Received: Sun, 15 Feb 2026 21:18:55 +0000. Sending IP: 185.157.222.205 (EHLO 185-157-222-205-static. ...
show moreReceived: Sun, 15 Feb 2026 21:18:55 +0000. Sending IP: 185.157.222.205 (EHLO 185-157-222-205-static.glesys.net). Purported sender: [email protected] Return-Path same). Delivered to Yahoo via atlas-production.v2-mail-prod1-gq1.omega.yahoo.com.
This message is an extortion/sextortion-style scam. Body (base64) claims the sender compromised the recipient and/or device, threatens reputational harm, and demands cryptocurrency payment (Monero/XMR), using pressure and intimidation. No legitimate context or prior relationship is present; subject is “re:”, consistent with social-engineering.
Auth results: SPF NONE (no permitted sender hosts published), DKIM UNKNOWN, DMARC FAIL. This appears to violate CAN-SPAM (15 USC 7701 et seq.) and is consistent with fraud/extortion attempts; also implicates RFC 5322/5321 misuse plus RFC 7208 (SPF) and RFC 7489 (DMARC) failures. IP owner/host: Glesys AB. Abuse contact: [email protected]
.
show less
Received Feb 14 2026 17:21:46 UTC. Email originated from IP 51.81.88.69 (EHLO mail-us83.getmailinads ...
show moreReceived Feb 14 2026 17:21:46 UTC. Email originated from IP 51.81.88.69 (EHLO mail-us83.getmailinads.com) and relayed via mail-us1.getmailinads.com [3.135.13.75] before reaching Yahoo servers. Return path [email protected]
. Message promotes “Amsoil Synthetic Motor Oil funding” offering large financing with low rates, unsolicited and unrelated to recipient, indicating bulk spam or phishing solicitation using business lure.
Authentication shows SPF SOFTFAIL (sending IP not authorized), DKIM PASS, DMARC PASS. SPF softfail indicates potential domain misuse or unauthorized sending source. Content uses generic greeting, financial inducement, and vague claims, common in spam campaigns. Sender identity “Alex Kellerman” appears unverified and domain longb2bspace.info likely used for mass mailing. No evidence of consent, suggesting abusive unsolicited commercial email activity.
show less
Received Feb 13 2026 16:26:14 UTC. Email sent from IP 106.75.49.97 (EHLO ucmail2.sendcloud.io) using ...
show moreReceived Feb 13 2026 16:26:14 UTC. Email sent from IP 106.75.49.97 (EHLO ucmail2.sendcloud.io) using SendCloud infrastructure, relayed through atlas-production.v2-mail-prod1-gq1.omega.yahoo.com. Return path [email protected]
. Message uses transactional formatting to impersonate an order notification, stating “your order is waiting” and urging payment. This is unsolicited commercial messaging with tracking links and unsubscribe tokens, indicative of bulk marketing or phishing.
SPF PASS, DKIM PASS, DMARC PASS; however authentication success does not confirm legitimacy. Content uses deceptive urgency and generic personalization, suggesting mass mailing or potential phishing. Links redirect through tracking domains (sctrack.sendcloud.net) which obscures final destination. Presence of “List-Unsubscribe” and SendCloud headers indicates automated bulk mail platform. No prior relationship evident, suggesting unsolicited email or abuse of marketing system.
show less
Spam/phishing email received Fri, 13 Feb 2026 12:16:31 -0800. Source IP: 167.86.94.246 (HELO at-do.c ...
show moreSpam/phishing email received Fri, 13 Feb 2026 12:16:31 -0800. Source IP: 167.86.94.246 (HELO at-do.com / vmi3026295.contaboserver.net). Message impersonates “Lowe’s Bonus” and uses the recipient’s name in the From/Subject to lure a “Free DeWalt Wet/Dry Vacuum” via a survey, linking to an Amazon S3 hosted landing page (likely credential/finance harvesting).
Auth results: SPF=pass for the envelope domain, but DKIM and DMARC results are not present/verified in this header. The message also contains a malformed/forged Date header (“Date: _smtpDate . 552582287”), consistent with spam operations and possible identity spoofing/misrepresentation.
