Received Sat, 23 Aug 2025 18:17:18 +0000. Message poses as “Ninja Offers” (“Your_Ninja_CREAMi_awaits ...
show moreReceived Sat, 23 Aug 2025 18:17:18 +0000. Message poses as “Ninja Offers” (“Your_Ninja_CREAMi_awaits”) with HTML image-map driving clicks to medinfonowblog.com. Unsolicited commercial lure consistent with phishing/affiliate spam.
Sending IP: 8.219.35.139 (EHLO out35-139.sg.b.dm.aliyun.com). Earlier hop via Amazon SES a26-59.smtp-out.us-west-2.amazonses.com, mail server IP 54.240.26.59. Auth results are inconsistent across hops: SPF=pass (daratele.shop); DKIM/DMARC show pass at Yahoo/Google but fail at Microsoft; ARC present/overridden—indicative of header/identity manipulation and bulk abuse.
Violations: CAN-SPAM (unsolicited marketing, misleading headers). Possible RFC issues: 5322 (header integrity) and alignment vs 7208/6376/7489 (SPF/DKIM/DMARC) at some hops; forged “Resent-From”. Please investigate and terminate abuse. Abuse contacts: Alibaba Cloud for 8.219.35.139 — [email protected]show less
Received Sat, Aug 30, 2025 19:37:06 +0000. Phishing/spam impersonating “Cloud Alerts/Twitch”: subjec ...
show moreReceived Sat, Aug 30, 2025 19:37:06 +0000. Phishing/spam impersonating “Cloud Alerts/Twitch”: subject “Final Warning: Your Files Will Be Deleted Today!”. HTML uses an image with mapped links to en-ran[.]com and an unsubscribe tracker. Return-Path is [email protected]
Auth results: SPF pass for lettertense.shop; DKIM pass for lettertense.shop and (at some hops) twitch.tv/amazonses.com; ARC shows overrides; DMARC inconsistent—pass at Yahoo for header.from=twitch.tv but fail at Microsoft—consistent with spoofed/forwarded headers and brand misuse.
Source at receipt: 8.219.35.137 (out35-137.sg.b.dm.aliyun.com, Alibaba Cloud). Earlier hop mail server: 54.240.26.78 (a26-78.smtp-out.us-west-2.amazonses.com). Violations: CAN-SPAM Act (15 U.S.C. §7704: deceptive headers), potential wire fraud (18 U.S.C. §1343). RFC 5321/5322 issues due to forged/contradictory Received/From lines.
show less
Received Fri, 29 Aug 2025 17:43:57 +0000. Unsolicited real-estate marketing email titled “Just Sold ...
show moreReceived Fri, 29 Aug 2025 17:43:57 +0000. Unsolicited real-estate marketing email titled “Just Sold Another Successful Sale! Congrats to the New Owners,” promoting a Cupertino property (10424 Dempster Ave, $3,200,000) with detailed features, multiple tracking links/pixels, and a “GET STARTED” CTA.
Sending IP / MTA: 198.2.175.99 (mail99.suw151.rsgsv.net). Host: The Rocket Science Group LLC (Mailchimp). Abuse contact: [email protected]show less
Received Fri, 29 Aug 2025 17:43:57 +0000. Message delivered via Mailchimp infrastructure: sending IP ...
show moreReceived Fri, 29 Aug 2025 17:43:57 +0000. Message delivered via Mailchimp infrastructure: sending IP 198.2.175.99 (mail99.suw151.rsgsv.net), handed to Yahoo MTA 10.214.155.146 over TLS1.3.
Promotional real-estate email titled “Just Sold…Congrats to the New Owners,” from “Rachel” at kw.com, publicizing sale of 10424 Dempster Ave, Cupertino CA for $3,200,000. Includes detailed property features, links to rachelghomes.com, Mailchimp tracking, Instagram/YouTube, and call-to-action buttons.
