Received Tue, Nov 4, 2025 10:31:09 PST. Message claims “Recurring Payment Reactivated” from “service ...
show moreReceived Tue, Nov 4, 2025 10:31:09 PST. Message claims “Recurring Payment Reactivated” from “[email protected]
,” but pushes a fake “Apple Store INC.” charge, an obfuscated phone number to “stop payment,” and a non-HTTPS, look-alike URL (applestore[.]com with injected Unicode spacing). Content also lists a bogus domain “[email protected]
” (invalid TLD). Clear phishing/social-engineering attempt to harvest payment info. Auth results: DKIM=pass (paypal.com), DMARC=pass, SPF=pass at 173.0.84.228 then SPF=softfail on 209.85.220.69 (forwarder), ARC=pass. Deceptive content and mismatched links indicate abuse despite some auth passes. Likely violations: CAN-SPAM (15 U.S.C. §7701 et seq.), FTC Act §5 (deceptive practices), possible wire fraud (18 U.S.C. §1343). RFC issues: syntactically invalid email domain (RFC 5322/1035), misleading links. Please investigate and block. Using phishing phone # for thieving call center: +𝟏-𝟖𝟎𝟓-𝟓𝟎𝟎-𝟖𝟒𝟖𝟕
show less
This unsolicited message was received Sat, Nov 01 2025 at 02:22:58 PDT. It pushes a “Claim Your rewa ...
show moreThis unsolicited message was received Sat, Nov 01 2025 at 02:22:58 PDT. It pushes a “Claim Your rewards”/AsterDEX status link meant to funnel the recipient into clicking a tracking/credential path under the guise of eligibility and distribution updates. The tone and content indicate deceptive crypto-style solicitation without prior consent and constitute unwanted commercial email.
Technical details: Sending IP 128.17.1.158 via mta3.email-biolifeplasma.com (same IP as the mail server). SPF: pass, DKIM: pass (email-biolifeplasma.com; s1.y.mc.salesforce.com), DMARC: pass. Despite authentication passes, this is abusive by content/intent and was not solicited.
This violates CAN-SPAM (15 U.S.C. §7701 et seq.) and FTC rules on deceptive marketing. It also breaches RFC 5321/5322 norms (unsolicited bulk, misleading inducements).
show less
This unsolicited email was received on Sat, Nov 01 2025 at 01:30:51 PDT. The message falsely promote ...
show moreThis unsolicited email was received on Sat, Nov 01 2025 at 01:30:51 PDT. The message falsely promoted an “Airdrop Portal” access, attempting to lure the recipient into clicking a tracking/credential-capture link. The content mimicked an insurance/financial brand and crypto-airdrop messaging, indicating deceptive intent and unauthorized marketing contact. This behavior strongly resembles phishing-adjacent crypto solicitation abuse.
Technical review: Sending IP 13.111.34.128 and mailserver mta.correo.verti.es were used. SPF, DKIM, and DMARC all passed on the header, indicating the sender is leveraging a bulk-email platform to send unwanted crypto-style marketing. Despite passing auth, the message is unsolicited and constitutes abuse by content and intent, violating CAN-SPAM and UCE laws. The content attempts to solicit wallet access through misleading financial language.
This email violates RFC 5321/5322 on appropriate unsolicited bulk transmission and proper consent.
show less
This spam email was received on Sun, 26 Oct 2025 at 18:09 (PDT). The message pretends to come from a ...
show moreThis spam email was received on Sun, 26 Oct 2025 at 18:09 (PDT). The message pretends to come from a BBC Studios newsletter titled “World Cup Briefing – The Daily Jürgen,” but the From field falsely used the recipient’s own name, making it a clear spoof. The body contains profane text and a forged BBC footer attempting to appear legitimate. Multiple unrelated reply-to addresses were inserted, showing that it was sent as a bulk phishing/bounce-spam attack.
Header analysis shows the sending IP 49.13.220.51 (hosted by Hetzner Online GmbH) connecting through static.51.220.13.49.clients.your-server.de. SPF shows pass, DKIM and DMARC were not present, indicating header forgery. The content violates the U.S. CAN-SPAM Act §7704(a)(1)(C) (false or misleading header info) and RCF 5321/5322 for falsified sender fields. This is deliberate email spam, spoofing, and phishing-style impersonation using profane and abusive content.
