Greetings spam from Microsoft Outlook Part 2
Posted by Dave Yadallee on
Content analysis details: (5.0 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[52.101.52.134 listed in dnsbl.ahbl.org]
[52.101.52.134 listed in dnsbl.ahbl.org]
[52.101.52.134 listed in dnsbl.ahbl.org]
[52.101.52.134 listed in dnsbl.ahbl.org]
[2603:10b6:406:8f:0:0:0:10 listed in]
[dnsbl.ahbl.org]
[2603:10b6:406:8f:0:0:0:10 listed in]
[dnsbl.ahbl.org]
[2603:10b6:406:8f:0:0:0:10 listed in]
[dnsbl.ahbl.org]
[2603:10b6:406:8f:0:0:0:10 listed in]
[dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[52.101.52.134 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[52.101.52.134 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[52.101.52.134 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[52.101.52.134 listed in dnsbl.ahbl.org]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[2603:10b6:406:8f:0:0:0:10 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:406:8f:0:0:0:10 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:406:8f:0:0:0:10 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:406:8f:0:0:0:10 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:406:8f:0:0:0:10 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:406:8f:0:0:0:10 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:406:8f:0:0:0:10 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:406:8f:0:0:0:10 listed in]
[will-spam-for-food.eu.org]
[52.101.52.134 listed in will-spam-for-food.eu.org]
[52.101.52.134 listed in will-spam-for-food.eu.org]
[52.101.52.134 listed in will-spam-for-food.eu.org]
[52.101.52.134 listed in will-spam-for-food.eu.org]
[52.101.52.134 listed in will-spam-for-food.eu.org]
[52.101.52.134 listed in will-spam-for-food.eu.org]
[52.101.52.134 listed in will-spam-for-food.eu.org]
[52.101.52.134 listed in will-spam-for-food.eu.org]
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[52.101.52.134 listed in list.dnswl.org]
-3.0 RCVD_IN_RP_CERTIFIED RBL: Sender in ReturnPath Certified - Contact
cert-sa@returnpath.net
[Excessive Number of Queries |]
-2.0 RCVD_IN_RP_SAFE RBL: Sender in ReturnPath Safe - Contact
safe-sa@returnpath.net
[Excessive Number of Queries |]
-0.0 SPF_PASS SPF: sender matches SPF record
-0.0 SPF_HELO_PASS SPF: HELO matches SPF record
0.2 MR_NOT_ATTRIBUTED_IP Beta rule: an non-attributed IPv4 found in
headers
0.2 FREEMAIL_REPLYTO_END_DIGIT Reply-To freemail username ends in digit
[fentonnikki212(at)gmail.com]
1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,
https://senderscore.org/blacklistlookup/
[52.101.52.134 listed in bl.score.senderscore.com]
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[52.101.52.134 listed in wl.mailspike.net]
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
1.0 FREEMAIL_REPLYTO Reply-To/From or Reply-To/body contain different
freemails
2.5 FREEMAIL_FORGED_REPLYTO Freemail in Reply-To, but not From
Subject: {SPAM?} =?iso-8859-2?Q?RE:_***>>>Gr=EC=ECting=B9?=
--_000_BN7PR08MB4065C6DFDB99346B1CDAE9E9DA012BN7PR08MB4065namp_
Content-Type: text/plain; charset="iso-8859-2"
Content-Transfer-Encoding: quoted-printable
From: Jorge Riera
Sent: Wednesday, May 20, 2026 11:49 AM
To: 'fentonnikki212@gmail.com'
Subject: ***>>>Gr=EC=ECting=B9
I h=E1v=E9 a busin=E9ss propos=E1l with =FDo=F9r l=E1st n=E1m=E9:
--_000_BN7PR08MB4065C6DFDB99346B1CDAE9E9DA012BN7PR08MB4065namp_
Content-Type: text/html; charset="iso-8859-2"
Content-Transfer-Encoding: quoted-printable
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
2">
break-word">
0in 0in">
pts rule name description
---- ---------------------- --------------------------------------------------
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[52.101.52.134 listed in dnsbl.ahbl.org]
