Treat with caution
Screenshot Phishing Visual
MalwareTips analyst · message material
legitimateThis is a legitimate Google security notification sent to an incorrect recovery email address.
- The email is addressed to a different user account than the recipient's own email address.
- The notification is unsolicited as the recipient did not initiate a recovery request for the mentioned account.
- The presence of a recovery link for an account the recipient does not own could be used for account takeover attempts if the recipient interacts with it.
Do not click any links in the email. If you do not own the account mentioned, simply delete the message.
Every scoring adjustment, in dominance order. Shows exactly how we got from 100 to the final trust number.
Why this verdict
100 → 64The scorer starts every address at 100 trust and applies each signal below in turn. Negative deltas are penalties (red), positive deltas are bonuses (emerald). Final clamped trust: 64.
- Screenshot OCR + visual pass flagged 85/100 phishing risk: The email appears to be a legitimate automated security notification from Google, but it is addressed to a user (beatris@seznam.cz) regarding a completely different Google account (beuseee10@gmail.com). This indicates the recipient's email address has been incorrectly linked to a stranger's account, likely as a recovery address.screenshot_phishing_visual-26
- Listed on 1 DNSBL: URIBL.dnsbl_listed-15
- Domain publishes strong authentication policy: DMARC p=reject · SPF soft-fail.dmarc_reject_enforced+13
- AI analyst flagged 10% phishing likelihood (legitimate).ai_phishing_detected-5
- AI analyst flagged 20% spam likelihood.ai_spam_detected-3
Display name, domain reputation, and authentication checks for the From address.
Display-name impersonation
NO BRAND CLAIMThe display name doesn't resemble any of the top phished brands we track — this isn't a brand-impersonation attempt.
Brand-lookalike radar
okNo typosquat or homoglyph match against the top 50 phished brands.
Domain age
errorRDAP check did not run.
Signals extracted from the message body, embedded URLs, and uploaded screenshot.
Screenshot vision analysis
VISUAL · 85/100The email appears to be a legitimate automated security notification from Google, but it is addressed to a user (beatris@seznam.cz) regarding a completely different Google account (beuseee10@gmail.com). This indicates the recipient's email address has been incorrectly linked to a stranger's account, likely as a recovery address.
- mismatched recipient email address
- unsolicited security code request
MX records, deliverability probe, provider classification, and DNS blocklists.
Deliverability
ok- RFC 5322 syntax valid
- 1 MX record publishedsmtp.google.com
- SMTP probe · unknown — SMTP probe disabled (set SMTP_PROBE_ENABLED=true to enable)
Provider classification
okNot on our disposable-provider list and not a recognised consumer freemail (Gmail / Outlook / Yahoo etc.) — likely a custom domain.
DNS blocklists
okListed by 1 of 3 blocklists:
Breach history for this address and the structural identity of the sending domain.
Breach exposure (HIBP)
okHIBP_API_KEY not configured