Has hidden text then this: please stop messaging me 😡😡😡Fu********* youuu 😡😡
show less
The email was sent through Amazon SES using SMTP host a78-75.smtp-out.amazonses.com and IP address 5 ...
show moreThe email was sent through Amazon SES using SMTP host a78-75.smtp-out.amazonses.com and IP address 54.240.78.75, which connected to mx.google.com for delivery. The Return-Path shows an amazonses.com bounce address and the From field is “Tonys Chart Hub [email protected]show less
This unsolicited bulk email was received on Mon, 29 Sep 2025 06:29:06 -0700 (PDT). The message origi ...
show moreThis unsolicited bulk email was received on Mon, 29 Sep 2025 06:29:06 -0700 (PDT). The message originated from Microsoft’s outbound infrastructure (IP: 2a01:111:f403:d200::, host: outbound.protection.outlook.com) with a spoofed sender at Hotmail. The subject was blank, the content meaningless ("Read samurai colophonium") and it contained a suspicious .ics attachment likely designed to lure recipients into opening malicious calendar invitations.
Header analysis shows SPF=pass, DKIM=pass, DMARC=pass, which suggests the account or mail system is being abused to relay spam. Despite passing checks, the transmission constitutes unsolicited mass mailing and attempted abuse of email attachments, violating CAN-SPAM Act, Computer Fraud and Abuse Act, and multiple RFC 5321/5322 standards on proper use of SMTP headers. If the "From" field falsely displayed the recipient’s address, it represents direct spoofing and deceptive misrepresentation.
show less
Another spam, different email from the same host.
On Sep 27, 2025 at 13:31:23 PDT, I received unsol ...
show moreAnother spam, different email from the same host.
On Sep 27, 2025 at 13:31:23 PDT, I received unsolicited commercial email with subject “[REVEALED] The silent profit-killer… (including yours).” Content promotes a “Converstar AI” webinar and pushes links to dfyexpert.com with aggressive marketing claims. Sender shown as “Leads/Sales Booster AI” [email protected] Reply-To is [email protected] path shows delivery from sendera28.transmail.net [135.84.80.28]; sending IP: 135.84.80.28; mail server IP: 135.84.80.28. Authentication: SPF=pass, DKIM=pass (d=zohomeeting.com), DMARC=pass (p=NONE). ARC=pass. Despite valid auth, this is unsolicited bulk advertising.
Requested action: investigate abuse from Zoho ZeptoMail/Transmail infrastructure. Likely CAN-SPAM (15 U.S.C. §7701 et seq.) violations if sent without consent and lacking a clear opt-out; potentially deceptive subject. No obvious RFC 5321/5322 formatting faults observed. Host: Zoho (Transmail/ZeptoMail). Abuse contacts: [email protected]show less
The host won't even accept Spamcop email complaints!
Received Sat, Sep 27, 2025 11:37:30 -0700 (PDT ...
show moreThe host won't even accept Spamcop email complaints!
Received Sat, Sep 27, 2025 11:37:30 -0700 (PDT). Unsolicited commercial email promoting “Converstar”/“Leads/Sales Booster AI” and a webinar (“[ACTION REQUIRED] How to Stop the Leaks and Fix Your Websites Sales in 5mins with AI”). Message contains aggressive marketing copy, multiple tracking/CTA links, and calendar/add-app prompts; I did not sign up or consent.
Technical: Sending IP 135.84.80.28 (host: sendera28.transmail.net, ZeptoMail/Zoho). Path shows mailer.zohomeeting.com via sendera28.transmail.net (135.84.80.28). Auth results: SPF=pass, DKIM=pass (zohomeeting.com), DMARC=pass, ARC=pass. Despite authenticated delivery, this is unsolicited bulk messaging.
show less
This spam email was received on Wed, 24 Sep 2025 at 12:43:34 PDT. The sending IP was 156.146.39.45 c ...
show moreThis spam email was received on Wed, 24 Sep 2025 at 12:43:34 PDT. The sending IP was 156.146.39.45 connecting through the mail server 190.82.96.27 (mail.dabed.cl). The message posed as coming from “Kadulina” [email protected] with a reply-to of a Gmail account. The subject was “Please Get back ASAP” and the body promoted a fake financial opportunity supposedly from a deputy chairman of Ukrsibbank, designed to deceive the recipient into responding.
