Arrival cards and travel visas attract fraud because travellers are in a hurry, abroad, and unfamiliar with the rules. This page tells you how the scams work, how to check that you are really dealing with us, and what to do if you have already paid someone you shouldn't have.
Already paid someone suspicious? Skip straight to what to do next →
The 20-second check
Four out of four, and you are almost certainly where you meant to be. One miss is enough reason to stop and check.
myarrival.com
Our only domain
Itemised
Every fee named before you pay
Never
We ask for your password
One inbox
info@myarrival.com
Fraudulent travel-document sites are convincing, well designed, and often advertised right next to the real thing. They still give themselves away.
No government and no legitimate agent asks for a bank transfer, cryptocurrency, or a gift-card code for an arrival card. Those payments are gone the moment you send them — there is nothing for a bank to reverse.
A travel service handling passport data should be reachable at its own domain. If the only contact address is a gmail.com or outlook.com account, nobody has verified that the person behind it controls the website at all.
A stranger on WhatsApp, Telegram, Facebook or Instagram offering to sort your arrival card is not an agent. We never start a conversation with you on a messaging app, and neither does any immigration department.
Any honest service can name every line in its price before you pay — the destination's own charge, the processing fee, anything optional you picked. A single unexplained number usually hides a large markup, or a fee going nowhere at all.
"Your arrival card is pending — pay now to release it." If you did not apply, there is nothing pending. Never pay from a link in a message you did not expect, however official the logo looks.
my-arrival.org, myarrivals.com, myarrival-card.net — clone sites copy the design pixel for pixel and change one character in the address. Read the domain left to right before you type anything into a form.
Nobody legitimate needs your account password, your full card number in an email, or a screen-sharing session to "complete" an application. Support that asks for any of the three is not support.
We are an independent service, and we say so on our homepage, in our help centre and on our disclaimer page. A commercial site that presents itself as an immigration department is lying about the one thing that matters most.
Do not take a website's word for who it is — including ours. Every item below is something you can confirm yourself, right now.
Our only website is myarrival.com. Not a lookalike, not a sub-brand, not a "partner portal". If the domain is anything else, close the tab — even if the page is an exact copy of this one.
Every page here is served over HTTPS, so your details are encrypted in transit. But a padlock on its own proves nothing: scam sites get certificates too. Click it and confirm the certificate was issued to myarrival.com.
Our email always comes from an address ending in myarrival.com. We have no SMS and no phone channel at all, so a text or a call claiming to be us is not us. When you create an account we email you a generated password — that mail is genuine, and it is the only password we will ever send you.
Every MyArrival order looks like MYR-2026-XXXXXX. If someone quotes you a reference in another format and says it is ours, it is not.
Our registered company name and postal address are printed in the footer of our public pages and on every invoice we send. Compare the two — they should match. A site that will not tell you who is behind it is telling you something.
Knowing what we will never do is more useful than knowing what we will. Anything in the right-hand column is an impostor, full stop.
Seen any of these under our name? Tell us — we want the URL.
It happens to careful people. Speed matters more than anything else here — work down this list today, in order.
Do not send a further payment to "release" or "verify" the first one — that is the same scam repeating. Do not click any remaining links in the message.
Do this first, and do it today. Card payments to a fraudulent merchant can often be blocked or charged back, but the window is measured in days. Use the number on the back of your card, never a number from the suspicious message.
If you created an account on the fake site with a password you use elsewhere, change it everywhere you use it, starting with your email account.
Screenshot the site and the full URL, save the emails (with headers if you can), and note the payment reference and amount. Your bank and the police will both ask.
Report to your own country's fraud or cybercrime body — IC3 in the United States, Action Fraud in the United Kingdom, the national police elsewhere. If you handed over passport details, tell your passport-issuing authority as well: that data is worth more to a criminal than the fee they took.
Send us the URL and we will pursue a takedown with the registrar and the browser safe-browsing lists. It costs you a minute and it protects the next traveller.
Fake arrival-card sites are often after identity data rather than the fee. If you gave a scam site your passport number, date of birth and full name, treat that as a data breach: tell your passport-issuing authority, watch for credit applications you did not make, and be sceptical of any follow-up message that already knows your travel details — that is the same criminal using what you gave them.
A suspicious email in our name, a clone of this site, an "agent" quoting our brand — we would rather hear about ten false alarms than miss one real one. Include the URL or forward the message in full.