How it works

HelloFresh runs one of the biggest creator programs in food, usually through large agencies, and its mail comes from hellofresh.com, or hellofresh.de for Germany. Scammers register hellofresh on a different ending: hellofresh.co, hellofresh.net, or hellofresh.org. The name is spelled perfectly, so a quick glance passes. The .co swap is the workhorse because .co is one keystroke from .com and looks legitimate on its own. They send a real-looking meal-kit brief with a promo code and a tracking link, all hosted on the wrong-ending domain, and count on you not noticing that the suffix changed.

The tell-tale signals

What to do

Check the ending, not just the spelling. If the name says HelloFresh but the domain is not hellofresh.com or hellofresh.de, treat it as impersonation. A wrong ending is different from a brand that genuinely uses a country code or a .co, and a few real brands do use .co (Secretlab, for one, is on secretlab.co), so the rule is to match the sender against the brand's actual known domains, not to assume any ending is safe or unsafe on its own. Confirm through hellofresh.com's own creator or press contact, and if you already have an agency relationship, reply to that existing thread instead of the new one. Do not enter the promo code flow or click the tracking link until the domain checks out.