#217263 by Faizan Docherty Mon Sep 01, 2014 5:55 pm
Dear Manager,

We want to make a large purchase from your company. We would be delighted to enter into business cooperation with you.

if you can produce and supply us good quality products in large quantity. Please advise your terms.

contact Email: [email protected]

Expecting to hear from you.

Best regards,

Kierownik David
Grupa Topex Sp. z o.o. Sp.k.,
Street: ul. Pograniczna 2/4,
ZIP: 02-285
CITY: Warszawa
POLAND
T +48 22 57 32 310

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
Advertisement

#217296 by Faizan Docherty Mon Sep 01, 2014 7:50 pm
Delivered-To: <snipped>
Received: by 10.220.221.79 with SMTP id ib15csp271491vcb;
Sun, 31 Aug 2014 09:56:43 -0700 (PDT)
Return-Path: <[email protected]>
Received-SPF: pass (google.com: domain of [email protected] designates 10.236.135.212 as permitted sender) client-ip=10.236.135.212
Authentication-Results: mr.google.com;
spf=pass (google.com: domain of [email protected] designates 10.236.135.212 as permitted sender) [email protected];
dkim=pass [email protected]
X-Received: from mr.google.com ([10.236.135.212])
by 10.236.135.212 with SMTP id u60mr1711958yhi.118.1409504203203 (num_hops = 1);
Sun, 31 Aug 2014 09:56:43 -0700 (PDT)
DKIM-Signature: <snipped>
MIME-Version: 1.0
X-Received: by 10.236.135.212 with SMTP id u60mr1909531yhi.118.1409504203019;
Sun, 31 Aug 2014 09:56:43 -0700 (PDT)
Received: by 10.170.122.18 with HTTP; Sun, 31 Aug 2014 09:56:42 -0700 (PDT)
Date: Sun, 31 Aug 2014 17:56:42 +0100
Message-ID: <[email protected]om>
Subject: SUPPLY TENDER
From: prince onuchie <[email protected]>
To: undisclosed-recipients:;
Content-Type: text/plain; charset=UTF-8
Bcc: <snipped>


Dear Sirs,

An open Tender for the supply of your company products to the
Government of Ghana. Urgently furnish us in full details about the
standard of your product.

We will appreciate it more if you give us with Details: Specification
and Catalogs or Price list via Email.To avoid making a wrong choice of
products before placing an order for it.

Terms of payment: An upfront payment of 70% (T/T) will be made to your
account for production, While 30% will be paid before shipment.

Thank

Mr Prince Onuchie


APASE GROUP GH LTD
12B Abeka Road,
opp Lapaz police station
[email protected]
Accra Ghana
+233 544 804 217.

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
#217301 by Faizan Docherty Mon Sep 01, 2014 8:17 pm
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 58.64.130.35
Originating ISP: New World Telephone
City: Central District
Country of Origin: Hong Kong
* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.220.221.79 with SMTP id ib15csp352256vcb;
Mon, 1 Sep 2014 03:55:17 -0700 (PDT)
X-Received: by 10.68.134.130 with SMTP id pk2mr10472935pbb.133.1409568917329;
Mon, 01 Sep 2014 03:55:17 -0700 (PDT)
Return-Path: <[email protected]>
Received: from mail.eznow.com (emlm4.sitecname.com. [58.64.190.174])
by mx.google.com with ESMTP id de4si667649pbb.135.2014.09.01.03.55.15
for <multiple recipients>;
Mon, 01 Sep 2014 03:55:16 -0700 (PDT)
Received-SPF: pass (google.com: domain of [email protected] designates 58.64.190.174 as permitted sender) client-ip=58.64.190.174;
Authentication-Results: mx.google.com;
spf=pass (google.com: domain of [email protected] designates 58.64.190.174 as permitted sender) [email protected]
Received: from localhost (localhost.localdomain [127.0.0.1])
by mail.eznow.com (mail gateway) with ESMTP id 1F2B34380273;
Mon, 1 Sep 2014 18:51:51 +0800 (HKT)
Received: from mail.eznow.com ([127.0.0.1])
by localhost (mail.eznow.com [127.0.0.1]) (theinterface-new, port 10024)
with ESMTP id 6zwSrUsObYdq; Mon, 1 Sep 2014 18:51:50 +0800 (HKT)
Received: from mail.eznow.com (mail.eznow.com [58.64.130.35])
by mail.eznow.com (mail gateway) with ESMTP id 886024380242;
Mon, 1 Sep 2014 18:51:50 +0800 (HKT)
Date: Mon, 1 Sep 2014 18:51:50 +0800 (HKT)
From: Ruchi <[email protected]>
Reply-To: [email protected]s
Message-ID: <[email protected]com>
Subject: P/O
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_Part_181866_581874798.1409568710525"
X-Originating-IP: [58.64.130.35]
To: undisclosed-recipients:;


P/O
We are interested in purchasing your company's products, we would like to see your company's latest catalogs with the Minimum Order Quantity Delivery time FOB, payment terms warranty,
kindly reply us asap through this email address...( [email protected] )
Regards

