Confirmed scam — delete it
Thread Hijack Clustered
MalwareTips analyst · message material
generic_spamThe email uses a personal Gmail address to solicit business quotes while routing replies through a different corporate domain.
- The sender uses a personal Gmail address to conduct business inquiries, which is inconsistent with professional communication standards.
- There is a significant mismatch between the sender's domain and the reply-to/return-path domain, suggesting potential unauthorized use of the corporate infrastructure.
- The domain zenithengineers.com has triggered hits on DNS blocklists, indicating a history of poor reputation or spam-related activity.
Exercise caution when replying to unsolicited business inquiries from personal email addresses. Verify the sender's identity through official channels before sharing project details.
Every scoring adjustment, in dominance order. Shows exactly how we got from 100 to the final trust number.
Why this verdict
100 → 8The scorer starts every address at 100 trust and applies each signal below in turn. Negative deltas are penalties (red), positive deltas are bonuses (emerald). Final clamped trust: 8.
- Multiple reply-chain channels disagree with From — likely BEC hijack (reply_to_apex_mismatch, return_path_apex_mismatch).thread_hijack_clustered-35
- AI analyst flagged 40% phishing likelihood (generic_spam).ai_phishing_detected-20
- Listed on 1 DNSBL: URIBL.dnsbl_listed-15
- "via" domain zenithengineers.com is on 1 DNSBL.via_domain_dnsbl_listed-15
- Routed "via zenithengineers.com" — an unfamiliar relay not on our ESP allowlist.via_domain_unrecognised-10
Display name, domain reputation, and authentication checks for the From address.
Display-name impersonation
NO BRAND CLAIMThe display name doesn't resemble any of the top phished brands we track — this isn't a brand-impersonation attempt.
Brand-lookalike radar
okNo typosquat or homoglyph match against the top 50 phished brands.
Via-domain analysis
VIA · UNKNOWNNot on our Email Service Provider allowlist and not obviously algorithmically generated. The relay infra is unrecognised — proceed with the same caution you'd use for an unknown sender.
- Publishes MX records
- Listed on 1 blocklist (URIBL)
- Registered Jul 18, 2008 · 6612 days old
Authentication results
3/3 PASSResults extracted from the Authentication-Results header. When all three pass the message verifiably came from a server authorised to send for that domain.
Domain age
okwell-known free provider — age check skipped
MX records, deliverability probe, provider classification, and DNS blocklists.
Deliverability
ok- RFC 5322 syntax valid
- 5 MX records publishedgmail-smtp-in.l.google.comalt1.gmail-smtp-in.l.google.comalt2.gmail-smtp-in.l.google.comalt3.gmail-smtp-in.l.google.com+1 more
- SMTP probe · unknown — SMTP probe disabled (set SMTP_PROBE_ENABLED=true to enable)
Provider classification
okHosted on the consumer freemail provider gmail. Not a red flag in itself — billions of legitimate users — but do verify identity through other channels for anything sensitive.
DNS blocklists
okListed by 1 of 3 blocklists:
Breach history for this address and the structural identity of the sending domain.
Breach exposure (HIBP)
okHIBP_API_KEY not configured