Delivered-To:
<snipped>Received: by 10.70.126.40 with SMTP id mv8csp25285pdb;
Thu, 23 Jan 2014 21:08:56 -0800 (PST)
X-Received: by 10.50.222.99 with SMTP id ql3mr2769600igc.42.1390540135917;
Thu, 23 Jan 2014 21:08:55 -0800 (PST)
Return-Path: <
[email protected]>
Received: from r8-chicago.webserversystems.com (r8-chicago.webserversystems.com. [184.154.1.124])
by mx.google.com with ESMTPS id jc1si2537437igb.69.2014.01.23.21.08.55
for
<snipped> (version=TLSv1 cipher=RC4-SHA bits=128/128);
Thu, 23 Jan 2014 21:08:55 -0800 (PST)
Received-SPF: fail (google.com: domain of
[email protected] does not designate 184.154.1.124 as permitted sender) client-ip=184.154.1.124;
Authentication-Results: mx.google.com;
spf=hardfail (google.com: domain of
[email protected] does not designate 184.154.1.124 as permitted sender)
[email protected]Received: from emea01-db3-ndr.ptr.protection.outlook.com ([157.56.120.101]:30447 helo=emea01-db3-obe.outbound.protection.outlook.com)
by r8-chicago.webserversystems.com with esmtps (TLSv1:AES128-SHA:128)
(Exim 4.80)
(envelope-from <
[email protected]>)
id 1W6Z0g-0002R3-2z
for
<snipped>; Thu, 23 Jan 2014 23:08:55 -0600
Received: from [116.203.247.108] (116.203.247.108) by
SIXPR01MB207.apcprd01.prod.exchangelabs.com (10.242.151.145) with Microsoft
SMTP Server (TLS) id 15.0.847.13; Fri, 24 Jan 2014 05:08:47 +0000
Content-Type: text/plain; charset="iso-8859-1"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Content-Description: Mail message body
To: Recipients <
[email protected]>
From: Bayford Bayford <
[email protected]>
Date: Fri, 24 Jan 2014 10:38:13 +0530
Reply-To: <[email protected]>Message-ID: <15612574-1942-424f-96f6-69609d4cf436@SIXPR01MB207.apcprd01.prod.exchangelabs.com>
X-Originating-IP: [116.203.247.108]
X-ClientProxiedBy: CO1PR07CA018.namprd07.prod.outlook.com (10.141.49.48) To
SIXPR01MB207.apcprd01.prod.exchangelabs.com (10.242.151.145)
X-Forefront-PRVS: 01018CB5B3
X-Forefront-Antispam-Report: SFV:SPM;SFS:(10019001)(6049001)(6009001)(6039001)(189002)(199002)(53256004)(87266001)(76786001)(77096001)(79102001)(81816001)(63696002)(81542001)(69226001)(59766001)(43066001)(86442001)(77982001)(85306002)(54316002)(49866001)(56776001)(15975445006)(76796001)(74502001)(81342001)(221733001)(47446002)(42186004)(15202345003)(65816001)(47736001)(47976001)(80022001)(19580395003)(50466002)(85852003)(76482001)(4396001)(46102001)(54356001)(66066001)(50986001)(83322001)(86362001)(86372001)(64872005)(1496005)(74706001)(51856001)(92726001)(33646001)(74876001)(74316001)(81686001)(80976001)(74662001)(83072002)(56816005)(47776003)(23756003)(93136001)(74366001)(89136003)(87976001)(94316002)(93516002)(90146001)(76176001)(62346011);DIR:OUT;SFP:1501;SCL:5;SRVR:SIXPR01MB207;H:[116.203.247.108];CLIP:116.203.247.108;FPR:;RD:InfoNoRecords;MX:1;A:0;LANG:en;
X-OriginatorOrg: ZZZZ201.onmicrosoft.com
X-Spam-Status: Yes, score=12.8
X-Spam-Score: 128
X-Spam-Bar: ++++++++++++
X-Spam-Report: Spam detection software, running on the system "r8-chicago.webserversystems.com", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
root\@localhost for details.
Content preview: My wife and I Bayford won Jackpot Lottery and Decided to donate
$2million USD to you, for more details CONTACT:Announcer: Noval Suryadi and
For Confirmation Click on the link below:
http://www.dailymail.co.uk/news/article ... t-get.html [...]
Content analysis details: (12.8 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at
http://www.dnswl.org/, no
trust
[157.56.120.101 listed in list.dnswl.org]
2.5 MILLION_USD BODY: Talks about millions of dollars
3.4 AXB_X_FF_SEZ_S Forefront sez this is spam
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider
(rururu[at]zzzz201.onmicrosoft.com)
-0.0 SPF_HELO_PASS SPF: HELO matches SPF record
-0.0 SPF_PASS SPF: sender matches SPF record
0.2 FREEMAIL_REPLYTO_END_DIGIT Reply-To freemail username ends in digit
(<bayford00[at]hotmail.com>
)
2.0 DCC_CHECK Detected as bulk mail by DCC (dcc-servers.net)
0.0 LOTS_OF_MONEY Huge... sums of money
3.2 AXB_ONMS_LEAKS Onmicrosoft Leak Party
1.0 FREEMAIL_REPLYTO Reply-To/From or Reply-To/body contain different
freemails
0.5 CRM114_PROB_SPAM CRM114: CRM114_PROB_SPAM
X-Spam-Flag: YES
Subject:
***SPAM*** DonationX-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - r8-chicago.webserversystems.com
X-AntiAbuse: Original Domain -
<snipped>X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - ZZZZ201.onmicrosoft.com
X-Get-Message-Sender-Via: r8-chicago.webserversystems.com: none
X-Source:
X-Source-Args:
X-Source-Dir: