Received Mon, 23 Feb 2026 07:20:36 -0800. Suspected phishing/invoice spam claiming “Review billing d ...
show moreReceived Mon, 23 Feb 2026 07:20:36 -0800. Suspected phishing/invoice spam claiming “Review billing document / receipt” for a purchase, referencing 23 Feb 2026 and a “Service Team” phone number, aiming to trick the recipient into calling or treating it as real.
Origin IP: 43.157.24.162 (authenticated submission to smtp.gmail.com); outbound mail server IP: 209.85.220.65 (mail-sor-f65.google.com). Header auth shows SPF=pass, DKIM=pass, DMARC=pass (no failures seen), suggesting a compromised account or abused infrastructure vs simple spoof failure.
Likely violates U.S. CAN-SPAM (deceptive content; missing required identification/opt-out) and anti-fraud/phishing laws, and abusive use of email standards (RFC 5321/5322). Network owner for 43.157.24.162 appears to be Tencent Cloud / Aceville PTE LTD (AS132203). Abuse: [email protected]show less
Received Tue, Feb 24, 2026 03:55:27 -0800 (PST). Unsolicited bulk marketing email promoting “career ...
show moreReceived Tue, Feb 24, 2026 03:55:27 -0800 (PST). Unsolicited bulk marketing email promoting “career hacks/productivity for men over 40,” formatted as a fake TikTok-style digest with multiple tracked redirect links and images, encouraging clicks and engagement. Message originated from 69.169.224.52 using Amazon SES outbound host (b224-52.smtp-out.eu-central-1.amazonses.com) with visible branding of “tokivo.site” (From: [email protected]
) and numerous click-tracking URLs. Header auth results show SPF=PASS for the SES envelope sender and DKIM=PASS (tokivo.site and amazonses.com). DMARC result not shown in the provided header (unknown). This appears to be unsolicited commercial email / list-style spam delivered to a mailbox nickname (recipient name used in the To: display), with one-click unsubscribe headers present but content is still unwanted.
The sending infrastructure appears to be Amazon Simple Email Service (SES) based on the amazonses.com outbound hostname and X-SES-Outgoing.
show less
Received 2026-02-21 15:16:06 +0000. Phishing-style “Cloud subscription payment expired” notice claim ...
show moreReceived 2026-02-21 15:16:06 +0000. Phishing-style “Cloud subscription payment expired” notice claiming your cloud data will be deleted unless you “update payment”. It uses an urgent deadline and a payment/renewal pretext to drive the victim to an external site (cronosaviel.shop) to harvest credentials/payment details.
Sending IP / mail server: 104.140.53.132 (HELO cpia.zkbkhuuyfg.eu.com). Return-Path and From use qassimy.com; the message is HTML-only with tracking pixel and “unsubscribe” links typical of spam operations. No evidence the sender is a legitimate cloud provider.
Auth results: SPF=pass, DKIM=unknown (not signed/verified), DMARC=pass with policy p=NONE. Likely violations: CAN-SPAM (deceptive content/headers and misleading solicitation), and anti-fraud/anti-phishing prohibitions (attempted credential/payment theft); also inconsistent with email authenticity best practices (RFC 5322/5321 norms). Network owner/host: Eonix Corporation (AS62904). Abuse contact: [email protected].
show less
Received Thu, 19 Feb 2026 20:21:36 -0800. Source IP: 60.36.166.33 (msc111.plala.or.jp). Unsolicited ...
