Has someone offered you a huge sum of money or a valuable consignment? It's a 419 or advance fee fraud - find out how they work, and what to do to be safe.
by Faizan Docherty Thu Oct 02, 2014 7:48 pm
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 65.54.51.99
Originating ISP: Microsoft Hosting
City: Redmond
Country of Origin: United States
* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.76.168.38 with SMTP id zt6csp8730oab;
Wed, 1 Oct 2014 23:24:30 -0700 (PDT)
X-Received: by 10.66.145.133 with SMTP id su5mr85509561pab.11.1412231070322;
Wed, 01 Oct 2014 23:24:30 -0700 (PDT)
Return-Path: <[email protected]>
Received: from relay.mailchannels.net (aso-006-i429.relay.mailchannels.net. [174.136.13.86])
by mx.google.com with ESMTP id dd1si2954511pbc.122.2014.10.01.23.24.27
for <snipped>;
Wed, 01 Oct 2014 23:24:30 -0700 (PDT)
Received-SPF: softfail (google.com: domain of transitioning [email protected] does not designate 174.136.13.86 as permitted sender) client-ip=174.136.13.86;
Authentication-Results: mx.google.com;
spf=softfail (google.com: domain of transitioning [email protected] does not designate 174.136.13.86 as permitted sender) [email protected]
X-Sender-Id: _forwarded-from|65.55.90.200
Received: from r8-chicago.webserversystems.com (ip-10-237-13-110.us-west-2.compute.internal [10.237.13.110])
by relay.mailchannels.net (Postfix) with ESMTPA id 23DF9600BB
for <snipped>; Thu, 2 Oct 2014 06:24:24 +0000 (UTC)
X-Sender-Id: _forwarded-from|65.55.90.200
Received: from r8-chicago.webserversystems.com (r8-chicago.webserversystems.com [10.245.145.206])
(using TLSv1 with cipher DHE-RSA-AES256-SHA)
by 0.0.0.0:2500 (trex/5.2.14);
Thu, 02 Oct 2014 06:24:26 GMT
X-MC-Relay: Forwarding
X-MailChannels-SenderId: _forwarded-from|65.55.90.200
X-MailChannels-Auth-Id: wwwh
X-MC-Loop-Signature: 1412231066465:3600100221
X-MC-Ingress-Time: 1412231065609
Received: from snt004-omc4s48.hotmail.com ([65.54.51.99]:57996)
by r8-chicago.webserversystems.com with esmtps (TLSv1:AES256-SHA:256)
(Exim 4.82)
(envelope-from <[email protected]>)
id 1XZZoM-0009oX-5u
for <snipped>; Thu, 02 Oct 2014 01:24:22 -0500
Received: from SNT152-W50 ([65.55.90.200]) by SNT004-OMC4S48.hotmail.com over TLS secured channel with Microsoft SMTPSVC(7.5.7601.22751);
Wed, 1 Oct 2014 23:24:21 -0700
X-TMN: [nQsWcMnn3+8MMnvX/DiFPtmhbEyYdkYw]
X-Originating-Email: [[email protected]]
Message-ID: <[email protected]>
Content-Type: multipart/alternative;
boundary="_4915c49b-b51a-492d-8f52-7c43c60bf306_"
Reply-To: <[email protected]>
From: "Sylva A. Ayebide" <[email protected]>
Date: Thu, 2 Oct 2014 07:24:21 +0100
Importance: Normal
MIME-Version: 1.0
X-OriginalArrivalTime: 02 Oct 2014 06:24:21.0442 (UTC) FILETIME=[80D30A20:01CFDE09]
X-Spam-Status: Yes, score=7.0
X-Spam-Score: 70
X-Spam-Bar: +++++++
X-Spam-Report: Spam detection software, running on the system "r8-chicago.webserversystems.com", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
root\@localhost for details.

Content preview: Dear, Having gone through your remarkable profile, I decided
to solicit your support for a lucrative business. Kindly get back to me for
comprehensive details. I am waiting for your valued response. [...]

Content analysis details: (7.0 points, 5.0 required)

pts rule name description
---- ---------------------- --------------------------------------------------
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[65.54.51.99 listed in list.dnswl.org]
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider
(sylaybide[at]hotmail.com)
-0.0 SPF_PASS SPF: sender matches SPF record
-0.6 RP_MATCHES_RCVD Envelope sender domain matches handover relay domain
1.0 MISSING_HEADERS Missing To: header
0.0 HTML_MESSAGE BODY: HTML included in message
2.0 DCC_CHECK Detected as bulk mail by DCC (dcc-servers.net)
2.1 MALFORMED_FREEMAIL Bad headers on message from free email service
1.6 REPLYTO_WITHOUT_TO_CC REPLYTO_WITHOUT_TO_CC
1.0 FREEMAIL_REPLYTO Reply-To/From or Reply-To/body contain different
freemails
X-Spam-Flag: YES
Subject: ***SPAM*** Business Proposalþþ
X-MC-Forward: <snipped>
X-AuthUser:


Dear,

Having gone through your remarkable profile, I decided to solicit your support for a lucrative business. Kindly get back to me for comprehensive details.

I am waiting for your valued response.

Regards,

Mr. Sylva Ayebide

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
Advertisement

Who is online

Users browsing this forum: Bing [Bot], ClaudeBot, Google [Bot] and 33 guests