by buried under 419s
Sat Sep 08, 2012 3:22 am
Return-path: <[email protected]>
Envelope-to:
Delivery-date: Sat, 08 Sep 2012 00:15:13 -0700
Received: from [210.211.125.184] (port=3984 helo=glhost36.gltec.net)
by with esmtps (SSLv3:AES256-SHA:256)
(Exim 4.77)
(envelope-from <[email protected]>)
id 1TAFG2-0004gJ-80
for ; Sat, 08 Sep 2012 00:15:13 -0700
Received: from localhost ([127.0.0.1])
by glhost36.gltec.net (IceWarp 9.1.0) with SMTP id SQX56607;
Sat, 08 Sep 2012 14:15:07 +0700
Date: Sat, 08 Sep 2012 15:15:07 +0800
From: [email protected]
Reply-To: [email protected]
Message-ID: <[email protected]>
X-Mailer: IceWarp Web Mail 5.6.7
X-Originating-IP: 41.203.65.217
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 8bit
X-Spam-Status: Yes, score=7.8
X-Spam-Score: 78
X-Spam-Bar: +++++++
X-Spam-Report: Spam detection software, running on the system "", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: Get reliable loan offer for 2.99% interest rate Monthly. Reply
for details [...]
Content analysis details: (7.8 points, 7.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider
(leonard.firms[at]gmail.com)
1.3 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net
[Blocked - see <http://www.spamcop.net/bl.shtml?41.203.65.217>]
0.0 RCVD_IN_SORBS_DUL RBL: SORBS: sent directly from dynamic IP address
[210.211.125.184 listed in dnsbl.sorbs.net]
0.8 RCVD_IN_SORBS_WEB RBL: SORBS: sender is an abusable web server
[41.203.65.217 listed in dnsbl.sorbs.net]
1.5 SUBJ_ALL_CAPS Subject is all capitals
-0.0 SPF_PASS SPF: sender matches SPF record
1.0 MISSING_HEADERS Missing To: header
0.8 BAYES_50 BODY: Bayes spam probability is 40 to 60%
[score: 0.5040]
1.6 REPLYTO_WITHOUT_TO_CC REPLYTO_WITHOUT_TO_CC
0.8 RDNS_NONE Delivered to internal network by a host with no rDNS
X-Spam-Flag: YES
Subject: ***SPAM*** LOAN OFFER!
Get reliable loan offer for 2.99% interest rate Monthly. Reply for details
Envelope-to:
Delivery-date: Sat, 08 Sep 2012 00:15:13 -0700
Received: from [210.211.125.184] (port=3984 helo=glhost36.gltec.net)
by with esmtps (SSLv3:AES256-SHA:256)
(Exim 4.77)
(envelope-from <[email protected]>)
id 1TAFG2-0004gJ-80
for ; Sat, 08 Sep 2012 00:15:13 -0700
Received: from localhost ([127.0.0.1])
by glhost36.gltec.net (IceWarp 9.1.0) with SMTP id SQX56607;
Sat, 08 Sep 2012 14:15:07 +0700
Date: Sat, 08 Sep 2012 15:15:07 +0800
From: [email protected]
Reply-To: [email protected]
Message-ID: <[email protected]>
X-Mailer: IceWarp Web Mail 5.6.7
X-Originating-IP: 41.203.65.217
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 8bit
X-Spam-Status: Yes, score=7.8
X-Spam-Score: 78
X-Spam-Bar: +++++++
X-Spam-Report: Spam detection software, running on the system "", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: Get reliable loan offer for 2.99% interest rate Monthly. Reply
for details [...]
Content analysis details: (7.8 points, 7.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider
(leonard.firms[at]gmail.com)
1.3 RCVD_IN_BL_SPAMCOP_NET RBL: Received via a relay in bl.spamcop.net
[Blocked - see <http://www.spamcop.net/bl.shtml?41.203.65.217>]
0.0 RCVD_IN_SORBS_DUL RBL: SORBS: sent directly from dynamic IP address
[210.211.125.184 listed in dnsbl.sorbs.net]
0.8 RCVD_IN_SORBS_WEB RBL: SORBS: sender is an abusable web server
[41.203.65.217 listed in dnsbl.sorbs.net]
1.5 SUBJ_ALL_CAPS Subject is all capitals
-0.0 SPF_PASS SPF: sender matches SPF record
1.0 MISSING_HEADERS Missing To: header
0.8 BAYES_50 BODY: Bayes spam probability is 40 to 60%
[score: 0.5040]
1.6 REPLYTO_WITHOUT_TO_CC REPLYTO_WITHOUT_TO_CC
0.8 RDNS_NONE Delivered to internal network by a host with no rDNS
X-Spam-Flag: YES
Subject: ***SPAM*** LOAN OFFER!
Get reliable loan offer for 2.99% interest rate Monthly. Reply for details
Questions about scams? fraudatiocruor @ gmail.com to contact remove spaces