Tier · dangerous
Verdict

Likely scam — do not engage

Our AI analyst read the message body and judged it likely to be phishing.

christinedelacruz@rubixcare.co.uk
At a glance
AI · 65% phishingDNSBL · 1 list
Risk score
69
/ 100
malicious
AI analyst

MalwareTips analyst · message material

employment_scam

This unsolicited interview invitation from an unknown sender uses a Google Calendar invite to bypass traditional email filters.

Phishing likelihood65%
Spam likelihood40%
Red flags identified
  • The email originates from an unknown sender who has not previously interacted with the recipient.
  • The guest list includes a personal Gmail address alongside professional corporate accounts, a common tactic in social engineering.
  • The platform displays a native security warning indicating the sender is not in the recipient's contacts.
  • The invitation is unsolicited and lacks context regarding a prior job application or professional connection.
What to do

Do not accept the calendar invitation or join the meeting link. Mark the email as spam and delete it from your calendar.

Why this verdict

Every scoring adjustment, in dominance order. Shows exactly how we got from 100 to the final trust number.

Why this verdict

10031

The scorer starts every address at 100 trust and applies each signal below in turn. Negative deltas are penalties (red), positive deltas are bonuses (emerald). Final clamped trust: 31.

  • AI analyst flagged 65% phishing likelihood (employment_scam).
    ai_phishing_detected
    -33
  • Screenshot OCR + visual pass flagged 65/100 phishing risk: The email is a Google Calendar invitation from an unknown sender, which triggers a native security warning from the platform. The inclusion of a personal Gmail address alongside professional corporate email addresses in the guest list is a common indicator of potential social engineering.
    screenshot_phishing_visual
    -20
  • Listed on 1 DNSBL: URIBL.
    dnsbl_listed
    -15
  • AI analyst flagged 40% spam likelihood.
    ai_spam_detected
    -6
  • Domain publishes strong authentication policy: DMARC p=none · SPF soft-fail.
    auth_dns_published
    +5
Sender identity

Display name, domain reputation, and authentication checks for the From address.

Display-name impersonation

NO BRAND CLAIM

The display name doesn't resemble any of the top phished brands we track — this isn't a brand-impersonation attempt.

Brand-lookalike radar

ok

No typosquat or homoglyph match against the top 50 phished brands.

Domain age

timeout

RDAP check did not run.

Content evidence

Signals extracted from the message body, embedded URLs, and uploaded screenshot.

Links extracted from this email

1 shown

Each link was scored against a host-level suspicion heuristic. Click Scan link to run our full URL scanner on the destination — it'll show our verdict alongside Google Safe Browsing, VirusTotal, URLhaus, and the others.

  • meet.google.com
    /eyy-iwqz-unv
    Suspicion
    0

Screenshot vision analysis

VISUAL · 65/100

The email is a Google Calendar invitation from an unknown sender, which triggers a native security warning from the platform. The inclusion of a personal Gmail address alongside professional corporate email addresses in the guest list is a common indicator of potential social engineering.

Displayed From
Christine Dela Cruz <christinedelacruz@rubixcare.co.uk> via google.com
Subject
Invitation from an unknown sender: Compliance Admin Interview @ Mon Jul 27, 2026 7pm - 7:30pm (GMT+8) (zabatemichelleann98@gmail.com)
Visual red flags
  • Unknown sender warning banner
  • Unsolicited interview invitation
  • Mismatch between professional domain and personal guest email
Detected logos
Google CalendarGoogle Meet
Visible URLs in screenshot
  • https://meet.google.com/eyy-iwqz-unv
Infrastructure

MX records, deliverability probe, provider classification, and DNS blocklists.

Deliverability

ok
  • RFC 5322 syntax valid
  • 3 MX records published
    smtp.google.comalt4.aspmx.l.google.comalt3.aspmx.l.google.com
  • SMTP probe · unknownSMTP probe disabled (set SMTP_PROBE_ENABLED=true to enable)

Provider classification

ok

Not on our disposable-provider list and not a recognised consumer freemail (Gmail / Outlook / Yahoo etc.) — likely a custom domain.

DNS blocklists

ok

Listed by 1 of 3 blocklists:

URIBL
Reputation

Breach history for this address and the structural identity of the sending domain.

Breach exposure (HIBP)

ok

HIBP_API_KEY not configured

Sender infrastructure

Domain
rubixcare.co.uk
Domain age
Unknown
Provider
custom domain
MX hosts
smtp.google.comalt4.aspmx.l.google.comalt3.aspmx.l.google.com
This report URL contains a SHA-256 hash, while the cached report retains normalized sender components, display name when available, and derived evidence. Raw .eml and screenshot bytes are discarded after extraction. The page is noindex, but anyone with the link may be able to view it; do not submit secrets or confidential messages. If you received this email and are worried, do not click any links and do not reply — verify the sender through a known-good channel.