Nk.CA Credential Phishing
Posted by Dave Yadallee onX-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Sat, 22 Aug 2026 10:34:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.100 (FreeBSD))
(envelope-from
id 1wxof7-000000008aG-0jcv
for dave@doctor.nl2k.ab.ca;
Sat, 22 Aug 2026 10:33:41 -0600
Resent-From: The Doctor
Resent-Date: Sat, 22 Aug 2026 10:33:41 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mail.emergingrating.com ([103.16.72.108]:60178)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384
(Exim 4.100 (FreeBSD))
(envelope-from
id 1wxnMZ-00000000OPK-1xY0
for sales@nk.ca;
Sat, 22 Aug 2026 09:10:38 -0600
Received: from localhost (localhost.localdomain [127.0.0.1])
by mail.emergingrating.com (Postfix) with ESMTP id 040233E3FE2
for
Received: from mail.emergingrating.com ([127.0.0.1])
by localhost (mail.emergingrating.com [127.0.0.1]) (amavis, port 10032)
with ESMTP id ABkzDZ6xayNb for
Sat, 22 Aug 2026 21:13:47 +0600 (+06)
Received: from localhost (localhost.localdomain [127.0.0.1])
by mail.emergingrating.com (Postfix) with ESMTP id 89F8E40DEAF
for
X-Virus-Scanned: amavis at emergingrating.com
Received: from mail.emergingrating.com ([127.0.0.1])
by localhost (mail.emergingrating.com [127.0.0.1]) (amavis, port 10026)
with ESMTP id pHGn8B5ogJpz for
Sat, 22 Aug 2026 21:13:47 +0600 (+06)
Received: from 96e973dc.com (unknown [62.169.135.177])
by mail.emergingrating.com (Postfix) with ESMTPSA id D76C113F8314
for
Content-Type: multipart/mixed; boundary="===============1045353409688801620=="
MIME-Version: 1.0
From: Admin Nk Helpdesk online mail support account
imgfjqniwktkargewvphetsxffzcgkqsrtwdqcbvnlyitfaocsjjrpdyzljjsdmcxslloo
To: sales@nk.ca
Subject: Sales Nk Closure last notice update
Date: Sat, 22 Aug 2026 15:09:04 -0000
Message-ID: <178741134466.243240.6383465376943250951@emergingrating.com>
X-YRLMSZ: NBOBNT
X-TOQMD: QTWFCZCBF
X-Accept-Language: en-us, en
X-Spam_score: 13.0
X-Spam_score_int: 130
X-Spam_bar: +++++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview:
Content analysis details: (13.0 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[62.169.135.177 listed in will-spam-for-food.eu.org]
[62.169.135.177 listed in will-spam-for-food.eu.org]
[62.169.135.177 listed in will-spam-for-food.eu.org]
[62.169.135.177 listed in will-spam-for-food.eu.org]
[62.169.135.177 listed in will-spam-for-food.eu.org]
[62.169.135.177 listed in will-spam-for-food.eu.org]
[62.169.135.177 listed in will-spam-for-food.eu.org]
[62.169.135.177 listed in will-spam-for-food.eu.org]
[103.16.72.108 listed in will-spam-for-food.eu.org]
[103.16.72.108 listed in will-spam-for-food.eu.org]
[103.16.72.108 listed in will-spam-for-food.eu.org]
[103.16.72.108 listed in will-spam-for-food.eu.org]
[103.16.72.108 listed in will-spam-for-food.eu.org]
[103.16.72.108 listed in will-spam-for-food.eu.org]
[103.16.72.108 listed in will-spam-for-food.eu.org]
[103.16.72.108 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[103.16.72.108 listed in dnsbl.ahbl.org]
[103.16.72.108 listed in dnsbl.ahbl.org]
[103.16.72.108 listed in dnsbl.ahbl.org]
[103.16.72.108 listed in dnsbl.ahbl.org]
[62.169.135.177 listed in dnsbl.ahbl.org]
[62.169.135.177 listed in dnsbl.ahbl.org]
[62.169.135.177 listed in dnsbl.ahbl.org]
[62.169.135.177 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[103.16.72.108 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[103.16.72.108 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[103.16.72.108 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[103.16.72.108 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_SBL_XBL RBL: Received via a relay in Spamhaus SBL+XBL
[62.169.135.177 listed in sbl-xbl.spamhaus.org]
3.6 RCVD_IN_SBL_CSS RBL: Received via a relay in Spamhaus SBL-CSS
[62.169.135.177 listed in zen.spamhaus.org]
-2.0 RCVD_IN_RP_SAFE RBL: Sender in ReturnPath Safe - Contact
safe-sa@returnpath.net
[Excessive Number of Queries |
-3.0 RCVD_IN_RP_CERTIFIED RBL: Sender in ReturnPath Certified - Contact
cert-sa@returnpath.net
[Excessive Number of Queries |
1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,
https://senderscore.org/blacklistlookup/
[103.16.72.108 listed in bl.score.senderscore.com]
-0.0 SPF_PASS SPF: sender matches SPF record
0.2 MR_NOT_ATTRIBUTED_IP Beta rule: an non-attributed IPv4 found in
headers
3.5 VOWEL_FROM_7 Impronouncable from header (7+ consecutive vowels)
0.5 NO_RDNS Sending MTA has no reverse DNS (Postfix variant)
-0.0 T_RP_MATCHES_RCVD Envelope sender domain matches handover relay
domain
0.0 NORMAL_HTTP_TO_IP URI: URI host has a public dotted-decimal IPv4
address
0.7 MPART_ALT_DIFF BODY: HTML and text parts are different
0.0 MIME_HTML_MOSTLY BODY: Multipart message mostly text/html MIME
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.3 HTML_IMAGE_ONLY_04 BODY: HTML: images with 0-400 bytes of words
0.1 MXG_EMAIL_FRAG BODY: URI with email in fragment
0.8 SARE_FROM_SPAM_WORD3 I don't know people named this!
0.0 NO_RDNS2 Sending MTA has no reverse DNS
0.0 DC_PNG_UNO_LARGO Message contains a single large inline gif
0.1 DC_IMAGE_SPAM_HTML Possible Image-only spam
0.1 DC_IMAGE_SPAM_TEXT Possible Image-only spam with little text
0.2 GMD_PDF_EMPTY_BODY BODY: Attached PDF with empty message body
Subject: {SPAM?} Sales Nk Closure last notice update

Nkclosure.pdf