Received 21 Aug 2025 10:14:39 -0400. Message is a deceptive “Please check your account” notice with ...
show moreReceived 21 Aug 2025 10:14:39 -0400. Message is a deceptive “Please check your account” notice with bogus balance claims and credential-harvest/monetized links (incl. Google Storage URLs). Sent from 172.245.92.116 (ESMTPS) with a forged chain (“localhost” at uic.edu; Reply-To at *.uic.edu). The “From” display name used the recipient’s name falsely. Auth: SPF=pass for return@…deparamily.com (unrelated to header From); DKIM=permerror (no key for d=otmp…net); DMARC=no result observed/likely misaligned. Indicators strongly suggest bulk phishing/spam. Likely violates CAN-SPAM (15 U.S.C. §7701 et seq.); credential theft could implicate 18 U.S.C. §1343 (wire fraud) and §1030 (CFAA). RFCs implicated: 5322 (misleading From), 7489 (DMARC misalignment), 6376 (invalid DKIM). Please investigate and terminate this abuse.
show less
Unsolicited bulk email received on 2025-08-21 09:17 EDT. Delivered to Gmail from 50.3.139.164 (bins. ...
show moreUnsolicited bulk email received on 2025-08-21 09:17 EDT. Delivered to Gmail from 50.3.139.164 (bins.syllabore.com); Subject “Built for All Seasons – See How Leafguard Works”; randomized From <…@4ykstg.c7l6g3.9qlc3x.us>. Body is promotional HTML with obfuscated links + filler gibberish and “activate your account/password stored” bait—classic spam/phishing kit. Auth: SPF PASS ([email protected]
); DKIM PERMERROR (no key) for 4ykstg.c7l6g3.9qlc3x.us; DMARC absent. RFC issues: missing original Message-ID (Gmail inserted SMTPIN_ADDED_MISSING; RFC 5322), misuse of multipart/report for marketing (RFC 6522), broken DKIM (RFC 6376). Likely CAN-SPAM violations (deceptive headers, unsolicited ads, unreliable opt-out); potential FTC Act §5 deception. Ongoing abuse from this network despite prior complaints. Provider: Eonix Corporation (AS49532) — abuse: [email protected]
, [email protected]
, +1-702-605-2981.
show less
Received Aug 21, 2025 05:24 EDT. Unsolicited bulk email claiming a $2,000 “direct deposit” leading t ...
show moreReceived Aug 21, 2025 05:24 EDT. Unsolicited bulk email claiming a $2,000 “direct deposit” leading to promo/gambling links (iWin Fortune, “bonus up to 2000 + 145 free spins”), designed to induce clicks and harvest data. The From field used the recipient’s name falsely; envelope sender and HELO/IP (134.195.196.224) do not align with visible From. Auth: SPF=pass for responsingle.com; DKIM=permerror (no key) for ul4zfj.us; DMARC=not aligned/likely fail (From domain differs from SPF/DKIM). Protocol issues: misleading headers vs RFC 5322 (From semantics); DMARC alignment (RFC 7489) not met; DKIM invalid (RFC 6376). Likely violates CAN-SPAM (15 U.S.C. §7704: deceptive subject/headers, missing valid postal address/opt-out) and may constitute wire fraud (18 U.S.C. §1343). Network owner: GLOBALTELEHOST Corp (GTHost). Abuse: [email protected], phone +1-855-550-1010.
show less
Received 2025-08-20 17:51:19 PDT. Mass phishing/lure: subject claims a $5,000 direct deposit and urg ...
