Short answer: the sender address alone will not tell you. Dropbox really does send notifications from addresses at dropbox.com and dropboxmail.com, including several subdomains for different notification types. So seeing one of those does not prove a message is genuine, and seeing an unfamiliar one does not prove it is fake. Attackers copy both.

What settles it is the link, the context, and what the message asks you to do. Here is the check that takes about fifteen seconds.

The sender domains Dropbox actually uses

Dropbox publishes this list, and it is worth reading before you judge a message, because these are exactly the addresses that send people searching for reassurance:

  • dropbox.com — account and security notices, including no-reply@dropbox.com
  • dropboxmail.com — sharing and comment notifications
  • em-s.dropbox.com and em.dropbox.com — bulk sends, tips and promotional mail
  • txn.dropbox.com — transactional mail such as receipts
  • docsend.com, dropboxteam.com, dropboxpartners.com and dropbox.zendesk.com — DocSend, team and support mail

So no-reply@em-s.dropbox.com and no-reply@txn.dropbox.com — the two people look up most often — are real Dropbox senders. A lookalike such as dropboxlink.com or dropbox-notifications.com is not on the list, and nothing that matters will ever arrive from one.

Use the list to rule a message out, though, not to wave one through. Two things stop it being proof on its own. A From address can simply be forged, so the name in your inbox is a claim rather than a fact. And a genuine Dropbox account can be used to share a malicious file, which produces a real notification, from a real Dropbox address, pointing at something you should not open. That is why the checks below are about the link and the context rather than the sender.

Dropbox keeps the current list at help.dropbox.com/security/official-domains.

1. Look at where the link actually goes

Hover over the button or link without clicking. On a phone, press and hold until the address appears. Every legitimate Dropbox link resolves to dropbox.com before the first single slash.

Read that part carefully, because this is where the trick lives:

  • https://www.dropbox.com/s/... — the real thing
  • https://dropbox.com.files-share.net/... — not Dropbox. The real domain here is files-share.net; “dropbox.com” is just a label in front of it
  • https://dropb0x.com/... — a character swapped, easy to miss at a glance

The rule: read backwards from the first single slash. Whatever sits immediately to its left is the domain you are really visiting.

2. Ask whether you were expecting it

A genuine notification is a consequence of something someone did — a colleague shared a folder, a client uploaded a file you asked for. If a share arrives from a name you do not recognize, or from someone who has no reason to send you anything, that is worth more than any technical signal.

Attackers exploit this by using names that fit your world: an invoice, a signed contract, a scan from the office copier.

3. Notice what it wants from you

Dropbox does not email you asking to confirm your password. If a message leads to a page asking you to sign in — particularly a page showing a Microsoft, Google, or Dropbox login form after you clicked a file link — stop. That page exists to collect your credentials.

The same goes for attachments. A real Dropbox notification links to the file; it does not attach one. We began warning clients about this pattern in 2020, when fake Dropbox notifications started arriving with malicious PDFs attached, and the technique is still in use because it works: everyone treats PDFs as safe.

The safest way to check, always

Do not use the email at all. Open a browser, type dropbox.com yourself, and sign in. If somebody genuinely shared something with you, it will be in your account. If it is not there, the email was a fake, and you never had to make a judgment call.

That habit works for every service, not just Dropbox — banks, Microsoft 365, your payroll provider. The link in the message is the one thing you should never trust.

If you already clicked

  1. Did you enter a password? Change it now, on that service and anywhere you reused it. Turn on multi-factor authentication while you are there.
  2. Did you open an attachment? Disconnect from the network and tell your IT team. Do not shut the machine down first — that can destroy evidence about what ran.
  3. Did you just click and close it? Usually fine, but say something anyway. It is far easier to check than to unpick a breach later.

Nobody should feel foolish about this. These messages are designed by people who do it professionally and test what works.

Stopping them before anyone has to decide

Every judgment call above only happens because the message reached an inbox. Filtering that checks sender authentication, rewrites links so they are inspected at the moment they are clicked, and opens attachments in isolation first removes most of these before anyone sees them — which is what Shring Secure Mail does.

For the ones that get through, the deciding factor is whether your team recognizes the pattern. That is what our security awareness training builds, using simulated messages rather than a slide deck.

If you have an email in front of you right now and you are not sure, send it to us or call 678-680-4900. We would far rather look at ten harmless messages than miss one.

Need a hand with this? Shring Technologies keeps businesses across the Southeast reliable, resilient, and secure. Book a free IT assessment or call 678-680-4900.