Intercom phish from sendgrid
Posted by Dave Yadallee on
X-Mozilla-Status: 0001
X-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Thu, 09 Apr 2026 11:22:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from)
id 1wAt4n-000000003hF-3jeo
for dave@doctor.nl2k.ab.ca;
Thu, 09 Apr 2026 11:21:57 -0600
Resent-From: The Doctor
Resent-Date: Thu, 9 Apr 2026 11:21:57 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from [159.183.224.105] (port=39010 helo=s.wfbtzhsw.outbound-mail.sendgrid.net)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256
(Exim 4.98.2 (FreeBSD))
(envelope-from)
id 1wAssF-000000002kU-3G8z
for root@nk.ca;
Thu, 09 Apr 2026 11:09:08 -0600
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rnxicca.com;
h=from:subject:date:mime-version:to:content-type:
content-transfer-encoding:cc:content-type:date:from:subject:to;
s=s1; t=1775754479; bh=SjrheF0qTe2xAhHs/dw4txUkWrxA6cp/X1rW9cfXIKI=;
b=P4XtGgrf6B5FOzuQY+xRl6sLm/6Tm1DG91Erfl1vJomlW+w4zzNvKIHfkvK/bzjjABIo
AoJ7CWTnBxHrmxU1E8bakanjSVK5p4N24iJgtDrRs9uiU7zLJZse7qB5fTb7SC0p8VAHBC
ssx2tYtJ+3Kejt8BL1yzwpE04UK9T9Hjixhh8wVjiElk8VEv8UlmVPnrP6A9Gu8m2N3lkd
f8KK/xN/A618FaeuJ3lsJfEOlRTklrRKt3VA9U+1xRlyKjWi+pr/1KjjaqqZxaweGjZhax
pfndLsc3KC1RNFY6b32iCxAHm21IXNO1x2SVkgz3LJzymlFVLg7530yhgcYrwV7A==
Received: by recvd-79b8648bc8-vx66k with SMTP id recvd-79b8648bc8-vx66k-1-69D7DCEF-C5
2026-04-09 17:07:59.658695377 +0000 UTC m=+850260.225931298
Received: from menuiserie-ardeco.com (unknown)
by geopod-ismtpd-17 (SG)
with ESMTP id I_oj8Bk3QHKfb5SrQ5z50w
for;
Thu, 09 Apr 2026 17:07:59.596 +0000 (UTC)
Message-Id: <26d14ef340aade6becd362f8204817d7@rnxicca.com>
From: Intelcom Express
Subject: Action Required: Update Your Delivery Address
Date: Thu, 09 Apr 2026 17:07:59 +0000 (UTC)
X-Priority: 5
X-Mailer: zymdsorgufuveui 569.6227
Mime-Version: 1.0
X-SG-EID:
=?us-ascii?Q?u001=2EGM1ezKrRA2nnkzmYqQfR9eLy+bbNMnyvYZM2y5llpx0Ky45GfN+aRH+Bs?=
=?us-ascii?Q?QsbCruswe=2FYt+WS2wEAmM9Ijk544nZFTCuuQQ3g?=
=?us-ascii?Q?o=2FxsbS4eG6LvMqDJJXpf=2FqmgEDMtebjEAOebVNv?=
=?us-ascii?Q?a9aYgHmq5jHLeWkL2+EnaDJvTVQfV9djzE6dJQt?=
=?us-ascii?Q?eBfYTef=2FyIKjyEh5qvxVgDBf8RNMCvvLuUCRF1M?=
=?us-ascii?Q?xLffR2o=2FoTRF+9UgmhOMrA=3D?=
To: root@nk.ca
X-Entity-ID: u001.qH2fZMCyZKfMzlR7q72mOA==
Content-Type: text/html; charset=us-ascii
Content-Transfer-Encoding: base64
X-Spam_score: 31.6
X-Spam_score_int: 316
X-Spam_bar: +++++++++++++++++++++++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Delivery Exception Notice Dear Customer,
Content analysis details: (31.6 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[159.183.224.105 listed in dnsbl.ahbl.org]
[159.183.224.105 listed in dnsbl.ahbl.org]
[159.183.224.105 listed in dnsbl.ahbl.org]
[159.183.224.105 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[159.183.224.105 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[159.183.224.105 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[159.183.224.105 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[159.183.224.105 listed in dnsbl.ahbl.org]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[159.183.224.105 listed in will-spam-for-food.eu.org]
[159.183.224.105 listed in will-spam-for-food.eu.org]
[159.183.224.105 listed in will-spam-for-food.eu.org]
[159.183.224.105 listed in will-spam-for-food.eu.org]
[159.183.224.105 listed in will-spam-for-food.eu.org]
[159.183.224.105 listed in will-spam-for-food.eu.org]
[159.183.224.105 listed in will-spam-for-food.eu.org]
[159.183.224.105 listed in will-spam-for-food.eu.org]
1.9 URIBL_JP_SURBL Contains an URL listed in the JP SURBL blocklist
[URI: xfonyfg.com]