show moreReceived 2025-08-20 17:51:19 PDT. Mass phishing/lure: subject claims a $5,000 direct deposit and urges “Confirm ID/PayOut”; HTML is junked with newsletter boilerplate, base64 blobs and obfuscated links (e.g., storage.googleapis.com), plus a forged “Reply-To” at a pseudo *.uic.edu subdomain. Auth: SPF=PASS but on unrelated envelope domain (orbit-veil.zyntheron.amazon-row.com); DKIM=PERMERROR (no key) for dnqwdgetpycasiuckqgogfhjvc.net; DMARC not aligned/likely none→fail. Headers show forged “Received: from localhost by uic.edu”, inconsistent dates, ARC cv=none. Sending IP 209.126.113.7 belongs to Liquid Web, L.L.C — [email protected], +1-800-580-4985. Violates CAN-SPAM (15 U.S.C. §7704 deceptive header/subject) and 18 U.S.C. §1343 (wire fraud); also non-conformant with RFC 5321/5322. Spam persists despite complaints to host.
show less
Received on Aug 20, 2025 at 7:25:49 PM ET. Malicious “account check / payout” spam: subject urges ur ...
show moreReceived on Aug 20, 2025 at 7:25:49 PM ET. Malicious “account check / payout” spam: subject urges urgent action and claims a final message with an $8,500 payout, pushing a “Confirm Here” click that hides behind obfuscated HTML and a storage.googleapis.com redirect. The From field used the recipient’s name falsely. Auth results: SPF PASS for [email protected] via 81.7.11.48; DKIM PERMERROR (no key) for s2es1f.yap26e.uvnxxo.us; DMARC alignment fails (From domain mismatches SPF/DKIM). Violations: CAN-SPAM (misleading headers/identity, deceptive content, inadequate sender identification) and potentially 18 U.S.C. §1343 (wire fraud) due to deceptive scheme. Standards issues: RFC 6376 (invalid DKIM), RFC 7489 (DMARC misalignment), and RFC 5322 intent (misleading From). Prior complaints to this host have not stopped the abuse; spam continues.
show less
Received 2025-08-20 18:59:29 −0400. Unsolicited gambling promo “Casino4You” with a deceptive subject ...
show moreReceived 2025-08-20 18:59:29 −0400. Unsolicited gambling promo “Casino4You” with a deceptive subject (“Generous bonuses and huge winnings…”) pushing clicks to “Confirm Your Info,” payout verification, and coupon code; body includes heavy obfuscation/random strings.
Auth: SPF pass for [email protected]
via 81.7.11.77 but not aligned with From=ibsvuz.f08i9j.r77h5q.us; DKIM permerror/no key; DMARC not shown and alignment fails.
Path shows delivery by appendad.net [81.7.11.77] to Google MX, with earlier hop njmta-53.sailthru.com [173.228.155.53]. These headers have been reported to the mail server’s host; ongoing complaints have not stopped the stream.
Likely violations: CAN-SPAM (15 U.S.C. §7701 et seq.) deceptive claims/unclear opt-out/identity; RFC 5322 (misleading header practices); RFC 6376 (DKIM); RFC 7489 (DMARC alignment).
Host for 81.7.11.77: ISPpro Internet KG — [email protected]
, +49364150440.
show less
Received Aug 20, 2025 6:37 PM EDT. Subject “Please Check Your account” is a credential-harvesting sp ...
show moreReceived Aug 20, 2025 6:37 PM EDT. Subject “Please Check Your account” is a credential-harvesting spam posing as an urgent account verification. Body includes random filler and “Confirm/Verify” links; unsubscribe text is misleading. From field impersonates the recipient’s name and uses a mismatched domain. Sending IP 104.206.82.62 (bernier.yaroshones.com). Auth: SPF=pass for insights-dashboard.system.commerce.gov.cooperatester.nl; DKIM=none; DMARC=none/absent; alignment with From fails. Likely violations: CAN-SPAM (15 U.S.C. §7704: deceptive headers/subject), potential wire-fraud (18 U.S.C. §1343). RFC issues: 5322/5321 misleading/forged header fields; 6376/7489 not implemented/aligned. Headers already reported to the host; spam continues from this network despite complaints. Network owner: Eonix Corporation — abuse: [email protected]
, phone +1-702-605-2981.
