Tier · dangerous
Verdict

Almost certainly a scam

Our AI analyst read the message body and judged it likely to be phishing.

marcjacobs.pr.us@gmail.com
At a glance
AI · 85% phishingDNSBL · 1 list
Risk score
82
/ 100
malicious
AI analyst

MalwareTips analyst · message material

employment_scam

A high-profile brand partnership offer is sent from a generic Gmail address rather than an official corporate domain.

Phishing likelihood85%
Spam likelihood40%
Red flags identified
  • Uses a free Gmail address to conduct official corporate business for a major fashion brand.
  • Unsolicited business partnership outreach often used in recruitment or influencer scams.
  • Sender address structure is unprofessional and does not align with the brand's official domain.
  • Contains URIBL hits indicating the sender infrastructure is associated with known spam or malicious activity.
What to do

Do not reply to this email or provide any personal social media handles. Delete the message as it is likely a fraudulent attempt to harvest information or initiate a scam.

Why this verdict

Every scoring adjustment, in dominance order. Shows exactly how we got from 100 to the final trust number.

Why this verdict

10018

The scorer starts every address at 100 trust and applies each signal below in turn. Negative deltas are penalties (red), positive deltas are bonuses (emerald). Final clamped trust: 18.

  • AI analyst flagged 85% phishing likelihood (employment_scam).
    ai_phishing_detected
    -43
  • Screenshot OCR + visual pass flagged 85/100 phishing risk: The email uses a free Gmail address to impersonate a major fashion brand's PR department, which is a common indicator of a recruitment or partnership scam. The sender address does not match the official corporate domain of the brand.
    screenshot_phishing_visual
    -26
  • Listed on 1 DNSBL: URIBL.
    dnsbl_listed
    -15
  • AI analyst flagged 40% spam likelihood.
    ai_spam_detected
    -6
  • Sender uses a well-known free-mail provider (gmail).
    free_provider
    +5
Sender identity

Display name, domain reputation, and authentication checks for the From address.

Display-name impersonation

NO BRAND CLAIM

The display name doesn't resemble any of the top phished brands we track — this isn't a brand-impersonation attempt.

Brand-lookalike radar

ok

No typosquat or homoglyph match against the top 50 phished brands.

Domain age

ok

well-known free provider — age check skipped

Content evidence

Signals extracted from the message body, embedded URLs, and uploaded screenshot.

Screenshot vision analysis

VISUAL · 85/100

The email uses a free Gmail address to impersonate a major fashion brand's PR department, which is a common indicator of a recruitment or partnership scam. The sender address does not match the official corporate domain of the brand.

Displayed From
Marc Jacobs <marcjacobs.pr.us@gmail.com>
Subject
Marc Jacobs — Creator Partnership Opportunity
Visual red flags
  • generic public email domain used for corporate communication
  • unprofessional sender address structure
  • unsolicited business partnership outreach
Infrastructure

MX records, deliverability probe, provider classification, and DNS blocklists.

Deliverability

ok
  • RFC 5322 syntax valid
  • 5 MX records published
    gmail-smtp-in.l.google.comalt1.gmail-smtp-in.l.google.comalt2.gmail-smtp-in.l.google.comalt3.gmail-smtp-in.l.google.com+1 more
  • SMTP probe · unknownSMTP probe disabled (set SMTP_PROBE_ENABLED=true to enable)

Provider classification

ok

Hosted on the consumer freemail provider gmail. Not a red flag in itself — billions of legitimate users — but do verify identity through other channels for anything sensitive.

DNS blocklists

ok

Listed by 1 of 3 blocklists:

URIBL
Reputation

Breach history for this address and the structural identity of the sending domain.

Breach exposure (HIBP)

ok

HIBP_API_KEY not configured

Sender infrastructure

Domain
gmail.com
Domain age
well-known free provider — age check skipped
Provider
gmail (free)
MX hosts
gmail-smtp-in.l.google.comalt1.gmail-smtp-in.l.google.comalt2.gmail-smtp-in.l.google.comalt3.gmail-smtp-in.l.google.comalt4.gmail-smtp-in.l.google.com
This report URL contains a SHA-256 hash, while the cached report retains normalized sender components, display name when available, and derived evidence. Raw .eml and screenshot bytes are discarded after extraction. The page is noindex, but anyone with the link may be able to view it; do not submit secrets or confidential messages. If you received this email and are worried, do not click any links and do not reply — verify the sender through a known-good channel.