Has someone offered you a huge sum of money or a valuable consignment? It's a 419 or advance fee fraud - find out how they work, and what to do to be safe.
by Faizan Docherty Sun Oct 26, 2014 9:40 am
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 65.55.116.111
Originating ISP: Microsoft Hosting
City: Redmond
Country of Origin: United States
* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.70.125.234 with SMTP id mt10csp161184pdb;
Sun, 26 Oct 2014 06:02:39 -0700 (PDT)
X-Received: by 10.70.130.81 with SMTP id oc17mr1793157pdb.48.1414328559322;
Sun, 26 Oct 2014 06:02:39 -0700 (PDT)
Return-Path: <[email protected]>
Received: from relay.mailchannels.net (si-002-i152.relay.mailchannels.net. [108.178.49.164])
by mx.google.com with ESMTP id ln4si8265829pab.151.2014.10.26.06.02.38
for <snipped>;
Sun, 26 Oct 2014 06:02:39 -0700 (PDT)
Received-SPF: fail (google.com: domain of [email protected] does not designate 108.178.49.164 as permitted sender) client-ip=108.178.49.164;
Authentication-Results: mx.google.com;
spf=hardfail (google.com: domain of [email protected] does not designate 108.178.49.164 as permitted sender) [email protected]
X-Sender-Id: _forwarded-from|65.55.116.72
Received: from r8-chicago.webserversystems.com (ip-10-220-9-73.us-west-2.compute.internal [10.220.9.73])
by relay.mailchannels.net (Postfix) with ESMTPA id 7A5B91206B0
for <snipped>; Sun, 26 Oct 2014 13:02:25 +0000 (UTC)
X-Sender-Id: _forwarded-from|65.55.116.72
Received: from r8-chicago.webserversystems.com (r8-chicago.webserversystems.com [10.216.27.60])
(using TLSv1 with cipher DHE-RSA-AES256-SHA)
by 0.0.0.0:2500 (trex/5.3.2);
Sun, 26 Oct 2014 13:02:25 GMT
X-MC-Relay: Forwarding
X-MailChannels-SenderId: _forwarded-from|65.55.116.72
X-MailChannels-Auth-Id: wwwh
X-MC-Loop-Signature: 1414328545708:3127724626
X-MC-Ingress-Time: 1414328545707
Received: from blu004-omc3s36.hotmail.com ([65.55.116.111]:63195)
by r8-chicago.webserversystems.com with esmtps (TLSv1:AES256-SHA:256)
(Exim 4.82)
(envelope-from <[email protected]>)
id 1XiNSh-00093y-Py
for <snipped>; Sun, 26 Oct 2014 08:02:24 -0500
Received: from BLU181-W87 ([65.55.116.72]) by BLU004-OMC3S36.hotmail.com over TLS secured channel with Microsoft SMTPSVC(7.5.7601.22751);
Sun, 26 Oct 2014 06:02:22 -0700
X-TMN: [jlmB2hI27hVHkmHdKtOFSCucmEagvTyt]
X-Originating-Email: [[email protected]]
Message-ID: <[email protected]>
Content-Type: multipart/alternative;
boundary="_19c4f864-aa96-4da8-aaa8-c916a7c7e32c_"
From: Ahmad Farid <[email protected]>
Sender: <[email protected]>
Subject: from Ahmad
Date: Sun, 26 Oct 2014 13:02:22 +0000
Importance: Normal
MIME-Version: 1.0
X-OriginalArrivalTime: 26 Oct 2014 13:02:22.0752 (UTC) FILETIME=[151BC200:01CFF11D]
X-Spam-Status: No, score=3.0
X-Spam-Score: 30
X-Spam-Bar: +++
X-Ham-Report: Spam detection software, running on the system "r8-chicago.webserversystems.com", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
root\@localhost for details.

Content preview: Hello Friend, Assalamualaikum, My names are Ahmad Farid, a
legal practitioner at AHMAD FARID & ASSOCIATES. A legal firm based in Kedah,
Malaysia. I have a business proposal which I will like to discuss with you.
Kindly get back to me if you wish for more information regarding my proposal.
[...]

Content analysis details: (3.0 points, 5.0 required)

pts rule name description
---- ---------------------- --------------------------------------------------
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider
(anuarbinahmad[at]lawyer.com)
0.0 SPF_FAIL SPF: sender does not match SPF record (fail)
[SPF failed: Please see http://www.openspf.net/Why?s=mfrom;id=a ... ystems.com]
1.0 MISSING_HEADERS Missing To: header
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[65.55.116.111 listed in list.dnswl.org]
0.0 HTML_MESSAGE BODY: HTML included in message
2.0 DCC_CHECK Detected as bulk mail by DCC (dcc-servers.net)
X-Spam-Flag: NO
X-MC-Forward: <snipped>
X-AuthUser:


Hello Friend,
Assalamualaikum,

My names are Ahmad Farid, a legal practitioner at AHMAD FARID & ASSOCIATES. A legal firm based in Kedah, Malaysia. I have a business proposal which I will like to discuss with you. Kindly get back to me if you wish for more information regarding my proposal.

Regards,
AHMAD FARID

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
Advertisement

Who is online

Users browsing this forum: ClaudeBot, Google [Bot] and 19 guests