show less
Received on Aug 20, 2025 at 14:30:55 PDT by Gmail. Message is a gambling/casino promotion “400% Bonu ...
show moreReceived on Aug 20, 2025 at 14:30:55 PDT by Gmail. Message is a gambling/casino promotion “400% Bonus up to €2000 + 145 Free Spins” sent from 110.172.101.64 (torphy.discientarcraft.jp.net), with spoofed/mismatched headers: From 'Games online' <[email protected]
>; Sender [email protected]
; Return-Path [email protected]
. SPF: PASS for sandmarkansas.com; DKIM: FAIL for facebook.uybzwzwe.reachesbeast.com.de; DMARC: not shown and alignment would not pass given From-domain mismatch. Body includes obfuscated links to storage.googleapis.com and base64 HTML. Content-Type misuses multipart/report for marketing. Prior complaints to the host have not stopped this stream; the host appears to ignore spam complaints. This is unsolicited commercial email with deceptive headers. Violates CAN-SPAM (15 U.S.C. §7704), RFC 6376/7489/5322; misuses RFC 6522 multipart/report.
show less
Received Aug 20, 2025 14:04:57 PDT. Phishing email claims a $5,000 “direct deposit” and urges the re ...
show moreReceived Aug 20, 2025 14:04:57 PDT. Phishing email claims a $5,000 “direct deposit” and urges the recipient to confirm account/payment details via links; content includes fake dashboards/newsletters and credential-harvest lures. Sending MTA: seattite.com [212.83.158.79]; also forged hop “localhost (127.0.0.1) by uic.edu” appears in headers.
Auth results: SPF pass for MAIL FROM thalven.signal-lock… (212.83.158.79); DKIM permerror (no key for @kjmwfffksxolzlrqmzbocdjkjr.net); DMARC not shown and fails alignment (From ≠ SPF domain). Laws: CAN-SPAM (15 U.S.C. §7701 et seq.) deceptive subject/headers and no valid consent; potential wire fraud (18 U.S.C. §1343). RFC issues: forged Received line, malformed Date zone token.
Network: Scaleway S.A.S (AS12876). Abuse: [email protected]. These headers are reported to the host; prior complaints have not stopped the abuse and spam continues. Their form no longer works to submit spam.
show less
Received 2025-08-19 20:39:01 EDT (PDT 17:39:01) via msc118.plala.or.jp [60.36.166.40]. Scam email cl ...
show moreReceived 2025-08-19 20:39:01 EDT (PDT 17:39:01) via msc118.plala.or.jp [60.36.166.40]. Scam email claims a $842.4M Powerball win by “The Breakfast Club,” offering a $12.5M “donation” and directing the victim to contact a so-called bank rep (Reply-To: [email protected]
) and send full PII, ID/passport, and a phone text. Includes a YouTube link to feign legitimacy. Clear advance-fee/lottery phishing and data-harvesting attempt. Header authentication: SPF pass; DKIM pass; DMARC pass (no alignment failures). Violations: CAN-SPAM (15 U.S.C. §7701 et seq.—deceptive headers/subject; no physical address/opt-out), wire-fraud attempt (18 U.S.C. §1343). RFC: 5322 syntax appears valid; no RFC 7208/6376/7489 fails.
show less
Received 2025-08-20 14:44:33 -0400. Unsolicited casino/“free spins + €4500 bonus” blast with decepti ...
