Confirmed scam — delete it
The domain doesn't publish MX records, so mail to this address can't be delivered.
MalwareTips analyst · message material
credential_theftThis email uses high-pressure tactics and threats of data deletion to coerce the recipient into updating payment details.
- Uses extreme urgency by threatening permanent data deletion within 24 hours.
- Employs a generic cloud storage brand impersonation to solicit sensitive billing information.
- The sender domain is unrelated to any major cloud service provider.
- Contains multiple high-severity signals related to credential and financial data harvesting.
- The infrastructure shows DNSBL hits, indicating a poor reputation for the sending domain.
Do not click any links or provide payment information. Delete the email immediately.
Every scoring adjustment, in dominance order. Shows exactly how we got from 100 to the final trust number.
Why this verdict
100 → 0The scorer starts every address at 100 trust and applies each signal below in turn. Negative deltas are penalties (red), positive deltas are bonuses (emerald). Final clamped trust: 0.
- No MX records at all — the domain can't legitimately send mail.no_mx_records-55
- AI analyst flagged 95% phishing likelihood (credential_theft).ai_phishing_detected-48
- Message body triggered 2 rule-based red-flag categories (credential-harvest / urgency / attachment-bait / money-movement / etc.).body_red_flags-23
- Listed on 1 DNSBL: URIBL.dnsbl_listed-15
- AI analyst flagged 80% spam likelihood.ai_spam_detected-12
Display name, domain reputation, and authentication checks for the From address.
Display-name impersonation
NO BRAND CLAIMThe display name doesn't resemble any of the top phished brands we track — this isn't a brand-impersonation attempt.
Brand-lookalike radar
okNo typosquat or homoglyph match against the top 50 phished brands.
Domain age
errorRDAP check did not run.
Signals extracted from the message body, embedded URLs, and uploaded screenshot.
Phishing-pattern signals
2 signalsRule-based pattern matches we ran across the message body and OCR text BEFORE the AI analyst. Each is a hint, not a verdict.
- Asks you to confirm, verify, or re-enter credentialshigh“248.9 GB / 250 GB Please update your billing details to keep your storage”
- Uses urgency or time pressuremedium“pgrade your plan at any time. Immediate action required: your data will be d”
MX records, deliverability probe, provider classification, and DNS blocklists.
Deliverability
ok- RFC 5322 syntax valid
- No MX or A/AAAA records found.
- SMTP probe · unknown — SMTP probe disabled (set SMTP_PROBE_ENABLED=true to enable)
Provider classification
okNot on our disposable-provider list and not a recognised consumer freemail (Gmail / Outlook / Yahoo etc.) — likely a custom domain.
DNS blocklists
okListed by 1 of 3 blocklists:
Breach history for this address and the structural identity of the sending domain.
Breach exposure (HIBP)
okHIBP_API_KEY not configured