Fake billing seemingly forwarded from Germany to me in Canada?
Received: from cheetah.banana.relay. ...
show moreFake billing seemingly forwarded from Germany to me in Canada?
Received: from cheetah.banana.relay.mailchannels.net (23.83.217.34) by
X-Sender-Id: _forwarded-from|88.99.226.230
Subject: Action Required: Update Your Payment Method to Avoid Service
Interruption
Date: Thu, 11 Dec 2025 01:35:00 +0000
Message-ID: <176541690058.10912.7232704186899095347@WIN-7ICUNI8HBME>
X-Mailer: Mozilla Thunderbird
show less
Starbucks Spoofing:
X-MS-Exchange-Authentication-Results: spf=fail (sender IP is 178.162.245.30)
...
show moreStarbucks Spoofing:
X-MS-Exchange-Authentication-Results: spf=fail (sender IP is 178.162.245.30)
smtp.mailfrom=mic19226674.onmicrosoft.com; dkim=none (message not signed)
header.d=none;dmarc=fail action=none header.from=hotmail.com;
To: <[email protected]>
Date: Tue, 2 Dec 2025 14:49:55 +0000
List-Unsubscribe-Post: List-Unsubscribe=One-Click
Subject: Your Complimentary Coffee Companion Has Arrived ð
From: "=?UTF-8?B?U3RhcmJ1Y2tz?=" <[email protected]>
show less
Subject: Black Friday â 80% OFF Cloud Storage
X-Mailgun-Sending-Ip: 185.250.239.7
X-Feedback-Id: ...
show moreSubject: Black Friday â 80% OFF Cloud Storage
X-Mailgun-Sending-Ip: 185.250.239.7
X-Feedback-Id: [email protected]::629f643a639a80ba38276cb6:mailgun
Date: Mon, 24 Nov 2025 18:59:48 +0000
X-Mailgun-Sending-Ip-Pool:
From: <notifications@âï¸cloudstorage-teamâï¸>
show less
Subject: We've Blocked Your Account!Your photos and videos will be deleted on November 22, 2025
X-M ...
show moreSubject: We've Blocked Your Account!Your photos and videos will be deleted on November 22, 2025
X-Mailgun-Sending-Ip: 185.250.239.7
X-Feedback-Id: [email protected]::629f643a639a80ba38276cb6:mailgun
Date: Thu, 20 Nov 2025 19:04:37 +0000
X-Mailgun-Sending-Ip-Pool:
From: =?utf-8?B?Y2xvdWQgc3VwcG9ydCB0ZWFtIMKu77iP?=
<notifications@âï¸cloudserviceâï¸>
show less
ARC-Authentication-Results: i=2; mx.microsoft.com 1; spf=none (sender ip is
23.83.209.14) smtp.rcp ...
show moreARC-Authentication-Results: i=2; mx.microsoft.com 1; spf=none (sender ip is
23.83.209.14) smtp.rcpttodomain=hotmail.com
smtp.mailfrom=biz301.inmotionhosting.com; dmarc=bestguesspass action=none
show less
Subject: Final WARNING â ï¸: All your photos will be removed
X-Mailgun-Sending-Ip: 185.250.239.7
...
show moreSubject: Final WARNING â ï¸: All your photos will be removed
X-Mailgun-Sending-Ip: 185.250.239.7
X-Feedback-Id: [email protected]::629f643a639a80ba38276cb6:mailgun
Date: Sat, 8 Nov 2025 20:35:21 +0000
X-Mailgun-Sending-Ip-Pool:
From: <info@âï¸cloud-storageâï¸>
show less
Subject: Final WARNING â ï¸: All your photos will be removed
X-Mailgun-Sending-Ip: 185.250.239.7
...
show moreSubject: Final WARNING â ï¸: All your photos will be removed
X-Mailgun-Sending-Ip: 185.250.239.7
X-Feedback-Id: [email protected]::629f643a639a80ba38276cb6:mailgun
Date: Thu, 30 Oct 2025 20:28:36 +0000
X-Mailgun-Sending-Ip-Pool:
From: <info@âï¸cloud-storageâï¸>
show less
Extortion attempt.... spoofing my own email: seemingly from.....inescapably.biz
X-MS-UserLastLogon ...