SPF: pass; DKIM: pass (fbl.mcsv.net & kw.com); DMARC: pass (p=none). No obvious RFC 5321/5322, 7208, 6376, 7489 failures. If unsolicited and/or opt-out ignored, potential CAN-SPAM issues (15 U.S.C. §7704). Report host: Mailchimp (The Rocket Science Group). Abuse contact: [email protected]show less
Received Thu, 28 Aug 2025 15:32:20 +0000 via atlas113.free.mail.bf1.yahoo.com. Sending IP 51.77.95.6 ...
show moreReceived Thu, 28 Aug 2025 15:32:20 +0000 via atlas113.free.mail.bf1.yahoo.com. Sending IP 51.77.95.65 (EHLO sn2.ebilling-quickbooks.help); receiving MTA logged 10.197.39.235 (Yahoo internal). Authentication shows SPF=pass, DKIM=pass, DMARC=pass for ebilling-quickbooks.help, yet the message impersonates Intuit.
Content: “Payment Issue with QuickBooks Subscription” claims a failed renewal and urges calling +1-805-695-6578 to “update payment.” High priority and a blank “List-Unsubscribe” mailto. This is a billing-support phone-phish intended to harvest card details and/or money.
Host likely: OVH SAS (OVHcloud) for 51.77.95.65; abuse contact: [email protected]show less
Received Aug 27, 2025 15:07 PDT. Advance-fee/inheritance lure: claims to be an attorney (“Confidenti ...
show moreReceived Aug 27, 2025 15:07 PDT. Advance-fee/inheritance lure: claims to be an attorney (“Confidential Legal matters”) referencing a deceased client with a shared surname and asks for a reply to a different mailbox. Clear social-engineering scam.Sending IP (client): 192.227.217.223 (likely origin). Mail server IP: 219.117.227.89 cs.ifcomputer.co.jp (forwarding MTA). SPF: pass for ifcomputer.co.jp; DKIM: not present in header; DMARC: not shown; ARC: cv=none. From display name “Ronald Evergreen” with Reply-To mismatch indicates deceptive intent.Likely violations: CAN-SPAM (15 U.S.C. §7704 — deceptive pretext; no valid physical address/opt-out) and wire-fraud statute (18 U.S.C. §1343). RFC notes: DKIM absent (RFC 6376); DMARC result absent (RFC 7489); misleading header semantics contravene RFC 5322’s intent. Provider contacts—ColoCrossing (owner of 192.227.217.223): [email protected], +1-800-518-9716. NTT PC Communications (219.117.227.89 host for cs.ifcomputer.co.jp): [email protected], +81-3-6203-2703
show less
Received Aug 27, 2025 08:55:33 PDT via 60.36.166.34 (msc112.plala.or.jp). Message is an advance-fee/ ...
show moreReceived Aug 27, 2025 08:55:33 PDT via 60.36.166.34 (msc112.plala.or.jp). Message is an advance-fee/lottery-donation hoax: claims an $842.4M Powerball win and offers $10M, directing the target to contact “Mr. John Hoag” at [email protected] with code TBC-97121USA, plus requests full PII and ID/passport; cites “U.S. government monitoring” and a CIBC Bank contact +1-917-392-7199. Auth results: SPF pass; DKIM pass (plala.or.jp); DMARC pass (p=none). Reply-To mismatch used to divert responses. Likely violations: CAN-SPAM (15 U.S.C. §7704) for deceptive/unsolicited solicitation; attempted wire fraud (18 U.S.C. §1343) and identity-theft solicitation; contravenes RFC 5322 header-field semantics (misleading From/Reply-To). Origin IP owner: NTT DOCOMO/Plala (plala.or.jp); abuse: [email protected]; phone: 0120-971-391 / 0570-008-887. All headers retained and reported.
show less
Received Mon, 25 Aug 2025 15:05:08 −0700 (PDT). Sending/mailserver IP: 159.183.224.0 via s.wfbtzhhh. ...