show moreReceived 2025-08-20 14:44:33 -0400. Unsolicited casino/“free spins + €4500 bonus” blast with deceptive “Re:” subject and urgent calls to open/sign up. Headers show bulk-sender infrastructure and content obfuscation (random strings, multipart HTML). Authentication: SPF pass for smtp.mailfrom=transmissing.nl but not aligned with From=ygudzrrmw.us; DKIM fail (d=facebook.uybzwzwe.reachesbeast.com.de); DMARC fail due to misalignment. Source IP 162.211.120.41 seen in Received chain. Pattern fits mass email spam/phishing intended to harvest sign-ups and drive traffic via tracking links. These headers are being reported to the mail server’s hosting provider. This IP/server continues to emit spam despite complaints; host appears unresponsive to abuse reports. Categories: Email Spam, Phishing, Spoofing, Web Spam. Laws/policy: CAN-SPAM Act 15 U.S.C. §7704 (misleading headers/deceptive subject, unsolicited marketing), DMARC (RFC 7489) failure; SPF (RFC 7208) misalignment; header field misuse per RFC 5322.
show less
Received Wed, Aug 20, 2025 14:12:45 -0400. Unsolicited gambling promo email (“400% Bonus up to €2000 ...
show moreReceived Wed, Aug 20, 2025 14:12:45 -0400. Unsolicited gambling promo email (“400% Bonus up to €2000 + 145 Free Spins”) with obfuscated content and random strings. Auth results: SPF pass (non-matching bounce domain), DKIM fail (invalid sig), DMARC: no result shown and alignment fails (From domain does not align). Header/form issues: forged/misaligned From (RFC 5322), failed DKIM (RFC 6376), DMARC misalignment (RFC 7489), misuse of multipart/report delivery-status for marketing (RFC 3464). Sending path references Sailthru MTA; host in header: roberts.willica.net [162.211.120.40]. IP owner per ARIN: velia.net (AS30083). Abuse contact: [email protected]
, +49 221 429 143. Headers already reported; spam persists—host appears unresponsive. Likely violates CAN-SPAM (15 U.S.C. §7701 et seq.).
I keep emailing the host the mail headers and they do absolutely nothing to stop the spam.
show less
Received on Aug 20, 2025 11:09:27 PDT. Commercial spam promoting “MyStart” weight-loss offers with m ...
show moreReceived on Aug 20, 2025 11:09:27 PDT. Commercial spam promoting “MyStart” weight-loss offers with multiple tracker/redirect links (Google Cloud Storage/tinyurl/imgur) pushing “Ozempic alternatives.” Headers show MAIL FROM 2093m.com with SPF PASS via 98.142.97.26 (hinet-ip.hinet.net) while header From uses tmi86s85tj.qbdlflolhloluc.us — no DKIM present and DMARC alignment absent/failed. Message-ID is malformed and MIME declares multipart/report but contains HTML only; Sender header is invalid (“o40gp4d0”) — violates RFC 5322 and misuses RFC 3462. Pattern indicates bulk, deceptive mail. Network owner: Chunghwa Telecom/HiNet (AS3462). Abuse: [email protected]; phone +886-2-2344-3007. Laws: CAN-SPAM (15 U.S.C. §7704) for misleading headers/unsolicited ads; possible wire-fraud (18 U.S.C. §1343) if used to obtain money.
show less
Received on Aug 20, 2025 at 10:47 PDT. Message impersonates Apple/iCloud (“iCloud_Storage”) and pres ...
show moreReceived on Aug 20, 2025 at 10:47 PDT. Message impersonates Apple/iCloud (“iCloud_Storage”) and pressures an “upgrade” due to storage “nearly full,” driving the user to a credential-harvesting page hosted on Google Cloud Storage via tracking links. Headers show delivery from mclaughlin.designatin.com [27.102.106.144]. Auth: SPF pass for bounce domain practice-questions.bartrainer.com.elevises.nl (not aligned with visible From); DKIM permerror for rbxhgnlidrqenamgzbheznrd.com (no key); DMARC alignment fails (no aligned SPF/DKIM). Reply-To at an unrelated subdomain further indicates spoofing. Likely violations: CAN-SPAM (15 U.S.C. § 7704; deceptive header/subject), Wire Fraud (18 U.S.C. § 1343, phishing intent). RFC issues: RFC 5322 (misleading From/Reply-To), DMARC alignment per RFC 7489 not satisfied. Ongoing abuse; host has ignored prior spam complaints and the spam continues.
