CRA PHish
Posted by Dave Yadallee on
X-Mozilla-Status: 0001
X-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Sun, 29 Mar 2026 05:19:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from)
id 1w6o9j-00000000IRs-1C3P
for dave@doctor.nl2k.ab.ca;
Sun, 29 Mar 2026 05:18:11 -0600
Resent-From: The Doctor
Resent-Date: Sun, 29 Mar 2026 05:18:11 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from smtp2-3261.email-labs.net ([147.78.234.25]:55128)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384
(Exim 4.98.2 (FreeBSD))
(envelope-from)
id 1w6k4r-000000006ul-3eps
for sales@nk.ca;
Sun, 29 Mar 2026 00:57:01 -0600
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ato.ink; s=default;
t=1774767327; bh=pGzJUCAXbfOH9TFj5laLMoEW/0IBSNwEa30UxB9d3Dg=;
h=From:To:Date:Subject:Feedback-ID;
b=QWvbyDUE4qIjVNibKqXg1Z3LKUC4So6PH3ffH4IgEOGdG/TBj2Jy2PLUIabCJi8zE
MSXCahMYOdLfS6CIdDy5JaD8FsSG80wtyyZOSuWxWZVIpmJUhehw2ExKZoJUTFjAmx
72y9vvmnnb+AYlpCSx0OiVws/jMcs05vMZB6duwp+PKv+y/MScItg6NUwbbchMNnuL
z8OTscCEKAnjOn6QfCvfGEyMd3hfTdzOMWyWh/teZ7UC/khN4t6cl/d0WgbXFRXuEz
31FBhx3g8thX83kJifsytmiVT+B0KVu/6qyp7UVllBOiPzMyQYckVDOaxaFU2l6Dwr
rUfOe3RCZqeqQ==
Authentication-Results: smtp-12; auth=none
MIME-Version: 1.0
From: "Canada Revenue Agency (CRA)"
To: sales@nk.ca
Date: 29 Mar 2026 08:55:27 +0200
Subject: Canada Revenue Agency (CRA) sent you new mail online
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: base64
Feedback-ID: :tracking.ato.ink:1.ato.smtp:default
X-Sid: info@ato.ink
X-Return-Path:
Message-Id: <4fk4rv4X3XzHwvyLW@smtp2-3261.email-labs.net>
X-Spam_score: 14.0
X-Spam_score_int: 140
X-Spam_bar: ++++++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: English version ** La version française suit ** sales@nk.ca
The Canada Revenue Agency (CRA) sent you new mail online called:
Content analysis details: (14.0 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[147.78.234.25 listed in dnsbl.ahbl.org]
[147.78.234.25 listed in dnsbl.ahbl.org]
[147.78.234.25 listed in dnsbl.ahbl.org]
[147.78.234.25 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[147.78.234.25 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[147.78.234.25 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[147.78.234.25 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[147.78.234.25 listed in dnsbl.ahbl.org]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[147.78.234.25 listed in will-spam-for-food.eu.org]
[147.78.234.25 listed in will-spam-for-food.eu.org]
[147.78.234.25 listed in will-spam-for-food.eu.org]
[147.78.234.25 listed in will-spam-for-food.eu.org]
[147.78.234.25 listed in will-spam-for-food.eu.org]
[147.78.234.25 listed in will-spam-for-food.eu.org]
[147.78.234.25 listed in will-spam-for-food.eu.org]
[147.78.234.25 listed in will-spam-for-food.eu.org]
1.9 URIBL_ABUSE_SURBL Contains an URL listed in the ABUSE SURBL blocklist
[URI: casaki.ru]
1.9 URIBL_JP_SURBL Contains an URL listed in the JP SURBL blocklist
[URI: casaki.ru]
-0.0 SPF_PASS SPF: sender matches SPF record
0.0 RCVD_IN_VALIDITY_CERTIFIED_BLOCKED RBL: ADMINISTRATOR NOTICE: The
query to Validity was blocked. See
https://knowledge.validity.com/hc/en-us/articles/20961730681243
for more information.
[147.78.234.25 listed in sa-trusted.bondedsender.org]
-3.0 RCVD_IN_RP_CERTIFIED RBL: Sender in ReturnPath Certified - Contact
cert-sa@returnpath.net
[Excessive Number of Queries |]
2.5 URIBL_DBL_SPAM Contains a spam URL listed in the DBL blocklist
[URI: casaki.ru]
-2.0 RCVD_IN_RP_SAFE RBL: Sender in ReturnPath Safe - Contact
safe-sa@returnpath.net
[Excessive Number of Queries |]
0.0 RCVD_IN_VALIDITY_SAFE_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to
Validity was blocked. See
https://knowledge.validity.com/hc/en-us/articles/20961730681243
for more information.
