Geek squad phish from Amazon
Posted by Dave Yadallee onX-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Mon, 30 Mar 2026 15:00:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from
id 1w7JiI-00000000E4A-1SG9
for dave@doctor.nl2k.ab.ca;
Mon, 30 Mar 2026 14:59:58 -0600
Resent-From: The Doctor
Resent-Date: Mon, 30 Mar 2026 14:59:58 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from e226-52.smtp-out.us-east-2.amazonses.com ([23.251.226.52]:60051)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256
(Exim 4.98.2 (FreeBSD))
(envelope-from <010f019d3f9494f3-2578c585-35cb-4a9d-94cb-280d37908e4b-000000@us-east-2.amazonses.com>)
id 1w7FVo-00000000HwU-2Aae
for doctor@mail.nl2k.ab.ca;
Mon, 30 Mar 2026 10:30:56 -0600
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple;
s=e3mivvcabueua6g7tfebwo26caqq5ypa; d=sns.amazonaws.com;
t=1774888195;
h=Date:From:To:Message-ID:Subject:MIME-Version:Content-Type:Content-Transfer-Encoding;
bh=XmROXhIfikgCvQYb/x4/NfrmYuoNbjN1pg4lKygQ/zY=;
b=I5eO1msW0yGl5jNK5H08tesSAsBB/GhvmMpe5hiLHAdIgtzUli+451AW3ipReKEK
LjPHEceWdAopv/y8EqGMOJVXYEn2uZfq5sFHxubqH5oczXZTTDZgJVLehwfQFYqVvZp
bVyH+jX9zu9HV/3oGyu5SNMkXSUvKbrOw3sJqv5dUnZLzBhRKCYJ/ViYmn5TzmXpZw7
oqUArD0KV2wA2QTZhiDsf7f6rXNbz6+YduCR2YmuSBWf5waTz54NLtLlzA8ZzXVY0Jt
kR2dotstcpGLm4tVsVJr22XSs3ohSKsvxzCU/I3QOjjOUWfbToo6GU9hm1mCX3FqBga
LFJ0cj2zFQ==
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple;
s=ndjes4mrtuzus6qxu3frw3ubo3gpjndv; d=amazonses.com; t=1774888195;
h=Date:From:To:Message-ID:Subject:MIME-Version:Content-Type:Content-Transfer-Encoding:Feedback-ID;
bh=XmROXhIfikgCvQYb/x4/NfrmYuoNbjN1pg4lKygQ/zY=;
b=gnQggr5aCsO/XY39llGpG8ff3eYxCR9kj8x0Le/+oia/QLQpD4N4WjB+FbY1PBRU
FR+BDUUPK/g1Nd01Ebq7Z3KzUPQzYwVl5JZQ1F2GBXgJ90vyspBNIDFcZw9YFWfbDvJ
jZ3bwkVdjXptsMrgIj08QwCqPgq0TqCpYqtitwNg=
Date: Mon, 30 Mar 2026 16:29:55 +0000
From: Invoice #025902
To: doctor@mail.nl2k.ab.ca
Message-ID: <010f019d3f9494f3-2578c585-35cb-4a9d-94cb-280d37908e4b-000000@us-east-2.amazonses.com>
Subject: AWS Notification - Subscription Confirmation
MIME-Version: 1.0
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: 7bit
x-amz-sns-message-id: e5233453-179c-498c-9127-4a09633cd70d
Feedback-ID: ::1.us-east-2.au9SDFHNnZUTWC9L0/qzeelAPnlWjuAjGTIjEyD+UeE=:AmazonSES
X-SES-Outgoing: 2026.03.30-23.251.226.52
X-Spam_score: 11.1
X-Spam_score_int: 111
X-Spam_bar: +++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: You have chosen to subscribe to the topic: arn:aws:sns:us-east-2:639986414836:Geek-Squad-Total-Protection-auto-renewal-complete-for-2-years-490-USD-charged-service-restored-with-safe-browsing-protecti
[...]
Content analysis details: (11.1 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[23.251.226.52 listed in list.dnswl.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[23.251.226.52 listed in dnsbl.ahbl.org]
[23.251.226.52 listed in dnsbl.ahbl.org]
[23.251.226.52 listed in dnsbl.ahbl.org]
[23.251.226.52 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[23.251.226.52 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[23.251.226.52 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[23.251.226.52 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[23.251.226.52 listed in dnsbl.ahbl.org]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[23.251.226.52 listed in will-spam-for-food.eu.org]
[23.251.226.52 listed in will-spam-for-food.eu.org]
[23.251.226.52 listed in will-spam-for-food.eu.org]
[23.251.226.52 listed in will-spam-for-food.eu.org]
[23.251.226.52 listed in will-spam-for-food.eu.org]
[23.251.226.52 listed in will-spam-for-food.eu.org]
[23.251.226.52 listed in will-spam-for-food.eu.org]
[23.251.226.52 listed in will-spam-for-food.eu.org]
-0.0 SPF_HELO_PASS SPF: HELO matches SPF record
-0.0 SPF_PASS SPF: sender matches SPF record
0.2 MR_NOT_ATTRIBUTED_IP Beta rule: an non-attributed IPv4 found in
headers
2.0 GR_DOMAIN_AMAZON1 Received contains spam friendly host (amazon)
0.0 HEADER_FROM_DIFFERENT_DOMAINS From and EnvelopeFrom 2nd level mail
domains are different
-0.0 T_RP_MATCHES_RCVD Envelope sender domain matches handover relay
domain
1.0 OPT_OUT BODY: No description available.
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 HTML_MESSAGE BODY: HTML included in message
2.0 RATWR8_MESSID Message-ID with excessive dashes and dollars
0.0 SARE_FROM_SPAM_WORD4 From address suggests this may be spam
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[23.251.226.52 listed in wl.mailspike.net]
Subject: {SPAM?} AWS Notification - Subscription Confirmation
You have chosen to subscribe to the topic:
arn:aws:sns:us-east-2:639986414836:Geek-Squad-Total-Protection-auto-renewal-complete-for-2-years-490-USD-charged-service-restored-with-safe-browsing-protection-performance-optimization-premium-VPN-Wi-Fi-hotspots-specialists-ready-at-for-management-call-support-8562099547
To confirm this subscription, click or visit the link below (If this was in error no action is necessary):
Confirm subscription
Please do not reply directly to this email. If you wish to remove yourself from receiving all future SNS subscription confirmation requests please send an email to sns-opt-out