Confirmed scam — delete it
This email uses a fake account maintenance fee threat to pressure the recipient into clicking a link to their Microsoft Cashback account.
MalwareTips analyst · message material
credential_theftThis email uses a fake account maintenance fee threat to pressure the recipient into clicking a link to their Microsoft Cashback account.
- Uses a fabricated account maintenance fee to create artificial urgency and fear of financial loss.
- Includes highly irregular and unprofessional header content like 'Alarm Clock' which is inconsistent with official corporate communications.
- Employs a generic threat of recurring monthly charges to coerce the user into interacting with the provided link.
- Lacks transparent sender authentication and uses a suspicious display name format.
Do not click any links or attempt to sign in through this email. Delete the message immediately and navigate to the official Microsoft website directly if you have concerns about your account.
Every scoring adjustment, in dominance order. Shows exactly how we got from 100 to the final trust number.
Why this verdict
100 → 0The scorer starts every address at 100 trust and applies each signal below in turn. Negative deltas are penalties (red), positive deltas are bonuses (emerald). Final clamped trust: 0.
- The pasted address doesn't parse as a valid RFC-5322 email address.syntax_invalid-100
Screenshot vision analysis
VISUAL · 75/100The email uses a generic threat of account maintenance fees to create urgency and prompt a login. The inclusion of 'Alarm Clock' as a header is highly irregular for official corporate correspondence.
- unusual subject line content
- generic account maintenance threat
- lack of sender address transparency
Paste the sender to unlock identity + infrastructure analysis
This scan analysed the message body only. Adding the sender address, a Gmail Name <a@b.com> line, or full headers unlocks:
- Display-name impersonationSpot mismatched names like "PayPal Support" on a random Gmail.
- SPF · DKIM · DMARCSee whether the sending server is authorised to use that domain.
- Domain age + registrarBrand-new domains are one of the strongest phish signals.
- Breach exposureHow many known data breaches this specific address appears in.
- MX + DNSBL reputationWhether the domain can even receive mail and if it's on any blocklists.
Your previous paste won't be sent — you'll start a fresh scan with both fields.