show moreReceived Mon, 25 Aug 2025 15:05:08 −0700 (PDT). Sending/mailserver IP: 159.183.224.0 via s.wfbtzhhh.outbound-mail.sendgrid.net (SendGrid/AS11377). From: Cole McCann [email protected]. Subject: “Your personal data has leaked”. Message is an extortion/sextortion scam alleging device compromise, webcam/mic control, and threatens to publish recordings unless 12,000 USD in bitcoin is paid. Auth results from header: SPF=pass (client-ip 159.183.224.0), DKIM=pass (d=ldoncoffee.com; s=s1), DMARC=not present in header; ARC cv=none. Malicious social-engineering; no legitimate prior relationship. Likely violations: 18 U.S.C. §875(d) (extortion), 18 U.S.C. §1343 (wire fraud), and CAN-SPAM (15 U.S.C. §7701 et seq.) for deceptive subject/content. No obvious RFC 5321/5322 header-format violations observed; abuse lies in content/intent. Hosting: Twilio SendGrid — report to [email protected]show less
Received on Aug 21, 2025 18:10:36 -0400. Message delivered via mx.google.com from mann.therests.co [ ...
show moreReceived on Aug 21, 2025 18:10:36 -0400. Message delivered via mx.google.com from mann.therests.co [51.161.73.164]; previous hop njmta-53.sailthru.com [173.228.155.53]. Subject “Please Check Your account.” From field used the recipient’s name falsely.
Email claims urgent account review and payout confirmation, pushes “Confirm/Verify” links hosted behind obfuscated storage URLs, with junk filler text to evade filters. Content unsolicited and deceptive, attempting to harvest credentials/payment info under guise of security notice/newsletter.
Auth results: SPF PASS for data-updates.tools.commerce.gov.extraordic.com via 51.161.73.164; DKIM PERMERROR (no public key) for o8bxom.3zdsvi.xwkt7l.us; DMARC not shown/unaligned. Violations: CAN-SPAM (15 U.S.C. §7704) misleading headers/subject; potential wire fraud (18 U.S.C. §1343); RFC 5322/5321 header spoofing and identifier misalignment.
show less
Received Thu, Aug 21, 2025 13:48:55 PDT. Unsolicited gambling promo (“400% Bonus up to €2000 + 145 F ...
show moreReceived Thu, Aug 21, 2025 13:48:55 PDT. Unsolicited gambling promo (“400% Bonus up to €2000 + 145 Free Spins”) with redirect/tracking links and obfuscated text; no prior consent. These headers are being reported to the hosting providers; ongoing identical spam shows the host ignores complaints and delivery continues.
Auth: SPF pass ([email protected] via 163.172.81.246); DKIM permerror (no key) for xb5hfz.21n306.21xwai.us; DMARC not shown and domains misaligned, so DMARC likely fails. Header anomalies indicate RFC 5322/7208/6376/7489 issues. Likely violates CAN-SPAM (15 U.S.C. §7701 et seq.) for deceptive headers & unsolicited ads.
Sending IP: 163.172.81.246 (Scaleway/Online S.A.S — [email protected]). Mail server in chain: 173.228.155.53 njmta-53.sailthru.com (NYI — [email protected]). Please terminate the source and enforce AUP; persistent spam indicates inadequate enforcement.
show less
Received on Aug 21, 2025 16:06 ET. Unsolicited bulk marketing “You left items in your cart” from “Mi ...
show moreReceived on Aug 21, 2025 16:06 ET. Unsolicited bulk marketing “You left items in your cart” from “Mixedesire” via Shopify Email/SendGrid. Contains tracking links/pixel and one-click unsubscribe, but I never subscribed and messages persist.
Source MTA: o37.mailer.shopify.com [149.72.116.219]. Auth results show SPF=pass, DKIM=pass (g.shopifyemail.com, sendgrid.info), DMARC=pass (shopifyemail.com); so not a spoof, but unsolicited.
