Has someone offered you a huge sum of money or a valuable consignment? It's a 419 or advance fee fraud - find out how they work, and what to do to be safe.
#219910 by Faizan Docherty Sun Sep 21, 2014 10:05 pm
ipTRACKERonline.com wrote:Header Analysis Quick Report
Originating IP: 188.126.71.198
Originating ISP: Portlane Networks Ab
City: n/a
Country of Origin: Sweden
* For a complete report on this email header goto ipTRACKERonline


Delivered-To: <snipped>
Received: by 10.70.125.234 with SMTP id mt10csp189979pdb;
Sun, 21 Sep 2014 16:09:19 -0700 (PDT)
X-Received: by 10.70.134.139 with SMTP id pk11mr18399999pdb.81.1411340959807;
Sun, 21 Sep 2014 16:09:19 -0700 (PDT)
Return-Path: <[email protected]>
Received: from relay.mailchannels.net (ar-005-i202.relay.mailchannels.net. [162.253.144.84])
by mx.google.com with ESMTP id ag3si13300902pbc.61.2014.09.21.16.09.18
for <snipped>;
Sun, 21 Sep 2014 16:09:19 -0700 (PDT)
Received-SPF: neutral (google.com: 162.253.144.84 is neither permitted nor denied by domain of [email protected]) client-ip=162.253.144.84;
Authentication-Results: mx.google.com;
spf=neutral (google.com: 162.253.144.84 is neither permitted nor denied by domain of [email protected]) [email protected]
X-Sender-Id: _forwarded-from|198.168.48.58
Received: from r8-chicago.webserversystems.com (ip-10-237-13-110.us-west-2.compute.internal [10.237.13.110])
by relay.mailchannels.net (Postfix) with ESMTPA id AAE89100368
for <snipped>; Sun, 21 Sep 2014 23:09:14 +0000 (UTC)
X-Sender-Id: _forwarded-from|198.168.48.58
Received: from r8-chicago.webserversystems.com (r8-chicago.webserversystems.com [10.253.92.5])
(using TLSv1 with cipher DHE-RSA-AES256-SHA)
by 0.0.0.0:2500 (trex/5.2.13);
Sun, 21 Sep 2014 23:09:16 GMT
X-MC-Relay: Forwarding
X-MailChannels-SenderId: _forwarded-from|198.168.48.58
X-MailChannels-Auth-Id: wwwh
X-MC-Loop-Signature: 1411340956739:2803817305
X-MC-Ingress-Time: 1411340956739
Received: from mail-bn1lp0139.outbound.protection.outlook.com ([207.46.163.139]:17986 helo=na01-bn1-obe.outbound.protection.outlook.com)
by r8-chicago.webserversystems.com with esmtps (TLSv1:AES256-SHA:256)
(Exim 4.82)
(envelope-from <[email protected]>)
id 1XVqFk-0000UX-R7
for <snipped>; Sun, 21 Sep 2014 18:09:13 -0500
Received: from BN1PR02CA0012.namprd02.prod.outlook.com (10.141.56.12) by
BN1PR02MB246.namprd02.prod.outlook.com (10.242.214.143) with Microsoft SMTP
Server (TLS) id 15.0.1034.13; Sun, 21 Sep 2014 23:09:08 +0000
Received: from BN1BFFO11FD008.protection.gbl (2a01:111:f400:7c10::1:129) by
BN1PR02CA0012.outlook.office365.com (2a01:111:e400:2a::12) with Microsoft
SMTP Server (TLS) id 15.0.1034.13 via Frontend Transport; Sun, 21 Sep 2014
23:09:08 +0000
Received: from webmail.dawsoncollege.qc.ca (198.168.48.58) by
BN1BFFO11FD008.mail.protection.outlook.com (10.58.144.71) with Microsoft SMTP
Server (TLS) id 15.0.1029.15 via Frontend Transport; Sun, 21 Sep 2014
23:09:08 +0000
Received: from DC229.ad.dawsoncollege.qc.ca ([fe80::5516:cfbb:a04a:3c04]) by
DC219.ad.dawsoncollege.qc.ca ([::1]) with mapi id 14.03.0195.001; Sun, 21 Sep
2014 19:09:01 -0400
From: Elisabeth Cadieux <[email protected]>
To: Elisabeth Cadieux <[email protected]>
Subject: RE: GRANT FUNDS
Thread-Topic: GRANT FUNDS
Thread-Index: Ac/V474PZ6JaaJzcRsOyzHqELBkI/gAAyyvaAAGS+4YAAIDiXQ==
Date: Sun, 21 Sep 2014 23:08:45 +0000
Message-ID: <5C9C26064D2EA547969DB773D0BC51DF2CE694CE@DC229.ad.dawsoncollege.qc.ca>
References: <5C9C26064D2EA547969DB773D0BC51DF2CE60D4C@DC229.ad.dawsoncollege.qc.ca>,<5C9C26064D2EA547969DB773D0BC51DF2CE66C91@DC229.ad.dawsoncollege.qc.ca>,<5C9C26064D2EA547969DB773D0BC51DF2CE682FE@DC229.ad.dawsoncollege.qc.ca>
In-Reply-To: <5C9C26064D2EA547969DB773D0BC51DF2CE682FE@DC229.ad.dawsoncollege.qc.ca>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
x-originating-ip: [188.126.71.198]
Content-Type: multipart/alternative;
boundary="_000_5C9C26064D2EA547969DB773D0BC51DF2CE694CEDC229addawsonco_"
MIME-Version: 1.0
X-EOPAttributedMessage: 0
X-Forefront-Antispam-Report:
CIP:198.168.48.58;CTRY:CA;IPV:CAL;IPV:NLI;EFV:NLI;SFV:NSPM;SFS:(10009020)(6009001)(448002)(199003)(189002)(377454003)(74502003)(512934002)(71186001)(110136001)(4396001)(16236675004)(104016003)(85306004)(66066001)(44976005)(19580405001)(83322001)(19580395003)(26826002)(6806004)(120916001)(221733001)(20776003)(31966008)(50986999)(85326001)(19625215002)(107886001)(107046002)(76482002)(84326002)(86362001)(21056001)(77096002)(64706001)(87936001)(95666004)(90102001)(92566001)(76176999)(54356999)(77982003)(81342003)(46102003)(74662003)(2656002)(92726001)(106466001)(33656002)(99396002)(80022003)(74482002)(79102003)(83072002)(55846006)(81542003)(85852003)(80792004)(571714004)(567454003);DIR:OUT;SFP:1101;SCL:1;SRVR:BN1PR02MB246;H:webmail.dawsoncollege.qc.ca;FPR:;MLV:ovr;PTR:autodiscover.dawsoncollege.qc.ca,webmail.dawsoncollege.qc.ca;A:1;MX:1;LANG:en;
X-OriginatorOrg: webmail.dawsoncollege.qc.ca
X-Microsoft-Antispam: UriScan:;
X-Microsoft-Antispam: BCL:0;PCL:0;RULEID:;SRVR:BN1PR02MB246;
X-Forefront-PRVS: 034119E4F6
Received-SPF: PermError (protection.outlook.com: domain of dawsoncollege.qc.ca
used an invalid SPF mechanism)
Authentication-Results: spf=permerror (sender IP is 198.168.48.58)
[email protected];
X-Spam-Status: No, score=0.3
X-Spam-Score: 3
X-Spam-Bar: /
X-Ham-Report: Spam detection software, running on the system "r8-chicago.webserversystems.com", has
identified this incoming email as possible spam. The original message
has been attached to this so you can view it (if it isn't spam) or label
similar future email. If you have any questions, see
root\@localhost for details.

