Treat with caution
Our AI analyst read the message body and judged it likely to be phishing.
MalwareTips analyst · message material
generic_spamThe email originates from a personal iCloud account and contains a long, obfuscated tracking link.
- Sender address uses a personal iCloud account to send what appears to be commercial or automated content.
- The URL is unusually long and uses a third-party marketing platform domain, which is common for tracking but often used to mask final destinations.
- The email lacks a clear subject line or professional branding, which is inconsistent with legitimate transactional or marketing communications.
Do not click the link provided in the email. Mark the message as spam and delete it from your inbox.
Every scoring adjustment, in dominance order. Shows exactly how we got from 100 to the final trust number.
Why this verdict
100 → 62The scorer starts every address at 100 trust and applies each signal below in turn. Negative deltas are penalties (red), positive deltas are bonuses (emerald). Final clamped trust: 62.
- AI analyst flagged 45% phishing likelihood (generic_spam).ai_phishing_detected-23
- Listed on 1 DNSBL: URIBL.dnsbl_listed-15
- AI analyst flagged 80% spam likelihood.ai_spam_detected-12
- Domain publishes strong authentication policy: DMARC p=quarantine · SPF none.auth_dns_published+7
- Sender uses a well-known free-mail provider (icloud).free_provider+5
Display name, domain reputation, and authentication checks for the From address.
Display-name impersonation
NO BRAND CLAIMThe display name doesn't resemble any of the top phished brands we track — this isn't a brand-impersonation attempt.
Brand-lookalike radar
okNo typosquat or homoglyph match against the top 50 phished brands.
Domain age
okwell-known free provider — age check skipped
Signals extracted from the message body, embedded URLs, and uploaded screenshot.
Links extracted from this email
1 shownEach link was scored against a host-level suspicion heuristic. Click Scan link to run our full URL scanner on the destination — it'll show our verdict alongside Google Safe Browsing, VirusTotal, URLhaus, and the others.
- cdn.uk.exponea.com/cardrush-prod/e/.eJwTUuCXEZ9QdWDa6lOTq-dIflrzRe_gheRjIX8uXJe_e6zvxd4EKbmMkpKCYit9_fLycr3kxKKU5KLS4gy95Pxc_Yz83FRDY1E9sYo1txytBLiYSouFuJJy8vNzi1ITkzOsuIEiuUKsqbmJmTlWykBOspCsS2KlgomCroJhcYlCQGlRckZicapCUGpuZl5KalFUgr5-Un5KpX5JYlJOqn4JhF2kX5ICEYk2jMUUxCaCpgXMTcks009MsrQwMkpKMUoyTk00NDc2STWuCQ31dLEyt0i2NE22NNI3NDS0MLawMLasMTMzTjIzMjBKTDZMNU01TcziydSX7Jiaei9aOPBPYgMTCwBIe25k.XC2tHlm3jFtkvw/clickHost uses multiple subdomainsUnusually long URLSuspicion10
MX records, deliverability probe, provider classification, and DNS blocklists.
Deliverability
ok- RFC 5322 syntax valid
- 2 MX records publishedmx01.mail.icloud.commx02.mail.icloud.com
- SMTP probe · unknown — SMTP probe disabled (set SMTP_PROBE_ENABLED=true to enable)
Provider classification
okHosted on the consumer freemail provider icloud. Not a red flag in itself — billions of legitimate users — but do verify identity through other channels for anything sensitive.
DNS blocklists
okListed by 1 of 3 blocklists:
Breach history for this address and the structural identity of the sending domain.
Breach exposure (HIBP)
okHIBP_API_KEY not configured