Abuse owner/host: Contabo GmbH (Contabo). Report to: [email protected] Likely violations: CAN-SPAM (15 USC §7701 et seq.) for deceptive commercial email and inadequate identification/consent; potential FTC Act §5 deceptive practices. RFC issues: RFC 5322 header/date format anomalies and misleading From display.
show less
Received Wed, Feb 11, 2026 07:33:00 PST. Unsolicited commercial real-estate marketing email promotin ...
show moreReceived Wed, Feb 11, 2026 07:33:00 PST. Unsolicited commercial real-estate marketing email promoting an “Open House this Wednesday” in Pompano Beach, FL, advertising a townhouse-style property (garage, updated kitchen, HOA reserves, amenities) and urging the recipient to click a tracked “View Listing” link and schedule a showing/private tour. Message includes multiple embedded links and tracking pixels typical of bulk marketing. Source mail server IP: 149.72.191.23 (SendGrid outbound). SPF: PASS, DKIM: PASS (brivity.com and sendgrid.info), DMARC: PASS (policy p=none). No authentication failures observed, but the content appears to be unsolicited bulk advertising and may violate anti-spam rules if sent without consent and/or lacking required disclosures (e.g., clear ad identification/valid physical address) per CAN-SPAM requirements. No clear RFC 5321/5322 protocol errors seen in headers.
show less
Received Tue, 10 Feb 2026 16:31:45 +0000. From: “Payment/Declined” [email protected]
...
show moreReceived Tue, 10 Feb 2026 16:31:45 +0000. From: “Payment/Declined” [email protected]
. Message impersonates a “Cloud/Cloud+” billing notice, claims payment expired, and threatens immediate deletion of photos, contacts, notes, and device backups unless payment is “updated” urgently via a link to cronosaviel.shop (domain mismatch).
Sending IP: 91.109.21.239 (HELO 4f2ooj.3486113t.testfit.io). Yahoo internal relay shows 10.217.134.205, but the public originating sender is 91.109.21.239. Auth results: SPF=PASS (qassimy.com); DKIM=unknown (no valid DKIM seen); DMARC=PASS (p=NONE). SMTP hop used deprecated TLS1.0.
Assessment: phishing / email spam designed to steal payment info. Potential violations: CAN-SPAM Act (15 USC 7701–7713) if unsolicited/deceptive, and FTC Act §5 (15 USC 45) for deceptive impersonation. No obvious RFC 5322 formatting violations in the header. IP owner/network: Leaseweb Deutschland GmbH (AS28753). Abuse:
show less
Received Tue, 10 Feb 2026 11:00:43 -0800 (PST). Subject: “The Trump Loophole Wall Street Hates”. Fro ...
show moreReceived Tue, 10 Feb 2026 11:00:43 -0800 (PST). Subject: “The Trump Loophole Wall Street Hates”. From: Prime Sight AI [email protected]. Message promotes “AI Royalties”/retirement income claims and pushes the recipient to click a tracking link to “watch now,” using sensational political/financial language and urgency (“payout deadline”).
Sending infrastructure: client/sending IP 23.251.255.234 (hostname e255-234.smtp-out.amazonses.com) via Amazon SES. Mail server IP appears the same: 23.251.255.234. Authentication results show SPF=PASS, DKIM=PASS (primesightai.com and amazonses.com), DMARC=PASS (policy p=NONE). No SPF/DKIM/DMARC failures are indicated in the header.
Likely unsolicited commercial bulk email with potentially deceptive claims. Potential legal issues: CAN-SPAM Act (15 USC 7701–7713) if sent without proper consent and/or if subject/content is materially misleading; FTC Act Section 5 (15 USC 45) if the marketing claims are deceptive.
show less
Received Tue, 10 Feb 2026 at 11:34:44–11:34:45 UTC. The message claims a “497 USD enrollment fee” wi ...
show moreReceived Tue, 10 Feb 2026 at 11:34:44–11:34:45 UTC. The message claims a “497 USD enrollment fee” will be automatically deducted from a bank account and urges the recipient to call a phone number to reach “support staff.” The content impersonates a Microsoft service and combines payment threat language with a verification code to pressure the recipient into calling. This is a classic social-engineering scam designed to induce financial fraud and phone-based extortion.
The sending IP was 40.93.2.64, with the same IP acting as the outbound mail server via Outlook infrastructure. SPF, DKIM, and DMARC all technically passed for microsoftonline.com; however, the message content is fraudulent and misleading, indicating abuse of a legitimate mail platform or compromised tenant. The email falsely asserts pending financial charges and misrepresents account activity to coerce action. This activity violates the CAN-SPAM Act (15 U.S.C. §7701), U.S. wire fraud statutes (18 U.S.C. §1343).
show less
This email was received on Mon, 09 Feb 2026 at 14:48:48 PST. The message presents itself as a loan s ...
show moreThis email was received on Mon, 09 Feb 2026 at 14:48:48 PST. The message presents itself as a loan solicitation from “National Standard Finance,” advertising low-interest financing and requesting a reply for further engagement. The content is unsolicited commercial email designed to initiate contact and potentially harvest responses, using generic financial language and no prior relationship or consent.
