Tier · dangerous
Verdict

Almost certainly a scam

Our AI analyst read the message body and judged it likely to be phishing.

recruitment@onlyupagency.net
At a glance
AI · 85% phishingDNSBL · 1 list
Risk score
85
/ 100
malicious
AI analyst

MalwareTips analyst · message material

employment_scam

This unsolicited job offer for an adult-themed chat role uses high-pressure financial incentives and exhibits domain-mismatch indicators.

Phishing likelihood85%
Spam likelihood60%
Red flags identified
  • The sender domain onlyupagency.net does not match the company name OU Social Scaling LLC mentioned in the signature.
  • The email uses a generic greeting and lacks specific details about the recipient's previous application or CV submission.
  • The offer promises high commission-based earnings for adult-themed chat roles, a common pattern in recruitment scams.
  • The domain has triggered hits on DNSBL blacklists, suggesting a poor reputation for the sending infrastructure.
What to do

Do not click any links or provide personal information. Mark the email as junk and delete it immediately.

Why this verdict

Every scoring adjustment, in dominance order. Shows exactly how we got from 100 to the final trust number.

Why this verdict

10015

The scorer starts every address at 100 trust and applies each signal below in turn. Negative deltas are penalties (red), positive deltas are bonuses (emerald). Final clamped trust: 15.

  • AI analyst flagged 85% phishing likelihood (employment_scam).
    ai_phishing_detected
    -43
  • Screenshot OCR + visual pass flagged 75/100 phishing risk: The email exhibits characteristics of a common recruitment scam, specifically targeting individuals for adult-themed chat roles with promises of high commission. The sender domain does not match the company name mentioned in the signature, which is a significant indicator of potential fraud.
    screenshot_phishing_visual
    -23
  • Listed on 1 DNSBL: URIBL.
    dnsbl_listed
    -15
  • AI analyst flagged 60% spam likelihood.
    ai_spam_detected
    -9
  • Domain publishes strong authentication policy: DMARC p=none · SPF soft-fail.
    auth_dns_published
    +5
Sender identity

Display name, domain reputation, and authentication checks for the From address.

Display-name impersonation

NO BRAND CLAIM

The display name doesn't resemble any of the top phished brands we track — this isn't a brand-impersonation attempt.

Brand-lookalike radar

ok

No typosquat or homoglyph match against the top 50 phished brands.

Domain age

timeout

RDAP check did not run.

Content evidence

Signals extracted from the message body, embedded URLs, and uploaded screenshot.

Screenshot vision analysis

VISUAL · 75/100

The email exhibits characteristics of a common recruitment scam, specifically targeting individuals for adult-themed chat roles with promises of high commission. The sender domain does not match the company name mentioned in the signature, which is a significant indicator of potential fraud.

Displayed From
OUA Recruitment <recruitment@onlyupagency.net>
Subject
Chatter Position - Application Invitation
Visual red flags
  • unsolicited job offer
  • generic greeting
  • high-pressure financial incentives
  • recruitment for adult-themed chat roles
Infrastructure

MX records, deliverability probe, provider classification, and DNS blocklists.

Deliverability

ok
  • RFC 5322 syntax valid
  • 5 MX records published
    aspmx.l.google.comalt2.aspmx.l.google.comalt1.aspmx.l.google.comalt3.aspmx.l.google.com+1 more
  • SMTP probe · unknownSMTP probe disabled (set SMTP_PROBE_ENABLED=true to enable)

Provider classification

ok

Not on our disposable-provider list and not a recognised consumer freemail (Gmail / Outlook / Yahoo etc.) — likely a custom domain.

DNS blocklists

ok

Listed by 1 of 3 blocklists:

URIBL
Reputation

Breach history for this address and the structural identity of the sending domain.

Breach exposure (HIBP)

ok

HIBP_API_KEY not configured

Sender infrastructure

Domain
onlyupagency.net
Domain age
Unknown
Provider
custom domain
MX hosts
aspmx.l.google.comalt2.aspmx.l.google.comalt1.aspmx.l.google.comalt3.aspmx.l.google.comalt4.aspmx.l.google.com
This report URL contains a SHA-256 hash, while the cached report retains normalized sender components, display name when available, and derived evidence. Raw .eml and screenshot bytes are discarded after extraction. The page is noindex, but anyone with the link may be able to view it; do not submit secrets or confidential messages. If you received this email and are worried, do not click any links and do not reply — verify the sender through a known-good channel.