Header analysis shows SPF = none, with no authorized sending host for the claimed domain. DKIM signatures were missing, and DMARC validation was not aligned, all failing basic authentication. This demonstrates clear spoofing and falsification of sender identity. The use of forged financial authority names and the attempt to solicit engagement makes the intent fraudulent.
Sending bulk spam of this nature violates CAN-SPAM Act provisions and constitutes fraud under computer crime statutes. It also breaches RFC 5321/5322 by forging the MAIL FROM
show less
WordPress WordFence blocking report: The reason is: "Exceeded the maximum number of page not found ...
show moreWordPress WordFence blocking report: The reason is: "Exceeded the maximum number of page not found errors per minute for a crawler.". User location: Shanghai, China
show less
On Sep 23, 2025 at 12:59:25 PDT I received an unsolicited “Login Details” email claiming a new user ...
show moreOn Sep 23, 2025 at 12:59:25 PDT I received an unsolicited “Login Details” email claiming a new user registration at “Log Cabin Kits,” with a BINANCE-themed username and links pushing to wp-login and tracking redirects. This appears to be abusive account creation / credential-phishing via a third-party sender.
Header auth: SPF=pass (mg.logcabinkits.com via 69.72.42.10); DKIM=pass (mg.logcabinkits.com; mailgun.org); DMARC=none/not present. Despite passing auth, content is deceptive/unsolicited. Potential RFC 5321/5322 misuse (unsolicited bulk, misleading content). Violates CAN-SPAM (15 U.S.C. §7701 et seq.; deceptive practices).
Sending IP: 69.72.42.10 (m42-10.mailgun.net, Mailgun Technologies). Mail server IP: 69.72.42.10. Please investigate and terminate abuse. Abuse contact: [email protected]show less
WordPress blocked by WordFence: 2607:9000:6000:17::a03e (Canada)
Blocked for Directory Traversal ...
show moreWordPress blocked by WordFence: 2607:9000:6000:17::a03e (Canada)
Blocked for Directory Traversal in query string: s = ../\think\Container/invokefunction
show less
This spam was received on Sat, 20 Sep 2025 at 08:56:37 -0700. The sending IP was 102.129.234.177, re ...
show moreThis spam was received on Sat, 20 Sep 2025 at 08:56:37 -0700. The sending IP was 102.129.234.177, relayed through the mail server mail.dabed.cl at 190.82.96.27. The message falsely presented itself as coming from “Kadulina [email protected] with a reply-to of a Gmail account. The “From” field used the recipient’s name in a deceptive way. The subject line read “Please Get back ASAP” and the body claimed to be from a deputy chairman at Ukrsibbank Ukraine offering an urgent financial opportunity.
Header analysis shows SPF returned “none,” and no DKIM or DMARC authentication passed, indicating this was not authorized mail from the claimed domain. The use of localhost and internal relays (127.0.0.1) further suggest this was deliberately injected to evade filters. The content is a classic phishing advance-fee fraud attempt designed to harvest personal or financial details.
This activity constitutes email fraud, wire fraud attempts, and violates international anti-spam laws as well as RFC 5321/5322
show less
he spam email was received on Wed, 17 Sep 2025 at 17:20:05 -0700. It originated from sending IP 62.6 ...
show morehe spam email was received on Wed, 17 Sep 2025 at 17:20:05 -0700. It originated from sending IP 62.60.130.120 through mail server 217.112.31.24 (mx.litaform.ru). The message falsely claimed to be from Berkshire Hathaway and the Susan Thompson Buffett Foundation, offering $20.5 million for “poverty alleviation.” The content requested personal details such as name, address, phone number, and date of birth, which are classic signs of a financial phishing scam.
