DHL Phish from Mailgun
Posted by Dave Yadallee on
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Mon, 12 May 2025 09:31:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from)
id 1uEV6W-00000000BQ8-2TpK
for dave@doctor.nl2k.ab.ca;
Mon, 12 May 2025 09:30:08 -0600
Resent-From: The Doctor
Resent-Date: Mon, 12 May 2025 09:30:08 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from m239-4.eu.mailgun.net ([185.250.239.4]:19728)
by doctor.nl2k.ab.ca with utf8esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256
(Exim 4.98.2 (FreeBSD))
(envelope-from)
id 1uEUxj-000000008sW-2oz4
for root@nk.ca;
Mon, 12 May 2025 09:21:11 -0600
DKIM-Signature: a=rsa-sha256; v=1; c=relaxed/relaxed; d=mailgun.glsbetaling.dk; q=dns/txt; s=mta; t=1747063136; x=1747070336;
h=Content-Type: Content-Transfer-Encoding: Message-Id: List-Unsubscribe: Reply-To: To: To: From: From: Subject: Subject: Mime-Version: Date: Sender: Sender;
bh=cC6Hw6hb9ET+/84etHiW2eSfoPvJN02eoGfTs9ANebs=;
b=dJ8M8lzRB4SJxPCz3VZD1EQRFxsi0Oega5mmL2/d0fxKf6ZT9vOW3udDjC0T28GXKHOlf2eVpWZ2FZnJQz11KzNC0P0jRAXqj0D8ufH+NSrhmC4R7j0oNA5+Xhf+k7ou4zEbSbugzeYQ+d8JT2ZswHtd8KZkueR0rQs4mGEnIFc=
X-Mailgun-Sending-Ip: 185.250.239.4
X-Mailgun-Sending-Ip-Pool-Name:
X-Mailgun-Sending-Ip-Pool:
X-Mailgun-Sid: WyIzOGZhNyIsInJvb3RAbmsuY2EiLCIzY2E5YSJd
Received: by 0b07c5e437f2 with HTTP id 68221160065ee5c4295747ef; Mon, 12 May 2025
15:18:56 GMT
Sender: info@mailgun.glsbetaling.dk
Date: Mon, 12 May 2025 15:18:56 +0000
Mime-Version: 1.0
Subject: =?UTF-8?q?Your_DHL_shipment_is_ready_=E2=80=93_Payment_required_for_deliv?=
=?UTF-8?q?ery?=
From: INFO
To: root@nk.ca
Precedence: bulk
Reply-To: support@mailgun.glsbetaling.dk
List-Unsubscribe:
Message-Id: <20250512151856.bba749a7e3eb2efb@mailgun.glsbetaling.dk>
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="utf-8"
X-Spam_score: 11.8
X-Spam_score_int: 118
X-Spam_bar: +++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: DHL Delivery Notification Delivery Notification Dear Customer,
Content analysis details: (11.8 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[185.250.239.4 listed in list.dnswl.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[185.250.239.4 listed in dnsbl.ahbl.org]
[185.250.239.4 listed in dnsbl.ahbl.org]
[185.250.239.4 listed in dnsbl.ahbl.org]
[185.250.239.4 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[185.250.239.4 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[185.250.239.4 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[185.250.239.4 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[185.250.239.4 listed in dnsbl.ahbl.org]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[185.250.239.4 listed in will-spam-for-food.eu.org]
[185.250.239.4 listed in will-spam-for-food.eu.org]
[185.250.239.4 listed in will-spam-for-food.eu.org]
[185.250.239.4 listed in will-spam-for-food.eu.org]
[185.250.239.4 listed in will-spam-for-food.eu.org]
[185.250.239.4 listed in will-spam-for-food.eu.org]
[185.250.239.4 listed in will-spam-for-food.eu.org]
[185.250.239.4 listed in will-spam-for-food.eu.org]
2.5 URIBL_DBL_SPAM Contains a spam URL listed in the DBL blocklist
[URI: glsbetaling.dk]
1.7 URIBL_BLACK Contains an URL listed in the URIBL blacklist
[URI: glsbetaling.dk]
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[185.250.239.4 listed in wl.mailspike.net]
-0.0 SPF_PASS SPF: sender matches SPF record
0.2 MR_NOT_ATTRIBUTED_IP Beta rule: an non-attributed IPv4 found in
headers
0.0 WIKI_IMG URI: Image from wikipedia
0.0 HTML_MESSAGE BODY: HTML included in message
0.7 HTML_IMAGE_ONLY_20 BODY: HTML: images with 1600-2000 bytes of words
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
0.8 SARE_FROM_SPAM_WORD3 I don't know people named this!
Subject: {SPAM?} =?UTF-8?q?Your_DHL_shipment_is_ready_=E2=80=93_Payment_required_for_deliv?=
=?UTF-8?q?ery?=
DHL Delivery Notification
adding: 20px;">
dth: 600px; margin: auto; background-color: #ffffff; border: 1px solid #ddd=
; padding: 20px;">

b3/DHL_Express_logo.svg/2560px-DHL_Express_logo.svg.png" alt=3D"DHL" width=
=3D"160">
Dear Customer,
Your shipment is ready for delivery. Please complete the delivery a=
nd service charges by using the payment link below.
Tracking Number: DHL-INTL-00147896524500
Courier Company: DHL Express
dding: 12px 20px; background-color: #ba0c2f; color: #ffffff; text-decoratio=
n: none; font-weight: bold; border-radius: 4px;">
Complete Payment
Your parcel will be delivered to your address within 24 hours of su=
ccessful payment.
Thank you for choosing DHL.
op: 20px;">
=C2=A9 2025 DHL International GmbH. All rights reserved.