[52.101.52.134 listed in dnsbl.ahbl.org]
[52.101.52.134 listed in dnsbl.ahbl.org]
[52.101.52.134 listed in dnsbl.ahbl.org]
[2603:10b6:406:8f:0:0:0:10 listed in]
[dnsbl.ahbl.org]
[2603:10b6:406:8f:0:0:0:10 listed in]
[dnsbl.ahbl.org]
[2603:10b6:406:8f:0:0:0:10 listed in]
[dnsbl.ahbl.org]
[2603:10b6:406:8f:0:0:0:10 listed in]
[dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[52.101.52.134 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[52.101.52.134 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[52.101.52.134 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[52.101.52.134 listed in dnsbl.ahbl.org]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[2603:10b6:406:8f:0:0:0:10 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:406:8f:0:0:0:10 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:406:8f:0:0:0:10 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:406:8f:0:0:0:10 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:406:8f:0:0:0:10 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:406:8f:0:0:0:10 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:406:8f:0:0:0:10 listed in]
[will-spam-for-food.eu.org]
[2603:10b6:406:8f:0:0:0:10 listed in]
[will-spam-for-food.eu.org]
[52.101.52.134 listed in will-spam-for-food.eu.org]
[52.101.52.134 listed in will-spam-for-food.eu.org]
[52.101.52.134 listed in will-spam-for-food.eu.org]
[52.101.52.134 listed in will-spam-for-food.eu.org]
[52.101.52.134 listed in will-spam-for-food.eu.org]
[52.101.52.134 listed in will-spam-for-food.eu.org]
[52.101.52.134 listed in will-spam-for-food.eu.org]
[52.101.52.134 listed in will-spam-for-food.eu.org]
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[52.101.52.134 listed in list.dnswl.org]
-3.0 RCVD_IN_RP_CERTIFIED RBL: Sender in ReturnPath Certified - Contact
cert-sa@returnpath.net
[Excessive Number of Queries |
-2.0 RCVD_IN_RP_SAFE RBL: Sender in ReturnPath Safe - Contact
safe-sa@returnpath.net
[Excessive Number of Queries |
-0.0 SPF_PASS SPF: sender matches SPF record
-0.0 SPF_HELO_PASS SPF: HELO matches SPF record
0.2 MR_NOT_ATTRIBUTED_IP Beta rule: an non-attributed IPv4 found in
headers
0.2 FREEMAIL_REPLYTO_END_DIGIT Reply-To freemail username ends in digit
[fentonnikki212(at)gmail.com]
1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,
https://senderscore.org/blacklistlookup/
[52.101.52.134 listed in bl.score.senderscore.com]
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[52.101.52.134 listed in wl.mailspike.net]
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
1.0 FREEMAIL_REPLYTO Reply-To/From or Reply-To/body contain different
freemails
2.5 FREEMAIL_FORGED_REPLYTO Freemail in Reply-To, but not From
Subject: {SPAM?} =?iso-8859-2?Q?RE:_***>>>Gr=EC=ECting=B9?=
--_000_BN7PR08MB4065C6DFDB99346B1CDAE9E9DA012BN7PR08MB4065namp_
Content-Type: text/plain; charset="iso-8859-2"
Content-Transfer-Encoding: quoted-printable
From: Jorge Riera
Sent: Wednesday, May 20, 2026 11:49 AM
To: 'fentonnikki212@gmail.com'
Subject: ***>>>Gr=EC=ECting=B9
I h=E1v=E9 a busin=E9ss propos=E1l with =FDo=F9r l=E1st n=E1m=E9:
--_000_BN7PR08MB4065C6DFDB99346B1CDAE9E9DA012BN7PR08MB4065namp_
Content-Type: text/html; charset="iso-8859-2"
Content-Transfer-Encoding: quoted-printable
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
2">
break-word">
0in 0in">
;Calibri",sans-serif;mso-ligatures:none">From:
=3D"font-size:11.0pt;font-family:"Calibri",sans-serif;mso-ligatur=
es:none"> Jorge Riera
Sent: Wednesday, May 20, 2026 11:49 AM
To: 'fentonnikki212@gmail.com' <fentonnikki212@gmail.com>
Subject: ***>>>Gr=EC=ECting=B9
I h=E1v=E9 a busin=E9ss propos=E1l with =FDo=F9r l=
=E1st n=E1m=E9:
--_000_BN7PR08MB4065C6DFDB99346B1CDAE9E9DA012BN7PR08MB4065namp_--