Mr.Michael Kenneth.
Executive Sales Manager
Ruchiexport Trade Co.Ltd
Email. [email protected]
Parcel Zoom 287 Cheesequake Road, Bldg 1B NJ 08859
Tel: +1-614 633-0135 Fax: +1-215-261-2043

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
#218081 by Faizan Docherty Sun Sep 07, 2014 1:44 pm
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 65.54.190.189
Originating ISP: Microsoft Hosting
City: Redmond
Country of Origin: United States
* For a complete report on this email header goto ipTRACKERonline


From MR KOFI MORRIS Sat Sep 6 16:45:17 2014
X-Apparently-To: <snipped> via 72.30.238.253; Sat, 06 Sep 2014 23:45:18 +0000
Return-Path: <[email protected]>
X-YahooFilteredBulk: 65.54.190.147
Received-SPF: pass (domain of outlook.com designates 65.54.190.147 as permitted sender)
X-YMailISG: <snipped>
X-Originating-IP: [65.54.190.147]
Authentication-Results: mta1429.mail.bf1.yahoo.com from=outlook.com; domainkeys=neutral (no sig); from=outlook.com; dkim=neutral (no sig)
Received: from 127.0.0.1 (EHLO BAY004-OMC3S9.hotmail.com) (65.54.190.147)
by mta1429.mail.bf1.yahoo.com with SMTPS; Sat, 06 Sep 2014 23:45:18 +0000
Received: from BAY169-W89 ([65.54.190.189]) by BAY004-OMC3S9.hotmail.com with Microsoft SMTPSVC(7.5.7601.22724);
Sat, 6 Sep 2014 16:45:17 -0700
X-TMN: [7tW/2sbL/WZNGTasQJ8+Az+SQuKLCT/F]
X-Originating-Email: [[email protected]]
Message-ID: <[email protected]>
Return-Path: [email protected]
Content-Type: multipart/alternative;
boundary="_ad70f04d-5d1e-4676-80b2-fcb4cd398176_"
Reply-To: <[email protected]>
From: MR KOFI MORRIS <[email protected]>
To: "[email protected]" <[email protected]>
Subject: Inquiry for supply
Date: Sat, 6 Sep 2014 23:45:17 +0000
Importance: Normal
MIME-Version: 1.0
X-OriginalArrivalTime: 06 Sep 2014 23:45:17.0749 (UTC) FILETIME=[9CF1AE50:01CFCA2C]
Content-Length: 1314


Dear Sir,

An open Supply for the supply of your products to the Government of Ghana.

We will appreciate it more if you can give us with detail specification/price
lists of your product/s to avoid making a wrong choice of product.

Thanks.
Mr: Kofi Morris
(Accredited agent)
NO 36 NEW town
P.o Box 205 Accra Ghana
Email: [email protected]

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
#218099 by Faizan Docherty Sun Sep 07, 2014 5:54 pm
Delivered-To: <snipped>
Received: by 10.220.221.79 with SMTP id ib15csp32653vcb;
Sun, 7 Sep 2014 11:41:01 -0700 (PDT)
Return-Path: <[email protected]>
Received-SPF: pass (google.com: domain of [email protected] designates 10.180.24.225 as permitted sender) client-ip=10.180.24.225
Authentication-Results: mr.google.com;
spf=pass (google.com: domain of [email protected] designates 10.180.24.225 as permitted sender) [email protected];
dkim=pass [email protected]
X-Received: from mr.google.com ([10.180.24.225])
by 10.180.24.225 with SMTP id x1mr10885124wif.14.1410115260991 (num_hops = 1);
Sun, 07 Sep 2014 11:41:00 -0700 (PDT)
DKIM-Signature: <snipped>
DKIM-Signature: <snipped>
MIME-Version: 1.0
X-Received: by 10.180.24.225 with SMTP id x1mr17137214wif.14.1410115260632;
Sun, 07 Sep 2014 11:41:00 -0700 (PDT)
Sender: [email protected]
Received: by 10.180.4.2 with HTTP; Sun, 7 Sep 2014 11:41:00 -0700 (PDT)
Date: Sun, 7 Sep 2014 19:41:00 +0100
X-Google-Sender-Auth: KLihv9gSp5qS35BgLpvq4vJvkvI
Message-ID: <[email protected]om>
Subject: SUPPLY
From: Kolombo james <[email protected]>
To: undisclosed-recipients:;
Content-Type: multipart/alternative; boundary=f46d044280c433d5c605027e0b74
Bcc: <snipped>


Dear Sir/Madam,


We Are interested in your product and to do business with your company let us
know if you can handle the supply of most items and also send your
product website.

PAYMENT TERMS:The terms of payment is 80% advance payment via (T/T) by
telegraphic
transfer confirmed in your account before Production and 20% to be
confirmed as well
before shipment Delivery Time: 6 to 12 months after receipt your full payment.

