Received Wed, 04 Feb 2026 00:48:49 +0000. Unsolicited “test email for validation” with no prior rela ...
show moreReceived Wed, 04 Feb 2026 00:48:49 +0000. Unsolicited “test email for validation” with no prior relationship, no functional purpose, and no opt-in evidence. Message claims to be a validation test and asks to be ignored, indicating mailbox probing or infrastructure testing rather than legitimate communication.
Sending IP identified as 198.91.86.10, injected via Yahoo infrastructure. Header shows SPF PASS, while DKIM and DMARC are reported as UNKNOWN for the sending domain, indicating incomplete or misconfigured authentication and lack of domain-level accountability.
Likely violations include the CAN-SPAM Act (unsolicited email without consent) and abuse of SMTP for non-transactional test traffic. No clear RFC 5321/5322 header formatting violations detected, but behavior constitutes spam and potential reconnaissance activity. IP owner appears to be Leafdenary hosting. Abuse contact for the sending host: [email protected] and [email protected]show less
Received 2026-02-03 06:48:25 -0800. Suspected phishing/spam: subject 'Check Request' with branded HT ...
show moreReceived 2026-02-03 06:48:25 -0800. Suspected phishing/spam: subject 'Check Request' with branded HTML 'Harry&David Service/Exclusive Offer' and multiple calls-to-action linking to an Azure blob URL (knjgds.blob.core.windows.net) plus embedded image (bobo.png). Content uses urgency/referrals and invites clicks; includes unrelated pasted text (course syllabus) consistent with padding/obfuscation. Source shows submission from 45.151.155.54 (steelhaven.com) into Gmail; likely compromised host/VPS. Auth: SPF=pass; DKIM=pass; DMARC=pass (no auth failure). Header has invalid Date (year 9635) and misleading fields, conflicting with RFC 5322 formatting/accuracy. Likely violates CAN-SPAM Act (15 USC 7701-7713) deceptive header rules. Network Kamatera, Inc. (AS36007). Abuse: [email protected]show less
Received Tue, 03 Feb 2026 05:21:33 -0800. Message claims an urgent “Stripe invoice” and asks for an ...
show moreReceived Tue, 03 Feb 2026 05:21:33 -0800. Message claims an urgent “Stripe invoice” and asks for an invoice image, using a long/odd subject line and high priority flags; includes a suspicious BMP attachment. This is unsolicited and consistent with phishing/malware delivery via attachment.
Header shows originating client IP 43.131.53.162 (ESMTPSA into Gmail) and Gmail relay mail-sor-f41.google.com / 209.85.220.41. Authentication checks: SPF PASS, DKIM PASS, DMARC PASS for the sending gmail.com account (no SPF/DKIM/DMARC failures observed).
Likely violations: CAN-SPAM Act (deceptive commercial email practices) and attempted fraud/social engineering; no clear SMTP/RFC header forgery is evident because the message authenticates. IP ownership/abuse contacts: 43.131.53.162 appears on Tencent (AS132203) [email protected]; Google relay 209.85.220.41 [email protected].
show less
Fraudulent email sent with phishing links.
Received 2026-02-03 02:19:45 -0800 (PST) / 10:19:45 UT ...
show moreFraudulent email sent with phishing links.
Received 2026-02-03 02:19:45 -0800 (PST) / 10:19:45 UTC. Source IP: 167.89.80.92 (hostname o1290.shared.klaviyomail.com). Message routed via SendGrid/Klaviyo infrastructure; Message-ID JSHEWmQrRRWfiivoCH081A@geopod-ismtpd-32.
Auth results: SPF=PASS, DKIM=PASS (dreamhost.com and sendgrid.info), DMARC=PASS (policy p=none). From: “DreamHost <[email protected]>”. Subject: “PHP Extended Support has been removed.” Body says a scan found your sites upgraded to supported PHP versions and that “PHP Extended Support” was removed; invites you to contact support; includes one-click list unsubscribe headers.
