Sephora Beauty Phish from Google Gmail
Posted by Dave Yadallee onEnvelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Mon, 17 Nov 2025 22:00:00 -0700
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from
id 1vLDo9-000000001F7-3VWS
for dave@doctor.nl2k.ab.ca;
Mon, 17 Nov 2025 21:59:13 -0700
Resent-From: The Doctor
Resent-Date: Mon, 17 Nov 2025 21:59:13 -0700
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mail-ua1-f69.google.com ([209.85.222.69]:56476)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256
(Exim 4.98.2 (FreeBSD))
(envelope-from
id 1vLAk6-00000000MNW-1hSZ
for doctor@netknow.ca;
Mon, 17 Nov 2025 18:42:57 -0700
Received: by mail-ua1-f69.google.com with SMTP id a1e0cc1a2514c-9351ea95712so10050955241.0
for
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=firebaseapp.com; s=20230601; t=1763430117; x=1764034917; darn=netknow.ca;
h=to:from:subject:date:message-id:mime-version:from:to:cc:subject
:date:message-id:reply-to;
bh=k+rpIzirZUEJ6qRUvKq1XE6CgympDXCcnKjn9tMbVg0=;
b=dG1UiN9tvb+Pi1JbjTTxCR4jatO313lA2LLWU+aXfKSUQ0HrVqcvjo9zUfj3Laj3WE
hKQAEb4amq4O/E+MZypSV4JzsrJY4mUg69rceOV93ZlzeTvh8aPovTEvS1BYTt27au/f
+0fRzP3jnUWLMuzCftIwiNNXxHtT9xcuag4HMOd+AvVcGEiuPmSKXvTgZGrjAEj5/Xfd
1D2YXMG4JoRV+nyNPK3IupJAn0th6Z+8NekHJAgpN7d8ICoObNTgVzNHAQLoNiNT6otk
fejlHDCU2ovt8WA2Xt0lLpBOgKJgVk5crfH9jO2ZLh97TC9n9EM8nMZcvIUV6MoWhXNb
xBSQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20230601; t=1763430117; x=1764034917;
h=to:from:subject:date:message-id:mime-version:x-gm-message-state
:from:to:cc:subject:date:message-id:reply-to;
bh=k+rpIzirZUEJ6qRUvKq1XE6CgympDXCcnKjn9tMbVg0=;
b=lrWeRN9dQO1LrASVL+Gcs3KvohlPLj6MZznb0RTXkb223z0jcPT0SNd+ETKOnW5bks
Dfl4TIaGs1KkBzhA/NMcq2qOJ4DrBLt3SXiF8Rt/BdWdDI0ORtXgMA3HTONefqDuY2Gq
U164aqqmd7ETGB33PeuJK6HQoaTcgK4nGiFzcnBJZYTRec2GN8TdAvKo8eqCM2JzwO/g
Eb4DASREKfit6UTKEdBO/dznIIzDuuIq8Ieh3wYc/luZ+gCXvd+NEv+kXvZmSZnEkNZ7
4flLUTycfTv40639uncNiyPgl9UKJzGgt3eMpOCK3UyMKFJmKZT/9feFWh1GazgUNYvT
1Jlg==
X-Gm-Message-State: AOJu0YyoyGpcRjxbQCtx0s3A2v7pFxlD1BXHnuf+rHYiIHLHVyVWjVOz
AtAZ45zjjeNVwyXhUSavactHWOB3hBdkU6+OAPmHwtcf+Da5oiR7MAU17E6E/1VLWlcpAOplA12
72erzggQ2fg==
X-Google-Smtp-Source: AGHT+IFbzNllobb6euieFUHpaFAbJWNtHJC0uv/C+ogUVBEfFw8OV0adBBHNorjtOtSOoTiPaE44GbqmsVpcrjw=
MIME-Version: 1.0
X-Received: by 2002:a05:6102:3707:b0:5db:f15a:5394 with SMTP id
ada2fe7eead31-5dfc54aba0bmr5328690137.2.1763430117356; Mon, 17 Nov 2025
17:41:57 -0800 (PST)
Message-ID: <000000000000bb36b50643d4917d@google.com>
Date: Tue, 18 Nov 2025 01:41:57 +0000
Subject: =?UTF-8?Q?Your_Free_Sephora_Advent_Calendar_Awaits_=2D_Secure_Yo?=
=?UTF-8?Q?ur_Holiday_Glam_=F0=9F=8E=81?=
From: =?UTF-8?Q?Sephora_Beauty_Rewards_=E2=9C=A8?=
To: doctor@netknow.ca
Content-Type: multipart/alternative; boundary="000000000000bb36aa0643d4917a"
X-Spam_score: 9.2
X-Spam_score_int: 92
X-Spam_bar: +++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Don't Miss This Holiday Treat - Your Sephora Advent Calendar
Is Ready 🎠View in browser Don't want to get emails like this? unsubscribe
from our emails
Content analysis details: (9.2 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[209.85.222.69 listed in will-spam-for-food.eu.org]
[209.85.222.69 listed in will-spam-for-food.eu.org]
[209.85.222.69 listed in will-spam-for-food.eu.org]
[209.85.222.69 listed in will-spam-for-food.eu.org]
[209.85.222.69 listed in will-spam-for-food.eu.org]
[209.85.222.69 listed in will-spam-for-food.eu.org]
[209.85.222.69 listed in will-spam-for-food.eu.org]
[209.85.222.69 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[209.85.222.69 listed in dnsbl.ahbl.org]