show moreExtortion attempt.... spoofing my own email: seemingly from.....inescapably.biz
X-MS-UserLastLogonTime: 10/21/2025 7:59:46 AM
X-MS-Office365-Filtering-Correlation-Id: 58135fe2-fe9e-40c7-4269-08de109c9fef
X-MS-Exchange-EOPDirect: true
X-Sender-IP: 80.93.60.161
X-SID-PRA: [email protected]
X-SID-Result: NONE
X-MS-Exchange-Organization-SCL: 5
21 Oct 2025 12:23:20 +0000
Authentication-Results: spf=pass (sender IP is 80.93.60.161)
smtp.mailfrom=inescapably.biz; dkim=none (message not signed)
Quote:
(Earlier I purchased from hackers a unique access to diversified email accounts (at the moment, it is really easy to do using internet ).
log in to your email account without breaking a sweat ([email protected]).
Within one week afterwards, I instal led a Trojan virus in your OS av ailable on all devices that you utilize for logging in your email.
To be frank, it was somewhat a very easy task (since you were kind enough to open some of links provided in your inbox email s).)
show less
Fraudulent payment request::
Dear customer,
The payment method on file could not be processed.
Pl ...
show moreFraudulent payment request::
Dear customer,
The payment method on file could not be processed.
Please update your payment details using the link below to avoid suspension of services:
show less
From: "Microsoft account team" <[email protected]>
Subject: M ...
show moreFrom: "Microsoft account team" <[email protected]>
Subject: Microsoft account unusual sign-in activity
Date: Mon, 18 Aug 2025 01:20:49 -0700
Content-Type: text/html; charset="Windows-1251"
Content-Transfer-Encoding: 7bit
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000
show less
Delivery-date: Mon, 11 Aug 2025 16:04:41 -0700
Received: from ffns.ac.rs ([79.101.42.175]:35904)
...
show moreDelivery-date: Mon, 11 Aug 2025 16:04:41 -0700
Received: from ffns.ac.rs ([79.101.42.175]:35904)
by biz301.inmotionhosting.com with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384
(Exim 4.98.2)
(envelope-from <[email protected]>)
To resolve this, click below to verify and maintain your SSL/TLS=20
coverage:
Resolve SSL/TLS Issue=20
(=C2=A0https://ipfs.io/ipfs/bafkreifvvr6ud2vip5ga6qpjh5pzqdaawljllsz7noc7re=
fchxrsg35lwm#[email protected]=C2=A0)
show less
Extortion attempt as per below:
Received-SPF: Fail (protection.outlook.com: domain of hotmail.com d ...
show moreExtortion attempt as per below:
Received-SPF: Fail (protection.outlook.com: domain of hotmail.com does not
designate 23.230.153.206 as permitted sender)
receiver=protection.outlook.com; client-ip=23.230.153.206;
helo=tranquilcanyontrail.com;
Received: from tranquilcanyontrail.com (23.230.153.206) b
X-Sender-IP: 23.230.153.206
X-SID-PRA: [email protected]
X-SID-Result: FAIL
X-MS-Exchange-Organization-SCL: 5
Hello pervert, I've sent th=D1=96s message from your Microsoft account.
I want to =D1=96nform you about a very bad s=D1=96tuat=D1=96on for you. H=
owever, you can benef=D1=96t from =D1=96t, =D1=96f you w=D1=96ll act w=D1=
=96sely.
