Almost certainly a scam
Our AI analyst read the message body and judged it likely to be phishing.
MalwareTips analyst · message material
invoice_scamA personal Gmail account is being used to send an unsolicited order confirmation containing a suspicious PDF attachment.
- Uses a personal Gmail address to conduct business-related order communications.
- Contains an unsolicited PDF attachment which is a common vector for malware distribution.
- Subject line uses a generic, non-standard order number format typical of automated phishing campaigns.
- Sender domain is a free provider with no alignment to any legitimate business entity.
Do not open or download the PDF attachment. Delete the email immediately to prevent potential malware infection.
Every scoring adjustment, in dominance order. Shows exactly how we got from 100 to the final trust number.
Why this verdict
100 → 18The scorer starts every address at 100 trust and applies each signal below in turn. Negative deltas are penalties (red), positive deltas are bonuses (emerald). Final clamped trust: 18.
- AI analyst flagged 85% phishing likelihood (invoice_scam).ai_phishing_detected-43
- Screenshot OCR + visual pass flagged 85/100 phishing risk: The email uses a personal Gmail address to send a transactional order confirmation, which is highly atypical for legitimate business communications. The presence of an unsolicited PDF attachment is a common vector for malware delivery.screenshot_phishing_visual-26
- Listed on 1 DNSBL: URIBL.dnsbl_listed-15
- AI analyst flagged 40% spam likelihood.ai_spam_detected-6
- Sender uses a well-known free-mail provider (gmail).free_provider+5
Display name, domain reputation, and authentication checks for the From address.
Display-name impersonation
NO BRAND CLAIMThe display name doesn't resemble any of the top phished brands we track — this isn't a brand-impersonation attempt.
Brand-lookalike radar
okNo typosquat or homoglyph match against the top 50 phished brands.
Domain age
okwell-known free provider — age check skipped
Signals extracted from the message body, embedded URLs, and uploaded screenshot.
Screenshot vision analysis
VISUAL · 85/100The email uses a personal Gmail address to send a transactional order confirmation, which is highly atypical for legitimate business communications. The presence of an unsolicited PDF attachment is a common vector for malware delivery.
- personal email address used for business order
- suspicious PDF attachment
- generic order number in subject line
MX records, deliverability probe, provider classification, and DNS blocklists.
Deliverability
ok- RFC 5322 syntax valid
- 5 MX records publishedgmail-smtp-in.l.google.comalt1.gmail-smtp-in.l.google.comalt2.gmail-smtp-in.l.google.comalt3.gmail-smtp-in.l.google.com+1 more
- SMTP probe · unknown — SMTP probe disabled (set SMTP_PROBE_ENABLED=true to enable)
Provider classification
okHosted on the consumer freemail provider gmail. Not a red flag in itself — billions of legitimate users — but do verify identity through other channels for anything sensitive.
DNS blocklists
okListed by 1 of 3 blocklists:
Breach history for this address and the structural identity of the sending domain.
Breach exposure (HIBP)
okHIBP_API_KEY not configured