Regards,
Mr:Kolombo James
Email: [email protected]

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
#219939 by Umut ocak Mon Sep 22, 2014 5:00 am
Ruchiexport.com.es new scammer find their victims from alibaba or smiliar webpage. Hope no one here stupid enough to email back more then two time :) I answer the first one then realise it's a scum
#220425 by Faizan Docherty Thu Sep 25, 2014 10:36 pm
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 176.74.27.91
Originating ISP: Dreamscape Networks Fz-llc
City: n/a
Country of Origin: United Kingdom
* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.220.184.74 with SMTP id cj10csp606562vcb;
Wed, 24 Sep 2014 09:30:47 -0700 (PDT)
X-Received: by 10.194.63.205 with SMTP id i13mr9489218wjs.74.1411576246357;
Wed, 24 Sep 2014 09:30:46 -0700 (PDT)
Return-Path: <[email protected]>
Received: from cpanel2.uk.syrahost.com ([176.74.27.91])
by mx.google.com with ESMTPS id fh6si7431556wic.85.2014.09.24.09.30.35
for <multiple recipients>
(version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128);
Wed, 24 Sep 2014 09:30:46 -0700 (PDT)
Received-SPF: fail (google.com: domain of [email protected] does not designate 176.74.27.91 as permitted sender) client-ip=176.74.27.91;
Authentication-Results: mx.google.com;
spf=hardfail (google.com: domain of [email protected] does not designate 176.74.27.91 as permitted sender) [email protected]
Received: from localhost ([::1]:51434 helo=webmail.dangotegroup.info)
by cpanel2.uk.syrahost.com with esmtpa (Exim 4.82)
(envelope-from <[email protected]>)
id 1XWpSZ-000epz-PQ; Wed, 24 Sep 2014 16:30:31 +0000
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="=_df24522c3bf2936801588eab8415e7da"
Date: Wed, 24 Sep 2014 16:30:31 +0000
From: Mvp Trading Company <[email protected]>
To: undisclosed-recipients:;
Subject: Inquiry
Reply-To: [email protected]
Mail-Reply-To: [email protected]
Return-Receipt-To: Mvp Trading Company <[email protected]>
Disposition-Notification-To: Mvp Trading Company <[email protected]>
Message-ID: <[email protected]>
X-Sender: [email protected]
User-Agent: Roundcube Webmail/1.0.1
X-OutGoing-Spam-Status: No, score=
X-AntiAbuse: This header was added to track abuse, please include it with any abuse report
X-AntiAbuse: Primary Hostname - cpanel2.uk.syrahost.com
X-AntiAbuse: Original Domain - gmail.com
X-AntiAbuse: Originator/Caller UID/GID - [47 12] / [47 12]
X-AntiAbuse: Sender Address Domain - mvptrading.com
X-Get-Message-Sender-Via: cpanel2.uk.syrahost.com: authenticated_id: [email protected]


Good day,

This is kelvin from Mvp Trading Company, permit me to introduce our company to you

We are leading U.S.-based distributor of branded quality products, from initial product

Enquiry to final delivery of goods, Mvp Trading company offers over 12 years of experience

In domestic and international distribution, We are 100% Interested in buying your Products

It would be appreciated if can you send the brochures and price lists for the entire range of your products. Please quote us the following to enable us submit our Purchasing

order immediately.



1.The minimum Order Quantity

2.Delivery time

3.The payment term and other terms and condition.



Your early reply will be highly appreciated,

Thanks and best regards.

Purchasing dept,
Mr,Kelvin Martins
MVP TRADING COMPANY
2 Wisconsin circle,suite 700
Chevy chase,MD 20815 U.S.A.
Phone: +1-240-235-5029
Fax: +1-240-331-7101
Website: http://www.mvptrading.com/

