Tier · dangerous
Verdict

Confirmed scam — delete it

Thread Hijack Clustered

Ashley Quigley·ashleyquigley431@gmail.com
relayed viazenithengineers.com
At a glance
Unknown relayAI · 40% phishingDNSBL · 1 list
Risk score
92
/ 100
malicious
AI analyst

MalwareTips analyst · message material

generic_spam

The email uses a personal Gmail address to solicit business quotes while routing replies through a different corporate domain.

Phishing likelihood40%
Spam likelihood30%
Red flags identified
  • The sender uses a personal Gmail address to conduct business inquiries, which is inconsistent with professional communication standards.
  • There is a significant mismatch between the sender's domain and the reply-to/return-path domain, suggesting potential unauthorized use of the corporate infrastructure.
  • The domain zenithengineers.com has triggered hits on DNS blocklists, indicating a history of poor reputation or spam-related activity.
What to do

Exercise caution when replying to unsolicited business inquiries from personal email addresses. Verify the sender's identity through official channels before sharing project details.

Why this verdict

Every scoring adjustment, in dominance order. Shows exactly how we got from 100 to the final trust number.

Why this verdict

1008

The scorer starts every address at 100 trust and applies each signal below in turn. Negative deltas are penalties (red), positive deltas are bonuses (emerald). Final clamped trust: 8.

  • Multiple reply-chain channels disagree with From — likely BEC hijack (reply_to_apex_mismatch, return_path_apex_mismatch).
    thread_hijack_clustered
    -35
  • AI analyst flagged 40% phishing likelihood (generic_spam).
    ai_phishing_detected
    -20
  • Listed on 1 DNSBL: URIBL.
    dnsbl_listed
    -15
  • "via" domain zenithengineers.com is on 1 DNSBL.
    via_domain_dnsbl_listed
    -15
  • Routed "via zenithengineers.com" — an unfamiliar relay not on our ESP allowlist.
    via_domain_unrecognised
    -10
Sender identity

Display name, domain reputation, and authentication checks for the From address.

Display-name impersonation

NO BRAND CLAIM

The display name doesn't resemble any of the top phished brands we track — this isn't a brand-impersonation attempt.

Brand-lookalike radar

ok

No typosquat or homoglyph match against the top 50 phished brands.

Via-domain analysis

VIA · UNKNOWN
Apexzenithengineers.com

Not on our Email Service Provider allowlist and not obviously algorithmically generated. The relay infra is unrecognised — proceed with the same caution you'd use for an unknown sender.

Via-domain infrastructure
  • Publishes MX records
  • Listed on 1 blocklist (URIBL)
  • Registered Jul 18, 2008 · 6612 days old

Authentication results

3/3 PASS

Results extracted from the Authentication-Results header. When all three pass the message verifiably came from a server authorised to send for that domain.

SPF
pass
DKIM
pass
DMARC
pass
Reply-Toquotes@zenithengineers.com
Return-Pathquotes+bncBCP6LZ5SSEGBBFGSW7KAMGQEKOJE3SQ@zenithengineers.com

Domain age

ok

well-known free provider — age check skipped

Infrastructure

MX records, deliverability probe, provider classification, and DNS blocklists.

Deliverability

ok
  • RFC 5322 syntax valid
  • 5 MX records published
    gmail-smtp-in.l.google.comalt1.gmail-smtp-in.l.google.comalt2.gmail-smtp-in.l.google.comalt3.gmail-smtp-in.l.google.com+1 more
  • SMTP probe · unknownSMTP probe disabled (set SMTP_PROBE_ENABLED=true to enable)

Provider classification

ok

Hosted on the consumer freemail provider gmail. Not a red flag in itself — billions of legitimate users — but do verify identity through other channels for anything sensitive.

DNS blocklists

ok

Listed by 1 of 3 blocklists:

URIBL
Reputation

Breach history for this address and the structural identity of the sending domain.

Breach exposure (HIBP)

ok

HIBP_API_KEY not configured

Sender infrastructure

Domain
gmail.com
Domain age
well-known free provider — age check skipped
Provider
gmail (free)
MX hosts
gmail-smtp-in.l.google.comalt1.gmail-smtp-in.l.google.comalt2.gmail-smtp-in.l.google.comalt3.gmail-smtp-in.l.google.comalt4.gmail-smtp-in.l.google.com
This report URL contains a SHA-256 hash, while the cached report retains normalized sender components, display name when available, and derived evidence. Raw .eml and screenshot bytes are discarded after extraction. The page is noindex, but anyone with the link may be able to view it; do not submit secrets or confidential messages. If you received this email and are worried, do not click any links and do not reply — verify the sender through a known-good channel.