Tier · suspicious
Verdict

Treat with caution

Screenshot Phishing Visual

owkuwqtf@rpgdz.cn
At a glance
AI · 30% phishing
Risk score
42
/ 100
suspicious
AI analyst

MalwareTips analyst · message material

generic_spam

This is an unsolicited commercial solicitation from an unverified sender regarding electronic component supply.

Phishing likelihood30%
Spam likelihood90%
Red flags identified
  • The sender address domain does not match the claimed company name.
  • The email is an unsolicited commercial outreach typical of bulk spam.
  • The sender domain has a hard-fail SPF record, indicating poor email authentication practices.
What to do

Do not reply to this email or provide any business information. Mark it as spam and delete it.

Why this verdict

Every scoring adjustment, in dominance order. Shows exactly how we got from 100 to the final trust number.

Why this verdict

10058

The scorer starts every address at 100 trust and applies each signal below in turn. Negative deltas are penalties (red), positive deltas are bonuses (emerald). Final clamped trust: 58.

  • Screenshot OCR + visual pass flagged 75/100 phishing risk: The email is an unsolicited commercial solicitation sent from a suspicious domain that does not match the claimed company name. It has been automatically flagged as spam by the email provider.
    screenshot_phishing_visual
    -23
  • AI analyst flagged 30% phishing likelihood (generic_spam).
    ai_phishing_detected
    -15
  • AI analyst flagged 90% spam likelihood.
    ai_spam_detected
    -14
  • Domain publishes strong authentication policy: DMARC p=none · SPF hard-fail.
    auth_dns_published
    +7
  • Clean across 3 DNSBLs checked.
    dnsbl_clean
    +3
Sender identity

Display name, domain reputation, and authentication checks for the From address.

Display-name impersonation

NO BRAND CLAIM

The display name doesn't resemble any of the top phished brands we track — this isn't a brand-impersonation attempt.

Brand-lookalike radar

ok

No typosquat or homoglyph match against the top 50 phished brands.

Domain age

error

RDAP check did not run.

Content evidence

Signals extracted from the message body, embedded URLs, and uploaded screenshot.

Screenshot vision analysis

VISUAL · 75/100

The email is an unsolicited commercial solicitation sent from a suspicious domain that does not match the claimed company name. It has been automatically flagged as spam by the email provider.

Displayed From
Sandy <owkuwqtf@rpgdz.cn>
Subject
MLCC | 4.7uF 6.3V X5R +/-10% [number] do you meet delivery issue?
Visual red flags
  • sender address domain mismatch
  • unsolicited commercial outreach
  • generic business inquiry
  • flagged as spam by email provider
Infrastructure

MX records, deliverability probe, provider classification, and DNS blocklists.

Deliverability

ok
  • RFC 5322 syntax valid
  • 2 MX records published
    mx-001.cy-email.commx01.dm.aliyun.com
  • SMTP probe · unknownSMTP probe disabled (set SMTP_PROBE_ENABLED=true to enable)

Provider classification

ok

Not on our disposable-provider list and not a recognised consumer freemail (Gmail / Outlook / Yahoo etc.) — likely a custom domain.

DNS blocklists

ok

Clean across all 3 blocklists checked (SURBL, Spamhaus DBL, URIBL).

Reputation

Breach history for this address and the structural identity of the sending domain.

Breach exposure (HIBP)

ok

HIBP_API_KEY not configured

Sender infrastructure

Domain
rpgdz.cn
Domain age
Unknown
Provider
custom domain
MX hosts
mx-001.cy-email.commx01.dm.aliyun.com
This report URL contains a SHA-256 hash, while the cached report retains normalized sender components, display name when available, and derived evidence. Raw .eml and screenshot bytes are discarded after extraction. The page is noindex, but anyone with the link may be able to view it; do not submit secrets or confidential messages. If you received this email and are worried, do not click any links and do not reply — verify the sender through a known-good channel.