If unsolicited, this may violate the U.S. CAN-SPAM Act (unsolicited commercial email / consent issues). No obvious RFC 5321/5322 header-format violations are apparent from the trace. IP owner/ESP abuse contacts: [email protected] and [email protected].
show less
Received 2026-02-02 15:21:57 UTC. Source 128.245.182.232 (ali232.mta.exacttarget.com) sent an unsoli ...
show moreReceived 2026-02-02 15:21:57 UTC. Source 128.245.182.232 (ali232.mta.exacttarget.com) sent an unsolicited marketing message titled “Bootcamp for New Managers and Supervisors: Develop These Essential”. Message includes bulk-email headers (List-Unsubscribe/one-click) and reply routing via resource.onlinetranings.com. Auth checks: SPF=PASS, DKIM=PASS (2 signatures: campaign.onlinlearnings.com and s12.y.mc.salesforce.com), DMARC=PASS, compauth=PASS. Not a user-originated message; appears to be mass-mail advertising/training promo. Possible CAN-SPAM concerns if no prior consent or if opt-out not honored; request investigation and suppression. Abuse contact: ExactTarget/Salesforce Marketing Cloud [email protected]show less
Received Sun, 01 Feb 2026 14:56:41 +0000. Unsolicited bulk email labeled “Reminder: Event Tomorrow” ...
show moreReceived Sun, 01 Feb 2026 14:56:41 +0000. Unsolicited bulk email labeled “Reminder: Event Tomorrow” sent without prior relationship or consent. Message contains minimal visible content, hidden HTML elements, and bulk-mail indicators, consistent with deceptive or low-content spam delivery rather than a legitimate transactional notice.
Header analysis shows originating IP 77.36.28.68 using mx1.astrophysicshub.com as the sending mail server. SPF=pass, DKIM=unknown, DMARC=pass. Despite authentication passing, the message was sent as bulk mail with concealed content and no clear opt-in, indicating abuse of a valid domain and infrastructure rather than authentication failure.
This activity violates the CAN-SPAM Act (15 U.S.C. §7701–7713) due to unsolicited bulk transmission and deceptive content practices. It also conflicts with RFC 5322 transparency requirements and RFC 7489 intent regarding responsible domain use. The apparent sending host is astrophysicshub.com. Abuse contact: [email protected]show less
Received Sun, 01 Feb 2026 11:26:48 +0000. Unsolicited financial fraud email claiming to be from a go ...
show moreReceived Sun, 01 Feb 2026 11:26:48 +0000. Unsolicited financial fraud email claiming to be from a government ministry and requesting assistance transferring USD $35,500,000 derived from an inflated contract. Message solicits foreign bank account details, promises a percentage payout, demands secrecy, and asserts the transaction is “risk free,” which is a classic advance-fee / corruption scam.
Header analysis shows originating IP 103.170.5.29 relayed via huiyixx.cn, with upstream submission from 185.22.65.20. SPF=fail, DKIM=unknown, DMARC=fail. The From address uses a domain not authorized to send mail from the originating IP, and Reply-To points to a different mailbox, indicating spoofing and deliberate misrepresentation.
This activity violates the CAN-SPAM Act (15 U.S.C. §7701–7713) due to deceptive content and false header identity, and constitutes wire-fraud solicitation. It also violates RFC 5322 (misleading From/Reply-To fields) and RFC 7208 authentication best practices.
show less
Received Sat, 31 Jan 2026 06:50:42 +0000. Unsolicited advance-fee scam email claiming religious char ...
show moreReceived Sat, 31 Jan 2026 06:50:42 +0000. Unsolicited advance-fee scam email claiming religious charity intent and requesting assistance distributing a supposed USD $15,000,000 deposit. Message uses emotional manipulation, terminal illness narrative, and promises a 40% personal reward to induce response. This is a classic financial fraud / social-engineering scheme.
Header analysis: originating IP 103.235.118.147 relayed via dealerfeeds.io; upstream authenticated submission from 185.169.4.18. SPF=none, DKIM=unknown, DMARC=unknown. The From address uses a generic domain with no authorization, indicating spoofed or unauthenticated sender identity. Reply-To redirects to a different mailbox, further indicating fraud.
