Treat with caution
The domain appears on one or more DNS blocklists used for spam filtering.
MalwareTips analyst · message material
legitimateLegitimate newsletter from Rituals Cosmetics notifying subscribers about a potential data issue with membership information.
- Screenshot shows no visible From field or subject, likely due to cropped image.
- URIBL DNSBL hit detected on domain.
- Visual flags claim of unauthorized data download affecting personal info.
- Screenshot advises extra phishing vigilance and contact via email only.
- One link uses plain HTTP to www.w3.org.
- Email headers show future date of April [number].
This email is authenticated and from Rituals' official newsletter domain using a legitimate ESP; no action required unless you want to review their FAQ. Delete if you didn't subscribe or mark as read.
Every scoring adjustment, in dominance order. Shows exactly how we got from 100 to the final trust number.
Why this verdict
skippedThis report was generated before the per-signal breakdown was available. Rescan this address to see the full score log.
Display name, domain reputation, and authentication checks for the From address.
Display-name impersonation
NO BRAND CLAIMThe display name doesn't resemble any of the top phished brands we track — this isn't a brand-impersonation attempt.
Brand-lookalike radar
okNo typosquat or homoglyph match against the top 50 phished brands.
Domain age
okno RDAP record found
Signals extracted from the message body, embedded URLs, and uploaded screenshot.
Links extracted from this email
4 sites shownGoogle Safe Browsing could not be checked for this scan. The links were checked against our own URL scan database, then scored on how they are built. Click Scan link for a full report on the destination.
- click.c.rituals.comHost uses multiple subdomainsSuspicion5
- www.w3.org/TR/REC-html40Link uses plain HTTP, not HTTPSSuspicion5
- image.c.rituals.com/lib/[token]/m/1/[token]Host uses multiple subdomainsSuspicion5
- www.rituals.com/nl-nl/faq/data/Suspicion0
Screenshot vision analysis
VISUAL · 60/100Email claims a data breach involving Rituals membership data and personal info, underlining no immediate action needed but urging phishing awareness and email contact. Suspicious due to absent sender details and subject, though Rituals branding appears authentic.
- No From field visible
- No subject visible
- Claims unauthorized data download affecting personal info
- Advises extra phishing vigilance
- Contact via email only
- Styled brand logo prominent
MX records, deliverability probe, provider classification, and DNS blocklists.
Deliverability
ok- RFC 5322 syntax valid
- 1 MX record publishedreply.s50.exacttarget.com
Provider classification
okNot on our disposable-provider list and not a recognised consumer freemail (Gmail / Outlook / Yahoo etc.) — likely a custom domain.
DNS blocklists
okListed by 1 of 3 blocklists:
Breach history for this address and the structural identity of the sending domain.
Breach exposure (HIBP)
okSkipped — the breach check was not available for this scan.