Treat with caution
Our AI analyst read the message body and judged it likely to be phishing.
MalwareTips analyst · message material
credential_theftAn email from a government domain requests the opening of an attachment using a provided passcode.
- The email requests the recipient to open an attachment protected by a passcode, a common tactic to bypass email security scanners.
- The message lacks specific context or a clear reason for the attachment, which is characteristic of unsolicited document-based lures.
- The sender's domain shows a DMARC policy of 'none', providing no protection against domain spoofing.
Do not open the attachment or enter the provided passcode. Delete the email immediately as it may contain malicious software.
Every scoring adjustment, in dominance order. Shows exactly how we got from 100 to the final trust number.
Why this verdict
100 → 72The scorer starts every address at 100 trust and applies each signal below in turn. Negative deltas are penalties (red), positive deltas are bonuses (emerald). Final clamped trust: 72.
- AI analyst flagged 65% phishing likelihood (credential_theft).ai_phishing_detected-33
- Domain publishes strong authentication policy: DMARC p=none · SPF soft-fail.auth_dns_published+5
- Clean across 3 DNSBLs checked.dnsbl_clean+3
- AI analyst flagged 20% spam likelihood.ai_spam_detected-3
Display name, domain reputation, and authentication checks for the From address.
Display-name impersonation
NO BRAND CLAIMThe display name doesn't resemble any of the top phished brands we track — this isn't a brand-impersonation attempt.
Brand-lookalike radar
okNo typosquat or homoglyph match against the top 50 phished brands.
Domain age
timeoutRDAP check did not run.
MX records, deliverability probe, provider classification, and DNS blocklists.
Deliverability
ok- RFC 5322 syntax valid
- 1 MX record publishedlavergnetn-gov.snwlhosted.com
- SMTP probe · unknown — SMTP probe disabled (set SMTP_PROBE_ENABLED=true to enable)
Provider classification
okNot on our disposable-provider list and not a recognised consumer freemail (Gmail / Outlook / Yahoo etc.) — likely a custom domain.
DNS blocklists
okClean across all 3 blocklists checked (SURBL, Spamhaus DBL, URIBL).
Breach history for this address and the structural identity of the sending domain.
Breach exposure (HIBP)
okHIBP_API_KEY not configured