show moreReceived Thu, 19 Feb 2026 20:21:36 -0800. Source IP: 60.36.166.33 (msc111.plala.or.jp). Unsolicited advance-fee phishing scam claiming a “$10 Million Donation Award” tied to a past Powerball jackpot. Message asks recipient to contact a supposed bank CFO/representative to “confirm acceptance” and demands sensitive data (full name, age, address, occupation, phone/WhatsApp, photo, and ID/passport copy) plus a payment code—high risk of identity theft and fraud. Reply-To differs from From, indicating impersonation/social-engineering. Auth results: SPF=PASS, DKIM=PASS, DMARC=PASS (no failures noted).U.S. CAN-SPAM Act (deceptive unsolicited commercial email practices)Wire fraud / attempted fraud (soliciting money/PII via deception)Identity theft / identity fraud attempts (requesting ID/passport + photo + personal details)Deceptive/misleading use of message identity fields (e.g., From/Reply-To mismatch used to mislead recipients), inconsistent with good-faith email practices under RFC 5322 norms.
show less
Received Fri, 20 Feb 2026 04:09:35 -0800 (PST). Source IP 51.38.208.114 sent a deceptive “account bl ...
show moreReceived Fri, 20 Feb 2026 04:09:35 -0800 (PST). Source IP 51.38.208.114 sent a deceptive “account blocked” alert claiming the victim’s photos/videos will be deleted unless payment details are updated immediately. Message uses urgency + a deadline and includes call-to-action links leading to unrelated domains (e.g., hinyvfz.com / storage.googleapis.com), consistent with credential/billing phishing. The display name impersonates the recipient’s name to look legitimate. Header authentication shows SPF=pass and DKIM=pass; no DMARC result is shown in this header. Unsolicited social-engineering attempt intended to trick the recipient into clicking and submitting sensitive info.
CAN-SPAM Act (U.S.): deceptive/false header or routing info, misleading content, and failure to meet commercial email requirements can trigger violations (even when the goal is fraud).
18 U.S.C. § 1343 (Wire fraud): if the intent is to trick the recipient into sending money or credentials via electronic communications.
show less
Received Thu, Feb 19, 2026 15:41:10 PST. SMTP source: e226-4.smtp-out.us-east-2.amazonses.com (23.25 ...
show moreReceived Thu, Feb 19, 2026 15:41:10 PST. SMTP source: e226-4.smtp-out.us-east-2.amazonses.com (23.251.226.4). Message promotes “Florida Annual Report” filing and a paid “3-in-1 compliance package” (annual report + registered agent + labor law posters), urging the recipient to click tracking links to “get started,” warns about deadlines/late fees, and includes marketing language plus an unsubscribe link. Authentication seen: SPF=pass, DKIM=pass (domain + amazonses), DMARC=pass (policy quarantine). This appears to be unsolicited bulk/commercial email and potentially misleading “official-sounding” solicitation intended to drive a paid purchase.
Based on the sending host/IP in the header, this is Amazon SES / Amazon.com, Inc.
Abuse contact: [email protected]
Phone: +1-206-741-3696
CAN-SPAM (US): unsolicited commercial email can be unlawful if it uses deceptive headers/subject, lacks a valid opt-out, or fails other requirements. From the header/body shown, it does include an unsubscribe link
show less
Spamcop says HOST DOES NOT CARE about the spam and will do nothing to stop it. They should be sued ...
show moreSpamcop says HOST DOES NOT CARE about the spam and will do nothing to stop it. They should be sued for harassment.
show less
Received on Feb 19, 2026 at 07:09 PST. Unsolicited bulk marketing email promoting “Top TikTok Picks” ...
show moreReceived on Feb 19, 2026 at 07:09 PST. Unsolicited bulk marketing email promoting “Top TikTok Picks” with embedded tracking links, unsubscribe token, and multiple third-party redirect URLs. Message appears sent via Amazon SES infrastructure, indicating possible abuse of cloud email services. No prior consent observed and message contains promotional content with mass-mail characteristics. Uses generic noreply sender and branded display name to appear legitimate. Presence of one-click unsubscribe does not validate consent and is commonly used in spam campaigns. Authentication shows SPF=pass, DKIM=pass (tokivo.site and amazonses.com), DMARC alignment not clearly enforced, suggesting domain reputation misuse rather than authentication failure. Pattern indicates commercial spam distribution at scale through relay services, violating acceptable use policies and CAN-SPAM Act requirements for consent and truthful identification. Possible deceptive marketing and unsolicited advertising activity.
