Likely scam — do not engage
Our AI analyst read the message body and judged it likely to be phishing.
MalwareTips analyst · message material
credential_theftThis email uses a deceptive link structure to redirect users to a non-official domain under the guise of an Eversource document request.
- The email contains multiple links that redirect through a suspicious third-party domain (url[number].url[number].eversource.com) rather than the official eversource.com domain.
- The message creates artificial urgency by demanding document uploads within a 14-day window.
- The sender domain, while appearing related, uses a SendGrid-based infrastructure often leveraged for mass-mailing campaigns.
- The body contains inconsistent formatting and redundant sections, which is common in automated phishing templates.
Do not click any links in the email. If you have concerns about your account, navigate directly to the official Eversource website by typing the address into your browser.
Every scoring adjustment, in dominance order. Shows exactly how we got from 100 to the final trust number.
Why this verdict
100 → 37The scorer starts every address at 100 trust and applies each signal below in turn. Negative deltas are penalties (red), positive deltas are bonuses (emerald). Final clamped trust: 37.
- AI analyst flagged 85% phishing likelihood (credential_theft).ai_phishing_detected-43
- Listed on 1 DNSBL: URIBL.dnsbl_listed-15
- Domain publishes strong authentication policy: DMARC p=reject · SPF soft-fail.dmarc_reject_enforced+13
- Screenshot OCR + visual pass flagged 40/100 phishing risk: The email uses official branding and a legitimate-looking domain, but lacks specific sender information and uses a generic greeting. The request for documentation without prior context or account verification is a common social engineering tactic.screenshot_phishing_visual-12
- AI analyst flagged 40% spam likelihood.ai_spam_detected-6
Display name, domain reputation, and authentication checks for the From address.
Display-name impersonation
NO BRAND CLAIMThe display name doesn't resemble any of the top phished brands we track — this isn't a brand-impersonation attempt.
Brand-lookalike radar
okNo typosquat or homoglyph match against the top 50 phished brands.
Authentication results
2/3 PASSResults extracted from the Authentication-Results header. When all three pass the message verifiably came from a server authorised to send for that domain.
Domain age
timeoutRDAP check did not run.
Signals extracted from the message body, embedded URLs, and uploaded screenshot.
Links extracted from this email
2 sites shownGoogle Safe Browsing could not be checked for this scan. The links were checked against our own URL scan database, then scored on how they are built. Click Scan link for a full report on the destination.
- url5617.url2818.eversource.com/ls/clickHost uses multiple subdomainsUnusually long URLLink uses plain HTTP, not HTTPSSuspicion15
- www.eversource.com/cg/customer/upload/securelink/9ef[number]a-[number]-Path contains credential-harvest keywordsSuspicion5
Screenshot vision analysis
VISUAL · 40/100The email uses official branding and a legitimate-looking domain, but lacks specific sender information and uses a generic greeting. The request for documentation without prior context or account verification is a common social engineering tactic.
- generic greeting
- lack of sender identification
- unsolicited request for documentation
- https://www.eversource.com/cg/customer/upload/securelink/[token]
MX records, deliverability probe, provider classification, and DNS blocklists.
Deliverability
ok- RFC 5322 syntax valid
- 1 MX record publishedmx.sendgrid.net
Provider classification
okNot on our disposable-provider list and not a recognised consumer freemail (Gmail / Outlook / Yahoo etc.) — likely a custom domain.
DNS blocklists
okListed by 1 of 3 blocklists:
Breach history for this address and the structural identity of the sending domain.
Breach exposure (HIBP)
okSkipped — the breach check was not available for this scan.