show less
Received Aug 20, 2025 13:09 EDT. Source: appendad.net [81.7.11.77]. Unsolicited gambling promo (“Bes ...
show moreReceived Aug 20, 2025 13:09 EDT. Source: appendad.net [81.7.11.77]. Unsolicited gambling promo (“BestMobileCasino”): claims “+135 Free Spins” and “$2,000 Welcome Bonus,” pushes a “Confirm Your Info” link (to a storage.googleapis.com URL) intended to harvest clicks. Header masquerades as delivery-status (Content-Type: multipart/report), which is improper for marketing. Auth: SPF PASS for bounce-endpoint.smtpbox.com.victorizon.net (81.7.11.77); DKIM PERMERROR (no key for 2hf5fg.rmmoz7.dg2kfu.us); DMARC result not shown; From domain does not align with SPF domain. Likely CAN-SPAM violations (15 U.S.C. §§7701–7713; deceptive subject, no valid business address/opt-out). RFC 6522/3462 misuse of multipart/report. Hosting: ISPpro Internet KG (EUserv Internet). Abuse: [email protected]
• Tel: +49 3641 50440.
show less
Received Aug 20, 2025 12:47 PM EDT. Source mail came from marks.nmpcvwngzh10.com (51.161.38.130) adv ...
show moreReceived Aug 20, 2025 12:47 PM EDT. Source mail came from marks.nmpcvwngzh10.com (51.161.38.130) advertising a German-language online-casino offer (200% bonus + 50 free spins) with tracking/redirect links. Header auth: SPF PASS for the envelope domain slavesent.uk.com via 51.161.38.130; DKIM PERMERROR — no DNS key for d=ubtkqyanitxchczoqcgidoojp.com; DMARC not aligned for header.from (no visible DMARC pass). Content is unsolicited commercial spam with deceptive routing/identity, contrary to CAN-SPAM (15 U.S.C. §7704) and fails best practices/RFCs: DKIM (RFC 6376) permerror and DMARC (RFC 7489) alignment failure.
show less
Received on Aug 20, 2025 at 11:36:41 EDT. Message claims a $5,000 deposit and urges the recipient to ...
show moreReceived on Aug 20, 2025 at 11:36:41 EDT. Message claims a $5,000 deposit and urges the recipient to click/confirm; From uses a random domain (slafjelpdqplxyozabmzwdrvcu.net), Return-Path is selthor.node-spire.vandrix.germantistic.nl, and Reply-To points to a uic.edu address—classic phishing and domain misalignment. Headers show SPF: pass for selthor.node-spire.vandrix.germantistic.nl (51.222.35.74) but not aligned with From; DKIM: permerror (no key) for slafjel…; DMARC: not present/expected fail due to non-alignment. Additional indicators: deceptive subject, mismatched timezone token in Date, and bulky HTML designed to evade filters. Spam persists despite prior complaints; host appears unresponsive. Likely violations: CAN-SPAM (deceptive header/subject), 18 U.S.C. §1343 (wire fraud attempt), RFC 5322 (header anomalies), RFC 7489 (DMARC fail), RFC 6376 (DKIM failure).
show less
Received Aug 20, 2025 at 10:12:33 EDT. Unsolicited adult-themed solicitation urging me to “view prof ...
show moreReceived Aug 20, 2025 at 10:12:33 EDT. Unsolicited adult-themed solicitation urging me to “view profile,” “naked photo/video,” and click a tracking URL. Delivered from 209.141.39.45 (bergstrom.avvyglow.com) using a throwaway subdomain. Auth: SPF=pass; DKIM=pass (rsa-sha1, deprecated); no DMARC result shown. Headers contain forged/misleading fields (X-Original-Sender, X-Google-Sender-Delegation, List-ID) that impersonate the recipient and fabricate a mailing list. MIME misuse: advertising sent as multipart/report. Violations: CAN-SPAM/FTC 16 CFR Part 316 (deceptive headers/subject, no valid physical address/opt-out), RFC 5321/5322 header integrity; DKIM uses deprecated hash (RFC 8301 guidance). This spam continues despite prior complaints; the host appears indifferent. All headers preserved for the provider. [email protected] bounces back as UNDELIVERABLE!!!! 100% NON-RESPONSIVE to spam complaints!!!!
