Tier · safe
Verdict

Clean across the board

All checks passed cleanly.

notifications@rci.rogers.com
Risk score
0
/ 100
safe
AI analyst

MalwareTips analyst · message material

legitimate

This appears to be a legitimate automated billing notification from Rogers.

Phishing likelihood5%
Spam likelihood10%
What to do

This email appears to be a standard transactional notification. You can safely view your bill through the official Rogers website.

Why this verdict

Every scoring adjustment, in dominance order. Shows exactly how we got from 100 to the final trust number.

Why this verdict

100 → 100

The scorer starts every address at 100 trust and applies each signal below in turn. Negative deltas are penalties (red), positive deltas are bonuses (emerald). Final clamped trust: 100.

  • Domain publishes strong authentication policy: DMARC p=quarantine (pct=50) · SPF hard-fail.
    auth_dns_published
    +5
  • Clean across 3 DNSBLs checked.
    dnsbl_clean
    +3
  • AI analyst rated phishing likelihood low (5%) (legitimate).
    ai_phishing_detected
    -3
  • Screenshot OCR + visual pass flagged 10/100 phishing risk: The email appears to be a standard automated billing notification from Rogers. The sender address matches the official domain, and there are no obvious indicators of malicious intent.
    screenshot_phishing_visual
    -3
  • AI analyst rated spam likelihood low (10%).
    ai_spam_detected
    -2
Sender identity

Display name, domain reputation, and authentication checks for the From address.

Display-name impersonation

NO BRAND CLAIM

The display name doesn't resemble any of the top phished brands we track — this isn't a brand-impersonation attempt.

Brand-lookalike radar

ok

No typosquat or homoglyph match against the top 50 phished brands.

Domain age

error

RDAP check did not run.

Content evidence

Signals extracted from the message body, embedded URLs, and uploaded screenshot.

Links extracted from this email

1 site shown

Every link was checked live against Google Safe Browsing (1 checked) and against our own URL scan database, then scored on how they are built. Click Scan link for a full report on the destination.

Screenshot vision analysis

VISUAL · 10/100

The email appears to be a standard automated billing notification from Rogers. The sender address matches the official domain, and there are no obvious indicators of malicious intent.

Displayed From
Rogers <notifications@rci.rogers.com>
Detected logos
Rogers
Visible URLs in screenshot
  • https://rogers.com/
Infrastructure

MX records, deliverability probe, provider classification, and DNS blocklists.

Deliverability

ok
  • RFC 5322 syntax valid
  • 1 MX record published
    rci-rogers-com.mail.protection.outlook.com

Provider classification

ok

Not on our disposable-provider list and not a recognised consumer freemail (Gmail / Outlook / Yahoo etc.) — likely a custom domain.

DNS blocklists

ok

Clean across all 3 blocklists that answered (SURBL, Spamhaus DBL, URIBL).

Reputation

Breach history for this address and the structural identity of the sending domain.

Breach exposure (HIBP)

ok

Skipped — the breach check was not available for this scan.

Sender infrastructure

Domain
rci.rogers.com
Domain age
Unknown
Provider
custom domain
MX hosts
rci-rogers-com.mail.protection.outlook.com
This report URL contains a SHA-256 hash, while the cached report retains normalized sender components, display name when available, and derived evidence. Raw .eml and screenshot bytes are discarded after extraction. The page is noindex, but anyone with the link may be able to view it; do not submit secrets or confidential messages. If you received this email and are worried, do not click any links and do not reply — verify the sender through a known-good channel.