This activity violates anti-fraud and anti-spam laws including CAN-SPAM Act (15 U.S.C. §7701–7713) for deceptive messaging, false header identity, and lack of consent. It also violates RFC 5322 (misleading From/Reply-To fields) and RFC 7208 best practices by failing sender authentication.
show less
Received Sat, 31 Jan 2026 00:26:49 -0800 (PST). IPs in header: 179.43.151.64 (injected to api.elasti ...
show moreReceived Sat, 31 Jan 2026 00:26:49 -0800 (PST). IPs in header: 179.43.151.64 (injected to api.elasticemail.com) and outbound MTA 69.72.31.173 (w173.mxout.mta1.net / Elastic Email). Subject: “RILEY RESEARCH CORPORATION - 2026 Annual Report Filing Notice for P13000000815”. SPF=pass, DKIM=pass, DMARC=pass.
Unsolicited “annual report” filing reminder pushing a paid filing service, urging quick action to avoid late fees, with tracking/checkout links; states it is not affiliated with any government agency while using official-sounding branding. Includes unsubscribe.
Likely email spam / deceptive solicitation. May implicate CAN-SPAM (misleading solicitation/header claims) and conflicts with RFC 5322/5321 bulk-mail best practices if sent without consent.
show less
Received Thu, 29 Jan 2026 13:51:21 -0800. Unsolicited bulk email advertising EN590 10PPM diesel, Vir ...
show moreReceived Thu, 29 Jan 2026 13:51:21 -0800. Unsolicited bulk email advertising EN590 10PPM diesel, Virgin D6 fuel oil, and Jet Fuel A1 and requesting a “company profile”/buying requirements; Reply-To points to [email protected] (different from From domain), suggesting B2B scam/spam.Sending host/mail server: 2.239.221.170 (mx3/fortimail.ospedalesantandrea.it). Auth: SPF=pass; no DKIM or DMARC results shown in header. Likely misuse/compromise of a legitimate domain or outbound relay.Net owner: Fastweb SpA (AS12874). Suspected violations: unsolicited commercial email (CAN-SPAM principles), deceptive routing/identity, and RFC 5321/5322 best-practice violations for truthful, non-misleading email.
show less
Received on Fri, 30 Jan 2026 at 03:54:53 PST. Unsolicited commercial email advertising IPTV / stream ...
show moreReceived on Fri, 30 Jan 2026 at 03:54:53 PST. Unsolicited commercial email advertising IPTV / streaming services with deceptive marketing language, urgency prompts, and an external click-through hosted on a cloud storage service. The message was sent without consent and falsely implies prior interest. The content is purely promotional and bulk in nature, designed to drive traffic to an off-site landing page.
Header analysis shows sending IP 172.202.120.149 with mail server benyty4.hkrenoman.com (Azure cloud VM hostname make-172-202-120-149-rr1ums.centralus.cloudapp.azure.com). SPF passed, however no DKIM or DMARC authentication results are present, indicating incomplete email authentication and increased spoofing risk. The From field used a fabricated sender identity unrelated to the sending infrastructure, indicating impersonation.
show less
Received Tue, 27 Jan 2026 13:35:59 +0000. Source IP (X-Originating-IP): 51.83.205.40; sending MTA: m ...
show moreReceived Tue, 27 Jan 2026 13:35:59 +0000. Source IP (X-Originating-IP): 51.83.205.40; sending MTA: mail.madison-cruz-inc.com (51.83.205.40). Auth results show SPF=pass, DKIM=pass, DMARC=pass (p=NONE), so this appears to be authenticated bulk mail rather than a spoofed header.
Message presents as an unsolicited “Weekender/South Florida events” newsletter (“Chocolate fest… Secret Woods Nature Center…”) containing numerous tracking links and marketing language (“This is an advertisement”) plus list-unsubscribe mechanisms. Reporting as spam due to unwanted commercial email delivery.
ISP won't accept abuse report emails. All headers and IP address have to be manually submitted here: https://www.ovhcloud.com/en/abuse/
show less
Received Mon, 26 Jan 2026 14:38:38 -0800 (PST). Source mail server IP: 185.132.183.25 (mx07-003a9f01 ...
show moreReceived Mon, 26 Jan 2026 14:38:38 -0800 (PST). Source mail server IP: 185.132.183.25 (mx07-003a9f01.pphosted.com). Upstream sending IP observed in header chain: 185.91.69.136. Message presents itself as a business inquiry from “Fawaaz Global Associates” using [email protected] and asks the recipient to forward product specifications for large-quantity contracts tied to “foundation projects,” a common unsolicited procurement lure.