[147.78.234.25 listed in sa-accredit.habeas.com]
0.0 HEADER_FROM_DIFFERENT_DOMAINS From and EnvelopeFrom 2nd level mail
domains are different
-0.0 T_RP_MATCHES_RCVD Envelope sender domain matches handover relay
domain
1.7 URIBL_BLACK Contains an URL listed in the URIBL blacklist
[URI: casaki.ru]
0.0 RCVD_IN_VALIDITY_RPBL_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to
Validity was blocked. See
https://knowledge.validity.com/hc/en-us/articles/20961730681243
for more information.
[147.78.234.25 listed in bl.score.senderscore.com]
1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,
https://senderscore.org/blacklistlookup/
[147.78.234.25 listed in bl.score.senderscore.com]
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 HTML_MESSAGE BODY: HTML included in message
0.8 SARE_FROM_SPAM_WORD3 I don't know people named this!
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
2.0 MIXED_HREF_CASE Has href in mixed case
0.6 HTML_MIME_NO_HTML_TAG HTML-only message, but there is no HTML tag
0.1 URIBL_SBL_A Contains URL's A record listed in the SBL blocklist
[URI: b.dnspod.com/43.161.3.75]
[URI: a.dnspod.com/43.134.249.74]
[URI: c.dnspod.com/43.134.249.75]
[URI: b.dnspod.com/220.196.136.75]
[URI: b.dnspod.com/163.177.5.79]
[URI: a.dnspod.com/117.135.128.175]
[URI: a.dnspod.com/101.227.168.75]
[URI: c.dnspod.com/125.94.59.175]
[URI: c.dnspod.com/112.80.181.175]
[URI: a.dnspod.com/43.130.172.75]
Subject: {SPAM?} Canada Revenue Agency (CRA) sent you new mail online
English version ** La version française suit **
sales@nk.ca
The Canada Revenue Agency (CRA) sent you new mail online called:
Notice of assessment
This mail may require your attention.
View attachment in PDF
If you have My Account, sign-in and click on "Mail" to read your mail.
If you signed up to receive mail online but don't have My Account, go to the CRA web page to register.
This is an automated email message. Please do not reply.
Version française ** The English version precedes **
sales@nk.ca
L'Agence du revenu du Canada (ARC) vous a envoyé du nouveau courrier en ligne intitulé :
Avis de cotisation
Ce courrier peut nécessiter votre attention.
Voir la pièce jointe en PDF
Si vous êtes inscrit à Mon dossier, ouvrez une session et cliquez sur « Courrier » pour lire votre courrier.
Si vous vous êtes inscrit pour recevoir votre courrier en ligne, mais n'êtes pas inscrit à Mon dossier, allez à la page Web de l'ARC pour vous y inscrire.
Ceci est un message électronique automatisé. Veuillez ne pas y répondre.
X-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Sun, 29 Mar 2026 05:19:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from
id 1w6o9j-00000000IRs-1C3P
for dave@doctor.nl2k.ab.ca;
Sun, 29 Mar 2026 05:18:11 -0600
Resent-From: The Doctor
Resent-Date: Sun, 29 Mar 2026 05:18:11 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from smtp2-3261.email-labs.net ([147.78.234.25]:55128)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384
(Exim 4.98.2 (FreeBSD))
(envelope-from
id 1w6k4r-000000006ul-3eps
for sales@nk.ca;
Sun, 29 Mar 2026 00:57:01 -0600
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=ato.ink; s=default;
t=1774767327; bh=pGzJUCAXbfOH9TFj5laLMoEW/0IBSNwEa30UxB9d3Dg=;
h=From:To:Date:Subject:Feedback-ID;
b=QWvbyDUE4qIjVNibKqXg1Z3LKUC4So6PH3ffH4IgEOGdG/TBj2Jy2PLUIabCJi8zE
MSXCahMYOdLfS6CIdDy5JaD8FsSG80wtyyZOSuWxWZVIpmJUhehw2ExKZoJUTFjAmx
72y9vvmnnb+AYlpCSx0OiVws/jMcs05vMZB6duwp+PKv+y/MScItg6NUwbbchMNnuL
z8OTscCEKAnjOn6QfCvfGEyMd3hfTdzOMWyWh/teZ7UC/khN4t6cl/d0WgbXFRXuEz
31FBhx3g8thX83kJifsytmiVT+B0KVu/6qyp7UVllBOiPzMyQYckVDOaxaFU2l6Dwr
rUfOe3RCZqeqQ==
Authentication-Results: smtp-12; auth=none
MIME-Version: 1.0
From: "Canada Revenue Agency (CRA)"
To: sales@nk.ca
Date: 29 Mar 2026 08:55:27 +0200
Subject: Canada Revenue Agency (CRA) sent you new mail online
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: base64
Feedback-ID: :tracking.ato.ink:1.ato.smtp:default
X-Sid: info@ato.ink
X-Return-Path:
Message-Id: <4fk4rv4X3XzHwvyLW@smtp2-3261.email-labs.net>
X-Spam_score: 14.0
X-Spam_score_int: 140
X-Spam_bar: ++++++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: English version ** La version française suit ** sales@nk.ca
The Canada Revenue Agency (CRA) sent you new mail online called:
Content analysis details: (14.0 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[147.78.234.25 listed in dnsbl.ahbl.org]
[147.78.234.25 listed in dnsbl.ahbl.org]
[147.78.234.25 listed in dnsbl.ahbl.org]
[147.78.234.25 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[147.78.234.25 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[147.78.234.25 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[147.78.234.25 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[147.78.234.25 listed in dnsbl.ahbl.org]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[147.78.234.25 listed in will-spam-for-food.eu.org]
[147.78.234.25 listed in will-spam-for-food.eu.org]
[147.78.234.25 listed in will-spam-for-food.eu.org]
[147.78.234.25 listed in will-spam-for-food.eu.org]
[147.78.234.25 listed in will-spam-for-food.eu.org]
[147.78.234.25 listed in will-spam-for-food.eu.org]
[147.78.234.25 listed in will-spam-for-food.eu.org]
[147.78.234.25 listed in will-spam-for-food.eu.org]
1.9 URIBL_ABUSE_SURBL Contains an URL listed in the ABUSE SURBL blocklist
[URI: casaki.ru]
1.9 URIBL_JP_SURBL Contains an URL listed in the JP SURBL blocklist
[URI: casaki.ru]
-0.0 SPF_PASS SPF: sender matches SPF record
0.0 RCVD_IN_VALIDITY_CERTIFIED_BLOCKED RBL: ADMINISTRATOR NOTICE: The
query to Validity was blocked. See
https://knowledge.validity.com/hc/en-us/articles/20961730681243
for more information.
