Safe to trust
The domain appears on one or more DNS blocklists used for spam filtering.
MalwareTips analyst · message material
legitimateThis appears to be a legitimate business inquiry from a manufacturer seeking structural engineering services.
- The sender domain is flagged by a URIBL blocklist, which may indicate a poor reputation for the domain or its hosting provider.
- The email uses a via-domain header, which can sometimes be associated with misconfigured email routing or third-party sending services.
The email appears to be a standard business solicitation. No action is required unless you suspect the sender is not who they claim to be.
Every scoring adjustment, in dominance order. Shows exactly how we got from 100 to the final trust number.
Why this verdict
100 → 84The scorer starts every address at 100 trust and applies each signal below in turn. Negative deltas are penalties (red), positive deltas are bonuses (emerald). Final clamped trust: 84.
- Listed on 1 DNSBL: URIBL.dnsbl_listed-15
- Domain publishes strong authentication policy: DMARC p=none · SPF soft-fail.auth_dns_published+4
- AI analyst flagged 5% phishing likelihood (legitimate).ai_phishing_detected-3
- AI analyst flagged 10% spam likelihood.ai_spam_detected-2
Display name, domain reputation, and authentication checks for the From address.
Display-name impersonation
NO BRAND CLAIMThe display name doesn't resemble any of the top phished brands we track — this isn't a brand-impersonation attempt.
Brand-lookalike radar
okNo typosquat or homoglyph match against the top 50 phished brands.
Domain age
errorRDAP check did not run.
MX records, deliverability probe, provider classification, and DNS blocklists.
Deliverability
ok- RFC 5322 syntax valid
- 1 MX record publishedsmtp.google.com
- SMTP probe · unknown — SMTP probe disabled (set SMTP_PROBE_ENABLED=true to enable)
Provider classification
okNot on our disposable-provider list and not a recognised consumer freemail (Gmail / Outlook / Yahoo etc.) — likely a custom domain.
DNS blocklists
okListed by 1 of 3 blocklists:
Breach history for this address and the structural identity of the sending domain.
Breach exposure (HIBP)
okHIBP_API_KEY not configured