Tier · dangerous
Verdict

Confirmed scam — delete it

This email uses a fake account maintenance fee threat to pressure the recipient into clicking a link to their Microsoft Cashback account.

Subject·Action required: Avoid monthly fees on your Microsoft Cashback balance
Body-only scan — sender identity and infrastructure checks are unavailable.Re-scan with sender
At a glance
AI · 85% phishingCredential Theft4 red flags
Risk score
100
/ 100
malicious
AI analyst

MalwareTips analyst · message material

credential_theft

This email uses a fake account maintenance fee threat to pressure the recipient into clicking a link to their Microsoft Cashback account.

Phishing likelihood85%
Spam likelihood20%
Red flags identified
  • Uses a fabricated account maintenance fee to create artificial urgency and fear of financial loss.
  • Includes highly irregular and unprofessional header content like 'Alarm Clock' which is inconsistent with official corporate communications.
  • Employs a generic threat of recurring monthly charges to coerce the user into interacting with the provided link.
  • Lacks transparent sender authentication and uses a suspicious display name format.
What to do

Do not click any links or attempt to sign in through this email. Delete the message immediately and navigate to the official Microsoft website directly if you have concerns about your account.

Why this verdict

Every scoring adjustment, in dominance order. Shows exactly how we got from 100 to the final trust number.

Why this verdict

1000

The scorer starts every address at 100 trust and applies each signal below in turn. Negative deltas are penalties (red), positive deltas are bonuses (emerald). Final clamped trust: 0.

  • The pasted address doesn't parse as a valid RFC-5322 email address.
    syntax_invalid
    -100
Screenshot analysis

Screenshot vision analysis

VISUAL · 75/100

The email uses a generic threat of account maintenance fees to create urgency and prompt a login. The inclusion of 'Alarm Clock' as a header is highly irregular for official corporate correspondence.

Displayed From
Microsoft Cashback
Visual red flags
  • unusual subject line content
  • generic account maintenance threat
  • lack of sender address transparency
Detected logos
Microsoft
Unlock more checks

Paste the sender to unlock identity + infrastructure analysis

This scan analysed the message body only. Adding the sender address, a Gmail Name <a@b.com> line, or full headers unlocks:

  • Display-name impersonation
    Spot mismatched names like "PayPal Support" on a random Gmail.
  • SPF · DKIM · DMARC
    See whether the sending server is authorised to use that domain.
  • Domain age + registrar
    Brand-new domains are one of the strongest phish signals.
  • Breach exposure
    How many known data breaches this specific address appears in.
  • MX + DNSBL reputation
    Whether the domain can even receive mail and if it's on any blocklists.
Add sender and re-scan

Your previous paste won't be sent — you'll start a fresh scan with both fields.

This report URL contains a SHA-256 hash, while the cached report retains normalized sender components, display name when available, and derived evidence. Raw .eml and screenshot bytes are discarded after extraction. The page is noindex, but anyone with the link may be able to view it; do not submit secrets or confidential messages. If you received this email and are worried, do not click any links and do not reply — verify the sender through a known-good channel.