The $499.99 Norton LifeLock charge on this calendar invite was fake. Norton didn't send it, nothing was charged, and the number in it reaches scammers. If you have one like it, don't call. Start with our guide to scam calendar invites for what to do right now.
On September 25, 2026, this invitation reached a family member's personal Outlook.com account. Microsoft's spam filter caught the email and moved it to Junk. The event appeared on the calendar anyway, and its reminder popped up on their phone almost as soon as it arrived. Several of our relatives have received variants since.
We build email-analysis tools, so we took this one apart, header by header. Here's what it shows.
What landed on the calendar
The event's title carried the whole scam:
💳 Automatic payment processing will occur within the next 24 hours. To cancel, contact U.S. Support: +1 (805) 843-0884
The description dressed it up as an invoice: an annual "Identity Protection Service" plan for $499.99, "Payment Status: Paid", invoice number NL-2026857376, and the same number labeled "Toll-Free Customer Support (U.S.)".
Seven details give it away:
- The whole lure is in the title. Calendar views and reminder pop-ups show the title, so the number reaches you without your opening anything.
- The "toll-free" number isn't toll-free. US toll-free numbers start with 800, 833, 844, 855, 866, 877 or 888 (FCC). 805 is an ordinary area code for California's Central Coast (NANPA). Real companies use ordinary numbers too, but they don't call them toll-free. Scam templates do: Malwarebytes found unfinished ones with a "#TFN#" (toll-free number) placeholder waiting to be filled in (Malwarebytes).
- A "Paid" invoice for something nobody bought. Norton says it "never sends calendar invites related to billing or payment" (Norton support).
- A 24-hour deadline. The urgency is there to get you to call before you check.
- Google's labels are in Spanish. The invitation's wrapper reads "Invitación" and "Organizador", while the bill is in English and aimed at a US customer. That's a clue about the account that sent it, not about Norton.
- The organizer is a student account at a Mexican school's domain. It's not Norton, and probably not an account the scammer created (more on that below). We're not publishing it.
- The sender line is real. The email came from [email protected] and carries Google's genuine signature. That's what makes it look trustworthy, and it's why "check the sender" advice doesn't help here.
| In this invite | Real or fake? |
|---|---|
| The notification email from [email protected] | Real: Google delivered it |
| Google's DKIM signature | Real: it shows Google sent the email, not that the content is true |
| The organizer's identity | Fake: a school account, not Norton |
| The Norton LifeLock brand, the $499.99 charge and the invoice number | Fake |
| "Toll-Free Customer Support (U.S.)" | Fake: 805 is a California area code |
| The 24-hour deadline | Fake urgency |
None of this is new to the scam's playbook. A May 2026 PayPal calendar invite used the same $499.99 amount and nearly the same "Support (U.S.): +1 (805)" wording (DeSoto). Norton's own researchers called a number from one of these fake Norton invites and reached an agent who claimed to be McAfee support and steered them toward installing a remote-access tool (Norton).
Why Junk didn't matter
Microsoft's filter gave the invitation email a spam confidence level of 8 and filed it in Junk. That decision applied to the email only. In Outlook.com, invitations are added to the calendar as tentative events while the message is being delivered, and the Junk verdict never touches that entry. Microsoft's own description: "Outlook automatically creates a calendar entry during delivery, which remains accessible to users" (Microsoft).
Our guide to scam calendar invites explains how this works on Outlook, Google and iCloud. For this sample, the evidence is simple: the receiving server's own verdict says spam, and the event was on the calendar anyway.
The 10-minute fuse
The event was created at 16:20 UTC and set to start at 16:30 UTC. A reminder set for 10 minutes before a 16:30 event is due at 16:20, the moment the event exists. So whenever the invitation arrived, the reminder was already due and fired at once.
It doesn't matter whether that reminder came from the invitation or from the recipient's own default reminder setting. Any reminder of 10 minutes or more is overdue on arrival. The result is a phone alert showing "To cancel, contact U.S. Support" and a number, on the lock screen, before anyone has looked at an email. Other write-ups mention that these events come with reminders; we haven't seen the timing itself spelled out.
Who sent it
Google Calendar sent the email, but the event was created by an account on a Mexican school's Google Workspace domain. Its username looks like a student ID.
When we looked the domain up on October 2, 2026, it was still registered to the school, but its DNS was broken: the nameservers it points to refuse every query about it. That fits an account that has been compromised or left unmonitored better than one the scammer set up. A school that no longer has working DNS may not be watching its student accounts either. It doesn't prove how the scammer got the account. Researchers have documented compromised student accounts at schools in other countries being used for spam (Spamhaus), and a McAfee calendar lure sent from a compromised education account (IRONSCALES).
We're withholding the account and the domain. The account holder may be a student, possibly a minor, who is more likely a victim than the scammer. Scammers also rotate accounts, so publishing it wouldn't protect anyone.
The Spanish wrapper fits the same picture: an account set up in Spanish, used to send an English-language scam to people in the US.
What the authentication results say
Passing authentication is often cited as the reason these invites get through. Our sample's results were more mixed:
| Check | Result | What it means here |
|---|---|---|
| DKIM | Pass for google.com | Google signed the notification. It says nothing about who wrote the event. |
| SPF | temperror | A DNS lookup failed during the check |
| DMARC | temperror | Same: a temporary error during evaluation |
"Temporary" is misleading here. The most likely cause is the organizer's broken DNS: a check that has to look up that domain can't get an answer, and retrying won't change that. Our admin guide walks through the header details and what this pattern tells a mail administrator.
Indicators from this sample
Shared so others can search their mail. Observed September 25, 2026. Do not call the number.
Lure: Norton LifeLock "Identity Protection Service"
$499.99/yr, "Payment Status: Paid"
Invoice: NL-2026857376 (format: "NL-" + 10 digits)
Callback: +1 (805) 843-0884
labeled "Toll-Free Customer Support (U.S.)"
Event title: [credit card emoji] Automatic payment processing will
occur within the next 24 hours. To cancel, contact
U.S. Support: +1 (805) 843-0884
Timing: created 16:20 UTC, starts 16:30 UTC
Sender: [email protected]
(legitimate Google; do not block)
Auth: dkim=pass (google.com); spf=temperror; dmarc=temperror
Organizer: student-style account on a Mexican .edu.mx
Google Workspace domain (withheld)
Organizer DNS: nameservers refuse queries (checked 2026-10-02)
Wrapper: Spanish ("Invitación", "Organizador"); lure in English
Recipient: personal Outlook.com; email in Junk; event created
As of October 2, 2026, we found no public reports of this phone number or invoice number in the formats we searched. Every published sample of this scam uses a different number, so expect this one to change too. Google's sending IP addresses and calendar.google.com links aren't useful indicators; every legitimate invitation shares them.
What to do with one of these
- Found one? Follow the do-this-now checklist, then remove it and change your settings.
- Called the number? Here's what to do next.
- Looking out for a parent? Protect older relatives from fake invoice scams.
- Running email for a business? Admin controls for Microsoft 365 and Google Workspace.
Our link checker had nothing to check in this invite, and that's the point: the scam carries no link. You can see the invitation email's sender and authentication results by saving it as an .eml file and running it through the Email Analyzer. We're working on checks for the calendar-specific signals described here.