Tier · safe
Verdict

Safe to trust

The domain appears on one or more DNS blocklists used for spam filtering.

Kory Ball·kory.ball@quickstart.com
At a glance
DNSBL · 1 list
Risk score
20
/ 100
safe
AI analyst

MalwareTips analyst · message material

legitimate

This email from a legitimate educational partner requests a registration deposit for a bootcamp program.

Phishing likelihood20%
Spam likelihood30%
Red flags identified
  • The sender domain is associated with a URIBL DNSBL hit, suggesting potential reputation issues with the mail server.
  • The message ID apex does not match the sender domain, which is a minor technical inconsistency.
  • The email requests a financial transaction for a registration deposit, which requires careful verification of the payment link.
What to do

Verify the payment link by navigating directly to the official University of Florida or QuickStart website rather than clicking links in the email. Contact the admissions office through a verified phone number if you have concerns about the payment request.

Why this verdict

Every scoring adjustment, in dominance order. Shows exactly how we got from 100 to the final trust number.

Why this verdict

10080

The scorer starts every address at 100 trust and applies each signal below in turn. Negative deltas are penalties (red), positive deltas are bonuses (emerald). Final clamped trust: 80.

  • Listed on 1 DNSBL: URIBL.
    dnsbl_listed
    -15
  • Domain publishes strong authentication policy: DMARC p=reject · SPF hard-fail.
    dmarc_reject_enforced
    +15
  • AI analyst flagged 20% phishing likelihood (legitimate).
    ai_phishing_detected
    -10
  • Message-ID is stamped with "outlook.com" rather than "quickstart.com" — the message was assembled on a server that doesn't belong to the claimed sender.
    message_id_apex_mismatch
    -5
  • AI analyst flagged 30% spam likelihood.
    ai_spam_detected
    -5
Sender identity

Display name, domain reputation, and authentication checks for the From address.

Display-name impersonation

NO BRAND CLAIM

The display name doesn't resemble any of the top phished brands we track — this isn't a brand-impersonation attempt.

Brand-lookalike radar

ok

No typosquat or homoglyph match against the top 50 phished brands.

Authentication results

3/3 PASS

Results extracted from the Authentication-Results header. When all three pass the message verifiably came from a server authorised to send for that domain.

SPF
pass
DKIM
pass
DMARC
pass
Return-PathKory.Ball@quickstart.com

Domain age

error

RDAP check did not run.

Infrastructure

MX records, deliverability probe, provider classification, and DNS blocklists.

Deliverability

ok
  • RFC 5322 syntax valid
  • 1 MX record published
    quickstart-com.mail.protection.outlook.com
  • SMTP probe · unknownSMTP probe disabled (set SMTP_PROBE_ENABLED=true to enable)

Provider classification

ok

Not on our disposable-provider list and not a recognised consumer freemail (Gmail / Outlook / Yahoo etc.) — likely a custom domain.

DNS blocklists

ok

Listed by 1 of 3 blocklists:

URIBL
Reputation

Breach history for this address and the structural identity of the sending domain.

Breach exposure (HIBP)

ok

HIBP_API_KEY not configured

Sender infrastructure

Domain
quickstart.com
Domain age
Unknown
Provider
custom domain
MX hosts
quickstart-com.mail.protection.outlook.com
This report URL contains a SHA-256 hash, while the cached report retains normalized sender components, display name when available, and derived evidence. Raw .eml and screenshot bytes are discarded after extraction. The page is noindex, but anyone with the link may be able to view it; do not submit secrets or confidential messages. If you received this email and are worried, do not click any links and do not reply — verify the sender through a known-good channel.