show less
This email was received on Thu, 19 Feb 2026 at 12:53:31 +0000 and appears to be unsolicited spam con ...
show moreThis email was received on Thu, 19 Feb 2026 at 12:53:31 +0000 and appears to be unsolicited spam containing a deceptive hyperlink. The message uses vague language ("There's a text from me waiting") intended to lure the recipient into clicking a malicious link. The content is minimal and impersonates a personal message to create urgency. This pattern is consistent with phishing campaigns designed to harvest credentials or deliver malware.
Analysis of the header shows the originating IP as 89.253.221.115, identifying itself as vps-33732823-401935.z.host4g.ru. Authentication checks failed or were missing: SPF=none (domain not authorized), DKIM=unknown, and DMARC=unknown, indicating no legitimate authentication and a high likelihood of spoofing. These failures confirm the message is not authorized by the sending domain and is likely forged.
This activity violates the CAN-SPAM Act by sending unsolicited commercial email without proper identification or consent and likely violates RFC 7208 (SPF)
show less
This unsolicited email was received on Wed, 18 Feb 2026 13:54:24 +0000. The message originated from ...
show moreThis unsolicited email was received on Wed, 18 Feb 2026 13:54:24 +0000. The message originated from IP 104.140.53.133 using HELO xvbw.drnsmrzkzl.us.com with Return-Path grubber.ru and was delivered through Yahoo infrastructure. The content impersonates a “Cloud Security Team” and uses urgent language claiming payment expiration and imminent deletion of files to pressure the recipient. It contains deceptive links directing to an external domain intended to harvest sensitive information.
Authentication results show SPF=pass and DMARC=pass (policy none), while DKIM is missing or unknown, indicating weak authentication controls. The message uses obfuscation techniques, generic branding, and misleading subscription data to appear legitimate. This behavior is consistent with phishing campaigns designed to obtain financial or login credentials through fraudulent payment update requests.
This activity violates the CAN-SPAM Act and constitutes phishing fraud. It also breaches RFC 5322 and RFC 7208
show less
Received 2026-02-18 07:09 PST. Unsolicited bulk email advertising “DIY Home Improvement / TikTok vid ...
show moreReceived 2026-02-18 07:09 PST. Unsolicited bulk email advertising “DIY Home Improvement / TikTok videos” sent without prior consent. Message uses tracking links, marketing tokens, and promotional content indicating commercial intent. The email appears to be part of a mass-mail campaign routed through a third-party sender. Although SPF and DKIM pass via a cloud email provider, the originating domain and campaign are likely unrelated to the recipient, indicating abuse of a relay service. Includes one-click unsubscribe link but lacks verifiable opt-in, suggesting unsolicited marketing. This activity may violate the CAN-SPAM Act (15 U.S.C. §7701), including requirements for consent and truthful identification, and RFC 5321/5322 principles regarding accurate sender representation. Evidence suggests potential misuse of sending infrastructure for spam distribution.
Mail Server / Host Details
Sending IP: 69.169.224.50
Service: Amazon Simple Email Service (SES)
Company: Amazon Web Services (AWS)
show less
Blocked user from trying to hack into WordPress. A user with IP address 43.165.67.251 has been locke ...
show moreBlocked user from trying to hack into WordPress. A user with IP address 43.165.67.251 has been locked out from signing in or using the password recovery form for the following reason: Used an invalid username 'r3dc0d3r' to try to sign in.
show less
Received Fri, 13 Feb 2026 20:03:44 -0800. Source/MTA: webmail.swanforlife.com (smtp.swanforlife.com) ...
show moreReceived Fri, 13 Feb 2026 20:03:44 -0800. Source/MTA: webmail.swanforlife.com (smtp.swanforlife.com) [202.123.29.132]. Return-Path/From used [email protected]
while the message claims a “U.S. Government/UN/World Bank compensation” via Chase ATM VISA card.
