser yourself when you want to sign in. We will never ask you to sign in from an email link, and there is no other address for AuraClout.

Set your phrase

Sign in, open Account settings → Sign-in & security, and choose a phrase that only you would pick — a few words, between four and twenty-four letters. Changing it asks for your two-step code, or your password if two-step is off. It appears at the top of every email from us and on that page, and nowhere else.