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
#220517 by Faizan Docherty Fri Sep 26, 2014 2:01 pm
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 209.85.213.196
Originating ISP: Google
City: Gulf Shores
Country of Origin: United States
* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.70.125.234 with SMTP id mt10csp557341pdb;
Wed, 24 Sep 2014 05:28:48 -0700 (PDT)
X-Received: by 10.66.180.98 with SMTP id dn2mr8775146pac.83.1411561728061;
Wed, 24 Sep 2014 05:28:48 -0700 (PDT)
Return-Path: <[email protected]>
Received: from relay.mailchannels.net (tkt-001-i390.relay.mailchannels.net. [72.249.144.205])
by mx.google.com with ESMTP id id8si26046572pad.155.2014.09.24.05.28.46
for <snipped>;
Wed, 24 Sep 2014 05:28:48 -0700 (PDT)
Received-SPF: softfail (google.com: domain of transitioning [email protected] does not designate 72.249.144.205 as permitted sender) client-ip=72.249.144.205;
Authentication-Results: mx.google.com;
spf=softfail (google.com: domain of transitioning [email protected] does not designate 72.249.144.205 as permitted sender) [email protected];
dkim=pass [email protected];
dmarc=pass (p=NONE dis=NONE) header.from=gmail.com
X-Sender-Id: _forwarded-from|209.85.213.196
Received: from r8-chicago.webserversystems.com (ip-10-220-9-73.us-west-2.compute.internal [10.220.9.73])
by relay.mailchannels.net (Postfix) with ESMTPA id E21946151E
for <snipped>; Wed, 24 Sep 2014 12:28:42 +0000 (UTC)
X-Sender-Id: _forwarded-from|209.85.213.196
Received: from r8-chicago.webserversystems.com (r8-chicago.webserversystems.com [10.253.92.5])
(using TLSv1 with cipher DHE-RSA-AES256-SHA)
by 0.0.0.0:2500 (trex/5.2.13);
Wed, 24 Sep 2014 12:28:46 GMT
X-MC-Relay: Forwarding
X-MailChannels-SenderId: _forwarded-from|209.85.213.196
X-MailChannels-Auth-Id: wwwh
X-MC-Loop-Signature: 1411561726125:1410340034
X-MC-Ingress-Time: 1411561726124
Received: from mail-ig0-f196.google.com ([209.85.213.196]:58964)
by r8-chicago.webserversystems.com with esmtps (TLSv1:RC4-SHA:128)
(Exim 4.82)
(envelope-from <[email protected]>)
id 1XWlgX-000Bml-7i
for <snipped>; Wed, 24 Sep 2014 07:28:41 -0500
Received: by mail-ig0-f196.google.com with SMTP id h18so1802619igc.7
for <snipped>; Wed, 24 Sep 2014 05:28:40 -0700 (PDT)
DKIM-Signature: <snipped>
MIME-Version: 1.0
X-Received: by 10.50.41.104 with SMTP id e8mr30800511igl.35.1411561720322;
Wed, 24 Sep 2014 05:28:40 -0700 (PDT)
Received: by 10.107.8.150 with HTTP; Wed, 24 Sep 2014 05:28:40 -0700 (PDT)
Date: Wed, 24 Sep 2014 21:28:40 +0900
Message-ID: <[email protected]om>
Subject: HELLO DEAR
From: smith jems <[email protected]>
To: <snipped>
Content-Type: multipart/alternative; boundary=089e01161a26eb20f50503ced2a9
X-Spam-Status: No, score=0.5
X-Spam-Score: 5
X-Spam-Bar: /
X-Ham-Report: Spam detection software, running on the system "r8-chicago.webserversystems.com", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
root\@localhost for details.

Content preview: HELLO DEAR We are interested in purchasing your company's
products, we would like to see your company's latest catalogs with the Minimum
Order Quantity Delivery time FOB, payment terms warranty, kindly send reply
[...]

Content analysis details: (0.5 points, 5.0 required)

pts rule name description
---- ---------------------- --------------------------------------------------
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider
(smithjems58[at]gmail.com)
-0.7 RCVD_IN_DNSWL_LOW RBL: Sender listed at http://www.dnswl.org/, low
trust
[209.85.213.196 listed in list.dnswl.org]
1.5 SUBJ_ALL_CAPS Subject is all capitals
-0.0 SPF_PASS SPF: sender matches SPF record
0.2 FREEMAIL_ENVFROM_END_DIGIT Envelope-from freemail username ends in
digit (smithjems58[at]gmail.com)
0.0 HTML_MESSAGE BODY: HTML included in message
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's
domain
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid
-0.5 CRM114_PROB_GOOD CRM114: CRM114_PROB_GOOD
X-Spam-Flag: NO
X-MC-Forward: <snipped>
X-AuthUser:


HELLO DEAR

We are interested in purchasing your company's products, we would like to see your company's latest catalogs with the Minimum Order Quantity Delivery time FOB, payment terms warranty,
kindly send reply


Regards

Executive Sales Manager
Ruchiexport Trade Co.Ltd
Parcel Zoom 287 Cheesequake Japan
Tel:634198852
Fax:634190055

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
#220655 by AlanJones Sun Sep 28, 2014 1:38 am
Credit card scammer.

kerry yomi - [email protected]

hello sales
we are interested in some order in your website and we want you to get back to us asap so that we can proceed
also email us back if you can ship 2 to 3 days delivery or 2nd day delivery with tracking number also for the payment is by our credit card details

for the payment
kindly email us if we can proceed as soon as possible
best regards

Please do not tell scammers that they are listed here - it will take them seconds to change their fake details and their new details will not be listed for any future victims to find.
#221097 by AlanJones Wed Oct 01, 2014 12:19 pm
From: Morris - [email protected]
Reply-to: [email protected]

Hi,
Please i will like to place an order in your company.



Morris.

