Someone has created an Apple ID using an email address in a domain I own

accountsapple-idpasswordSecurityverify

I own "mydomain.com" (actually something else!) and have a catchall to receive all emails sent to any xxxx@mydomain.com
Earlier this week I received an email from appleid@id.apple.com asking me to verify annepearson@mydomain.com. This person is unknown to me. I did not verify.

I have now received this email:

Dear Anne Pearson,

The password for your Apple ID annepearson@mydomain.com has been successfully reset.

If you believe you have received this email in error, or that an unauthorized person has accessed your account, please go to iforgot.apple.com to reset your password immediately. Then review and update your security settings at appleid.apple.com

Has this person succesfully greated an Apple ID account with an email address she doesn't own?

If so, what can I do?

Best Answer

I think this may be a phishing. I advise you to check the 3 following key points:

  1. Within the headers of the 2 E-mails you received, verify they are really originating from apple.com .
  2. Verify the included URL is really within the apple.com domain.
  3. Within the headers, verify there isn't any Return-Path: outside of apple.com .