by Faizan Docherty
Tue Jan 06, 2015 8:42 pm
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 65.55.116.38
Originating ISP: Microsoft Hosting
City: Redmond
Country of Origin: United States
* For a complete report on this email header goto ipTRACKERonline
Delivered-To: <snipped>
Received: by 10.70.51.10 with SMTP id g10csp5005035pdo;
Tue, 6 Jan 2015 01:38:04 -0800 (PST)
X-Received: by 10.70.35.109 with SMTP id g13mr91364841pdj.17.1420537084359;
Tue, 06 Jan 2015 01:38:04 -0800 (PST)
Return-Path: <[email protected]>
Received: from relay.mailchannels.net (nov-007-i623.relay.mailchannels.net. [46.232.183.177])
by mx.google.com with ESMTP id or15si61074000pab.49.2015.01.06.01.38.01
for <snipped>;
Tue, 06 Jan 2015 01:38:04 -0800 (PST)
Received-SPF: softfail (google.com: domain of transitioning [email protected] does not designate 46.232.183.177 as permitted sender) client-ip=46.232.183.177;
Authentication-Results: mx.google.com;
spf=softfail (google.com: domain of transitioning [email protected] does not designate 46.232.183.177 as permitted sender) [email protected]
X-Sender-Id: _forwarded-from|65.55.116.8
Received: from r8-chicago.webserversystems.com (ip-10-33-12-218.us-west-2.compute.internal [10.33.12.218])
by relay.mailchannels.net (Postfix) with ESMTPA id 1D0CA1D086D
for <snipped>; Tue, 6 Jan 2015 09:37:58 +0000 (UTC)
X-Sender-Id: _forwarded-from|65.55.116.8
Received: from r8-chicago.webserversystems.com (r8-chicago.webserversystems.com [10.254.9.84])
(using TLSv1 with cipher DHE-RSA-AES256-SHA)
by 0.0.0.0:2500 (trex/5.4.2);
Tue, 06 Jan 2015 09:37:58 GMT
X-MC-Relay: Junk
X-MailChannels-SenderId: _forwarded-from|65.55.116.8
X-MailChannels-Auth-Id: wwwh
X-MC-Loop-Signature: 1420537078463:2217524503
X-MC-Ingress-Time: 1420537078463
Received: from blu004-omc1s27.hotmail.com ([65.55.116.38]:54933)
by r8-chicago.webserversystems.com with esmtps (TLSv1:AES256-SHA:256)
(Exim 4.82)
(envelope-from <[email protected]>)
id 1Y8QaK-000BLe-BF
for <snipped>; Tue, 06 Jan 2015 03:37:57 -0600
Received: from BLU168-W104 ([65.55.116.8]) by BLU004-OMC1S27.hotmail.com over TLS secured channel with Microsoft SMTPSVC(7.5.7601.22751);
Tue, 6 Jan 2015 01:37:01 -0800
X-TMN: [0hd2td6vRd3orWUy8fk0uCZdjBbtDoOn]
X-Originating-Email: [[email protected]]
Message-ID: <[email protected]>
Content-Type: multipart/alternative;
boundary="_2f1bc03c-a9f6-41ee-8523-77f9b7ec23c6_"
Reply-To: <[email protected]>
From: adoh koffi <[email protected]>
Date: Tue, 6 Jan 2015 09:37:00 +0000
Importance: Normal
MIME-Version: 1.0
X-OriginalArrivalTime: 06 Jan 2015 09:37:01.0113 (UTC) FILETIME=[5294DA90:01D02994]
X-Spam-Status: Yes, score=8.5
X-Spam-Score: 85
X-Spam-Bar: ++++++++
X-Spam-Report: Spam detection software, running on the system "r8-chicago.webserversystems.com", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
root\@localhost for details.
Content preview: Can you confirm if you are still using this email address?
There is information I think might interest you. I am Mr. ADOH KOFFI. First
of all, I do not know if I am talking to the right person, but I will like
you to confirm if you are the owner of this email ID. Already I have your
name and details in my file in the office, but I want to be sure if I am
communicating with the right owner of this email. [...]
Content analysis details: (8.5 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider
(adohkoffi2018[at]hotmail.com)
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[65.55.116.38 listed in list.dnswl.org]
-0.0 T_RP_MATCHES_RCVD Envelope sender domain matches handover relay
domain
-0.0 SPF_PASS SPF: sender matches SPF record
0.2 FREEMAIL_REPLYTO_END_DIGIT Reply-To freemail username ends in digit
(<adohkoffi1[at]yahoo.com>
)
0.2 FREEMAIL_ENVFROM_END_DIGIT Envelope-from freemail username ends in
digit (adohkoffi2018[at]hotmail.com)
1.0 MISSING_HEADERS Missing To: header
0.0 HTML_MESSAGE BODY: HTML included in message
2.0 DCC_CHECK Detected as bulk mail by DCC (dcc-servers.net)
2.5 MALFORMED_FREEMAIL Bad headers on message from free email service
1.6 REPLYTO_WITHOUT_TO_CC REPLYTO_WITHOUT_TO_CC
1.0 FREEMAIL_REPLYTO Reply-To/From or Reply-To/body contain different
freemails
X-Spam-Flag: YES
Subject: ***SPAM*** information
X-AuthUser:
Can you confirm if you are still using this email address?
There is information I think might interest you. I am Mr. ADOH KOFFI. First of all, I do not know if I am talking to the right person, but I will like you to confirm if you are the owner of this email ID. Already I have your name and details in my file in the office, but I want to be sure if I am communicating with the right owner of this email.
If you can prove that you are the owner of this email ID, I will like you to furnish me with your information to enable me cross-check it with the one I have so that I can be convince that I am talking to the right person. I am taking this preventive measure because I do not want to talk to the wrong person because of the sensitivity of the information regarding the issue. Other details will be forwarded to you as soon.
I am convinced that I am communicating with the right person.
Regards,
Mr.ADOH KOFFI
Please DO NOT tell a scammer that he has been posted here!
If you wish you can email me at
faizandocherty @ scamwarners [dot] com
How do I find email headers???
How to analyze an email header.
If you wish you can email me at
faizandocherty @ scamwarners [dot] com
How do I find email headers???
How to analyze an email header.