Web/SEO/App Spam from Microsoft Outlook Part 2
Posted by Dave Yadallee onboundary="_000_SE2P216MB2572F1ED5202A624A599BBABD0AAASE2P216MB2572KORP_"
MIME-Version: 1.0
X-OriginatorOrg: outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-AuthSource: SE2P216MB2572.KORP216.PROD.OUTLOOK.COM
X-MS-Exchange-CrossTenant-RMS-PersistedConsumerOrg: 00000000-0000-0000-0000-000000000000
X-MS-Exchange-CrossTenant-Network-Message-Id: 01d8edf5-76f5-45b6-e0bf-08de3ccdc975
X-MS-Exchange-CrossTenant-originalarrivaltime: 16 Dec 2025 18:06:07.8725
(UTC)
X-MS-Exchange-CrossTenant-fromentityheader: Hosted
X-MS-Exchange-CrossTenant-id: 84df9e7f-e9f6-40af-b435-aaaaaaaaaaaa
X-MS-Exchange-CrossTenant-rms-persistedconsumerorg: 00000000-0000-0000-0000-000000000000
X-MS-Exchange-Transport-CrossTenantHeadersStamped: SE1P216MB1478
X-Spam_score: 5.8
X-Spam_score_int: 58
X-Spam_bar: +++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Hi, Just following up to see if you’re interested in that
local SEO I mentioned.
Content analysis details: (5.8 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[2603:1096:101:1c5:0:0:0:13 listed in]
[will-spam-for-food.eu.org]
[2603:1096:101:1c5:0:0:0:13 listed in]
[will-spam-for-food.eu.org]
[2603:1096:101:1c5:0:0:0:13 listed in]
[will-spam-for-food.eu.org]
[2603:1096:101:1c5:0:0:0:13 listed in]
[will-spam-for-food.eu.org]
[2603:1096:101:1c5:0:0:0:13 listed in]
[will-spam-for-food.eu.org]
[2603:1096:101:1c5:0:0:0:13 listed in]
[will-spam-for-food.eu.org]
[2603:1096:101:1c5:0:0:0:13 listed in]
[will-spam-for-food.eu.org]
[2603:1096:101:1c5:0:0:0:13 listed in]
[will-spam-for-food.eu.org]
[52.103.74.24 listed in will-spam-for-food.eu.org]
[52.103.74.24 listed in will-spam-for-food.eu.org]
[52.103.74.24 listed in will-spam-for-food.eu.org]
[52.103.74.24 listed in will-spam-for-food.eu.org]
[52.103.74.24 listed in will-spam-for-food.eu.org]
[52.103.74.24 listed in will-spam-for-food.eu.org]
[52.103.74.24 listed in will-spam-for-food.eu.org]
[52.103.74.24 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[52.103.74.24 listed in dnsbl.ahbl.org]
[52.103.74.24 listed in dnsbl.ahbl.org]
[52.103.74.24 listed in dnsbl.ahbl.org]
[52.103.74.24 listed in dnsbl.ahbl.org]
[2603:1096:101:1c5:0:0:0:13 listed in]
[dnsbl.ahbl.org]
[2603:1096:101:1c5:0:0:0:13 listed in]
[dnsbl.ahbl.org]
[2603:1096:101:1c5:0:0:0:13 listed in]
[dnsbl.ahbl.org]
[2603:1096:101:1c5:0:0:0:13 listed in]
[dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[52.103.74.24 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[52.103.74.24 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[52.103.74.24 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[52.103.74.24 listed in dnsbl.ahbl.org]
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[52.103.74.24 listed in list.dnswl.org]
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[52.103.74.24 listed in wl.mailspike.net]
-0.0 SPF_HELO_PASS SPF: HELO matches SPF record
-0.0 SPF_PASS SPF: sender matches SPF record
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's
domain
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid
0.0 ARC_SIGNED Message has a ARC signature
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
-0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from
envelope-from domain
0.0 ARC_VALID Message has a valid ARC signature
0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider
[https.www.remineal4562(at)outlook.com]
0.2 FREEMAIL_ENVFROM_END_DIGIT Envelope-from freemail username ends in
digit
[https.www.remineal4562(at)outlook.com]
-0.0 T_RP_MATCHES_RCVD Envelope sender domain matches handover relay
domain
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 HTML_MESSAGE BODY: HTML included in message
0.5 VOWEL_FROM_5 Impronouncable from header (6 consecutive vowels)
0.5 VOWEL_TOCC_5 To or Cc header with 5 consecutive vowels
Subject: {SPAM?} =?utf-8?B?UmU6IFllc+KApj8=?=
--_000_SE2P216MB2572F1ED5202A624A599BBABD0AAASE2P216MB2572KORP_--