Have you heard of Pegasus? Th=D1=96s =D1=96s a spyware program that =D1=96=
nstalls on computers and smartphones and allows hackers to mon=D1=96tor t=
he act=D1=96v=D1=96ty of dev=D1=96ce owners. It prov=D1=96des access to y=
our webcam, messengers, ema=D1=96ls, call records, etc. It works well on =
Andro=D1=96d, =D1=96OS, macOS=C2 I guess,
show less
Subject: You have been hacked ([email protected])
X-MS-UserLastLogonTime: 12/23/2024 12:28:41 ...
show moreSubject: You have been hacked ([email protected])
X-MS-UserLastLogonTime: 12/23/2024 12:28:41 AM
X-MS-Office365-Filtering-Correlation-Id: 14924d01-94a0-4557-6cb0-08dd2309ed19
X-MS-Exchange-EOPDirect: true
X-Sender-IP: 23.230.14.19
X-SID-PRA: [email protected]
X-SID-Result: FAIL
Received-SPF: Fail (protection.outlook.com: domain of hotmail.com does not
designate 23.230.14.19 as permitted sender) receiver=protection.outlook.com;
client-ip=23.230.14.19; helo=exhibitresourcesinc.com;
Received: from exhibitresourcesinc.com (23.230.14.19)
show less
PayPal fraud.... urgent call___ 1-(866)-512 7083
ARC-Authentication-Results: i=1; mx.microsoft.com ...
show morePayPal fraud.... urgent call___ 1-(866)-512 7083
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass (sender ip is
173.0.84.227) smtp.rcpttodomain=iesjuniper0.onmicrosoft.com
smtp.mailfrom=paypal.com; dmarc=pass (p=reject sp=reject pct=100) action=none
header.from=paypal.com; dkim=pass (signature was verified)
header.d=paypal.com; arc=none (0)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=iesjuniper0.onmicrosoft.com; s=selector1-iesjuniper0-onmicrosoft-com;
Microsoft SMTP Server (version=TLS1_2,
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7982.17; Thu, 19 Sep
2024 17:36:35 +0000
(( A small reminder from PayPal:-Don't recognize the seller? Quickly let us know at +1-(866)-512 7083 (Toll Free). If you don't contact us, this will be approved. ))
show less
Received: from Design-157.homeshopmart.com (23.106.39.157) by
AM1PEPF000252DC.mail.protection.outl ...
show moreReceived: from Design-157.homeshopmart.com (23.106.39.157) by
AM1PEPF000252DC.mail.protection.outlook.com (10.167.16.54) with Microsoft
SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id
15.20.7918.13 via Frontend Transport; Fri, 6 Sep 2024 18:43:28 +0000
X-IncomingTopHeaderMarker:
OriginalChecksum:5F1EF36275E7A68DF8A4EA85B437A119D2DA1817EEDEF7ED2D8806E658C39890;UpperCasedChecksum:229EAD56DA43C73AAAA00A4E1B66C93A87F84FFD7FC69951100A5E0990A5C4DA;SizeAsReceived:460;Count:10
Subject: Keep Your Gutters Clean At Up To 30% Off* With LeafFilter!
From: "Gutter Guard Offer", DPH0F4 <[email protected]>
Sender: "Gutter Guard Offer"<[email protected]>
show less
I keep getting this spam. Not sure what's going on but originating IP is also my website hosting com ...
show moreI keep getting this spam. Not sure what's going on but originating IP is also my website hosting company.... somehow associated with borngroup.com:
Authentication-Results: spf=fail (sender IP is 173.231.241.34)
smtp.mailfrom=em4852.borngroup.com; dkim=pass (signature was verified)
header.d=borngroup.com;dmarc=pass action=none
header.from=borngroup.com;compauth=pass reason=100
Received-SPF: Fail (protection.outlook.com: domain of em4852.borngroup.com
does not designate 173.231.241.34 as permitted sender)
show less
He sent this:
I'm some kind of God who sees everything.
However, don't panic. As we know, God is ...
show moreHe sent this:
I'm some kind of God who sees everything.
However, don't panic. As we know, God is merciful and forgiving, and so do I.
But my mercy is not free.