Auth results: SPF softfail (sender not authorized for bsvgroup.com), DKIM missing/unknown, DMARC FAIL (policy quarantine). Message is an advance-fee/identity-harvest scam requesting full name, address, phone, age, occupation, and a photo, and redirects replies to a separate Gmail “Chase bank” address.
Likely violations: CAN-SPAM (misleading origin/unauthorized sending, deceptive content) and fraud/identity-theft statutes (e.g., 18 USC 1343 wire fraud; 18 USC 1028 identity fraud). RFC issues: spoofed/unauthenticated mail inconsistent with RFC 5321/5322 and DMARC (RFC 7489) alignment failure. Abuse contact for network/owner (AS23889 MauritiusTelecom
show less
Received Wed, 11 Feb 2026 08:08:53 -0800 (PST). Sending IP: 54.240.14.146 (a14-146.smtp-out.amazonse ...
show moreReceived Wed, 11 Feb 2026 08:08:53 -0800 (PST). Sending IP: 54.240.14.146 (a14-146.smtp-out.amazonses.com / Amazon SES). Message claims “Social Security Administration” and says a “new statement is ready,” urging the recipient to click “Download Now” leading to a non-government site (forms.basixagency.com). This is credential-harvesting style social-engineering using a spoofed government brand and deceptive call-to-action.
Auth results observed: SPF=pass; DKIM=pass (ez.works and amazonses.com); DMARC=pass (from ez.works). Despite passing authentication, the display name uses look-alike characters and impersonates a government agency, indicating phishing/spoofing intent rather than legitimate SSA notification.
Likely violations: CAN-SPAM Act (15 U.S.C. §7701 et seq.) for deceptive header/identity and misleading content; potential wire fraud (18 U.S.C. §1343) and identity theft/impersonation (18 U.S.C. §1028) due to government-brand phishing. IP owner/host: Amazon Web Services / Amazon SES.
show less
Received: Sun, 15 Feb 2026 21:18:55 +0000. Sending IP: 185.157.222.205 (EHLO 185-157-222-205-static. ...
show moreReceived: Sun, 15 Feb 2026 21:18:55 +0000. Sending IP: 185.157.222.205 (EHLO 185-157-222-205-static.glesys.net). Purported sender: [email protected] Return-Path same). Delivered to Yahoo via atlas-production.v2-mail-prod1-gq1.omega.yahoo.com.
This message is an extortion/sextortion-style scam. Body (base64) claims the sender compromised the recipient and/or device, threatens reputational harm, and demands cryptocurrency payment (Monero/XMR), using pressure and intimidation. No legitimate context or prior relationship is present; subject is “re:”, consistent with social-engineering.
Auth results: SPF NONE (no permitted sender hosts published), DKIM UNKNOWN, DMARC FAIL. This appears to violate CAN-SPAM (15 USC 7701 et seq.) and is consistent with fraud/extortion attempts; also implicates RFC 5322/5321 misuse plus RFC 7208 (SPF) and RFC 7489 (DMARC) failures. IP owner/host: Glesys AB. Abuse contact: [email protected]
.
show less
Received Feb 14 2026 17:21:46 UTC. Email originated from IP 51.81.88.69 (EHLO mail-us83.getmailinads ...
show moreReceived Feb 14 2026 17:21:46 UTC. Email originated from IP 51.81.88.69 (EHLO mail-us83.getmailinads.com) and relayed via mail-us1.getmailinads.com [3.135.13.75] before reaching Yahoo servers. Return path [email protected]
. Message promotes “Amsoil Synthetic Motor Oil funding” offering large financing with low rates, unsolicited and unrelated to recipient, indicating bulk spam or phishing solicitation using business lure.