The header shows SPF passed, but no valid DKIM or DMARC alignment was found. The From field used the recipient’s name as false, attempting to impersonate a trusted identity. The email also included a deceptive external link to trick the recipient into believing the scam was legitimate. This demonstrates clear intent to defraud and harvest personal information.
This activity violates multiple laws including CAN-SPAM (unsolicited deceptive emails), wire fraud statutes (18 U.S.C. §1343), and constitutes RFC 5321/5322 violations
show less
Being sent to an email address I NEVER USE
-----
Received Tue, 16 Sep 2025 12:48:03 GMT. Originate ...
show moreBeing sent to an email address I NEVER USE
-----
Received Tue, 16 Sep 2025 12:48:03 GMT. Originated from mail.receita.pb.gov.br (Sending IP/MTA IP: 200.164.224.12) to iCloud SMTP. Host appears operated by sefaz.pb.gov.br / receita.pb.gov.br. Abuse/ops contacts: [email protected][email protected]
Subject: “Claim Code: 211822”. From: “Pch Lottery” [email protected] Reply-To: [email protected]
Unsolicited lottery/prize solicitation attempting to move replies to an unrelated domain, consistent with phishing/advance-fee tactics. Includes internal Zimbra headers; no prior relationship with recipient.
Auth: SPF=pass (200.164.224.12), DKIM=pass (d=sefaz.pb.gov.br), DMARC=pass (policy=none); ARC=none; BIMI=skipped (insufficient DMARC). Despite alignment, content/Reply-To mismatch suggests account/server abuse. Likely violates CAN-SPAM (15 U.S.C. §7704) for deceptive/misleading headers; potential wire fraud (18 U.S.C. §1343). Misleading fields contravene RFC 5322.
show less
The message was received Fri, 19 Sep 2025 01:18:47 -0700 (PDT). Content is an advance-fee “I am an A ...
show moreThe message was received Fri, 19 Sep 2025 01:18:47 -0700 (PDT). Content is an advance-fee “I am an American soldier on active duty in Yemen… legal offer” solicitation asking me to reply for details. Reply-To points to a different domain (Outlook) than the From, a common fraud lure.
Technical summary: Sent via in-mum-m57.icewarpcloud.in [103.161.42.41] (IceWarp). Header also shows probable client/origin tpcglobe.co.in [27.59.77.45]. SPF: pass; DKIM: pass; DMARC: pass (p=NONE). These “passes” indicate an abused mailbox/server rather than a simple spoof.
Legal/RFC: Unsolicited deceptive solicitation violates anti-spam/anti-fraud laws (e.g., CAN-SPAM/advance-fee fraud statutes) and likely the provider’s AUP. No obvious SMTP/5321/5322 header violations, but the scheme and bulk sending are abusive. Network owner/host: IceWarp Technologies Pvt. Ltd. (AS137488).
Host/ownership refs: in-mum-m57.icewarpcloud.in → 103.161.42.41 and IceWarp ASN/contacts (AS137488, abuse mailbox). stat.ripe.net+3
show less
Received Tue, Sep 16, 2025 11:23:49 -0700 (PDT). Unsolicited bulk “Merchant Cash Advance” solicitati ...
show moreReceived Tue, Sep 16, 2025 11:23:49 -0700 (PDT). Unsolicited bulk “Merchant Cash Advance” solicitation targeting my corporation, promising “48-hour funding” and pushing tracking links (tracking.business-revenue.com) via ESP ElasticEmail. Sending IP 67.227.85.156 m156.mxout.mta4.net (Host: Liquid Web — [email protected]
, +1-800-580-4985). Auth: SPF pass for business-revenue.com (67.227.85.156); DKIM pass for business-revenue.com and elasticemail.com; DMARC result not present in header (likely not published or not evaluated). This is unwanted UCE and likely violates CAN-SPAM (15 U.S.C. §7701 et seq.; 16 CFR Part 316) due to unsolicited commercial advertising and deceptive subject personalization using my company name. No obvious RFC 5321/5322 formatting errors; abuse is legal/policy, not protocol. Please investigate and halt spam from this host.
show less