The sending IP is 89.252.184.116 with upstream relay activity observed from 77.90.185.200 through the mail server server.efikir.org. SPF, DKIM, and DMARC all pass for the sending domain, indicating the infrastructure itself is authenticated but being used to distribute spam content. Authentication success suggests abuse of a legitimately configured mail server rather than a misconfiguration.
show less
The sending IP appears as 40.93.1.45 with mail server infrastructure using outbound.protection.outlo ...
show moreThe sending IP appears as 40.93.1.45 with mail server infrastructure using outbound.protection.outlook.com. Although SPF, DKIM, and DMARC technically pass, this indicates abuse of a legitimate cloud email platform to distribute scam content rather than authentication failure. The email uses deceptive branding, false billing claims, and telephone-based fraud indicators consistent with phishing and impersonation. No legitimate prior transaction or consent exists for this communication.
This activity violates the CAN-SPAM Act (15 U.S.C. § 7701), FTC rules on deceptive practices, and RFC 5322 requirements regarding truthful message intent and headers. The behavior constitutes phishing and spoofing despite valid authentication. The IP space is owned by Microsoft Corporation. Abuse complaints can be directed to [email protected]show less
Received Mon, 9 Feb 2026 06:08:59 -0800 (PST). Source IP 208.117.56.135 sent as o8.ptr1822.fileforms ...
show moreReceived Mon, 9 Feb 2026 06:08:59 -0800 (PST). Source IP 208.117.56.135 sent as o8.ptr1822.fileforms.com / em6962.notifications.fileforms.com (SendGrid). Unsolicited compliance/marketing solicitation: claims a Florida Annual Report is still required, urges filing by May 1 to avoid a $400 late fee, and pushes links/buttons to file via FileForms. Sender branding could be mistaken as an official state notice even though it includes a third-party disclaimer. Auth: SPF PASS, DKIM PASS (notifications.fileforms.com & sendgrid.info), DMARC PASS.
show less
Received Sun, 08 Feb 2026 at 11:20:21 +0000. Unsolicited email titled “Dear Beloved….” claiming to b ...
show moreReceived Sun, 08 Feb 2026 at 11:20:21 +0000. Unsolicited email titled “Dear Beloved….” claiming to be from “Ms. Marisa Smith,” alleging terminal illness and requesting assistance to distribute USD 15,000,000 for charity while offering the recipient 40% as compensation. The message uses emotional manipulation, religious language, and urgency to solicit cooperation and a reply to a free webmail address. This is a classic advance-fee / inheritance scam.
Sending IP: 103.235.118.147 via mail server dealerfeeds.io, with authenticated submission originating from 185.169.4.16. SPF=none, DKIM=unknown, and DMARC=unknown/absent for the sending domain, indicating unauthenticated mail with no domain alignment. The Reply-To uses an unrelated free email account, strongly indicating forged sender identity. The message was delivered through compromised or misused infrastructure.
This activity violates the CAN-SPAM Act (15 U.S.C. §7701), FTC Act Section 5 regarding deceptive practices, and laws concerning wire fraud
show less
Received Sat, 07 Feb 2026 at 01:49:07 -0800. Unsolicited email titled “TESLA AWARD” claiming the rec ...
show moreReceived Sat, 07 Feb 2026 at 01:49:07 -0800. Unsolicited email titled “TESLA AWARD” claiming the recipient was randomly selected to receive Tesla stock worth over six million USD. The message impersonates “@Tesla Inc.” and instructs the recipient to contact a Gmail address posing as a claims department. This is a classic advance-fee / prize fraud using brand impersonation and false financial claims.
Sending IP: 84.2.38.67 via mail server anubis.silihost.hu, with prior relay from posta.silihost.hu (80.249.160.195). SPF=none and DMARC=fail (policy REJECT/QUARANTINE). DKIM is absent. The Reply-To uses an unrelated free email account, indicating forged sender identity. Spam filters flagged the message for advance-fee fraud, large monetary claims, forged Reply-To, and impersonation indicators.
This activity violates the CAN-SPAM Act (15 U.S.C. §7701), FTC Act Section 5 for deceptive practices, and statutes related to wire fraud and impersonation. It also violates RFC 5322
show less
Received Sat, 07 Feb 2026 15:31:04 -0800. Unsolicited business email titled “2026 Annual Report Fili ...
show moreReceived Sat, 07 Feb 2026 15:31:04 -0800. Unsolicited business email titled “2026 Annual Report Filing Notice for P13000000815” from “2026 Annual Report [email protected]
”. It urges filing a Florida annual report, warns of $500+ late fees, and pushes a paid “filing service,” while disclaiming it is not a government agency. If not requested, this is deceptive/unsolicited solicitation.