Email content is unsolicited B2B spam designed to solicit engagement and documents under a vague procurement pretext. The subject references forwarding product specifications to an unrelated third-party address, indicating lead harvesting or potential fraud setup. No prior relationship is indicated, and branding/domain usage appears misleading.
Authentication results show SPF=pass, DKIM=pass, DMARC=pass for logwin-logistics.com, meaning the domain authorized the send, but this does not legitimize the content. Likely violations include CAN-SPAM Act (15 USC 7701-7713)
show less
Received Mon, 26 Jan 2026 11:14:15 -0800 (PST). Suspected phishing/billing lure: “Access Bill.pdf an ...
show moreReceived Mon, 26 Jan 2026 11:14:15 -0800 (PST). Suspected phishing/billing lure: “Access Bill.pdf and keep a hard copy” with message “Invoice for your recent purchase is attached… Service Hotline: +1(983) 220-2377”. Sender appears as “Vinita Smith <[email protected]>” (likely impersonation / unsolicited invoice scam).
Sending client IP: 43.163.124.116 (connected to smtp.gmail.com via authenticated submission). Mail relay/server IP: 209.85.220.41 (mail-sor-f41.google.com). Authentication seen: SPF=pass and DKIM=pass for ctic.ro / Google; DMARC result not shown in header excerpt; ARC present.
This activity appears to violate the U.S. CAN-SPAM Act (deceptive/unsolicited commercial email) and, if used to obtain money/data, may implicate wire fraud statutes. It also conflicts with SMTP/email best practices (unsolicited phish delivery with attachment).
show less
Received Mon Jan 26 2026 05:33:36 PST (08:33:36 ET). Source IP: 149.72.184.219. Bulk marketing/newsl ...
show moreReceived Mon Jan 26 2026 05:33:36 PST (08:33:36 ET). Source IP: 149.72.184.219. Bulk marketing/newsletter “TQ Morning Briefing” via beehiiv/SendGrid: market commentary on gold/Fed/politics, multiple promotional partner ads, numerous tracking links, and one-click unsubscribe headers present. Auth results: SPF PASS; DKIM PASS (mail.beehiiv.com & sendgrid.info); DMARC PASS (aligned with beehiiv.com). No spoofing/auth failure seen; report as unsolicited commercial email if not subscribed. Potential legal issues if unsolicited/noncompliant: U.S. CAN-SPAM Act (15 USC 7701–7713) requirements (consent, opt-out, truthful headers). RFC: no obvious 5322/5321 violations. IP owner/abuse: Twilio SendGrid (SendGrid, Inc.), phone +1 888-985-7363, [email protected]
Over a dozen emails sent to [email protected] and THEY REFUSE to block my email from their servers. Legal action will have to be taken. This is harassment.
show less
Received Fri, 16 Jan 2026 20:14:18 +0000. Sending IP / mail server: 65.20.111.239 (EHLO customer-liv ...
show moreReceived Fri, 16 Jan 2026 20:14:18 +0000. Sending IP / mail server: 65.20.111.239 (EHLO customer-livehelpdesk.info). Message impersonates the Social Security Administration with subject “Your eStatement is Ready” and urges the recipient to download an “updated statement.”
Auth results in header: SPF=fail (domain does not authorize 65.20.111.239); DKIM=pass ([email protected]); DMARC=pass (p=none). Despite DMARC passing, the content is deceptive and designed to induce unsafe action.
Email includes an attachment “SSA_eStatement.zip” (a zipped payload), consistent with malware delivery and/or credential theft. Likely violations include CAN-SPAM (15 U.S.C. §7701–7713) and wire fraud/phishing (18 U.S.C. §1343). RFC issues: SPF per RFC 7208 failed; misleading header/content under RFC 5322. Abuse contact for the IP owner: [email protected].
show less
Received Thu, 22 Jan 2026 20:28:22 +0000. Suspected source: 212.227.17.24 (EHLO mout.kundenserver.de ...
show moreReceived Thu, 22 Jan 2026 20:28:22 +0000. Suspected source: 212.227.17.24 (EHLO mout.kundenserver.de / IONOS SE). Internal client seen: 147.124.210.21. The display-name in From impersonates DocuSign and falsely includes the recipient’s name/email to appear trusted.
