Likely scam — do not engage
Our AI analyst read the message body and judged it likely to be phishing.
MalwareTips analyst · message material
credential_theftThe email displays a mismatch between the sender address and the claimed display name, alongside an unusual sender identity.
- The display name 'Sabrina Risklocker' is inconsistent with an automated OTP notification system.
- The sender address '[email]' does not match the claimed brand 'Liberty Insurance'.
- The domain shows a URIBL DNSBL hit, indicating potential association with malicious activity.
- The DMARC policy is set to 'none', providing no protection against domain spoofing.
Do not use the OTP or interact with the sender. Delete the email and contact the official support channel of the service provider directly if you were expecting a code.
Every scoring adjustment, in dominance order. Shows exactly how we got from 100 to the final trust number.
Why this verdict
100 → 44The scorer starts every address at 100 trust and applies each signal below in turn. Negative deltas are penalties (red), positive deltas are bonuses (emerald). Final clamped trust: 44.
- AI analyst flagged 65% phishing likelihood (credential_theft).ai_phishing_detected-33
- Listed on 1 DNSBL: URIBL.dnsbl_listed-15
- Screenshot OCR + visual pass flagged 40/100 phishing risk: The screenshot shows an email interface displaying an OTP request from a corporate domain. The context of the group name 'Sabrina Risklocker' is unusual for an automated security notification.screenshot_phishing_visual-12
- Domain publishes strong authentication policy: DMARC p=none · SPF hard-fail.auth_dns_published+7
- AI analyst flagged 20% spam likelihood.ai_spam_detected-3
Display name, domain reputation, and authentication checks for the From address.
Display-name impersonation
NO BRAND CLAIMThe display name doesn't resemble any of the top phished brands we track — this isn't a brand-impersonation attempt.
Brand-lookalike radar
okNo typosquat or homoglyph match against the top 50 phished brands.
Domain age
errorRDAP check did not run.
Signals extracted from the message body, embedded URLs, and uploaded screenshot.
Screenshot vision analysis
VISUAL · 40/100The screenshot shows an email interface displaying an OTP request from a corporate domain. The context of the group name 'Sabrina Risklocker' is unusual for an automated security notification.
- unusual group name
- generic OTP subject line
MX records, deliverability probe, provider classification, and DNS blocklists.
Deliverability
ok- RFC 5322 syntax valid
- 1 MX record publishedslinfo-com-my.mail.protection.outlook.com
- SMTP probe · unknown — SMTP probe disabled (set SMTP_PROBE_ENABLED=true to enable)
Provider classification
okNot on our disposable-provider list and not a recognised consumer freemail (Gmail / Outlook / Yahoo etc.) — likely a custom domain.
DNS blocklists
okListed by 1 of 3 blocklists:
Breach history for this address and the structural identity of the sending domain.
Breach exposure (HIBP)
okHIBP_API_KEY not configured