Authentication shows SPF SOFTFAIL (sending IP not authorized), DKIM PASS, DMARC PASS. SPF softfail indicates potential domain misuse or unauthorized sending source. Content uses generic greeting, financial inducement, and vague claims, common in spam campaigns. Sender identity “Alex Kellerman” appears unverified and domain longb2bspace.info likely used for mass mailing. No evidence of consent, suggesting abusive unsolicited commercial email activity.
show less
Received Feb 13 2026 16:26:14 UTC. Email sent from IP 106.75.49.97 (EHLO ucmail2.sendcloud.io) using ...
show moreReceived Feb 13 2026 16:26:14 UTC. Email sent from IP 106.75.49.97 (EHLO ucmail2.sendcloud.io) using SendCloud infrastructure, relayed through atlas-production.v2-mail-prod1-gq1.omega.yahoo.com. Return path [email protected]
. Message uses transactional formatting to impersonate an order notification, stating “your order is waiting” and urging payment. This is unsolicited commercial messaging with tracking links and unsubscribe tokens, indicative of bulk marketing or phishing.
SPF PASS, DKIM PASS, DMARC PASS; however authentication success does not confirm legitimacy. Content uses deceptive urgency and generic personalization, suggesting mass mailing or potential phishing. Links redirect through tracking domains (sctrack.sendcloud.net) which obscures final destination. Presence of “List-Unsubscribe” and SendCloud headers indicates automated bulk mail platform. No prior relationship evident, suggesting unsolicited email or abuse of marketing system.
show less
Spam/phishing email received Fri, 13 Feb 2026 12:16:31 -0800. Source IP: 167.86.94.246 (HELO at-do.c ...
show moreSpam/phishing email received Fri, 13 Feb 2026 12:16:31 -0800. Source IP: 167.86.94.246 (HELO at-do.com / vmi3026295.contaboserver.net). Message impersonates “Lowe’s Bonus” and uses the recipient’s name in the From/Subject to lure a “Free DeWalt Wet/Dry Vacuum” via a survey, linking to an Amazon S3 hosted landing page (likely credential/finance harvesting).
Auth results: SPF=pass for the envelope domain, but DKIM and DMARC results are not present/verified in this header. The message also contains a malformed/forged Date header (“Date: _smtpDate . 552582287”), consistent with spam operations and possible identity spoofing/misrepresentation.
Abuse owner/host: Contabo GmbH (Contabo). Report to: [email protected] Likely violations: CAN-SPAM (15 USC §7701 et seq.) for deceptive commercial email and inadequate identification/consent; potential FTC Act §5 deceptive practices. RFC issues: RFC 5322 header/date format anomalies and misleading From display.
show less
Received Wed, Feb 11, 2026 07:33:00 PST. Unsolicited commercial real-estate marketing email promotin ...
show moreReceived Wed, Feb 11, 2026 07:33:00 PST. Unsolicited commercial real-estate marketing email promoting an “Open House this Wednesday” in Pompano Beach, FL, advertising a townhouse-style property (garage, updated kitchen, HOA reserves, amenities) and urging the recipient to click a tracked “View Listing” link and schedule a showing/private tour. Message includes multiple embedded links and tracking pixels typical of bulk marketing. Source mail server IP: 149.72.191.23 (SendGrid outbound). SPF: PASS, DKIM: PASS (brivity.com and sendgrid.info), DMARC: PASS (policy p=none). No authentication failures observed, but the content appears to be unsolicited bulk advertising and may violate anti-spam rules if sent without consent and/or lacking required disclosures (e.g., clear ad identification/valid physical address) per CAN-SPAM requirements. No clear RFC 5321/5322 protocol errors seen in headers.
show less
Received Tue, 10 Feb 2026 16:31:45 +0000. From: “Payment/Declined” [email protected]
...
show moreReceived Tue, 10 Feb 2026 16:31:45 +0000. From: “Payment/Declined” [email protected]
. Message impersonates a “Cloud/Cloud+” billing notice, claims payment expired, and threatens immediate deletion of photos, contacts, notes, and device backups unless payment is “updated” urgently via a link to cronosaviel.shop (domain mismatch).
