Tier · suspicious
Verdict

Treat with caution

Our AI analyst read the message body and judged it likely to be phishing.

marcin.gajewski@iheartpoland.com
At a glance
Domain 16y oldAI · 85% phishing
Risk score
39
/ 100
suspicious
AI analyst

MalwareTips analyst · message material

advance_fee

This email uses a classic inheritance scam narrative to initiate contact under the guise of a legal matter.

Phishing likelihood85%
Spam likelihood40%
Red flags identified
  • Uses a vague and unsolicited inheritance-related narrative to solicit personal contact information.
  • Lacks professional contact details or verifiable credentials for the purported legal matter.
  • Contains repetitive text blocks suggesting a template-based or automated mass-mailing approach.
  • Displays signs of being blocked by security filters, indicating a history of malicious activity.
What to do

Do not reply to this email or provide any personal information. Delete the message immediately.

Why this verdict

Every scoring adjustment, in dominance order. Shows exactly how we got from 100 to the final trust number.

Why this verdict

10061

The scorer starts every address at 100 trust and applies each signal below in turn. Negative deltas are penalties (red), positive deltas are bonuses (emerald). Final clamped trust: 61.

  • AI analyst flagged 85% phishing likelihood (advance_fee).
    ai_phishing_detected
    -43
  • Screenshot OCR + visual pass flagged 75/100 phishing risk: The email uses a classic 'inheritance scam' narrative, attempting to initiate contact under the guise of a legal or estate matter. The lack of specific sender credentials and the automated security warning regarding the sender's status are significant indicators of potential social engineering.
    screenshot_phishing_visual
    -23
  • Domain has been registered for over 16 years.
    domain_longstanding
    +15
  • Domain publishes strong authentication policy: DMARC p=reject · SPF hard-fail.
    dmarc_reject_enforced
    +15
  • AI analyst flagged 40% spam likelihood.
    ai_spam_detected
    -6
Sender identity

Display name, domain reputation, and authentication checks for the From address.

Display-name impersonation

NO BRAND CLAIM

The display name doesn't resemble any of the top phished brands we track — this isn't a brand-impersonation attempt.

Brand-lookalike radar

ok

No typosquat or homoglyph match against the top 50 phished brands.

Domain age

ok
  • RegisteredApr 29, 2010long-established (10+ years)
  • Age5935 days
  • RegistrarGoDaddy.com, LLC
Content evidence

Signals extracted from the message body, embedded URLs, and uploaded screenshot.

Screenshot vision analysis

VISUAL · 75/100

The email uses a classic 'inheritance scam' narrative, attempting to initiate contact under the guise of a legal or estate matter. The lack of specific sender credentials and the automated security warning regarding the sender's status are significant indicators of potential social engineering.

Displayed From
Marcin Gajewski
Visual red flags
  • unsolicited estate-related inquiry
  • vague sender identity
  • lack of professional contact details
  • email blocked by security filter
Infrastructure

MX records, deliverability probe, provider classification, and DNS blocklists.

Deliverability

ok
  • RFC 5322 syntax valid
  • 1 MX record published
    mail.iheartpoland.com
  • SMTP probe · unknownSMTP probe disabled (set SMTP_PROBE_ENABLED=true to enable)

Provider classification

ok

Not on our disposable-provider list and not a recognised consumer freemail (Gmail / Outlook / Yahoo etc.) — likely a custom domain.

DNS blocklists

ok

Clean across all 3 blocklists checked (SURBL, Spamhaus DBL, URIBL).

Reputation

Breach history for this address and the structural identity of the sending domain.

Breach exposure (HIBP)

ok

HIBP_API_KEY not configured

Sender infrastructure

Domain
iheartpoland.com
Domain age
5935 days · long-established (10+ years)
Provider
custom domain
MX hosts
mail.iheartpoland.com
This report URL contains a SHA-256 hash, while the cached report retains normalized sender components, display name when available, and derived evidence. Raw .eml and screenshot bytes are discarded after extraction. The page is noindex, but anyone with the link may be able to view it; do not submit secrets or confidential messages. If you received this email and are worried, do not click any links and do not reply — verify the sender through a known-good channel.