Tier · suspicious
Verdict

Treat with caution

The domain appears on one or more DNS blocklists used for spam filtering.

newsletter@c.rituals.com
At a glance
DNSBL · 1 list
Risk score
41
/ 100
suspicious
AI analyst

MalwareTips analyst · message material

legitimate

Legitimate newsletter from Rituals Cosmetics notifying subscribers about a potential data issue with membership information.

Phishing likelihood5%
Spam likelihood30%
Red flags identified
  • Screenshot shows no visible From field or subject, likely due to cropped image.
  • URIBL DNSBL hit detected on domain.
  • Visual flags claim of unauthorized data download affecting personal info.
  • Screenshot advises extra phishing vigilance and contact via email only.
  • One link uses plain HTTP to www.w3.org.
  • Email headers show future date of April [number].
What to do

This email is authenticated and from Rituals' official newsletter domain using a legitimate ESP; no action required unless you want to review their FAQ. Delete if you didn't subscribe or mark as read.

Why this verdict

Every scoring adjustment, in dominance order. Shows exactly how we got from 100 to the final trust number.

Why this verdict

skipped

This report was generated before the per-signal breakdown was available. Rescan this address to see the full score log.

Sender identity

Display name, domain reputation, and authentication checks for the From address.

Display-name impersonation

NO BRAND CLAIM

The display name doesn't resemble any of the top phished brands we track — this isn't a brand-impersonation attempt.

Brand-lookalike radar

ok

No typosquat or homoglyph match against the top 50 phished brands.

Domain age

ok

no RDAP record found

Content evidence

Signals extracted from the message body, embedded URLs, and uploaded screenshot.

Links extracted from this email

4 sites shown

Google Safe Browsing could not be checked for this scan. The links were checked against our own URL scan database, then scored on how they are built. Click Scan link for a full report on the destination.

  • click.c.rituals.com
    Host uses multiple subdomains
    Suspicion
    5
  • www.w3.org
    /TR/REC-html40
    Link uses plain HTTP, not HTTPS
    Suspicion
    5
  • image.c.rituals.com
    /lib/[token]/m/1/[token]
    Host uses multiple subdomains
    Suspicion
    5
  • www.rituals.com
    /nl-nl/faq/data/
    Suspicion
    0

Screenshot vision analysis

VISUAL · 60/100

Email claims a data breach involving Rituals membership data and personal info, underlining no immediate action needed but urging phishing awareness and email contact. Suspicious due to absent sender details and subject, though Rituals branding appears authentic.

Visual red flags
  • No From field visible
  • No subject visible
  • Claims unauthorized data download affecting personal info
  • Advises extra phishing vigilance
  • Contact via email only
  • Styled brand logo prominent
Detected logos
Rituals
Infrastructure

MX records, deliverability probe, provider classification, and DNS blocklists.

Deliverability

ok
  • RFC 5322 syntax valid
  • 1 MX record published
    reply.s50.exacttarget.com

Provider classification

ok

Not on our disposable-provider list and not a recognised consumer freemail (Gmail / Outlook / Yahoo etc.) — likely a custom domain.

DNS blocklists

ok

Listed by 1 of 3 blocklists:

URIBL
Reputation

Breach history for this address and the structural identity of the sending domain.

Breach exposure (HIBP)

ok

Skipped — the breach check was not available for this scan.

Sender infrastructure

Domain
c.rituals.com
Domain age
no RDAP record found
Provider
custom domain
MX hosts
reply.s50.exacttarget.com
This report URL contains a SHA-256 hash, while the cached report retains normalized sender components, display name when available, and derived evidence. Raw .eml and screenshot bytes are discarded after extraction. The page is noindex, but anyone with the link may be able to view it; do not submit secrets or confidential messages. If you received this email and are worried, do not click any links and do not reply — verify the sender through a known-good channel.