1.9 URIBL_ABUSE_SURBL Contains an URL listed in the ABUSE SURBL blocklist
[URI: intelcom.ca.xfonyfg.com]
-0.0 SPF_PASS SPF: sender matches SPF record
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[159.183.224.105 listed in wl.mailspike.net]
1.0 HK_RANDOM_FROM From username looks random
15 GR_DOMAIN_SENDGR1 Received contains spammer id (sendgr)
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 MIME_BASE64_TEXT RAW: Message text disguised using base64 encoding
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
0.5 VOWEL_FROM_5 Impronouncable from header (6 consecutive vowels)
1.3 RDNS_NONE Delivered to internal network by a host with no rDNS
1.0 XPRIO Has X-Priority header
3.0 VFY_ACCT_NORDNS Verify your account to a poorly-configured MTA -
probable phishing
0.0 T_FILL_THIS_FORM_SHORT Fill in a short form with personal information
Subject: {SPAM?} Action Required: Update Your Delivery Address
Delivery Exception Notice
Dear Customer,
We were unable to complete the delivery of your package because the address provided could not be fully verified.
To prevent any delays or the return of your shipment, please review and update your shipping details as soon as possible.
Current Status: Address details are incomplete or unclear
Action Needed: Please confirm your street address, unit number (if applicable), city, postal code, and phone number
Hold Window: 48 hours before the package may be returned to the sender
Review Delivery Details
For your security, please update your information only through the official portal of your account. If no updates are received within the hold window, we may be required to delay or return your shipment in accordance with carrier policies.
This is an automated notification from our delivery system. Please do not reply to this email.
Let me know if you need further adjustments!
X-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Thu, 09 Apr 2026 11:22:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from
id 1wAt4n-000000003hF-3jeo
for dave@doctor.nl2k.ab.ca;
Thu, 09 Apr 2026 11:21:57 -0600
Resent-From: The Doctor
Resent-Date: Thu, 9 Apr 2026 11:21:57 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from [159.183.224.105] (port=39010 helo=s.wfbtzhsw.outbound-mail.sendgrid.net)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256
(Exim 4.98.2 (FreeBSD))
(envelope-from
id 1wAssF-000000002kU-3G8z
for root@nk.ca;
Thu, 09 Apr 2026 11:09:08 -0600
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=rnxicca.com;
h=from:subject:date:mime-version:to:content-type:
content-transfer-encoding:cc:content-type:date:from:subject:to;
s=s1; t=1775754479; bh=SjrheF0qTe2xAhHs/dw4txUkWrxA6cp/X1rW9cfXIKI=;
b=P4XtGgrf6B5FOzuQY+xRl6sLm/6Tm1DG91Erfl1vJomlW+w4zzNvKIHfkvK/bzjjABIo
AoJ7CWTnBxHrmxU1E8bakanjSVK5p4N24iJgtDrRs9uiU7zLJZse7qB5fTb7SC0p8VAHBC
ssx2tYtJ+3Kejt8BL1yzwpE04UK9T9Hjixhh8wVjiElk8VEv8UlmVPnrP6A9Gu8m2N3lkd
f8KK/xN/A618FaeuJ3lsJfEOlRTklrRKt3VA9U+1xRlyKjWi+pr/1KjjaqqZxaweGjZhax
pfndLsc3KC1RNFY6b32iCxAHm21IXNO1x2SVkgz3LJzymlFVLg7530yhgcYrwV7A==
Received: by recvd-79b8648bc8-vx66k with SMTP id recvd-79b8648bc8-vx66k-1-69D7DCEF-C5
2026-04-09 17:07:59.658695377 +0000 UTC m=+850260.225931298
Received: from menuiserie-ardeco.com (unknown)
by geopod-ismtpd-17 (SG)
with ESMTP id I_oj8Bk3QHKfb5SrQ5z50w
for
Thu, 09 Apr 2026 17:07:59.596 +0000 (UTC)
Message-Id: <26d14ef340aade6becd362f8204817d7@rnxicca.com>
From: Intelcom Express
Subject: Action Required: Update Your Delivery Address
Date: Thu, 09 Apr 2026 17:07:59 +0000 (UTC)
X-Priority: 5
X-Mailer: zymdsorgufuveui 569.6227
Mime-Version: 1.0
X-SG-EID:
