Tier · suspicious
Verdict

Treat with caution

The domain appears on one or more DNS blocklists used for spam filtering.

no-reply@accounts.google.com
At a glance
AI · 30% phishingDNSBL · 1 list
Risk score
27
/ 100
suspicious
AI analyst

MalwareTips analyst · message material

generic_spam

This security alert contains a suspicious future-dated timestamp and redundant, repetitive body content.

Phishing likelihood30%
Spam likelihood10%
Red flags identified
  • The email contains a future date ([number]) in the footer, which is inconsistent with legitimate automated notifications.
  • The body text is duplicated, suggesting a poorly constructed or automated template error.
  • The email triggered a URIBL DNSBL hit, indicating potential issues with the sender's reputation or infrastructure.
What to do

Do not interact with the links provided. Navigate directly to your Google account settings via your browser to verify recent activity.

Why this verdict

Every scoring adjustment, in dominance order. Shows exactly how we got from 100 to the final trust number.

Why this verdict

10073

The scorer starts every address at 100 trust and applies each signal below in turn. Negative deltas are penalties (red), positive deltas are bonuses (emerald). Final clamped trust: 73.

  • Listed on 1 DNSBL: URIBL.
    dnsbl_listed
    -15
  • AI analyst flagged 30% phishing likelihood (generic_spam).
    ai_phishing_detected
    -15
  • Domain publishes strong authentication policy: DMARC p=reject · SPF none.
    dmarc_reject_enforced
    +11
  • Screenshot OCR + visual pass flagged 20/100 phishing risk: The email mimics a standard Google security notification, but the timestamp indicates a future date ([number]), which is inconsistent with legitimate automated alerts.
    screenshot_phishing_visual
    -6
  • AI analyst flagged 10% spam likelihood.
    ai_spam_detected
    -2
Sender identity

Display name, domain reputation, and authentication checks for the From address.

Display-name impersonation

NO BRAND CLAIM

The display name doesn't resemble any of the top phished brands we track — this isn't a brand-impersonation attempt.

Brand-lookalike radar

ok

No typosquat or homoglyph match against the top 50 phished brands.

Domain age

error

RDAP check did not run.

Content evidence

Signals extracted from the message body, embedded URLs, and uploaded screenshot.

Links extracted from this email

1 shown

Each link was scored against a host-level suspicion heuristic. Click Scan link to run our full URL scanner on the destination — it'll show our verdict alongside Google Safe Browsing, VirusTotal, URLhaus, and the others.

  • myaccount.google.com
    /notifications
    Host contains credential-harvest keywords
    Suspicion
    10

Screenshot vision analysis

VISUAL · 20/100

The email mimics a standard Google security notification, but the timestamp indicates a future date ([number]), which is inconsistent with legitimate automated alerts.

Displayed From
Google <no-reply@accounts.google.com>
Subject
Security alert
Visual red flags
  • future date in timestamp
Detected logos
Google
Visible URLs in screenshot
  • https://myaccount.google.com/notifications
Infrastructure

MX records, deliverability probe, provider classification, and DNS blocklists.

Deliverability

ok
  • RFC 5322 syntax valid
  • 5 MX records published
    gmr-smtp-in.l.google.comalt1.gmr-smtp-in.l.google.comalt2.gmr-smtp-in.l.google.comalt3.gmr-smtp-in.l.google.com+1 more
  • SMTP probe · unknownSMTP probe disabled (set SMTP_PROBE_ENABLED=true to enable)

Provider classification

ok

Not on our disposable-provider list and not a recognised consumer freemail (Gmail / Outlook / Yahoo etc.) — likely a custom domain.

DNS blocklists

ok

Listed by 1 of 3 blocklists:

URIBL
Reputation

Breach history for this address and the structural identity of the sending domain.

Breach exposure (HIBP)

ok

HIBP_API_KEY not configured

Sender infrastructure

Domain
accounts.google.com
Domain age
Unknown
Provider
custom domain
MX hosts
gmr-smtp-in.l.google.comalt1.gmr-smtp-in.l.google.comalt2.gmr-smtp-in.l.google.comalt3.gmr-smtp-in.l.google.comalt4.gmr-smtp-in.l.google.com
This report URL contains a SHA-256 hash, while the cached report retains normalized sender components, display name when available, and derived evidence. Raw .eml and screenshot bytes are discarded after extraction. The page is noindex, but anyone with the link may be able to view it; do not submit secrets or confidential messages. If you received this email and are worried, do not click any links and do not reply — verify the sender through a known-good channel.