by Faizan Docherty
Fri Jan 16, 2015 1:56 pm
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 98.138.105.198
Originating ISP: Yahoo
City: Sunnyvale
Country of Origin: United States
* For a complete report on this email header goto ipTRACKERonline
Delivered-To: <snipped>
Received: by 10.70.51.10 with SMTP id g10csp290449pdo;
Fri, 16 Jan 2015 01:38:13 -0800 (PST)
X-Received: by 10.68.204.66 with SMTP id kw2mr20688258pbc.149.1421401093436;
Fri, 16 Jan 2015 01:38:13 -0800 (PST)
Return-Path: <[email protected]>
Received: from relay.mailchannels.net (aso-006-i414.relay.mailchannels.net. [207.210.193.23])
by mx.google.com with ESMTP id g2si4829294pdj.155.2015.01.16.01.38.12
for <snipped>;
Fri, 16 Jan 2015 01:38:13 -0800 (PST)
Received-SPF: none (google.com: [email protected] does not designate permitted sender hosts) client-ip=207.210.193.23;
Authentication-Results: mx.google.com;
spf=none (google.com: [email protected] does not designate permitted sender hosts) [email protected];
dkim=fail [email protected];
dmarc=fail (p=NONE dis=NONE) header.from=yahoo.fr
X-Sender-Id: _forwarded-from|98.138.90.152
Received: from r8-chicago.webserversystems.com (ip-10-237-13-110.us-west-2.compute.internal [10.237.13.110])
by relay.mailchannels.net (Postfix) with ESMTPA id 656161009DE
for <snipped>; Fri, 16 Jan 2015 09:38:10 +0000 (UTC)
X-Sender-Id: _forwarded-from|98.138.90.152
Received: from r8-chicago.webserversystems.com (r8-chicago.webserversystems.com [10.252.27.228])
(using TLSv1 with cipher DHE-RSA-AES256-SHA)
by 0.0.0.0:2500 (trex/5.4.2);
Fri, 16 Jan 2015 09:38:11 GMT
X-MC-Relay: Junk
X-MailChannels-SenderId: _forwarded-from|98.138.90.152
X-MailChannels-Auth-Id: wwwh
X-MC-Loop-Signature: 1421401090982:3387651295
X-MC-Ingress-Time: 1421401090599
Received: from nm4-vm2.bullet.mail.ne1.yahoo.com ([98.138.90.152]:55264)
by r8-chicago.webserversystems.com with esmtps (TLSv1:RC4-SHA:128)
(Exim 4.82)
(envelope-from <[email protected]>)
id 1YC3M1-0009Rs-2V
for <snipped>; Fri, 16 Jan 2015 03:38:09 -0600
DKIM-Signature: <snipped>
Received: from [98.138.226.180] by nm4.bullet.mail.ne1.yahoo.com with NNFMP; 16 Jan 2015 09:38:08 -0000
Received: from [98.138.89.175] by tm15.bullet.mail.ne1.yahoo.com with NNFMP; 16 Jan 2015 09:38:08 -0000
Received: from [127.0.0.1] by omp1031.mail.ne1.yahoo.com with NNFMP; 16 Jan 2015 09:38:08 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: [email protected]
X-YMail-OSG: <snipped>
Received: by 98.138.105.198; Fri, 16 Jan 2015 09:38:07 +0000
Date: Fri, 16 Jan 2015 09:38:07 +0000 (UTC)
From: Deep martine <[email protected]>
Reply-To: Deep martine <[email protected]>
Message-ID: <901355656.1227363.1421401087373.JavaMail.yahoo@jws10065.mail.ne1.yahoo.com>
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_Part_1227362_832490712.1421401087370"
X-Spam-Status: Yes, score=5.7
X-Spam-Score: 57
X-Spam-Bar: +++++
X-Spam-Report: Spam detection software, running on the system "r8-chicago.webserversystems.com", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
root\@localhost for details.
Content preview: Olá Para começar eu teria de me apresentar: I Martine DeepÂ
Profundo 84 anos a nacionalidade francesa. viúva sem filhos! Eu sou doente
hospitalizado em uma inglesa hospital, eu sofro de carcinoma de células
escamosas é doente terminal e meu médico apenas me informou que meus dias
estão contados por causa do meu estado de saúde se deteriorou e eu vou
você legar minha herança passando de um valor de 2,045 milhões dólaresÂ
(dólares) para ajudar os pobres, os órfãos e eu serei feliz ao ler você
na minha caixa de correio:Â [email protected] [...]
Content analysis details: (5.7 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider
(toporavel[at]yahoo.ca)
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[98.138.90.152 listed in list.dnswl.org]
1.0 MISSING_HEADERS Missing To: header
0.2 BAYES_999 BODY: Bayes spam probability is 99.9 to 100%
[score: 1.0000]
0.0 HTML_MESSAGE BODY: HTML included in message
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's
domain
2.0 DCC_CHECK Detected as bulk mail by DCC (dcc-servers.net)
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid
1.0 MALFORMED_FREEMAIL Bad headers on message from free email service
1.6 REPLYTO_WITHOUT_TO_CC REPLYTO_WITHOUT_TO_CC
X-Spam-Flag: YES
Subject: ***SPAM*** OFERTA de minha herança
X-AuthUser:
Olá
Para começar eu teria de me apresentar: I Martine Deep Profundo 84 anos a nacionalidade francesa. viúva sem filhos! Eu sou doente hospitalizado em uma inglesa hospital, eu sofro de carcinoma de células escamosas é doente terminal e meu médico apenas me informou que meus dias estão contados por causa do meu estado de saúde se deteriorou e eu vou você legar minha herança passando de um valor de 2,045 milhões dólares (dólares) para ajudar os pobres, os órfãos e eu serei feliz ao ler você na minha caixa de correio: [email protected]
Google translation:
Hello
To begin I would have to introduce myself: I Martine Deep Deep 84 years of French nationality. childless widow! I'm sick hospitalized in an English hospital, I suffer from squamous cell carcinoma is terminally ill and my doctor just informed me that my days are numbered because of my health deteriorated and I'll leave you my heritage going from a value of $ 2.045 million (dollars) to help the poor, orphans and I will be happy to read you in my mailbox: [email protected]
Please DO NOT tell a scammer that he has been posted here!
If you wish you can email me at
faizandocherty @ scamwarners [dot] com
How do I find email headers???
How to analyze an email header.
If you wish you can email me at
faizandocherty @ scamwarners [dot] com
How do I find email headers???
How to analyze an email header.