Confirmed scam — delete it
This email uses government impersonation to promise a large sum of money in exchange for personal information.
MalwareTips analyst · message material
advance_feeThis email uses government impersonation to promise a large sum of money in exchange for personal information.
- Uses a fraudulent government impersonation scheme promising a large, unrealistic sum of money.
- Directs the recipient to contact an unofficial, suspicious email address for financial disbursement.
- Employs high-pressure tactics by promising funds within a 48-hour window.
- Requests sensitive personal information under the guise of a government restitution program.
- Uses a non-governmental domain for official Treasury communication.
Do not reply to the email or provide any personal information. Delete the message immediately as it is a fraudulent attempt to steal your data or money.
Every scoring adjustment, in dominance order. Shows exactly how we got from 100 to the final trust number.
Why this verdict
100 → 0The scorer starts every address at 100 trust and applies each signal below in turn. Negative deltas are penalties (red), positive deltas are bonuses (emerald). Final clamped trust: 0.
- The pasted address doesn't parse as a valid RFC-5322 email address.syntax_invalid-100
Rule-based detectors for urgency language, credential theft phrasing, attachment bait and brand impersonation in text.
Phishing-pattern signals
1 signalRule-based pattern matches we ran across the message body and OCR text BEFORE the AI analyst. Each is a hint, not a verdict.
- Uses urgency or time pressuremedium“accessing your $14,700,000.00 within 48 hours as planned. Warm regards,”
Paste the sender to unlock identity + infrastructure analysis
This scan analysed the message body only. Adding the sender address, a Gmail Name <a@b.com> line, or full headers unlocks:
- Display-name impersonationSpot mismatched names like "PayPal Support" on a random Gmail.
- SPF · DKIM · DMARCSee whether the sending server is authorised to use that domain.
- Domain age + registrarBrand-new domains are one of the strongest phish signals.
- Breach exposureHow many known data breaches this specific address appears in.
- MX + DNSBL reputationWhether the domain can even receive mail and if it's on any blocklists.
Your previous paste won't be sent — you'll start a fresh scan with both fields.