Sending IP: 192.174.88.80. Mail server: mta-174-88-80.sparkpostmail.com (SparkPost/Bird). SPF=pass and DKIM=pass; no SPF/DKIM failures shown. No DMARC result is present in this header. Likely bulk-mail delivery using harvested public business-contact information.
Potential violations: CAN-SPAM Act (15 U.S.C. §7701) for unsolicited commercial email and misleading urgency/claims; FTC Act Section 5 for deceptive practices. Possible RFC 5322/5321 misuse of header/subject to mislead.
show less
Received Fri, 6 Feb 2026 16:04:19 +0000. Message subject “Join us for an Open House!” sent as a prom ...
show moreReceived Fri, 6 Feb 2026 16:04:19 +0000. Message subject “Join us for an Open House!” sent as a promotional real-estate marketing email (image-based “OPEN HOUSE”), claiming to be from Shawn Knowles / Coldwell Banker Realty, with a physical mailing address shown in the body and one-click unsubscribe headers present. If you did not request these messages, this is unsolicited commercial email.
Sending IP: 54.240.62.51. Outbound mailhost shown as a62-51.smtp-out.us-west-2.amazonses.com (Amazon SES). SPF=pass, DKIM=pass (moxiimpress.sendproperty.com and amazonses.com), DMARC=pass (policy none). No SPF/DKIM/DMARC failures are indicated in the header, suggesting this was sent through an authorized bulk-mail system.
show less
Received Thu, 05 Feb 2026 15:33:51 -0800. Source IP: 20.51.178.41 (hostname make-20-51-178-41-rr1ums ...
show moreReceived Thu, 05 Feb 2026 15:33:51 -0800. Source IP: 20.51.178.41 (hostname make-20-51-178-41-rr1ums.eastus.cloudapp.azure.com / jaqartaa2.westbrookitpro.com). Provider appears to be Microsoft Azure; same IP used as sending mail server.
Message is unsolicited IPTV marketing (“TV made simple / Press Play”) with heavy sales copy, click-through CTA, and tracking-style links (Google Cloud Storage URL plus “unsubscribe”). Content is designed to drive clicks and potentially lead users into payment/credential capture flows.
Auth results: SPF=pass for westbrookitpro.com; DKIM not present in header; DMARC not shown/evaluated. From header uses a different random domain than the envelope sender (Return-Path), indicating deceptive sender identity. Likely violations: CAN-SPAM (misleading commercial email / insufficient sender transparency) and abusive use of SMTP/message headers contrary to RFC 5321/5322 norms. Abuse contact: [email protected].
show less
Received Thu, Feb 5, 2026 11:34:44 -0800 (PST). Email sent from 51.195.107.197 (HELO: RedheadSluts.c ...
show moreReceived Thu, Feb 5, 2026 11:34:44 -0800 (PST). Email sent from 51.195.107.197 (HELO: RedheadSluts.com / vps.ovh.net). Message impersonates a health insurer “UnitedHealthcare Rewards” and urges the recipient to “claim a free Oral-B Dental Kit” by clicking buttons that lead to a suspicious landing page (AWS S3 getinaccess.html) and a fake unsubscribe. Content includes malformed headers (Date field is not a real timestamp) and large amounts of injected/garbage text consistent with spam kit obfuscation. SPF: pass. DKIM: not present/none seen in header. DMARC: not present/none seen in header. Likely credential-harvest / redirect phishing + brand impersonation. Reported headers to OVH host via HTML Form submission.
show less
Spammer harvesting emails from Florida Sunbiz.
Received 2026-02-05 04:39:07 -0800. Unsolicited com ...
show moreSpammer harvesting emails from Florida Sunbiz.
Received 2026-02-05 04:39:07 -0800. Unsolicited commercial email themed as a “Florida Annual Report – 2026 Filing Reminder” for a named corporation. Message uses authoritative language (“required filing,” deadline emphasis) and prominent CTA buttons linking to third-party paid services (renewals.nationalfilingcorporation.com / e-filemycorp branding) while disclaiming government affiliation in fine print. This pattern is commonly used to pressure recipients into paying “convenience” fees for filings that can be completed directly with the state. Tracking parameters, branded SendGrid infrastructure, and reply-to pointing to a different entity indicate marketing solicitation rather than an official notice. Authentication shows SPF=pass, DKIM=pass (two DKIM signatures), DMARC=pass; no auth failure. Likely violates CAN-SPAM Act (15 U.S.C. §§7701–7713) provisions on deceptive subject/representation and unsolicited commercial email.
show less
Received Tue, 03 Feb 2026 12:00:03 +0000. Source: 54.240.9.12 (a9-12.smtp-out.amazonses.com / Amazon ...
show moreReceived Tue, 03 Feb 2026 12:00:03 +0000. Source: 54.240.9.12 (a9-12.smtp-out.amazonses.com / Amazon SES). Message claims “Social Security Administration” and urges “Download Now” to view a “statement/earnings and benefits,” linking to faxfalcon.com storage (z5aqvbivq.php?hightechoil.com) to lure credential/malware clicks.