show less
Received on Aug 20, 2025 at 07:20:44 EDT. Message impersonates “Gmail Support Team” and claims the r ...
show moreReceived on Aug 20, 2025 at 07:20:44 EDT. Message impersonates “Gmail Support Team” and claims the recipient’s subscription will be closed today with a [Final Warning], pushing clicks to a hosted page; body contains obfuscated text/HTML and a big “Secure Your Device” CTA. Headers show handoff from doyle.throportant.net [23.95.24.212] to Google; envelope-from is a long subdomain under disioning.nl. SPF: PASS (23.95.24.212 authorized); DKIM: none observed; DMARC: no result/alignment. Message-ID shows “SMTPIN_ADDED_MISSING”, indicating the original lacked a valid ID. Laws: CAN-SPAM (15 U.S.C. §7704) and wire fraud (18 U.S.C. §1343). RFC issues: deceptive headers (RFC 5322) and misuse of multipart/report DSN format (RFC 3462/6522). Headers already reported to the provider; ongoing spam from this source continues despite complaints; the host appears unresponsive.
show less
Received Aug 20, 2025 at 06:54 EDT. Source IP 198.23.172.222 sent bulk phishing posing as “Gmail Sup ...
show moreReceived Aug 20, 2025 at 06:54 EDT. Source IP 198.23.172.222 sent bulk phishing posing as “Gmail Support,” claiming imminent subscription/account closure and urging “secure/verify” via links (incl. storage.googleapis.com), with heavy HTML, obfuscated blobs and random IDs to bypass filters. Auth: SPF PASS for [email protected]
via 198.23.172.222; DKIM PERMERROR (no DNS TXT key; invalid per RFC 6376); DMARC alignment FAIL (From ≠ SPF-auth’d domain; per RFC 7489; no explicit DMARC result line). Misleading identifiers breach RFC 5322 intent. All headers forwarded to the mail server’s host; spam from this IP continues, indicating the host ignores complaints. Laws: CAN-SPAM (15 USC §7704), likely wire-fraud/identity-fraud statutes (18 USC §1343/§1028). Network owner: ColoCrossing (AS36352). Abuse: [email protected]
| +1-800-518-9716.
show less
Received 2025-08-20 06:52:46 -0400. Message impersonates “Gmail Support Team,” threatening imminent ...
show moreReceived 2025-08-20 06:52:46 -0400. Message impersonates “Gmail Support Team,” threatening imminent subscription/account closure and pushing urgent clicks to multiple “update/activate” links; page content shows fabricated tables/codes and obfuscated (base64-like) filler—classic credential-harvesting phish. Technical: visible From is an unrelated random subdomain; envelope sender differs. SPF: pass for bounce domain but not aligned with visible From. DKIM: permerror (no key) → fail. DMARC: alignment fails (no aligned SPF & DKIM). Delivered directly by 209.239.115.1. Non-compliant with RFC 5322/5321 (misleading/forged headers), RFC 6376 (invalid DKIM), RFC 7489 (DMARC mis-alignment). Violates CAN-SPAM (15 U.S.C. §7701 et seq.); may constitute wire fraud (18 U.S.C. §1343). Headers have been reported to the host; spam continues, indicating inaction.
show less
Received 2025-08-20 02:22:59 PDT. Bulk phishing/impersonation email posing as “Gmail Support” with s ...