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Mon, 12 May 2025 09:31:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from
id 1uEV6W-00000000BQ8-2TpK
for dave@doctor.nl2k.ab.ca;
Mon, 12 May 2025 09:30:08 -0600
Resent-From: The Doctor
Resent-Date: Mon, 12 May 2025 09:30:08 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from m239-4.eu.mailgun.net ([185.250.239.4]:19728)
by doctor.nl2k.ab.ca with utf8esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256
(Exim 4.98.2 (FreeBSD))
(envelope-from
id 1uEUxj-000000008sW-2oz4
for root@nk.ca;
Mon, 12 May 2025 09:21:11 -0600
DKIM-Signature: a=rsa-sha256; v=1; c=relaxed/relaxed; d=mailgun.glsbetaling.dk; q=dns/txt; s=mta; t=1747063136; x=1747070336;
h=Content-Type: Content-Transfer-Encoding: Message-Id: List-Unsubscribe: Reply-To: To: To: From: From: Subject: Subject: Mime-Version: Date: Sender: Sender;
bh=cC6Hw6hb9ET+/84etHiW2eSfoPvJN02eoGfTs9ANebs=;
b=dJ8M8lzRB4SJxPCz3VZD1EQRFxsi0Oega5mmL2/d0fxKf6ZT9vOW3udDjC0T28GXKHOlf2eVpWZ2FZnJQz11KzNC0P0jRAXqj0D8ufH+NSrhmC4R7j0oNA5+Xhf+k7ou4zEbSbugzeYQ+d8JT2ZswHtd8KZkueR0rQs4mGEnIFc=
X-Mailgun-Sending-Ip: 185.250.239.4
X-Mailgun-Sending-Ip-Pool-Name:
X-Mailgun-Sending-Ip-Pool:
X-Mailgun-Sid: WyIzOGZhNyIsInJvb3RAbmsuY2EiLCIzY2E5YSJd
Received: by 0b07c5e437f2 with HTTP id 68221160065ee5c4295747ef; Mon, 12 May 2025
15:18:56 GMT
Sender: info@mailgun.glsbetaling.dk
Date: Mon, 12 May 2025 15:18:56 +0000
Mime-Version: 1.0
Subject: =?UTF-8?q?Your_DHL_shipment_is_ready_=E2=80=93_Payment_required_for_deliv?=
=?UTF-8?q?ery?=
From: INFO
To: root@nk.ca
Precedence: bulk
Reply-To: support@mailgun.glsbetaling.dk
List-Unsubscribe:
Message-Id: <20250512151856.bba749a7e3eb2efb@mailgun.glsbetaling.dk>
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html; charset="utf-8"
X-Spam_score: 11.8
X-Spam_score_int: 118
X-Spam_bar: +++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: DHL Delivery Notification Delivery Notification Dear Customer,
Content analysis details: (11.8 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[185.250.239.4 listed in list.dnswl.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[185.250.239.4 listed in dnsbl.ahbl.org]
[185.250.239.4 listed in dnsbl.ahbl.org]
[185.250.239.4 listed in dnsbl.ahbl.org]
[185.250.239.4 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[185.250.239.4 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[185.250.239.4 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[185.250.239.4 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[185.250.239.4 listed in dnsbl.ahbl.org]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[185.250.239.4 listed in will-spam-for-food.eu.org]
[185.250.239.4 listed in will-spam-for-food.eu.org]
[185.250.239.4 listed in will-spam-for-food.eu.org]
[185.250.239.4 listed in will-spam-for-food.eu.org]
[185.250.239.4 listed in will-spam-for-food.eu.org]
[185.250.239.4 listed in will-spam-for-food.eu.org]
[185.250.239.4 listed in will-spam-for-food.eu.org]
[185.250.239.4 listed in will-spam-for-food.eu.org]
2.5 URIBL_DBL_SPAM Contains a spam URL listed in the DBL blocklist
[URI: glsbetaling.dk]
1.7 URIBL_BLACK Contains an URL listed in the URIBL blacklist
[URI: glsbetaling.dk]
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[185.250.239.4 listed in wl.mailspike.net]
-0.0 SPF_PASS SPF: sender matches SPF record
0.2 MR_NOT_ATTRIBUTED_IP Beta rule: an non-attributed IPv4 found in
headers
0.0 WIKI_IMG URI: Image from wikipedia
0.0 HTML_MESSAGE BODY: HTML included in message
0.7 HTML_IMAGE_ONLY_20 BODY: HTML: images with 1600-2000 bytes of words
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
0.8 SARE_FROM_SPAM_WORD3 I don't know people named this!
Subject: {SPAM?} =?UTF-8?q?Your_DHL_shipment_is_ready_=E2=80=93_Payment_required_for_deliv?=
=?UTF-8?q?ery?=
adding: 20px;">
dth: 600px; margin: auto; background-color: #ffffff; border: 1px solid #ddd=
; padding: 20px;">
b3/DHL_Express_logo.svg/2560px-DHL_Express_logo.svg.png" alt=3D"DHL" width=
=3D"160">
Delivery Notification
Dear Customer,
Your shipment is ready for delivery. Please complete the delivery a=
nd service charges by using the payment link below.
Tracking Number: DHL-INTL-00147896524500
Courier Company: DHL Express
dding: 12px 20px; background-color: #ba0c2f; color: #ffffff; text-decoratio=
n: none; font-weight: bold; border-radius: 4px;">
Complete Payment
Your parcel will be delivered to your address within 24 hours of su=
ccessful payment.
Thank you for choosing DHL.
op: 20px;">
=C2=A9 2025 DHL International GmbH. All rights reserved.