Auth results: SPF=softfail (pradelgroup.com not authorizing 212.227.17.24); DKIM=unknown; DMARC=fail (p=none). Message is a “Completed: Please Sign” lure with an encoded reference and a prominent “REVIEW DOCUMENT” button directing to a non-DocuSign domain, consistent with credential-theft/phishing.
Likely violations: CAN-SPAM Act (15 U.S.C. §7701–7713) and fraud/phishing statutes (e.g., 18 U.S.C. §1343). RFC/authentication failures: RFC 7208 (SPF) and RFC 7489 (DMARC), plus misleading header identity under RFC 5322. Abuse contact for the sending network: [email protected].
show less
Received Sun, 25 Jan 2026 13:28:41 -0800 (PST). Mail server IP: 93.113.62.250 (sb0003.zuk.uk.com). O ...
show moreReceived Sun, 25 Jan 2026 13:28:41 -0800 (PST). Mail server IP: 93.113.62.250 (sb0003.zuk.uk.com). Other observed source IPs: 217.18.210.147 (X-Originating-IP) and 216.244.76.116 (efianalytics.com hop). From field used the recipient’s name falsely.Message is a “Cloud Storage / account blocked” scare lure claiming photos/videos will be deleted unless the user “renews” immediately, pushing a click-through button and unsubscribe link typical of phishing. Content uses urgency, threat of account loss, and misleading branding to trick the recipient into visiting a remote link and potentially entering credentials or payment data.Header auth: SPF=pass and DKIM=pass are shown; DMARC result is not present in the header, so DMARC status cannot be confirmed. This is abusive bulk/phishing mail with spoofed identity intent and deceptive header/content behavior. Spamcop reports [email protected] as host.
show less
Received 2026-01-21 04:02:09 PST. Unsolicited commercial spam advertising “Premium IPTV streaming” ( ...
show moreReceived 2026-01-21 04:02:09 PST. Unsolicited commercial spam advertising “Premium IPTV streaming” (“The way people actually watch TV”, “Cancel Anytime, No Contracts”). Message is polished HTML/CSS and attempts to drive clicks to an external landing page hosted on storage.googleapis.com (link.html with tracking fragment) with a “See how it works” call-to-action, plus an “Unsubscribe” link pointing to the same hosted page. Sending host/IP: 4.180.183.214 (…cloudapp.azure.com). Return-Path: [email protected] while From displays a different domain/name, consistent with bulk/throwaway sender identity. Authentication results shown: SPF=PASS; DKIM not shown; DMARC not shown. Likely CAN-SPAM concerns (unsolicited marketing, no clear consent; no visible physical postal address in body). Header practices may be inconsistent with RFC 5322 expectations for transparent, non-misleading origin metadata.
show less
Received Fri, 09 Jan 2026 18:55:19 +0000. Phishing email impersonating Amazon Prime: claims membersh ...
show moreReceived Fri, 09 Jan 2026 18:55:19 +0000. Phishing email impersonating Amazon Prime: claims membership renews and payment method is invalid, urging “Update Payment Method” and directing to a Google Docs link to steal credentials/payment info. Sender uses random domain b38.azatothrotten6.biz.id with “Prime Notification” display name.
Header auth: SPF=none (no permitted sender), DMARC=unknown for b38.azatothrotten6.biz.id, DKIM=pass (domain-signed but still fraudulent). Relay shows Google MX mail-dy1-f193.google.com (74.125.82.193) and an authenticated submission to smtp.gmail.com from 47.251.182.202.
This violates CAN-SPAM (deceptive header/subject, no valid consent) and constitutes phishing/identity deception (FTC Act 15 USC 45; likely wire fraud 18 USC 1343). Message format is misleading and non-compliant with RFC 5322/5321 best practices for truthful From/subject.
show less
Received Wed, 07 Jan 2026 at 13:24:08 +0000 (UTC). Unsolicited bulk commercial email claiming to be ...
show moreReceived Wed, 07 Jan 2026 at 13:24:08 +0000 (UTC). Unsolicited bulk commercial email claiming to be from “Jdsports Loyalty Rewards” offering Adidas sneakers for £9.99 and using urgency, voucher codes, and deceptive reward language. The message attempts to entice the recipient into clicking tracking links and providing personal or payment information under a fake loyalty reward pretext.