show moreReceived 2025-08-20 02:22:59 PDT. Bulk phishing/impersonation email posing as “Gmail Support” with subject “Your Subscription will be Closed [Final Warning]”. Attempts to panic the user into clicking a redirect link hosted on a cloud storage domain. Headers show multiple mismatched domains (Return-Path: emergencience.co; From: hfmhiq.us; HELO: centersonal.info) delivered via 163.172.230.113. Auth results: SPF PASS for emergencience.co but not aligned with From; DKIM PERMERROR (no key for d=34euq1.ovifyj.hfmhiq.us); DMARC not present/likely fail due to no aligned pass. Indicators of forgery and header inconsistency (RFC 5322), DKIM failure (RFC 6376), DMARC misalignment (RFC 7489). Violates CAN-SPAM (15 U.S.C. §7704) and constitutes attempted wire fraud (18 U.S.C. §1343).
show less
Received Tue, 19 Aug 2025 19:02:00 PDT. Abuse from 51.83.187.60 / beegirl.net sent a bank/billing lu ...
show moreReceived Tue, 19 Aug 2025 19:02:00 PDT. Abuse from 51.83.187.60 / beegirl.net sent a bank/billing lure claiming a $5,000 “direct deposit,” urging the recipient to click “confirm/pay out,” with fake account and password notices and mismatched From/Reply-To domains. Header issues: bogus Received line claiming [email protected]
; Date header shows PDT but -0400 offset; MIME/report used for bulk promo. Auth: SPF pass for [email protected]
(not aligned with From); DKIM permerror for twztuyxsytokiwenkkncxxfudm.net (no key); DMARC alignment therefore fails/absent. This is phishing + email spam and sender impersonation; violates CAN-SPAM, wire-fraud/anti-phishing laws; likely contravenes RFC 5321/5322 (forged Received/date).
show less
Received Tue, 19 Aug 2025 at 18:45:51 -0400. Bulk deceptive email with subject “Please Check Your ac ...
show moreReceived Tue, 19 Aug 2025 at 18:45:51 -0400. Bulk deceptive email with subject “Please Check Your account” pretending to be an account/security notice. From field used the recipient’s name falsely; envelope uses a fabricated subdomain and a random local-part at a .us domain. Content links to storage.googleapis[.]com pages and advertises “SpinGranny Casino” and “FINAL MESSAGE: balance $8,500 Payout Verification,” typical phishing/bait-and-switch. Chain shows handoff via njmta-53.sailthru.com to 104.206.82.62 (bernier.yaroshones.com) which connected to Google. Auth results: SPF=PASS for the deceptive subdomain; DKIM=absent; DMARC=none/alignment not evaluated. Misuses MIME “multipart/report; report-type=delivery-status” (RFC 3464) and lacked proper Message-ID until added by Gmail (RFC 5322). Spam persists despite prior complaints; please shut this down. Headers reported to host.
show less
Received on Aug 19, 2025 at 15:18:44 PDT (per mx.google.com). Unsolicited “Payout Verification” emai ...
show moreReceived on Aug 19, 2025 at 15:18:44 PDT (per mx.google.com). Unsolicited “Payout Verification” email with payout-bait content and random filler. The From field used the recipient’s name as false. Sending IP: 104.206.82.62 (bernier.yaroshones.com). Also present in headers: 173.228.155.53 (njmta-53.sailthru.com).
Auth: SPF pass for a deceptive subdomain (insights-dashboard.system.commerce.gov.kidnappropriety.net); DKIM: none; DMARC: none observed. Gmail added SMTPIN_ADDED_MISSING, indicating a missing Message-ID — an RFC 5322 violation. Headers appear misleading/forged.
Violations: CAN-SPAM 15 U.S.C. §7704(a)(1) (deceptive headers/unsolicited mail); potential 18 U.S.C. §1343 wire-fraud intent due to payout lure. Host: Eonix Corporation (AS62904) — report to [email protected]. Related relay owner: NYI (AS11403) — [email protected].
show less