Tier · dangerous
Verdict

Likely scam — do not engage

Our AI analyst read the message body and judged it likely to be phishing.

Eversource·noreply@notifications.eversource.com
At a glance
AI · 85% phishingDNSBL · 1 list
Risk score
63
/ 100
malicious
AI analyst

MalwareTips analyst · message material

credential_theft

This email uses a deceptive link structure to redirect users to a non-official domain under the guise of an Eversource document request.

Phishing likelihood85%
Spam likelihood40%
Red flags identified
  • The email contains multiple links that redirect through a suspicious third-party domain (url5617.url2818.eversource.com) rather than the official eversource.com domain.
  • The message creates artificial urgency by demanding document uploads within a 14-day window.
  • The sender domain, while appearing related, uses a SendGrid-based infrastructure often leveraged for mass-mailing campaigns.
  • The body contains inconsistent formatting and redundant sections, which is common in automated phishing templates.
What to do

Do not click any links in the email. If you have concerns about your account, navigate directly to the official Eversource website by typing the address into your browser.

Why this verdict

Every scoring adjustment, in dominance order. Shows exactly how we got from 100 to the final trust number.

Why this verdict

10037

The scorer starts every address at 100 trust and applies each signal below in turn. Negative deltas are penalties (red), positive deltas are bonuses (emerald). Final clamped trust: 37.

  • AI analyst flagged 85% phishing likelihood (credential_theft).
    ai_phishing_detected
    -43
  • Listed on 1 DNSBL: URIBL.
    dnsbl_listed
    -15
  • Domain publishes strong authentication policy: DMARC p=reject · SPF soft-fail.
    dmarc_reject_enforced
    +13
  • Screenshot OCR + visual pass flagged 40/100 phishing risk: The email uses official branding and a legitimate-looking domain, but lacks specific sender information and uses a generic greeting. The request for documentation without prior context or account verification is a common social engineering tactic.
    screenshot_phishing_visual
    -12
  • AI analyst flagged 40% spam likelihood.
    ai_spam_detected
    -6
Sender identity

Display name, domain reputation, and authentication checks for the From address.

Display-name impersonation

NO BRAND CLAIM

The display name doesn't resemble any of the top phished brands we track — this isn't a brand-impersonation attempt.

Brand-lookalike radar

ok

No typosquat or homoglyph match against the top 50 phished brands.

Authentication results

2/3 PASS

Results extracted from the Authentication-Results header. When all three pass the message verifiably came from a server authorised to send for that domain.

SPF
pass
DKIM
neutral
DMARC
pass
Return-Pathbounces+14210139-0747-dring=stjohnshigh.org@em3076.notifications.eversource.com

Domain age

timeout

RDAP check did not run.

Content evidence

Signals extracted from the message body, embedded URLs, and uploaded screenshot.

Links extracted from this email

2 shown

Each link was scored against a host-level suspicion heuristic. Click Scan link to run our full URL scanner on the destination — it'll show our verdict alongside Google Safe Browsing, VirusTotal, URLhaus, and the others.

  • url5617.url2818.eversource.com
    /ls/click?upn=u001.6uQVgOa7SHjwG6qRw1iCoi8FTj37EYLYRfmFpRYQNqzEdUWE0yj60Hfgq4q6xfDKXAIc_vXC6nCBkmiC-2FuUsc3sNWIlOybdc3A3T8TsGtUubTyb45pMRHiS7Qf6yvD00iIJ8mqmlZd6Yb5Ijmi8O9yndrvMD3Chb9nmz05prmHzAzSbclAaTYYNKpQmQ22n6HhMPTYO-2FjSvCtvzmeRNwc-2BoOGBZP1TO6JKyds-2B343ZSV94RglWYAKb074Exe66PjnyqnwWNh7fmju6-2Fv32bPAoShiy1fkwdSZOAGb7mRi0YHP3zOMQRsAS7FFcVNtKrTlT0Fqun996cm34YH9hEsXYU7s8t5ZxncESrhsR-2BsuQvXNnhsksje9Ou53vZYbZXGNHJ8VuKfSeQ1uSFzV3kDWFxtFifwTB4zC8cObO3hIiab9yBs-3D
    Host uses multiple subdomainsUnusually long URLLink uses plain HTTP, not HTTPS
    Suspicion
    15
  • www.eversource.com
    /cg/customer/upload/securelink/9ef1068a-5153-
    Path contains credential-harvest keywords
    Suspicion
    5

Screenshot vision analysis

VISUAL · 40/100

The email uses official branding and a legitimate-looking domain, but lacks specific sender information and uses a generic greeting. The request for documentation without prior context or account verification is a common social engineering tactic.

Visual red flags
  • generic greeting
  • lack of sender identification
  • unsolicited request for documentation
Detected logos
Eversource
Visible URLs in screenshot
  • https://www.eversource.com/cg/customer/upload/securelink/9ef1068a-5153-4dba-9193-eeaa5a56af2f
Infrastructure

MX records, deliverability probe, provider classification, and DNS blocklists.

Deliverability

ok
  • RFC 5322 syntax valid
  • 1 MX record published
    mx.sendgrid.net
  • SMTP probe · unknownSMTP probe disabled (set SMTP_PROBE_ENABLED=true to enable)

Provider classification

ok

Not on our disposable-provider list and not a recognised consumer freemail (Gmail / Outlook / Yahoo etc.) — likely a custom domain.

DNS blocklists

ok

Listed by 1 of 3 blocklists:

URIBL
Reputation

Breach history for this address and the structural identity of the sending domain.

Breach exposure (HIBP)

ok

HIBP_API_KEY not configured

Sender infrastructure

Domain
notifications.eversource.com
Domain age
Unknown
Provider
custom domain
MX hosts
mx.sendgrid.net
This report URL contains a SHA-256 hash, while the cached report retains normalized sender components, display name when available, and derived evidence. Raw .eml and screenshot bytes are discarded after extraction. The page is noindex, but anyone with the link may be able to view it; do not submit secrets or confidential messages. If you received this email and are worried, do not click any links and do not reply — verify the sender through a known-good channel.