[209.85.222.69 listed in dnsbl.ahbl.org]
[209.85.222.69 listed in dnsbl.ahbl.org]
[209.85.222.69 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[209.85.222.69 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[209.85.222.69 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[209.85.222.69 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[209.85.222.69 listed in dnsbl.ahbl.org]
1.7 URIBL_BLACK Contains an URL listed in the URIBL blacklist
[URI: eblinks.cc]
[URI: eblink7.com]
0.0 URIBL_PH_SURBL Contains an URL listed in the PH SURBL blocklist
[URI: eblink7.com]
2.5 URIBL_DBL_SPAM Contains a spam URL listed in the DBL blocklist
[URI: eblink7.com]
-2.0 RCVD_IN_RP_SAFE RBL: Sender in ReturnPath Safe - Contact
safe-sa@returnpath.net
[Excessive Number of Queries |
0.0 RCVD_IN_VALIDITY_SAFE_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to
Validity was blocked. See
https://knowledge.validity.com/hc/en-us/articles/20961730681243
for more information.
[209.85.222.69 listed in sa-accredit.habeas.com]
-3.0 RCVD_IN_RP_CERTIFIED RBL: Sender in ReturnPath Certified - Contact
cert-sa@returnpath.net
[Excessive Number of Queries |
0.0 RCVD_IN_VALIDITY_CERTIFIED_BLOCKED RBL: ADMINISTRATOR NOTICE: The
query to Validity was blocked. See
https://knowledge.validity.com/hc/en-us/articles/20961730681243
for more information.
[209.85.222.69 listed in sa-trusted.bondedsender.org]
1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,
https://senderscore.org/blacklistlookup/
[209.85.222.69 listed in bl.score.senderscore.com]
0.0 RCVD_IN_VALIDITY_RPBL_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to
Validity was blocked. See
https://knowledge.validity.com/hc/en-us/articles/20961730681243
for more information.
[209.85.222.69 listed in bl.score.senderscore.com]
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[209.85.222.69 listed in wl.mailspike.net]
-0.0 SPF_PASS SPF: sender matches SPF record
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[209.85.222.69 listed in list.dnswl.org]
1.3 URI_HEX URI: URI hostname has long hexadecimal sequence
0.8 HTML_IMAGE_RATIO_02 BODY: HTML has a low ratio of text to image area
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.8 SARE_FROM_SPAM_WORD3 I don't know people named this!
1.0 VOWEL_URI_5 URI hostname with 5 consecutive vowels
Subject: {SPAM?} =?UTF-8?Q?Your_Free_Sephora_Advent_Calendar_Awaits_=2D_Secure_Yo?=
=?UTF-8?Q?ur_Holiday_Glam_=F0=9F=8E=81?=
--000000000000bb36aa0643d4917a
Content-Type: text/plain; charset="UTF-8"; format=flowed; delsp=yes
Content-Transfer-Encoding: base64
RG9uJ3QgTWlzcyBUaGlzIEhvbGlkYXkgVHJlYXQgLSBZb3VyIFNlcGhvcmEgQWR2ZW50IENhbGVu
ZGFyIElzIFJlYWR5IPCfjoENCg0KDQoNClZpZXcgaW4gYnJvd3Nlcg0KDQoNCg0KDQoNCg0KRG9u
J3Qgd2FudCB0byBnZXQgZW1haWxzIGxpa2UgdGhpcz8gdW5zdWJzY3JpYmUgZnJvbSBvdXIgZW1h
aWxzDQoNCg0KDQoNCg==
--000000000000bb36aa0643d4917a
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
ft-com:vml" xmlns:o=3D"urn:schemas-microsoft-com:office:office">
=20
=20
=20
=20
/>=20
1" />=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
rmal; background-color: #FFFFFF;" class=3D" eb-drag-and-drop-builder">=20
ffffff; line-height: 1px;max-height: 0px; max-width: 0px; opacity: 0; overf=
low: hidden;mso-hide: all; visibility: hidden;">
Don=E2=80=99t Miss This Holiday Treat - Your Sephora Advent Calendar Is Rea=
dy =F0=9F=8E=81
role=3D"presentation" style=3D"width:100%;">=20
=20
=20
=3D"0" role=3D"presentation" style=3D"width:100%;">=20
=20
;text-align:center;">=20
=20
-eb_f251c518-9c1c-4541-8a45-d7e3cf739e50" style=3D"background:#ffffff;backg=
