Clean across the board
All checks passed cleanly.
MalwareTips analyst · message material
legitimateThis appears to be a legitimate automated billing notification from Rogers.
This email appears to be a standard transactional notification. You can safely view your bill through the official Rogers website.
Every scoring adjustment, in dominance order. Shows exactly how we got from 100 to the final trust number.
Why this verdict
100 → 100The scorer starts every address at 100 trust and applies each signal below in turn. Negative deltas are penalties (red), positive deltas are bonuses (emerald). Final clamped trust: 100.
- Domain publishes strong authentication policy: DMARC p=quarantine (pct=50) · SPF hard-fail.auth_dns_published+5
- Clean across 3 DNSBLs checked.dnsbl_clean+3
- AI analyst rated phishing likelihood low (5%) (legitimate).ai_phishing_detected-3
- Screenshot OCR + visual pass flagged 10/100 phishing risk: The email appears to be a standard automated billing notification from Rogers. The sender address matches the official domain, and there are no obvious indicators of malicious intent.screenshot_phishing_visual-3
- AI analyst rated spam likelihood low (10%).ai_spam_detected-2
Display name, domain reputation, and authentication checks for the From address.
Display-name impersonation
NO BRAND CLAIMThe display name doesn't resemble any of the top phished brands we track — this isn't a brand-impersonation attempt.
Brand-lookalike radar
okNo typosquat or homoglyph match against the top 50 phished brands.
Domain age
errorRDAP check did not run.
Signals extracted from the message body, embedded URLs, and uploaded screenshot.
Links extracted from this email
1 site shownEvery link was checked live against Google Safe Browsing (1 checked) and against our own URL scan database, then scored on how they are built. Click Scan link for a full report on the destination.
- rogers.comSuspicion0
Screenshot vision analysis
VISUAL · 10/100The email appears to be a standard automated billing notification from Rogers. The sender address matches the official domain, and there are no obvious indicators of malicious intent.
- https://rogers.com/
MX records, deliverability probe, provider classification, and DNS blocklists.
Deliverability
ok- RFC 5322 syntax valid
- 1 MX record publishedrci-rogers-com.mail.protection.outlook.com
Provider classification
okNot on our disposable-provider list and not a recognised consumer freemail (Gmail / Outlook / Yahoo etc.) — likely a custom domain.
DNS blocklists
okClean across all 3 blocklists that answered (SURBL, Spamhaus DBL, URIBL).
Breach history for this address and the structural identity of the sending domain.
Breach exposure (HIBP)
okSkipped — the breach check was not available for this scan.