Emails from Bitwarden
Like using strong passwords, avoiding suspicious emails is an important tool in your online security toolkit. We recommend familiarizing yourself with these FTC Guidelines for spotting and avoiding phishing.
Here are some guidelines to help you determine whether an email that looks like it's from Bitwarden is legitimate:
Emails like new device alerts, invitations to join an Organization, and two-step login codes will come from
firstname.lastname@example.org or, if you're self-hosting, a configured domain like
These emails will never contain attachments. If you're prompted to download a file, please report the email to us.
Some of these emails, like Organization invites, will contain buttons. Always check the validity of the hyperlink before clicking on it by confirming that it leads to
https://vault.bitwarden.com or your Organization's self-hosted domain. If you don't know your Organization's domain, ask a member of your IT team or an administrator.
Automated payments emails for individual premium and paid Organizations subscriptions will come from an
@stripe.com address, like
These emails will contain attachments, specifically PDF invoices and receipts.
While you'll receive automated emails as part of everyday use of Bitwarden, you might also receive emails from the following addresses if you've interacted with various parts of the Bitwarden ecosystem:
Support requests will be received from
Product announcements will be received from
Trial information will be received from
Marketing campaigns will be received from
Emails from members of the Bitwarden team will be received from