Sending IP: 91.109.21.239 (HELO 4f2ooj.3486113t.testfit.io). Yahoo internal relay shows 10.217.134.205, but the public originating sender is 91.109.21.239. Auth results: SPF=PASS (qassimy.com); DKIM=unknown (no valid DKIM seen); DMARC=PASS (p=NONE). SMTP hop used deprecated TLS1.0.
Assessment: phishing / email spam designed to steal payment info. Potential violations: CAN-SPAM Act (15 USC 7701–7713) if unsolicited/deceptive, and FTC Act §5 (15 USC 45) for deceptive impersonation. No obvious RFC 5322 formatting violations in the header. IP owner/network: Leaseweb Deutschland GmbH (AS28753). Abuse:
show less
Received Tue, 10 Feb 2026 11:00:43 -0800 (PST). Subject: “The Trump Loophole Wall Street Hates”. Fro ...
show moreReceived Tue, 10 Feb 2026 11:00:43 -0800 (PST). Subject: “The Trump Loophole Wall Street Hates”. From: Prime Sight AI [email protected]. Message promotes “AI Royalties”/retirement income claims and pushes the recipient to click a tracking link to “watch now,” using sensational political/financial language and urgency (“payout deadline”).
Sending infrastructure: client/sending IP 23.251.255.234 (hostname e255-234.smtp-out.amazonses.com) via Amazon SES. Mail server IP appears the same: 23.251.255.234. Authentication results show SPF=PASS, DKIM=PASS (primesightai.com and amazonses.com), DMARC=PASS (policy p=NONE). No SPF/DKIM/DMARC failures are indicated in the header.
Likely unsolicited commercial bulk email with potentially deceptive claims. Potential legal issues: CAN-SPAM Act (15 USC 7701–7713) if sent without proper consent and/or if subject/content is materially misleading; FTC Act Section 5 (15 USC 45) if the marketing claims are deceptive.
show less
Received Tue, 10 Feb 2026 at 11:34:44–11:34:45 UTC. The message claims a “497 USD enrollment fee” wi ...
show moreReceived Tue, 10 Feb 2026 at 11:34:44–11:34:45 UTC. The message claims a “497 USD enrollment fee” will be automatically deducted from a bank account and urges the recipient to call a phone number to reach “support staff.” The content impersonates a Microsoft service and combines payment threat language with a verification code to pressure the recipient into calling. This is a classic social-engineering scam designed to induce financial fraud and phone-based extortion.
The sending IP was 40.93.2.64, with the same IP acting as the outbound mail server via Outlook infrastructure. SPF, DKIM, and DMARC all technically passed for microsoftonline.com; however, the message content is fraudulent and misleading, indicating abuse of a legitimate mail platform or compromised tenant. The email falsely asserts pending financial charges and misrepresents account activity to coerce action. This activity violates the CAN-SPAM Act (15 U.S.C. §7701), U.S. wire fraud statutes (18 U.S.C. §1343).
show less
This email was received on Mon, 09 Feb 2026 at 14:48:48 PST. The message presents itself as a loan s ...
show moreThis email was received on Mon, 09 Feb 2026 at 14:48:48 PST. The message presents itself as a loan solicitation from “National Standard Finance,” advertising low-interest financing and requesting a reply for further engagement. The content is unsolicited commercial email designed to initiate contact and potentially harvest responses, using generic financial language and no prior relationship or consent.
The sending IP is 89.252.184.116 with upstream relay activity observed from 77.90.185.200 through the mail server server.efikir.org. SPF, DKIM, and DMARC all pass for the sending domain, indicating the infrastructure itself is authenticated but being used to distribute spam content. Authentication success suggests abuse of a legitimately configured mail server rather than a misconfiguration.
show less
Fraud OrdersPhishingWeb SpamEmail SpamSpoofing
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.