Treat with caution
The domain appears on one or more DNS blocklists used for spam filtering.
MalwareTips analyst · message material
generic_spamThis security alert contains a suspicious future-dated timestamp and redundant, repetitive body content.
- The email contains a future date ([number]) in the footer, which is inconsistent with legitimate automated notifications.
- The body text is duplicated, suggesting a poorly constructed or automated template error.
- The email triggered a URIBL DNSBL hit, indicating potential issues with the sender's reputation or infrastructure.
Do not interact with the links provided. Navigate directly to your Google account settings via your browser to verify recent activity.
Every scoring adjustment, in dominance order. Shows exactly how we got from 100 to the final trust number.
Why this verdict
100 → 73The scorer starts every address at 100 trust and applies each signal below in turn. Negative deltas are penalties (red), positive deltas are bonuses (emerald). Final clamped trust: 73.
- Listed on 1 DNSBL: URIBL.dnsbl_listed-15
- AI analyst flagged 30% phishing likelihood (generic_spam).ai_phishing_detected-15
- Domain publishes strong authentication policy: DMARC p=reject · SPF none.dmarc_reject_enforced+11
- Screenshot OCR + visual pass flagged 20/100 phishing risk: The email mimics a standard Google security notification, but the timestamp indicates a future date ([number]), which is inconsistent with legitimate automated alerts.screenshot_phishing_visual-6
- AI analyst flagged 10% spam likelihood.ai_spam_detected-2
Display name, domain reputation, and authentication checks for the From address.
Display-name impersonation
NO BRAND CLAIMThe display name doesn't resemble any of the top phished brands we track — this isn't a brand-impersonation attempt.
Brand-lookalike radar
okNo typosquat or homoglyph match against the top 50 phished brands.
Domain age
errorRDAP check did not run.
Signals extracted from the message body, embedded URLs, and uploaded screenshot.
Links extracted from this email
1 shownEach link was scored against a host-level suspicion heuristic. Click Scan link to run our full URL scanner on the destination — it'll show our verdict alongside Google Safe Browsing, VirusTotal, URLhaus, and the others.
- myaccount.google.com/notificationsHost contains credential-harvest keywordsSuspicion10
Screenshot vision analysis
VISUAL · 20/100The email mimics a standard Google security notification, but the timestamp indicates a future date ([number]), which is inconsistent with legitimate automated alerts.
- future date in timestamp
- https://myaccount.google.com/notifications
MX records, deliverability probe, provider classification, and DNS blocklists.
Deliverability
ok- RFC 5322 syntax valid
- 5 MX records publishedgmr-smtp-in.l.google.comalt1.gmr-smtp-in.l.google.comalt2.gmr-smtp-in.l.google.comalt3.gmr-smtp-in.l.google.com+1 more
- SMTP probe · unknown — SMTP probe disabled (set SMTP_PROBE_ENABLED=true to enable)
Provider classification
okNot on our disposable-provider list and not a recognised consumer freemail (Gmail / Outlook / Yahoo etc.) — likely a custom domain.
DNS blocklists
okListed by 1 of 3 blocklists:
Breach history for this address and the structural identity of the sending domain.
Breach exposure (HIBP)
okHIBP_API_KEY not configured