Sending IP: 81.19.140.67 (mail.customersforce.com). Mail server: atlas118.free.mail.bf1.yahoo.com. Authentication results show SPF=pass, DKIM=pass, DMARC=pass for customersforce.com; however, passing authentication does not legitimize unsolicited bulk marketing or deceptive reward scams.
This activity violates CAN-SPAM Act (15 U.S.C. §7701–7713) for deceptive commercial email and misleading subject lines, and misuses SMTP and email standards under RFC 5321 and RFC 5322 for spam distribution and fraud-oriented solicitation.
show less
Microsoft won't take responsibility for the spam and has no interest in doing anything about it.
...
show moreMicrosoft won't take responsibility for the spam and has no interest in doing anything about it.
Received Thu, 08 Jan 2026 10:58:53 -0800 (PST). Unsolicited scam/phish email impersonating a Microsoft online service notice and “NortonLifeLock renewal” for $499.99, pushing a phone number (1 805 331 5481) and “account email verification code”. Body says “Verify your email address” and code 823113, consistent with social-engineering to trigger a call/payment or credential capture.
Sending MTA/IP: CH4PR04CU002.outbound.protection.outlook.com [2a01:111:f403:c105::7] (Microsoft). Additional server: substrate.office.com [2603:10b6:a03:363::19]. Header auth on arrival: SPF=pass, DKIM=pass, DMARC=pass for microsoftonline.com; despite passing auth, message content is deceptive and abusive.
Likely violations: CAN-SPAM (15 U.S.C. 7701-7713) for deceptive commercial email; FTC Act (15 U.S.C. 45) deceptive practices; misuse of SMTP/message standards (RFC 5321/5322) for fraudulent solicitation.
show less
Received on Wed, 07 Jan 2026 at 15:34:35 -0800 (PST). Unsolicited bulk commercial email advertising ...
show moreReceived on Wed, 07 Jan 2026 at 15:34:35 -0800 (PST). Unsolicited bulk commercial email advertising fuel products (EN590 10PPM Diesel, D6, Jet A1) and requesting company profiles and buying requirements. The message was sent without prior consent and constitutes spam and attempted lead harvesting. The content promotes petroleum sales, claims storage at multiple ports, and urges engagement with “qualified buyers,” which is a classic B2B spam solicitation pattern.
Sending IP: 62.48.241.109 (mx1.ps.pt / mail.ps.pt). Originating IP shown: 158.173.152.44. Mail server path includes smtp.ps.pt and mx1.ps.pt. Authentication results show SPF=pass, DKIM=pass, DMARC=pass for domain ps.pt; however, passing authentication does not legitimize unsolicited bulk email. The From header shows Administrator [email protected] Reply-To points to [email protected] indicating third-party commercial solicitation via this infrastructure.
This activity violates CAN-SPAM (15 U.S.C. §7701-7713)
show less
Received Wed, 07 Jan 2026 17:20:09 -0800. Source MTA: m206.mxout.mta4.net (67.227.85.206); this appe ...
show moreReceived Wed, 07 Jan 2026 17:20:09 -0800. Source MTA: m206.mxout.mta4.net (67.227.85.206); this appears to be the sending IP and the outbound mail server.
Message claims to be an “2026 Annual Report Filing Notice” for RILEY RESEARCH CORPORATION (P13000000815), urging you to file an annual report between Jan 1 and May 1 to avoid $500+ late fees, and pushes you to use a paid filing service while stating it is not affiliated with any government agency. Contains tracking links and one-click unsubscribe.
Auth results: SPF PASS, DKIM PASS (myflcorpfiling.com + elasticemail.com), DMARC PASS. Network owner: Colocation America Corporation (AS21769). Abuse contact: [email protected]. Potential unsolicited commercial email; if deceptive/misleading, may implicate CAN-SPAM (15 USC 7701-7713) and FTC Act Section 5.
show less
PhishingWeb SpamEmail Spam
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.