=?us-ascii?Q?u001=2EGM1ezKrRA2nnkzmYqQfR9eLy+bbNMnyvYZM2y5llpx0Ky45GfN+aRH+Bs?=
=?us-ascii?Q?QsbCruswe=2FYt+WS2wEAmM9Ijk544nZFTCuuQQ3g?=
=?us-ascii?Q?o=2FxsbS4eG6LvMqDJJXpf=2FqmgEDMtebjEAOebVNv?=
=?us-ascii?Q?a9aYgHmq5jHLeWkL2+EnaDJvTVQfV9djzE6dJQt?=
=?us-ascii?Q?eBfYTef=2FyIKjyEh5qvxVgDBf8RNMCvvLuUCRF1M?=
=?us-ascii?Q?xLffR2o=2FoTRF+9UgmhOMrA=3D?=
To: root@nk.ca
X-Entity-ID: u001.qH2fZMCyZKfMzlR7q72mOA==
Content-Type: text/html; charset=us-ascii
Content-Transfer-Encoding: base64
X-Spam_score: 31.6
X-Spam_score_int: 316
X-Spam_bar: +++++++++++++++++++++++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Delivery Exception Notice Dear Customer,
Content analysis details: (31.6 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[159.183.224.105 listed in dnsbl.ahbl.org]
[159.183.224.105 listed in dnsbl.ahbl.org]
[159.183.224.105 listed in dnsbl.ahbl.org]
[159.183.224.105 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[159.183.224.105 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[159.183.224.105 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[159.183.224.105 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[159.183.224.105 listed in dnsbl.ahbl.org]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[159.183.224.105 listed in will-spam-for-food.eu.org]
[159.183.224.105 listed in will-spam-for-food.eu.org]
[159.183.224.105 listed in will-spam-for-food.eu.org]
[159.183.224.105 listed in will-spam-for-food.eu.org]
[159.183.224.105 listed in will-spam-for-food.eu.org]
[159.183.224.105 listed in will-spam-for-food.eu.org]
[159.183.224.105 listed in will-spam-for-food.eu.org]
[159.183.224.105 listed in will-spam-for-food.eu.org]
1.9 URIBL_JP_SURBL Contains an URL listed in the JP SURBL blocklist
[URI: xfonyfg.com]
1.9 URIBL_ABUSE_SURBL Contains an URL listed in the ABUSE SURBL blocklist
[URI: intelcom.ca.xfonyfg.com]
-0.0 SPF_PASS SPF: sender matches SPF record
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[159.183.224.105 listed in wl.mailspike.net]
1.0 HK_RANDOM_FROM From username looks random
15 GR_DOMAIN_SENDGR1 Received contains spammer id (sendgr)
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 MIME_BASE64_TEXT RAW: Message text disguised using base64 encoding
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
0.5 VOWEL_FROM_5 Impronouncable from header (6 consecutive vowels)
1.3 RDNS_NONE Delivered to internal network by a host with no rDNS
1.0 XPRIO Has X-Priority header
3.0 VFY_ACCT_NORDNS Verify your account to a poorly-configured MTA -
probable phishing
0.0 T_FILL_THIS_FORM_SHORT Fill in a short form with personal information
Subject: {SPAM?} Action Required: Update Your Delivery Address
Delivery Exception Notice
Dear Customer,
We were unable to complete the delivery of your package because the address provided could not be fully verified.
To prevent any delays or the return of your shipment, please review and update your shipping details as soon as possible.
Current Status: Address details are incomplete or unclear
Action Needed: Please confirm your street address, unit number (if applicable), city, postal code, and phone number
Hold Window: 48 hours before the package may be returned to the sender
Review Delivery Details
For your security, please update your information only through the official portal of your account. If no updates are received within the hold window, we may be required to delay or return your shipment in accordance with carrier policies.
This is an automated notification from our delivery system. Please do not reply to this email.
Let me know if you need further adjustments!