Auth results: SPF=pass, DKIM=pass (apartamentehotel.ro and amazonses.com), DMARC=pass. Despite passes, this is classic brand-impersonation: display-name spoofing + government/benefits pretext + off-domain download link. Treat as phishing and unsolicited bulk email.
Likely violations: CAN-SPAM (materially misleading header/subject and deceptive routing), and potential wire-fraud attempt via phishing pretext. Network owner for 54.240.9.12 is Amazon Web Services; report to AWS Trust & Safety
show less
Received Tue, Feb 03 2026 03:39:25 -0800 (PST). Sending mail server/IP: a9-110.smtp-out.amazonses.co ...
show moreReceived Tue, Feb 03 2026 03:39:25 -0800 (PST). Sending mail server/IP: a9-110.smtp-out.amazonses.com (Amazon SES) [54.240.9.110]. Sender claimed: “Social Security Administration” <[email protected]> with subject “Your Statement: Ready for Download”.
Message content impersonates a government agency and urges the recipient to “download your statement,” embedding a credential/malware-style lure link to staging.caeta-dashb.com (z5aqvbivq.php with the recipient domain appended). This is consistent with phishing/social-engineering intended to drive clicks and steal data or deliver malware.
Auth results seen: SPF PASS, DKIM PASS (apartamentehotel.ro and amazonses.com), DMARC PASS (p=NONE). Despite passing auth, the content is deceptive and likely violates CAN-SPAM (15 USC 7704) regarding misleading header/subject and may implicate anti-fraud statutes if used to obtain money/data (e.g., 18 USC 1343). RFC concerns: misleading display-name/From identity (RFC 5322). Host/abuse contact: Amazon Web Services
show less
Received 2026-02-02 08:41:21 PST (Mon) / 16:41:18 UTC. Sending MTA IP: 40.93.20.68 (CH5PR02CU005.out ...
show moreReceived 2026-02-02 08:41:21 PST (Mon) / 16:41:18 UTC. Sending MTA IP: 40.93.20.68 (CH5PR02CU005.outbound.protection.outlook.com / outbound.protection.outlook.com). Message claims “Norton Auto-Renewal” charged $378.00 and urges calling (802) 225-2826, plus an “account email verification code” — classic tech-support/payment lure and brand impersonation.
Auth results in header: SPF=PASS, DKIM=PASS, DMARC=PASS for microsoftonline.com, so the abuse appears to come from (or route through) legitimately authenticated Microsoft mail infrastructure (likely compromised tenant/account or abused service), not simple SPF/DKIM spoofing.
Likely abuse categories: Email Spam, Phishing, Spoofing/Impersonation (and possibly Exploited Host if account compromise suspected). Potential legal issues include CAN-SPAM (15 USC 7704 deceptive routing/headers), FTC Act deception, and possible wire-fraud/impersonation statutes depending on intent. Abuse contact/host: Microsoft Corporation; report to [email protected].
show less
Received Wed, 04 Feb 2026 21:09:31 +0000. Unsolicited email claiming to be from an individual seekin ...
show moreReceived Wed, 04 Feb 2026 21:09:31 +0000. Unsolicited email claiming to be from an individual seeking assistance with vague “investment ventures” and requesting personal engagement. Message uses generic language, emotional appeal, and no verifiable business details, consistent with advance-fee or social-engineering scams.
Sending IP identified as 177.71.92.23 with upstream mail host srv01.juniornet.psi.br and client IP 190.242.98.162. Authentication results show SPF FAIL, DKIM UNKNOWN, and DMARC FAIL for the claimed hotmail.com sender, indicating spoofed sender identity and unauthenticated transmission.
Likely violations include the CAN-SPAM Act (deceptive unsolicited email) and attempted fraud/social engineering. RFC 5321/5322 abuse is evident through sender spoofing and authentication failures. IP ownership appears to be JuniorNet / PSI hosting. Abuse contact for the sending host: [email protected].
show less
Fraud OrdersPhishingWeb SpamEmail SpamSpoofing
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.