Please do not tell scammers that they are listed here - it will take them seconds to change their fake details and their new details will not be listed for any future victims to find.
#221342 by Faizan Docherty Thu Oct 02, 2014 7:56 pm
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 65.54.190.227
Originating ISP: Microsoft Hosting
City: Redmond
Country of Origin: United States
* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.76.168.38 with SMTP id zt6csp17387oab;
Thu, 2 Oct 2014 00:55:46 -0700 (PDT)
X-Received: by 10.70.128.137 with SMTP id no9mr105637565pdb.143.1412236545650;
Thu, 02 Oct 2014 00:55:45 -0700 (PDT)
Return-Path: <[email protected]>
Received: from relay.mailchannels.net (aso-006-i425.relay.mailchannels.net. [174.136.13.71])
by mx.google.com with ESMTP id ki1si3070482pbd.167.2014.10.02.00.55.44
for <snipped>;
Thu, 02 Oct 2014 00:55:45 -0700 (PDT)
Received-SPF: softfail (google.com: domain of transitioning [email protected] does not designate 174.136.13.71 as permitted sender) client-ip=174.136.13.71;
Authentication-Results: mx.google.com;
spf=softfail (google.com: domain of transitioning [email protected] does not designate 174.136.13.71 as permitted sender) [email protected];
dmarc=fail (p=NONE dis=NONE) header.from=outlook.com
X-Sender-Id: _forwarded-from|65.54.190.200
Received: from r8-chicago.webserversystems.com (ip-10-213-14-133.us-west-2.compute.internal [10.213.14.133])
by relay.mailchannels.net (Postfix) with ESMTPA id 2203D60CA6
for <snipped>; Thu, 2 Oct 2014 07:55:42 +0000 (UTC)
X-Sender-Id: _forwarded-from|65.54.190.200
Received: from r8-chicago.webserversystems.com (r8-chicago.webserversystems.com [10.252.6.112])
(using TLSv1 with cipher DHE-RSA-AES256-SHA)
by 0.0.0.0:2500 (trex/5.2.14);
Thu, 02 Oct 2014 07:55:43 GMT
X-MC-Relay: Forwarding
X-MailChannels-SenderId: _forwarded-from|65.54.190.200
X-MailChannels-Auth-Id: wwwh
X-MC-Loop-Signature: 1412236543710:1751586120
X-MC-Ingress-Time: 1412236543709
Received: from bay004-omc4s25.hotmail.com ([65.54.190.227]:58532)
by r8-chicago.webserversystems.com with esmtps (TLSv1:AES256-SHA:256)
(Exim 4.82)
(envelope-from <[email protected]>)
id 1XZbEi-000Fmb-Jr
for <snipped>; Thu, 02 Oct 2014 02:55:41 -0500
Received: from BAY169-W50 ([65.54.190.200]) by BAY004-OMC4S25.hotmail.com over TLS secured channel with Microsoft SMTPSVC(7.5.7601.22751);
Thu, 2 Oct 2014 00:55:39 -0700
X-TMN: [BNwPHLmFnTBKvM8CVaBgGR2C9kmtrlr1]
X-Originating-Email: [[email protected]]
Message-ID: <[email protected]>
Content-Type: multipart/alternative;
boundary="_124cab07-697a-4813-a8f1-6026a396f9a0_"
From: owusu james <[email protected]>
To: "[email protected]"
<[email protected]>
Subject: SUPLY
Date: Thu, 2 Oct 2014 07:55:39 +0000
Importance: Normal
MIME-Version: 1.0
X-OriginalArrivalTime: 02 Oct 2014 07:55:39.0831 (UTC) FILETIME=[4232DC70:01CFDE16]
X-Spam-Status: No, score=0.8
X-Spam-Score: 8
X-Spam-Bar: /
X-Ham-Report: Spam detection software, running on the system "r8-chicago.webserversystems.com", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
root\@localhost for details.

Content preview: Attention: Sir/Madam, Another Order has Been Published, If
You Can Supply This Quantity of Hospital Towels with Good Quality after You
Received Full Payment, Please Reply So That I Will Give You Full Details
Including Shipment Destination And Other Terms. [...]

Content analysis details: (0.8 points, 5.0 required)

pts rule name description
---- ---------------------- --------------------------------------------------
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[65.54.190.227 listed in list.dnswl.org]
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider
(owusuj500[at]outlook.com)
-0.0 SPF_PASS SPF: sender matches SPF record
0.2 FREEMAIL_ENVFROM_END_DIGIT Envelope-from freemail username ends in
digit (owusuj500[at]outlook.com)
0.0 HTML_MESSAGE BODY: HTML included in message
1.0 FREEMAIL_REPLY From and body contain different freemails
-0.5 CRM114_PROB_GOOD CRM114: CRM114_PROB_GOOD
X-Spam-Flag: NO
X-MC-Forward: <snipped>
X-AuthUser:


Attention: Sir/Madam,

Another Order has Been Published, If You Can Supply This Quantity of
Hospital Towels with Good Quality after You Received Full Payment,
Please Reply So That I Will Give You Full Details Including Shipment
Destination And Other Terms.


Name: Hospital Towels (Terry Towels)
Colour: White
Fabric: 100% Cotton
Construction: 2/20s x 2/20s x 16s
Size: 40 x 80 cm
Weight: 340 to 375 gram/GSM
Packing: 12 pcs in a poly pack. 144 Pcs per carton, Gross wt of carton
approx 16kg.
Quality Price: USD$2.59 Per Piece Including: C.I.F. & Packaging.
Order Quantity: 750,000. Pcs
Purpose: For Distribution In Selected Hospital

Please Reply On My Email Directly On; [email protected]


Packing: 12 pcs in a poly pack. 144 Pcs per carton, Gross wt of carton
approx 16kg.