Content preview: From: Elisabeth Cadieux Sent: Sunday, September 21, 2014
6:54 PM To: Elisabeth Cadieux Subject: RE: GRANT FUNDS Funds donated to you.
Contact [[email protected]] for details [...]

Content analysis details: (0.3 points, 5.0 required)

pts rule name description
---- ---------------------- --------------------------------------------------
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[207.46.163.139 listed in list.dnswl.org]
1.5 SUBJ_ALL_CAPS Subject is all capitals
0.0 SPF_HELO_FAIL SPF: HELO does not match SPF record (fail)
[SPF failed: Please see http://www.openspf.net/Why?s=helo;id=na ... ystems.com]
1.8 HTML_EMBEDS BODY: HTML with embedded plugin object
0.0 HTML_MESSAGE BODY: HTML included in message
-3.0 CRM114_GOOD CRM114: message is GOOD with crm114-score 13.9100
X-Spam-Flag: NO
X-MC-Forward: <snipped>
X-AuthUser:


Funds donated to you. Contact [[email protected]] for details

Please DO NOT tell a scammer that he has been posted here!

If you wish you can email me at
faizandocherty @ scamwarners [dot] com

How do I find email headers???

How to analyze an email header.
Advertisement

Who is online

Users browsing this forum: Google [Bot] and 208 guests