I don’t know if it’s easy to contact whoever controls this - but the “Action Required” email we just received contains links that look like https://plex.tv/reset but the actual URL is more like https://links.plex.tv/s/c/long-string-of-identifiers - this lowers my confidence immediately in this being a real alert. It meets all the hallmarks of a phishing attack - an urgent request, a “click here now or you’ll be hacked!” link, where the link is to a long unidentified redirect that could easily be something untrustworthy.
(I know this one is legitimate - that’s why I came to the forums! But this is a poor practice from Plex, it is much better not to encourage users to just click on URLs in emails, especially when the link text doesn’t match the link target)
Thanks for reporting. I’ll let folks know. I think they must have forgotten to turn off the Google Analytics stuff that is appended to URLs in regular emails.