Best Regard,

owusu Jame

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
#221971 by Jack Fendly Tue Oct 07, 2014 6:23 am
From "Raffles International Company" Tue Oct 7 08:28:47 2014
X-Apparently-To:
Return-Path: <[email protected]>
X-YahooFilteredBulk: 64.12.224.149
Received-SPF: none (domain of aol.de does not designate permitted sender hosts)
X-YMailISG:
X-Originating-IP: [64.12.224.149]
Authentication-Results: mta1130.mail.bf1.yahoo.com from=aol.de; domainkeys=neutral (no sig); from=mx.aol.com; dkim=pass (ok)
Received: from 127.0.0.1 (EHLO oms-m01.mx.aol.com) (64.12.224.149)
by mta1130.mail.bf1.yahoo.com with SMTPS; Tue, 07 Oct 2014 08:40:52 +0000
Received: from omr-m04.mx.aol.com (omr-m04.mx.aol.com [64.12.143.78])
(using TLSv1 with cipher ADH-AES256-SHA (256/256 bits))
(No client certificate requested)
by oms-m01.mx.aol.com (AOL Outbound OMS Interface) with ESMTPS id 36977380151DF
for <>; Tue, 7 Oct 2014 04:28:51 -0400 (EDT)
Received: from mtaout-maa02.mx.aol.com (mtaout-maa02.mx.aol.com [172.26.222.142])
by omr-m04.mx.aol.com (Outbound Mail Relay) with ESMTP id 28D34700000B3
for <>; Tue, 7 Oct 2014 04:28:49 -0400 (EDT)
Received: from USER-PC (unknown [41.56.221.9])
(using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))
(No client certificate requested)
by mtaout-maa02.mx.aol.com (MUA/Third Party Client Interface) with ESMTPSA id C9F2738000088
for <>; Tue, 7 Oct 2014 04:28:42 -0400 (EDT)
From: "Raffles International Company" <[email protected]>
Subject: ORDERS NEEDED
To:
Content-Type: multipart/alternative; charset="ISO-8859-1"; boundary="tIfHGQpGhtLQYg4KxvVDfxEWHQlFHh=_rH0"
MIME-Version: 1.0
Reply-To: [email protected]
Date: Tue, 7 Oct 2014 01:28:47 -0700
Message-ID: <[email protected]>
X-Antivirus: avast! (VPS 141006-1, 10/06/2014), Outbound message
X-Antivirus-Status: Clean
x-aol-global-disposition: S
X-SPAM-FLAG: YES
DKIM-Signature:
X-AOL-REROUTE: YES
x-aol-sid: 3039ac1ade8e5433a43a62ce
X-AOL-IP: 41.56.221.9
Content-Length: 2169


Dear Seller,



We saw your company's products online and very much interested in them. We need your recently updated catalog and payment terms so we can select what product we have to buy from you.

I wait for your prompt and kind reply.

Thanks.


Laurentia Feng

Raffles International Company

Group Chief Operating Officer

7 Teasek Bevard, #19-04,

Sun Tower One, 038987 singapore

Tel: 65) 68437-7372

Fax: 65) 68556-7372

You cannot win a lottery you haven't entered

Please DO NOT tell a scammer you found their details posted here
#223706 by AlanJones Sun Oct 19, 2014 10:48 pm
From: Floyd Carter - [email protected]
Tel. Nos.: +261432483218 & +261342459812

Hello My name is Floyd Carter. I'm the General Manager of CARTERS SHOP LTD. We are certainly willing to make some purchase of some items in your company or store but before we proceed answer the question below. 1. Do you have POS machine to charge credit card? 2. Do you accept master and visa credit card payment? 3. Do you accept private pick up by our forwarder? 4. Can you send me your website to view your products? 5. Can you send me your wholesale price sheet if possible? Kindly email me if this is possible to ship to us with out any problem. I will await your reply Asap Thank you Floyd Carter CARTERS SHOP LTD 15613 rue Indira Gandhi BP 8619 Antananarivo 101 Madagascar Tel::+261.43.2483218 Fax::+261.34.2459812

