Terminator5- welp, I can guarantee you that the website my email had a link for is the exact same website as in the OP, for starters.
Here is the first email header (sanitized to protect my identity) yes I am the "
[email protected]" and "XXXXX XXXXXX"...wowee lookit the return path "
[email protected]" domain in there....
Delivered-To:
[email protected]Received: by 10.58.161.106 with SMTP id xr10csp97020veb;
Fri, 3 Jan 2014 12:26:17 -0800 (PST)
X-Received: by 10.15.67.142 with SMTP id u14mr22938624eex.59.1388780777043;
Fri, 03 Jan 2014 12:26:17 -0800 (PST)
Return-Path: <
[email protected]>
Received: from barracuda1.qdc.nl (barracuda1.qdc.nl. [92.48.198.15])
by mx.google.com with ESMTP id u49si72706616eep.232.2014.01.03.12.26.16
for <
[email protected]>;
Fri, 03 Jan 2014 12:26:17 -0800 (PST)
Received-SPF: neutral (google.com: 92.48.198.15 is neither permitted nor denied by best guess record for domain of
[email protected]) client-ip=92.48.198.15;
Authentication-Results: mx.google.com;
spf=neutral (google.com: 92.48.198.15 is neither permitted nor denied by best guess record for domain of
[email protected])
[email protected];
dmarc=fail (p=NONE dis=NONE) header.from=gmail.com
X-ASG-Debug-ID: 1388780775-0425a71d702466d30001-dvvejF
Received: from web-05.qdc.nl (web-05.qdc.nl [212.79.253.194]) by barracuda1.qdc.nl with ESMTP id dsj3vDTCABmvJcJL for <
[email protected]>; Fri, 03 Jan 2014 21:26:15 +0100 (CET)
X-Barracuda-Envelope-From:
[email protected]X-Barracuda-Apparent-Source-IP: 212.79.253.194
Received: from localhost (localhost [127.0.0.1])
by web-05.qdc.nl (Postfix) with ESMTP id CEBE6210E38
for <
[email protected]>; Fri, 3 Jan 2014 21:26:15 +0100 (CET)
X-Virus-Scanned: amavisd-new at qdc.nl
Received: from web-05.qdc.nl ([127.0.0.1])
by localhost (web-05.qdc.nl [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id 1giZMnmXe0xy for <
[email protected]>;
Fri, 3 Jan 2014 21:26:15 +0100 (CET)
Received: from ispman-01.isp-services.nl (localhost [127.0.0.1])
by web-05.qdc.nl (Postfix) with SMTP id AD9AE210E2B
for <
[email protected]>; Fri, 3 Jan 2014 21:26:15 +0100 (CET)
Received: by ispman-01.isp-services.nl (sSMTP sendmail emulation); Fri, 3 Jan 2014 21:26:15 +0100
Date: Fri, 3 Jan 2014 21:26:15 +0100
To: XXXXX XXXXXX <
[email protected]>
Subject: Fri. Jan.3, 2014, 5:26 PM - XXXXXXXXXXXXX
X-PHP-Originating-Script: 3707:error.php
X-ASG-Orig-Subj: Fri. Jan.3, 2014, 5:26 PM - XXXXX XXXXXX
MIME-Version: 1.0
Message-ID: <
[email protected]>
From: Jason Lambert <
[email protected]>
Content-Type: text/plain
Content-Transfer-Encoding: 7bit
X-Barracuda-Connect: web-05.qdc.nl[212.79.253.194]
X-Barracuda-Start-Time: 1388780775
X-Barracuda-URL:
http://barracuda1.qdc.nl:8000/cgi-mod/mark.cgiX-Virus-Scanned: by bsmtpd at qdc.nl
X-Barracuda-BRTS-Status: 1
X-Barracuda-Spam-Score: 0.01
X-Barracuda-Spam-Status: No, SCORE=0.01 using global scores of TAG_LEVEL=1000.0 QUARANTINE_LEVEL=1000.0 KILL_LEVEL=9.0 tests=BSF_SC0_SA_TO_FROM_DOMAIN_MATCH
X-Barracuda-Spam-Report: Code version 3.2, rules version 3.2.2.143698
Rule breakdown below
pts rule name description
---- ---------------------- --------------------------------------------------
0.01 BSF_SC0_SA_TO_FROM_DOMAIN_MATCH Sender Domain Matches Recipient
Domain
Now here is the second email's header I received from "Jason"... notice the mailgun.org in there (likely for spamming):
Delivered-To: XXXXX
