McAfee Phish from Amazon
Posted by Dave Yadallee onX-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Mon, 30 Mar 2026 09:47:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from
id 1w7EpJ-00000000Aeg-2vQR
for dave@doctor.nl2k.ab.ca;
Mon, 30 Mar 2026 09:46:53 -0600
Resent-From: The Doctor
Resent-Date: Mon, 30 Mar 2026 09:46:53 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from e226-56.smtp-out.us-east-2.amazonses.com ([23.251.226.56]:37031)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256
(Exim 4.98.2 (FreeBSD))
(envelope-from <010f019d3f529e36-167663d8-43a9-48ca-92c7-574397af5d4c-000000@us-east-2.amazonses.com>)
id 1w7EO6-000000008hs-1UX4
for root@doctor.nl2k.ab.ca;
Mon, 30 Mar 2026 09:18:54 -0600
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple;
s=e3mivvcabueua6g7tfebwo26caqq5ypa; d=sns.amazonaws.com;
t=1774883872;
h=Date:From:To:Message-ID:Subject:MIME-Version:Content-Type:Content-Transfer-Encoding;
bh=sr8WD4Oj33tWgjXd8VgkszjCsa4x7/eYxV19vUSqs/M=;
b=qd3ZqF1JdFx3T3MZqmP1XwHXOFvgkBTlF1MHV4x8UduCnpcruQw3TG82SgCiZ3iV
xapey+TRUvC1CKVayOslZE8UIeGfViXnBQo7oHC5wmlvSnZmoUoZCv9TLlXcMYhBa/6
VdP6QXrpWxSKBx+1vhH50AW79yK5sUpwefs1eOR6VLUxRJHmhufMWlsTo752pWLYo5f
sjtSxdvbx81P6tpvfubDCCTD052PheFMSUX/jGppyly3lWIFQM/iOiAzme06thKXz6H
EC0lXykeAuZ2qaNJtElm7NP0l4P1+JBnqf7n/ktBnLg1XILOxe5efCTbHyaG1XNAi9J
vNp4aLp6Ew==
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/simple;
s=ndjes4mrtuzus6qxu3frw3ubo3gpjndv; d=amazonses.com; t=1774883872;
h=Date:From:To:Message-ID:Subject:MIME-Version:Content-Type:Content-Transfer-Encoding:Feedback-ID;
bh=sr8WD4Oj33tWgjXd8VgkszjCsa4x7/eYxV19vUSqs/M=;
b=hgTTKXUi2WBj1x39wS8hgTwbf4DkgFyAfDpgpAd15cIiW8JBrxxc2CAy95/Mlrpo
DXViD3UJ2c8baXT70PrbsijTmwnYePx7Td8U516MDzEhBJ9IwZOLkOAdWJPS91whi5n
IWv8TZpJB7nNnDcCHmdS1TDWQ3bASprrn19k3Rwg=
Date: Mon, 30 Mar 2026 15:17:52 +0000
From: Invocie #021609
To: root@doctor.nl2k.ab.ca
Message-ID: <010f019d3f529e36-167663d8-43a9-48ca-92c7-574397af5d4c-000000@us-east-2.amazonses.com>
Subject: AWS Notification - Subscription Confirmation
MIME-Version: 1.0
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: 7bit
x-amz-sns-message-id: 562b06ab-20a2-4404-9ee4-e8c406c53e26
Feedback-ID: ::1.us-east-2.au9SDFHNnZUTWC9L0/qzeelAPnlWjuAjGTIjEyD+UeE=:AmazonSES
X-SES-Outgoing: 2026.03.30-23.251.226.56
X-Spam_score: 11.3
X-Spam_score_int: 113
X-Spam_bar: +++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: You have chosen to subscribe to the topic: arn:aws:sns:us-east-2:409953609051:Your-McAfee-Identity-Protection-plan-extended-2-years-ahead-490-USD-charged-immediate-safe-browsing-protection-encrypted-s
[...]
Content analysis details: (11.3 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[23.251.226.56 listed in dnsbl.ahbl.org]
[23.251.226.56 listed in dnsbl.ahbl.org]
[23.251.226.56 listed in dnsbl.ahbl.org]
[23.251.226.56 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[23.251.226.56 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[23.251.226.56 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[23.251.226.56 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[23.251.226.56 listed in dnsbl.ahbl.org]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[23.251.226.56 listed in will-spam-for-food.eu.org]
[23.251.226.56 listed in will-spam-for-food.eu.org]
[23.251.226.56 listed in will-spam-for-food.eu.org]
[23.251.226.56 listed in will-spam-for-food.eu.org]
[23.251.226.56 listed in will-spam-for-food.eu.org]
[23.251.226.56 listed in will-spam-for-food.eu.org]
[23.251.226.56 listed in will-spam-for-food.eu.org]
[23.251.226.56 listed in will-spam-for-food.eu.org]
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[23.251.226.56 listed in list.dnswl.org]
-0.0 SPF_HELO_PASS SPF: HELO matches SPF record
-0.0 SPF_PASS SPF: sender matches SPF record
0.2 MR_NOT_ATTRIBUTED_IP Beta rule: an non-attributed IPv4 found in
headers
2.0 GR_DOMAIN_AMAZON1 Received contains spam friendly host (amazon)
0.0 HEADER_FROM_DIFFERENT_DOMAINS From and EnvelopeFrom 2nd level mail
domains are different
-0.0 T_RP_MATCHES_RCVD Envelope sender domain matches handover relay
domain
1.0 OPT_OUT BODY: No description available.
-0.0 RCVD_IN_MSPIKE_H3 RBL: Good reputation (+3)
[23.251.226.56 listed in wl.mailspike.net]
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 HTML_MESSAGE BODY: HTML included in message
2.0 RATWR8_MESSID Message-ID with excessive dashes and dollars
-0.0 RCVD_IN_MSPIKE_WL Mailspike good senders
0.0 SARE_FROM_SPAM_WORD4 From address suggests this may be spam
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
Subject: {SPAM?} AWS Notification - Subscription Confirmation
You have chosen to subscribe to the topic:
arn:aws:sns:us-east-2:409953609051:Your-McAfee-Identity-Protection-plan-extended-2-years-ahead-490-USD-charged-immediate-safe-browsing-protection-encrypted-storage-files-virus-spyware-protection-access-restored-Contact-to-manage-subscription-call-8562099547
To confirm this subscription, click or visit the link below (If this was in error no action is necessary):
Confirm subscription
Please do not reply directly to this email. If you wish to remove yourself from receiving all future SNS subscription confirmation requests please send an email to sns-opt-out