Tier · dangerous
Verdict

Confirmed scam — delete it

The domain doesn't publish MX records, so mail to this address can't be delivered.

paypalsupportassitnow@assit.com
At a glance
AI · 95% phishingDNSBL · 1 list
Risk score
100
/ 100
malicious
AI analyst

MalwareTips analyst · message material

tech_support_scam

This email uses a fake support address and urgent threats of account termination to solicit contact via a suspicious phone number.

Phishing likelihood95%
Spam likelihood20%
Red flags identified
  • Uses a non-official sender domain that does not belong to PayPal.
  • Employs high-pressure tactics by threatening account termination within 24 hours.
  • Contains significant grammatical errors and typos inconsistent with official corporate communications.
  • Directs the user to call an unverified phone number rather than using official support channels.
  • Fails all email authentication checks including SPF and DMARC.
What to do

Do not call the provided phone number or reply to the email. Delete the message immediately and report it to your email provider.

Why this verdict

Every scoring adjustment, in dominance order. Shows exactly how we got from 100 to the final trust number.

Why this verdict

1000

The scorer starts every address at 100 trust and applies each signal below in turn. Negative deltas are penalties (red), positive deltas are bonuses (emerald). Final clamped trust: 0.

  • No MX records at all — the domain can't legitimately send mail.
    no_mx_records
    -55
  • AI analyst flagged 95% phishing likelihood (tech_support_scam).
    ai_phishing_detected
    -48
  • Listed on 1 DNSBL: URIBL.
    dnsbl_listed
    -15
  • Message body triggered 1 rule-based red-flag category (credential-harvest / urgency / attachment-bait / money-movement / etc.).
    body_red_flags
    -8
  • Domain publishes strong authentication policy: no DMARC published · SPF hard-fail.
    auth_dns_published
    +4
Sender identity

Display name, domain reputation, and authentication checks for the From address.

Display-name impersonation

NO BRAND CLAIM

The display name doesn't resemble any of the top phished brands we track — this isn't a brand-impersonation attempt.

Brand-lookalike radar

ok

No typosquat or homoglyph match against the top 50 phished brands.

Domain age

error

RDAP check did not run.

Content evidence

Signals extracted from the message body, embedded URLs, and uploaded screenshot.

Phishing-pattern signals

1 signal

Rule-based pattern matches we ran across the message body and OCR text BEFORE the AI analyst. Each is a hint, not a verdict.

  • Uses urgency or time pressuremedium
    send to. After 24 hours your account will be terminated Need help ? Support at Paypa
Infrastructure

MX records, deliverability probe, provider classification, and DNS blocklists.

Deliverability

ok
  • RFC 5322 syntax valid
  • No MX or A/AAAA records found.
    (implicit A record)
  • SMTP probe · unknownSMTP probe disabled (set SMTP_PROBE_ENABLED=true to enable)

Provider classification

ok

Not on our disposable-provider list and not a recognised consumer freemail (Gmail / Outlook / Yahoo etc.) — likely a custom domain.

DNS blocklists

ok

Listed by 1 of 3 blocklists:

URIBL
Reputation

Breach history for this address and the structural identity of the sending domain.

Breach exposure (HIBP)

ok

HIBP_API_KEY not configured

Sender infrastructure

Domain
assit.com
Domain age
Unknown
Provider
custom domain
MX hosts
(implicit A record)
This report URL contains a SHA-256 hash, while the cached report retains normalized sender components, display name when available, and derived evidence. Raw .eml and screenshot bytes are discarded after extraction. The page is noindex, but anyone with the link may be able to view it; do not submit secrets or confidential messages. If you received this email and are worried, do not click any links and do not reply — verify the sender through a known-good channel.