by Faizan Docherty
Wed Apr 08, 2015 8:04 pm
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 209.85.223.194
Originating ISP: Google
City: Farmington
Country of Origin: United States
* For a complete report on this email header goto ipTRACKERonline
Delivered-To: <snipped>
Received: by 10.70.138.105 with SMTP id qp9csp4433418pdb;
Tue, 7 Apr 2015 22:50:41 -0700 (PDT)
X-Received: by 10.70.62.97 with SMTP id x1mr7687077pdr.41.1428472240717;
Tue, 07 Apr 2015 22:50:40 -0700 (PDT)
Return-Path: <[email protected]>
Received: from relay.mailchannels.net (ftx-008-i893.relay.mailchannels.net. [50.61.143.193])
by mx.google.com with ESMTP id lw6si14875471pab.229.2015.04.07.22.50.39
for <snipped>;
Tue, 07 Apr 2015 22:50:40 -0700 (PDT)
Received-SPF: softfail (google.com: domain of transitioning [email protected] does not designate 50.61.143.193 as permitted sender) client-ip=50.61.143.193;
Authentication-Results: mx.google.com;
spf=softfail (google.com: domain of transitioning [email protected] does not designate 50.61.143.193 as permitted sender) [email protected];
dkim=pass [email protected];
dmarc=pass (p=NONE dis=NONE) header.from=gmail.com
X-Sender-Id: _forwarded-from|209.85.223.194
Received: from r8-chicago.webserversystems.com (ip-10-204-4-183.us-west-2.compute.internal [10.204.4.183])
by relay.mailchannels.net (Postfix) with ESMTPA id 4E380100A38
for <snipped>; Wed, 8 Apr 2015 05:50:37 +0000 (UTC)
X-Sender-Id: _forwarded-from|209.85.223.194
Received: from r8-chicago.webserversystems.com (r8-chicago.webserversystems.com [10.21.145.197])
(using TLSv1 with cipher DHE-RSA-AES256-SHA)
by 0.0.0.0:2500 (trex/5.4.8 );
Wed, 08 Apr 2015 05:50:37 +0000
X-MC-Relay: Forwarding
X-MailChannels-SenderId: _forwarded-from|209.85.223.194
X-MailChannels-Auth-Id: wwwh
X-MC-Loop-Signature: 1428472237486:907192131
X-MC-Ingress-Time: 1428472237486
Received: from mail-ie0-f194.google.com ([209.85.223.194]:35480)
by r8-chicago.webserversystems.com with esmtps (TLSv1:RC4-SHA:128)
(Exim 4.82)
(envelope-from <[email protected]>)
id 1Yfisl-0003lf-7b
for <snipped>; Wed, 08 Apr 2015 00:50:36 -0500
Received: by iery20 with SMTP id y20so4014869ier.2
for <snipped>; Tue, 07 Apr 2015 22:50:34 -0700 (PDT)
DKIM-Signature: <snipped>
MIME-Version: 1.0
X-Received: by 10.43.61.80 with SMTP id wv16mt1502614icb.97.1428472234316;
Tue, 07 Apr 2015 22:50:34 -0700 (PDT)
Received: by 10.50.177.101 with HTTP; Tue, 7 Apr 2015 22:50:34 -0700 (PDT)
Date: Wed, 8 Apr 2015 07:50:34 +0200
Message-ID: <CAHFWAgFQ4YN8CpicmmNhnLNvMTwyRfSOJiCstW954E1+GOPNNw@mail.gmail.com>
Subject: loan
From: banks credit <[email protected]>
Cc: <snipped>
Content-Type: text/plain; charset=UTF-8
X-Spam-Status: No, score=0.5
X-Spam-Score: 5
X-Spam-Bar: /
X-Ham-Report: Spam detection software, running on the system "r8-chicago.webserversystems.com", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
root\@localhost for details.
Content preview: Hello Mr and Mrs This message caters to individuals, the poor,
or to all those who are in need of a particular loan to rebuild their lives.
you are looking for loan to revive your activities either for a project,
either for buying an apartment but you are forbidden Bank or your folder in
summer rejected Bank. I am an individual and I makes loans ranging from 2,000
to 5,000,000 persons able to meet the conditions. I am not a Bank and I does
not require many documents to trust you, but you must be a person just, honest,
wise and reliable. I grants loans to people alive in all Europe and in the
world Entier.Si you need money for other reasons, do not hesitate to contact
me for more information. I am available to meet my clients in a maximum of
72 hours of receipt of your application form. If you are interested, contact
me for more information. [...]
Content analysis details: (0.5 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
-0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at http://www.dnswl.org/, low
trust
[209.85.223.194 listed in list.dnswl.org]
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider
(bankscredit02[at]gmail.com)
-0.0 SPF_PASS SPF: sender matches SPF record
0.2 FREEMAIL_ENVFROM_END_DIGIT Envelope-from freemail username ends in
digit (bankscredit02[at]gmail.com)
1.0 MISSING_HEADERS Missing To: header
0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked.
See
http://wiki.apache.org/spamassassin/Dns ... nsbl-block
for more information.
[URIs: entier.si]
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's
domain
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid
X-Spam-Flag: NO
X-AuthUser:
Hello Mr and Mrs
This message caters to individuals, the poor, or to all those who are
in need of
a particular loan to rebuild their lives.
you are looking for loan to revive your activities either for a project, either
for buying an apartment but you are forbidden Bank or your folder in summer
rejected Bank. I am an individual and I makes loans ranging from 2,000 to
5,000,000 persons able to meet the conditions. I am not a Bank and I does not
require many documents to trust you, but you must be a person just,
honest, wise
and reliable. I grants loans to people alive in all Europe and in the world
Entier.Si you need money for other reasons, do not hesitate to contact me for
more information. I am available to meet my clients in a maximum of 72 hours of
receipt of your application form. If you are interested, contact me for more
information.
Please DO NOT tell a scammer that he has been posted here!
If you wish you can email me at
faizandocherty @ scamwarners [dot] com
How do I find email headers???
How to analyze an email header.
If you wish you can email me at
faizandocherty @ scamwarners [dot] com
How do I find email headers???
How to analyze an email header.