[147.78.234.25 listed in sa-trusted.bondedsender.org]
-3.0 RCVD_IN_RP_CERTIFIED RBL: Sender in ReturnPath Certified - Contact
cert-sa@returnpath.net
[Excessive Number of Queries |
2.5 URIBL_DBL_SPAM Contains a spam URL listed in the DBL blocklist
[URI: casaki.ru]
-2.0 RCVD_IN_RP_SAFE RBL: Sender in ReturnPath Safe - Contact
safe-sa@returnpath.net
[Excessive Number of Queries |
0.0 RCVD_IN_VALIDITY_SAFE_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to
Validity was blocked. See
https://knowledge.validity.com/hc/en-us/articles/20961730681243
for more information.
[147.78.234.25 listed in sa-accredit.habeas.com]
0.0 HEADER_FROM_DIFFERENT_DOMAINS From and EnvelopeFrom 2nd level mail
domains are different
-0.0 T_RP_MATCHES_RCVD Envelope sender domain matches handover relay
domain
1.7 URIBL_BLACK Contains an URL listed in the URIBL blacklist
[URI: casaki.ru]
0.0 RCVD_IN_VALIDITY_RPBL_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to
Validity was blocked. See
https://knowledge.validity.com/hc/en-us/articles/20961730681243
for more information.
[147.78.234.25 listed in bl.score.senderscore.com]
1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,
https://senderscore.org/blacklistlookup/
[147.78.234.25 listed in bl.score.senderscore.com]
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 HTML_MESSAGE BODY: HTML included in message
0.8 SARE_FROM_SPAM_WORD3 I don't know people named this!
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
2.0 MIXED_HREF_CASE Has href in mixed case
0.6 HTML_MIME_NO_HTML_TAG HTML-only message, but there is no HTML tag
0.1 URIBL_SBL_A Contains URL's A record listed in the SBL blocklist
[URI: b.dnspod.com/43.161.3.75]
[URI: a.dnspod.com/43.134.249.74]
[URI: c.dnspod.com/43.134.249.75]
[URI: b.dnspod.com/220.196.136.75]
[URI: b.dnspod.com/163.177.5.79]
[URI: a.dnspod.com/117.135.128.175]
[URI: a.dnspod.com/101.227.168.75]
[URI: c.dnspod.com/125.94.59.175]
[URI: c.dnspod.com/112.80.181.175]
[URI: a.dnspod.com/43.130.172.75]
Subject: {SPAM?} Canada Revenue Agency (CRA) sent you new mail online
English version ** La version française suit **
sales@nk.ca
The Canada Revenue Agency (CRA) sent you new mail online called:
Notice of assessment
This mail may require your attention.
View attachment in PDF
If you have My Account, sign-in and click on "Mail" to read your mail.
If you signed up to receive mail online but don't have My Account, go to the CRA web page to register.
This is an automated email message. Please do not reply.
Version française ** The English version precedes **
sales@nk.ca
L'Agence du revenu du Canada (ARC) vous a envoyé du nouveau courrier en ligne intitulé :
Avis de cotisation
Ce courrier peut nécessiter votre attention.
Voir la pièce jointe en PDF
Si vous êtes inscrit à Mon dossier, ouvrez une session et cliquez sur « Courrier » pour lire votre courrier.
Si vous vous êtes inscrit pour recevoir votre courrier en ligne, mais n'êtes pas inscrit à Mon dossier, allez à la page Web de l'ARC pour vous y inscrire.
Ceci est un message électronique automatisé. Veuillez ne pas y répondre.