Likely scam — do not engage
Our AI analyst read the message body and judged it likely to be phishing.
MalwareTips analyst · message material
generic_spamThis unsolicited event invitation uses generic greetings and lacks verifiable contact details, posing a potential risk for data collection.
- Uses a generic, impersonal greeting to address the recipient.
- Lacks verifiable sender contact information or official corporate branding.
- Employs high-pressure scarcity tactics by limiting seats to two per company.
- The sender domain shows URIBL hits, indicating potential reputation issues.
Do not click on the registration links or provide personal information. Delete the email and avoid interacting with the sender.
Every scoring adjustment, in dominance order. Shows exactly how we got from 100 to the final trust number.
Why this verdict
100 → 35The scorer starts every address at 100 trust and applies each signal below in turn. Negative deltas are penalties (red), positive deltas are bonuses (emerald). Final clamped trust: 35.
- AI analyst flagged 45% phishing likelihood (generic_spam).ai_phishing_detected-23
- Screenshot OCR + visual pass flagged 65/100 phishing risk: The email uses a generic greeting and lacks any verifiable sender contact information or official branding. The combination of a vague invitation and a call to action for registration creates a potential risk for credential harvesting.screenshot_phishing_visual-20
- Listed on 1 DNSBL: URIBL.dnsbl_listed-15
- AI analyst flagged 70% spam likelihood.ai_spam_detected-11
- Domain publishes strong authentication policy: DMARC p=none · SPF hard-fail.auth_dns_published+7
Display name, domain reputation, and authentication checks for the From address.
Display-name impersonation
NO BRAND CLAIMThe display name doesn't resemble any of the top phished brands we track — this isn't a brand-impersonation attempt.
Brand-lookalike radar
okNo typosquat or homoglyph match against the top 50 phished brands.
Domain age
errorRDAP check did not run.
Signals extracted from the message body, embedded URLs, and uploaded screenshot.
Phishing-pattern signals
1 signalRule-based pattern matches we ran across the message body and OCR text BEFORE the AI analyst. Each is a hint, not a verdict.
- Uses a generic, impersonal greetinglow“he Gardens Mall Register Now Dear Customer, SL Info would like to invit”
Screenshot vision analysis
VISUAL · 65/100The email uses a generic greeting and lacks any verifiable sender contact information or official branding. The combination of a vague invitation and a call to action for registration creates a potential risk for credential harvesting.
- generic greeting
- lack of sender identification
- unverifiable event details
- high-pressure scarcity tactic
MX records, deliverability probe, provider classification, and DNS blocklists.
Deliverability
ok- RFC 5322 syntax valid
- 1 MX record publishedslinfo-com-my.mail.protection.outlook.com
- SMTP probe · unknown — SMTP probe disabled (set SMTP_PROBE_ENABLED=true to enable)
Provider classification
okNot on our disposable-provider list and not a recognised consumer freemail (Gmail / Outlook / Yahoo etc.) — likely a custom domain.
DNS blocklists
okListed by 1 of 3 blocklists:
Breach history for this address and the structural identity of the sending domain.
Breach exposure (HIBP)
okHIBP_API_KEY not configured