Please do not tell scammers that they are listed here - it will take them seconds to change their fake details and their new details will not be listed for any future victims to find.
#223811 by Faizan Docherty Mon Oct 20, 2014 2:42 pm
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 65.54.190.31
Originating ISP: Microsoft Hosting
City: Redmond
Country of Origin: United States
* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.70.125.234 with SMTP id mt10csp119774pdb;
Fri, 17 Oct 2014 02:44:15 -0700 (PDT)
X-Received: by 10.66.66.101 with SMTP id e5mr7417050pat.102.1413539054986;
Fri, 17 Oct 2014 02:44:14 -0700 (PDT)
Return-Path: <[email protected]>
Received: from relay.mailchannels.net (si-002-i86.relay.mailchannels.net. [173.236.122.36])
by mx.google.com with ESMTP id ey4si608618pab.231.2014.10.17.02.44.13
for <snipped>;
Fri, 17 Oct 2014 02:44:14 -0700 (PDT)
Received-SPF: softfail (google.com: domain of transitioning [email protected] does not designate 173.236.122.36 as permitted sender) client-ip=173.236.122.36;
Authentication-Results: mx.google.com;
spf=softfail (google.com: domain of transitioning [email protected] does not designate 173.236.122.36 as permitted sender) [email protected];
dmarc=fail (p=NONE dis=NONE) header.from=outlook.com
X-Sender-Id: _forwarded-from|65.54.190.61
Received: from r8-chicago.webserversystems.com (ip-10-237-13-110.us-west-2.compute.internal [10.237.13.110])
by relay.mailchannels.net (Postfix) with ESMTPA id 7F74A1D055E
for <snipped>; Fri, 17 Oct 2014 09:44:11 +0000 (UTC)
X-Sender-Id: _forwarded-from|65.54.190.61
Received: from r8-chicago.webserversystems.com (r8-chicago.webserversystems.com [10.252.6.112])
(using TLSv1 with cipher DHE-RSA-AES256-SHA)
by 0.0.0.0:2500 (trex/5.3.1);
Fri, 17 Oct 2014 09:44:12 GMT
X-MC-Relay: Forwarding
X-MailChannels-SenderId: _forwarded-from|65.54.190.61
X-MailChannels-Auth-Id: wwwh
X-MC-Loop-Signature: 1413539052075:2322048229
X-MC-Ingress-Time: 1413539051724
Received: from bay004-omc1s20.hotmail.com ([65.54.190.31]:62505)
by r8-chicago.webserversystems.com with esmtps (TLSv1:AES256-SHA:256)
(Exim 4.82)
(envelope-from <[email protected]>)
id 1Xf44v-000129-4K
for <snipped>; Fri, 17 Oct 2014 04:44:10 -0500
Received: from BAY169-W82 ([65.54.190.61]) by BAY004-OMC1S20.hotmail.com over TLS secured channel with Microsoft SMTPSVC(7.5.7601.22751);
Fri, 17 Oct 2014 02:44:08 -0700
X-TMN: [Ch7Qen7T2OlGnQM55ipICM6KkYJbPZWb]
X-Originating-Email: [[email protected]]
Message-ID: <[email protected]>
Content-Type: multipart/alternative;
boundary="_5eecf01c-3ec6-4ca7-b532-18d5e1cff30b_"
From: owusu james <[email protected]>
Subject: SUPLY
Date: Fri, 17 Oct 2014 09:44:08 +0000
Importance: Normal
MIME-Version: 1.0
X-OriginalArrivalTime: 17 Oct 2014 09:44:08.0652 (UTC) FILETIME=[E5F460C0:01CFE9EE]
X-Spam-Status: No, score=4.8
X-Spam-Score: 48
X-Spam-Bar: ++++
X-Ham-Report: Spam detection software, running on the system "r8-chicago.webserversystems.com", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
root\@localhost for details.

Content preview: Attention: Sir/Madam, Another Order has Been Published, If
You Can Supply This Quantity of Hospital Towels with Good Quality after You
Received Full Payment, Please Reply So That I Will Give You Full Details
Including Shipment Destination And Other Terms. [...]

Content analysis details: (4.8 points, 5.0 required)

pts rule name description
---- ---------------------- --------------------------------------------------
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[65.54.190.31 listed in list.dnswl.org]
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider
(owusuj500[at]outlook.com)
-0.0 SPF_PASS SPF: sender matches SPF record
0.2 FREEMAIL_ENVFROM_END_DIGIT Envelope-from freemail username ends in
digit (owusuj500[at]outlook.com)
1.0 MISSING_HEADERS Missing To: header
0.0 HTML_MESSAGE BODY: HTML included in message
2.5 MALFORMED_FREEMAIL Bad headers on message from free email service
1.0 FREEMAIL_REPLY From and body contain different freemails
X-Spam-Flag: NO
X-MC-Forward: <snipped>
X-AuthUser:


Attention: Sir/Madam,

Another Order has Been Published, If You Can Supply This Quantity of
Hospital Towels with Good Quality after You Received Full Payment,
Please Reply So That I Will Give You Full Details Including Shipment
Destination And Other Terms.


Name: Hospital Towels (Terry Towels)
Colour: White
Fabric: 100% Cotton
Construction: 2/20s x 2/20s x 16s
Size: 40 x 80 cm
Weight: 340 to 375 gram/GSM
Packing: 12 pcs in a poly pack. 144 Pcs per carton, Gross wt of carton
approx 16kg.
Quality Price: USD$2.59 Per Piece Including: C.I.F. & Packaging.
Order Quantity: 750,000. Pcs
Purpose: For Distribution In Selected Hospital

Please Reply On My Email Directly On;[email protected]


Packing: 12 pcs in a poly pack. 144 Pcs per carton, Gross wt of carton
approx 16kg.