Transfer $1490 USD to my bitcoin wallet: 1E3mVbLSLLUgdmrp8GV5RRu1Qz5FkWs4rJ
show less
Spam... unless I actually won 5,000,000
To: Recipients <[email protected]>
From: "Mrs. Mav ...
show moreSpam... unless I actually won 5,000,000
To: Recipients <[email protected]>
From: "Mrs. Mavis Wanczyk" <[email protected]>
Date: Fri, 22 Dec 2023 18:07:40 -0800
Reply-To: [email protected]
X-IncomingHeaderCount: 11
Return-Path: [email protected]
A donation of 5,000,000.00 euro has been presented to you by Mrs. Mavis Wan=
czyk, the mega winner of $758 Million in Mega Millions Jackpot, I am donati=
ng to 5 random individuals. If you get this email then your email was selec=
ted after a spin ball, Reply back to get more details WATCH ME HERE: https=
://www.youtube.com/watch?v=3D7kWnqvJM1mM
show less
Inmotionhosting is my web hosting company. Somehow I get spam -- extortion requests from my own emai ...
show moreInmotionhosting is my web hosting company. Somehow I get spam -- extortion requests from my own email address which is my company name at the Host. It appears the hackers are inside the servers there.
Message-Id: <[email protected]>
Date: Sun, 15 Oct 2023 01:34:41 -0700
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - biz301.inmotionhosting.com
show less
Received: from [89.205.140.160] (port=54139)
by biz301.inmotionhosting.com with esmtp (Exim 4.96)
...
show moreReceived: from [89.205.140.160] (port=54139)
by biz301.inmotionhosting.com with esmtp (Exim 4.96)
Subject: Your private information has been stolen because of suspicious events.
Date: 1 Sep 2023 06:46:50 +0100
show less
This is a Hosting company I use and I'm getting a legitimate looking email spam from my own email ad ...
show moreThis is a Hosting company I use and I'm getting a legitimate looking email spam from my own email address so this is not good news for me. It could be an internal hack on their server, or bad actors using their hosting services.
show less
PayPal impersonation spam: (sent me a fake invoice from a real Paypal email address).... scary... v ...
show morePayPal impersonation spam: (sent me a fake invoice from a real Paypal email address).... scary... very good.
Date: Wed, 03 May 2023 13:18:07 -0700
Message-ID: <96.C5.04883.F71C2546@ccg13mail02>
X-PP-REQUESTED-TIME: 1683145080179
X-PP-Email-transmission-Id: 9c67b49c-e9ef-11ed-bda8-40a6b7290701
PP-Correlation-Id: f7823216f7d82
Subject: Payment Received. Call us +1 (833) 821-1931 to cancel it.
X-MaxCode-Template: RT000274
To: order placed successfully <[email protected]>
From: "[email protected]" <[email protected]>
X-Email-Type-Id: RT000274
X-PP-Priority: 0-none-false
AMQ-Delivery-Message-Id: nullval
X-XPT-XSL-Name: nullval
Return-Path: [email protected]show less
Spam from Turkey to Canada:
Impersonation of Amazon:
X-Sender-IP: 45.129.84.33
X-SID-PRA: COSTCOU ...
show moreSpam from Turkey to Canada:
Impersonation of Amazon:
X-Sender-IP: 45.129.84.33
X-SID-PRA: [email protected]
From: Dear Amazon Customer ; <[email protected]>
Subject: Your Amazon order has been shipped(#045-58887) #5218228798
Date: Sun, 2 Apr 2023
Authentication-Results: spf=softfail (sender IP is 45.129.84.33)
smtp.mailfrom=runelocus.com; dkim=none (message not signed)
header.d=none;dmarc=fail action=oreject
header.from=email.costco.co.uk;compauth=fail reason=000
Received-SPF: SoftFail (protection.outlook.com: domain of transitioning
runelocus.com discourages use of 45.129.84.33 as permitted sender)
Received: from m32-8.eu.mailgun.net (45.129.84.33)
show less
PhishingEmail SpamSpoofing
By clicking “Accept all”, you agree to the storing of cookies on your device to remember preferences and
analyze site usage.
Read more
- Required to log into your AbuseIPDB account, and store these cookie preferences.