round-color:#ffffff;margin:0px auto;max-width:700px;">=20
cing=3D"0" role=3D"presentation" style=3D"background:#ffffff;background-col=
or:#ffffff;width:100%;">=20
10px 10px;text-align:center;">=20
=20
column-eb_dfb82517-ceba-4b35-baaa-fcee3b72e3ab" style=3D"font-size:0px;text=
-align:left;direction:ltr;display:inline-block;vertical-align:middle;width:=
100%;">=20
ole=3D"presentation" width=3D"100%">=20
0px ;">=20
0" role=3D"presentation" style=3D"" width=3D"100%">=20
4b-4883-46a0-ac69-0a16e9494cf3 mj-text" style=3D"background:transparent;fon=
t-size:0px;padding:10px 15px 10px 15px;word-break:break-word;">=20
serif;font-size:13px;font-weight:normal;line-height:1.6;text-align:left;col=
or:#000000;">=20
y;margin: 0px; word-break: break-word; text-align: center;">
mso-line-height-rule:exactly;color: #52049b;">
underline; mso-line-height-rule: exactly; color: #52049b;" href=3D"https://=
omniwatchsmartwatch18.eblink7.com/openurl?lid=3D6234927436398592&nid=3D5730=
783235670016&" data-eblinkid=3D"6234927436398592">View in browser
>=20
=20
2734-61d7-43c5-ae28-c371c93c6205 eb-image-full-width max-width-100 eb-image=
" style=3D"background:transparent;font-size:0px;padding:0px 0px 0px 0px;wor=
d-break:break-word;">=20
=3D"0" role=3D"presentation" style=3D"min-width:100%;max-width:100%;width:6=
80px;border-collapse:collapse;border-spacing:0px;width:100%;" class=3D"mj-f=
ull-width-mobile">=20
th-mobile">
d=3D6234927436398592&nid=3D5730783235670016&" target=3D"_blank" style=3D"co=
lor: #510094; text-decoration: underline;" data-eblinkid=3D"623492743639859=
2">
939469312/Screenshot_2025_11_18_at_02_17_52_Dunkin_Donuts.png" style=3D"bor=
der:0px solid #3498DB;border-radius:0px;display:block;outline:none;text-dec=
oration:none;height:auto;min-width:100%;width:100%;max-width:100%;font-size=
:13px;max-width:100%;box-sizing: border-box;width:100%;" width=3D"680" heig=
ht=3D"auto" /> =20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
role=3D"presentation" style=3D"width:100%;">=20
=20
=20
=3D"0" role=3D"presentation" style=3D"width:100%;">=20
=20
;text-align:center;">=20
=20
ection mjml-section-eb_6a796e91-43cb-458c-a7db-ef914004ce2b" style=3D"backg=
round:transparent;background-color:transparent;margin:0px auto;max-width:70=
0px;">=20
cing=3D"0" role=3D"presentation" style=3D"background:transparent;background=
-color:transparent;width:100%;">=20
0px 10px;text-align:center;">=20
=20
column-undefined" style=3D"font-size:0px;text-align:left;direction:ltr;disp=
lay:inline-block;vertical-align:top;width:100%;">=20
ole=3D"presentation" width=3D"100%">=20
x ;">=20
0" role=3D"presentation" style=3D"" width=3D"100%">=20
f7-defd-4b40-b01e-63a4dd3e02dd mj-text" style=3D"background:transparent;fon=
t-size:0px;padding:5px 15px 5px 15px;word-break:break-word;">=20
serif;font-size:13px;font-weight:normal;line-height:1.6;text-align:left;col=
or:#000000;">=20
y;margin: 0px; word-break: break-word; line-height: 1.6; text-align: center=
;">
2px;">Don't want to get emails like this?
le:exactly;color: #7e8c8d;">
ine-height-rule: exactly; text-decoration: none; color: #7e8c8d;" href=3D"h=
ttp://#" target=3D"_blank" rel=3D"noopener">unsubscribe from our=
emails=20
=20
56-1328-40f8-87ea-a6917b05efe4 mj-text eb-address-container" style=3D"backg=
round:transparent;font-size:0px;padding:5px 15px 5px 15px;word-break:break-=
word;">=20
serif;font-size:13px;font-weight:normal;line-height:1.6;text-align:left;col=
or:#000000;"> =20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
=20
--000000000000bb36aa0643d4917a--
