Has someone offered you a huge sum of money or a valuable consignment? It's a 419 or advance fee fraud - find out how they work, and what to do to be safe.
by Faizan Docherty Sat Feb 07, 2015 9:45 pm
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 202.4.7.9
Originating ISP: Asian Development Bank
City: Manila
Country of Origin: Philippines
* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.70.123.164 with SMTP id mb4csp2184278pdb;
Sat, 7 Feb 2015 02:04:39 -0800 (PST)
X-Received: by 10.68.227.201 with SMTP id sc9mr12662798pbc.19.1423303479493;
Sat, 07 Feb 2015 02:04:39 -0800 (PST)
Return-Path: <[email protected]>
Received: from relay.mailchannels.net (aso-006-i429.relay.mailchannels.net. [174.136.13.86])
by mx.google.com with ESMTP id pi10si13474368pdb.164.2015.02.07.02.04.38
for <snipped>;
Sat, 07 Feb 2015 02:04:39 -0800 (PST)
Received-SPF: none (google.com: [email protected] does not designate permitted sender hosts) client-ip=174.136.13.86;
Authentication-Results: mx.google.com;
spf=none (google.com: [email protected] does not designate permitted sender hosts) [email protected]
X-Sender-Id: _forwarded-from|202.4.7.9
Received: from r8-chicago.webserversystems.com (ip-10-220-9-73.us-west-2.compute.internal [10.220.9.73])
by relay.mailchannels.net (Postfix) with ESMTPA id A0EDC1D0355
for <snipped>; Sat, 7 Feb 2015 10:04:37 +0000 (UTC)
X-Sender-Id: _forwarded-from|202.4.7.9
Received: from r8-chicago.webserversystems.com (r8-chicago.webserversystems.com [10.254.9.84])
(using TLSv1 with cipher DHE-RSA-AES256-SHA)
by 0.0.0.0:2500 (trex/5.4.3);
Sat, 07 Feb 2015 10:04:37 GMT
X-MC-Relay: Forwarding
X-MailChannels-SenderId: _forwarded-from|202.4.7.9
X-MailChannels-Auth-Id: wwwh
X-MC-Loop-Signature: 1423303477818:4222190293
X-MC-Ingress-Time: 1423303477817
Received: from ipmailgw1.adb.org ([202.4.7.9]:10286)
by r8-chicago.webserversystems.com with esmtp (Exim 4.82)
(envelope-from <[email protected]>)
id 1YK2Ff-0003LC-AI
for <snipped>; Sat, 07 Feb 2015 04:04:36 -0600
X-ExtLoop1: 1
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: <snipped>
X-IPAS-Result: <snipped>
Subject: [SPAM] RE
X-IronPort-AV: E=Sophos;i="5.09,534,1418054400";
d="scan'208";a="33283889"
Received: from adbmail4.asiandevbank.org ([172.23.8.13])
by ipmailgw1.adb.org with ESMTP; 07 Feb 2015 18:04:33 +0800
MIME-Version: 1.0
Importance: Normal
X-Priority: 3 (Normal)
In-Reply-To:
References:
From: [email protected]
Date: Sat, 7 Feb 2015 12:01:45 +0800
Message-ID: <OFDCAEEE81.DFCD6B9C-ON48257DE5.001621FE-48257DE5.00162228@adb.org>
Content-Type: multipart/alternative; boundary="=_alternative 0016220048257DE5_="
X-Notes-Item: <snipped>; name=AltBlindCopyTo
X-Spam-Status: No, score=0.3
X-Spam-Score: 3
X-Spam-Bar: /
X-Ham-Report: Spam detection software, running on the system "r8-chicago.webserversystems.com", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
root\@localhost for details.

Content preview: I'm J. Kelly from the US. I need your help please to help
me invest my money in charity homes. Reply me at my personal email at: [email protected]
I'm J. Kelly from the US. I need your help please to help me invest my money
in charity homes. Reply me at my personal email at: [email protected]
[...]

Content analysis details: (0.3 points, 5.0 required)

pts rule name description
---- ---------------------- --------------------------------------------------
-2.3 RCVD_IN_DNSWL_MED RBL: Sender listed at http://www.dnswl.org/, medium
trust
[202.4.7.9 listed in list.dnswl.org]
-0.0 T_RP_MATCHES_RCVD Envelope sender domain matches handover relay
domain
1.5 DATE_IN_PAST_06_12 Date: is 6 to 12 hours before Received: date
1.0 MISSING_HEADERS Missing To: header
0.0 HTML_MESSAGE BODY: HTML included in message
X-Spam-Flag: NO
X-AuthUser:


I'm J. Kelly from the US. I need your help please to help me invest my money in charity homes. Reply me at my personal email at: [email protected]

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
Advertisement

Who is online

Users browsing this forum: ClaudeBot and 31 guests