Best Regard,

owusu Jame

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
#223814 by Faizan Docherty Mon Oct 20, 2014 2:55 pm
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 65.54.51.84
Originating ISP: Microsoft Hosting
City: Redmond
Country of Origin: United States
* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.76.168.38 with SMTP id zt6csp555243oab;
Wed, 15 Oct 2014 02:26:37 -0700 (PDT)
X-Received: by 10.66.132.81 with SMTP id os17mr10786172pab.7.1413365197089;
Wed, 15 Oct 2014 02:26:37 -0700 (PDT)
Return-Path: <[email protected]>
Received: from relay.mailchannels.net (ar-005-i201.relay.mailchannels.net. [162.253.144.83])
by mx.google.com with ESMTP id fw4si5470149pbb.184.2014.10.15.02.26.35
for <snipped>;
Wed, 15 Oct 2014 02:26:37 -0700 (PDT)
Received-SPF: softfail (google.com: domain of transitioning [email protected] does not designate 162.253.144.83 as permitted sender) client-ip=162.253.144.83;
Authentication-Results: mx.google.com;
spf=softfail (google.com: domain of transitioning [email protected] does not designate 162.253.144.83 as permitted sender) [email protected]
X-Sender-Id: _forwarded-from|65.55.90.135
Received: from r8-chicago.webserversystems.com (ip-10-33-12-218.us-west-2.compute.internal [10.33.12.218])
by relay.mailchannels.net (Postfix) with ESMTPA id E010F601E3
for <snipped>; Wed, 15 Oct 2014 09:26:32 +0000 (UTC)
X-Sender-Id: _forwarded-from|65.55.90.135
Received: from r8-chicago.webserversystems.com (r8-chicago.webserversystems.com [10.248.11.136])
(using TLSv1 with cipher DHE-RSA-AES256-SHA)
by 0.0.0.0:2500 (trex/5.2.14);
Wed, 15 Oct 2014 09:26:34 GMT
X-MC-Relay: Forwarding
X-MailChannels-SenderId: _forwarded-from|65.55.90.135
X-MailChannels-Auth-Id: wwwh
X-MC-Loop-Signature: 1413365194244:2036915361
X-MC-Ingress-Time: 1413365194243
Received: from snt004-omc3s47.hotmail.com ([65.54.51.84]:55608)
by r8-chicago.webserversystems.com with esmtps (TLSv1:AES256-SHA:256)
(Exim 4.82)
(envelope-from <[email protected]>)
id 1XeKqk-00020g-NK
for <snipped>; Wed, 15 Oct 2014 04:26:31 -0500
Received: from SNT151-W60 ([65.55.90.135]) by SNT004-OMC3S47.hotmail.com over TLS secured channel with Microsoft SMTPSVC(7.5.7601.22751);
Wed, 15 Oct 2014 02:26:30 -0700
X-TMN: [d4U02FXugFtqF4RSStv9fxrQT7xpIzw5]
X-Originating-Email: [[email protected]]
Message-ID: <[email protected]>
Content-Type: multipart/alternative;
boundary="_1c94ceb2-6c86-4f7a-8160-f0d4290c2a8d_"
From: victor osei <[email protected]>
Date: Wed, 15 Oct 2014 09:26:29 +0000
Importance: Normal
MIME-Version: 1.0
X-OriginalArrivalTime: 15 Oct 2014 09:26:30.0032 (UTC) FILETIME=[1A244900:01CFE85A]
X-Spam-Status: Yes, score=6.8
X-Spam-Score: 68
X-Spam-Bar: ++++++
X-Spam-Report: Spam detection software, running on the system "r8-chicago.webserversystems.com", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
root\@localhost for details.

Content preview: Attention: Sir/Madam, Another Order has Been Published, If
You Can Supply This Quantity of Hospital Towels with Good Quality after You
Received Full Payment, Please Reply So That I Will Give You Full Details
Including Shipment Destination And Other Terms. [...]

Content analysis details: (6.8 points, 5.0 required)

pts rule name description
---- ---------------------- --------------------------------------------------
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider
(victorosei5[at]hotmail.com)
-0.0 T_RP_MATCHES_RCVD Envelope sender domain matches handover relay
domain
-0.0 SPF_PASS SPF: sender matches SPF record
0.2 FREEMAIL_ENVFROM_END_DIGIT Envelope-from freemail username ends in
digit (victorosei5[at]hotmail.com)
1.0 MISSING_HEADERS Missing To: header
0.0 HTML_MESSAGE BODY: HTML included in message
2.0 DCC_CHECK Detected as bulk mail by DCC (dcc-servers.net)
2.5 MALFORMED_FREEMAIL Bad headers on message from free email service
1.0 FREEMAIL_REPLY From and body contain different freemails
X-Spam-Flag: YES
Subject: ***SPAM*** SUPPLY
X-MC-Forward: <snipped>
X-AuthUser:


Attention: Sir/Madam,

Another Order has Been Published, If You Can Supply This Quantity of
Hospital Towels with Good Quality after You Received Full Payment,
Please Reply So That I Will Give You Full Details Including Shipment
Destination And Other Terms.


Name: Hospital Towels (Terry Towels)
Colour: White
Fabric: 100% Cotton
Construction: 2/20s x 2/20s x 16s
Size: 40 x 80 cm
Weight: 340 to 375 gram/GSM
Packing: 12 pcs in a poly pack. 144 Pcs per carton, Gross wt of carton
approx 16kg.
Quality Price: USD$2.59 Per Piece Including: C.I.F. & Packaging.
Order Quantity: 750,000. Pcs
Purpose: For Distribution In Selected Hospital

Please Reply On My Email Directly On; [email protected]



You Can Call Me On Phone


Thank You, Waiting To Hear From You.

Best Regard,

Mr.Victor Osei
Director
OFFICE: 657 Tudu James Town
MAIL BOX: P.O BOX, 110 Accra.

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.

Who is online

Users browsing this forum: No registered users and 6 guests