Likely CAN-SPAM §7704 violations (unsolicited marketing, continued sending after complaints). No obvious RFC 5321/5322 violations in header. Please investigate and terminate sender; host appears unresponsive to abuse as spam continues. Network owner: Twilio SendGrid — [email protected] / [email protected].
show less
Received Aug 21, 2025 12:52:15 PDT (15:52:15 EDT). Fraud email claims a “$5,000.50 direct deposit,” ...
show moreReceived Aug 21, 2025 12:52:15 PDT (15:52:15 EDT). Fraud email claims a “$5,000.50 direct deposit,” hides behind a fake delivery-status (multipart/report) and heavy base64/HTML noise, and pushes obfuscated links (incl. storage.googleapis.*)—classic credential-harvest phish. The From display name reused the recipient’s own name to mislead. Auth: SPF PASS for a return path at auth.email-secure.us.dramational.com via 95.168.160.83; DKIM permerror (no key) for rdyzmduomwykhkmdqxkqxlfb.com; DMARC alignment fails (SPF domain not aligned with From). Received chain shows balistreri.jamesonally.com.de [95.168.160.83] as sending host. Please investigate, disable the source, and remove related landing pages/assets.
Categories to tick: Email Spam, Phishing, Spoofing.
Likely host/abuse desk (for 95.168.160.0/20, AS60781): LeaseWeb — abuse: [email protected]
, phone: +31 20 316 2880 (global contact page also lists [email protected]
and support numbers).
show less
Unsolicited casino/gambling promo received Aug 21, 2025 14:48:09 -0400. Delivered via cronin.kongzhi ...
show moreUnsolicited casino/gambling promo received Aug 21, 2025 14:48:09 -0400. Delivered via cronin.kongzhiduan.com [89.252.173.119] to Google. MAIL FROM domain wdf4ds-14efde6-d4fg.platforway.com passed SPF, but the visible From “Casino Exclusive” uses 93r3xy.vyjq90.p4mnmh.us → clear domain/header misalignment (spoofing). DKIM=permerror (no public key for d=93r3xy.vyjq90.p4mnmh.us). No DMARC result visible; alignment therefore fails. Content uses redirector links and “free spins” inducements typical of bulk spam. Laws/RFCs: CAN-SPAM (15 U.S.C. §§7701–7713: unsolicited commercial email & misleading header info); RFC 5322/5321 (misleading From), RFC 6376 (DKIM unverifiable), RFC 7489 (DMARC misalignment). Please investigate and disable the sender at 89.252.173.119. IP owner & abuse desk for 89.252.173.119:
Netinternet Bilisim Teknolojileri AS (AS51559) — Abuse: [email protected]
— Phone: +90 850 885 08 85.
show less
Received Aug 21, 2025 at 14:40 −0400. Unsolicited bulk message advertising “concealed carry help”/ex ...
show moreReceived Aug 21, 2025 at 14:40 −0400. Unsolicited bulk message advertising “concealed carry help”/expedited permit with “50% off,” many tracking links and an “unsubscribe.” Body is heavily obfuscated (random strings/base64) and mislabeled as multipart/report. Delivered via 89.185.250.182 (moorganization.online; sl-reverse rDNS). Auth: SPF PASS on dynastige.com (envelope); DKIM PERMERROR (no key) for g35ecq.0k79t2.iuo47c.us; no DMARC result shown; From/Return-Path misalignment indicates spoofing. Mixed “Sailthru” Received lines inconsistent with source suggest forged headers or an exploited host. Violations: CAN-SPAM (15 U.S.C. §7704) deceptive/unsolicited email; potential 18 U.S.C. §1343 (fraud) where used to obtain data; RFC 5321/5322 header/authentication non-compliance. Host/abuse contact for 89.185.250.182:
MasterDC s.r.o. (aka Master Internet) — [email protected] +420 515 919 805 (NOC/Abuse). Alt: +420 777 919 484. 89.185.250.182 sits in 89.185.250.0/24 announced by AS24971 MasterDC
show less