[email protected]Received: by 10.58.161.106 with SMTP id xr10csp6335veb;
Sat, 4 Jan 2014 06:57:18 -0800 (PST)
X-Received: by 10.49.130.135 with SMTP id oe7mr165200405qeb.41.1388847438214;
Sat, 04 Jan 2014 06:57:18 -0800 (PST)
Return-Path: <
[email protected]>
Received: from mail-s65.mailgun.info (mail-s65.mailgun.info. [184.173.153.193])
by mx.google.com with ESMTP id h18si63276641qen.122.2014.01.04.06.57.17
for <
[email protected]>;
Sat, 04 Jan 2014 06:57:18 -0800 (PST)
Received-SPF: pass (google.com: domain of
[email protected] designates 184.173.153.193 as permitted sender) client-ip=184.173.153.193;
Authentication-Results: mx.google.com;
spf=pass (google.com: domain of
[email protected] designates 184.173.153.193 as permitted sender)
smtp.mail=bounce+2107a4.4c82-xxxxxxxxx= ... ailgun.org;
dkim=pass
[email protected]DKIM-Signature: a=rsa-sha256; v=1; c=relaxed/relaxed; d=mailgun.org; q=dns/txt; s=mg;
t=1388847437; h=X-Feedback-Id: Date: From: Message-Id: To: Subject:
In-Reply-To: References: Mime-Version: Content-Type:
Content-Transfer-Encoding: Sender;
bh=rSV6sVTx4r7GQrxKXenGN2QcTyUB8jBh+lzE67KSiK0=; b=k2TnBIM7KweeWemQKbCXlrEdi1lvfgngdymHURAeFNtnOdhiMYKFdU6PDJ5xZWcICQQg24Rd
Q/Jb5ZptXEPoD+y56uM30Bw6FevLVCoFDfW2ZVAQI4tYCPGS/nS9BoiGskDe+Yw38PMN3n/m
03pV2rXZjOjndmHpiTWw9eUIL8s=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=mailgun.org; s=mg; q=dns;
h=X-Feedback-Id: Date: From: Message-Id: To: Subject: In-Reply-To:
References: Mime-Version: Content-Type: Content-Transfer-Encoding:
Sender;
b=Gbf5hE5jjl+zLnxDpJBSvUaWMeAPjoC9RTXdYFI6425Fd/Fks6kzXuAoJQTC1qsYmYu/G7
CzOBF+kpRr753rUq8roGauclfs4NTbsQYLVfswqrpNljveEzdN0yLR6E1fA3fpuykUQaHWTx
20X1d7390kpxavMTYO6oehAcUEulI=
X-Feedback-Id: 51ed1b125a76182b3781a4f0:mailgun
DKIM-Signature: a=rsa-sha256; v=1; c=relaxed/relaxed; d=mailgun.org; q=dns/txt; s=mg;
t=1388847437; h=Date: From: Message-Id: To: Subject: In-Reply-To:
References: Mime-Version: Content-Type: Content-Transfer-Encoding:
Sender; bh=rSV6sVTx4r7GQrxKXenGN2QcTyUB8jBh+lzE67KSiK0=; b=Ii6pKXRG6bTbijZh7gw/OLrCtIShJBfJ3MaqUME95m5J9gqut5WDqgCErqFiA/sueiDP2aq6
jYzsIzDE5QdJpxLVHruo887NMchMFAPEA6pXOfH/XbSvuh40Gn+bpGG1V+u9WQDfJp3zFH74
YD3QjqvDBYZaJ+JhueF3/slZ5iM=
DomainKey-Signature: a=rsa-sha1; c=nofws; d=mailgun.org; s=mg; q=dns;
h=Date: From: Message-Id: To: Subject: In-Reply-To: References:
Mime-Version: Content-Type: Content-Transfer-Encoding: Sender;
b=BDdmnObyML70n0zQp3AVN3TnQ8pysE7qZ2oFg11NTWclaV8+0e0YTZKmuAJNQbZLvbpnfR
oEUc22HszYQPPiH0HIpOfJxv3HlGTxO6zPodI/MC7ZX7sdYG8fG9tPUVQbwPvRIi779HRzln
mTiU8xxWiYCVYq9HUUvxcjAngbIt4=
Received: from [172.20.19.10] (Unknown [76.73.59.98]) by mxa.mailgun.org
with ESMTP id 52c8214b.5a6fed8-in2; Sat, 04 Jan 2014 14:57:15 -0000 (UTC)
Date: Sat, 4 Jan 2014 09:52:27 -0500
From: Jason lambert <
[email protected]>
Organization: Global Outsource Inc.
X-Priority: 3 (Normal)
Message-Id: <
[email protected]>
To: XXXXX XXXXXX <
[email protected]>
Subject: Re: Fri. Jan.3, 2014, 5:26 PM - XXXXX XXXXXX
In-Reply-To: <CALuRHn1aytFzXnnbxyhJd=HypmqZyqO2OOve2_UKAH2wx-p-FQ@mail.gmail.com>
References: <
[email protected]>
<CALuRHn1aytFzXnnbxyhJd=HypmqZyqO2OOve2_UKAH2wx-p-FQ@mail.gmail.com>
Mime-Version: 1.0
Content-Type: text/html; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
X-Mailgun-Sid: WyIwOTY5OCIsICJyYW5keXdiZW5zb25AZ21haWwuY29tIiwgIjRjODIiXQ==
Sender:
[email protected]There you go. Thanks! Hope this helps. I'm not about to bite the bait from these characters.