Telnet communications phish
Posted by Dave Yadallee on
X-Mozilla-Status: 0001
X-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Thu, 12 Mar 2026 11:57:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from)
id 1w0kH3-000000000Sc-0zk2
for dave@doctor.nl2k.ab.ca;
Thu, 12 Mar 2026 11:56:41 -0600
Resent-From: The Doctor
Resent-Date: Thu, 12 Mar 2026 11:56:41 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mx.ite.net ([202.88.64.59]:47218 helo=mail.ite.net)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384
(Exim 4.98.2 (FreeBSD))
(envelope-from)
id 1w0fbo-00000000PMs-1zYp
for sales@nk.ca;
Thu, 12 Mar 2026 06:57:58 -0600
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=mail.ite.net;
s=smtp1dkim; t=1773320210;
bh=586i8RmFghXM+yWFZvYT783fnu9CNZDVNfj+lf5YtLk=;
h=From:Subject:Date:From;
b=DsYsgtcCI8jmPhEZPmNMRviSsavmuTHa0+ksx322LECAVcHGx9a9A5p42VM1NM+1p
+Q4m+IuhyhY6/sHOzLSJr6eHt1hopvFc8unf6QNiYV6Yf6JXsa9+vuu7Y47FuyfxgZ
i4Y9/EZYZ5AD7Dl6I4kK26uF59XVXvaXGlOELKDA=
Received: from User (216-131-80-80.lax.as62651.net [216.131.80.80])
by mail.ite.net (Postfix) with ESMTPA id A1BA38CCAC40;
Thu, 12 Mar 2026 22:56:22 +1000 (ChST)
From:
Subject: : TELNET EMAIL SERVICE SUSPENSION :
Date: Thu, 12 Mar 2026 07:56:49 -0500
MIME-Version: 1.0
Content-Type: multipart/related;
boundary="----=_NextPart_000_0028_01C2AA85.5E07EFC2"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2800.1081
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1081
X-Virus-Scanned: clamav-milter 1.4.3 at av01.ite.net
X-Virus-Status: Clean
X-Spam_score: 25.0
X-Spam_score_int: 250
X-Spam_bar: +++++++++++++++++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: For failure to Revalidate Your Telnet email account - Your
Telnet Account will be SUSPENDED by 14th March 2026. If you wish to continue
using the Telnet email services - CLICK HERE TO REVALIDATE
Content analysis details: (25.0 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
0.1 MISSING_MID Missing Message-Id: header
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[216.131.80.80 listed in will-spam-for-food.eu.org]
[216.131.80.80 listed in will-spam-for-food.eu.org]
[216.131.80.80 listed in will-spam-for-food.eu.org]
[216.131.80.80 listed in will-spam-for-food.eu.org]
[216.131.80.80 listed in will-spam-for-food.eu.org]
[216.131.80.80 listed in will-spam-for-food.eu.org]
[216.131.80.80 listed in will-spam-for-food.eu.org]
[216.131.80.80 listed in will-spam-for-food.eu.org]
[202.88.64.59 listed in will-spam-for-food.eu.org]
[202.88.64.59 listed in will-spam-for-food.eu.org]
[202.88.64.59 listed in will-spam-for-food.eu.org]
[202.88.64.59 listed in will-spam-for-food.eu.org]
[202.88.64.59 listed in will-spam-for-food.eu.org]
[202.88.64.59 listed in will-spam-for-food.eu.org]
[202.88.64.59 listed in will-spam-for-food.eu.org]
[202.88.64.59 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[202.88.64.59 listed in dnsbl.ahbl.org]
[202.88.64.59 listed in dnsbl.ahbl.org]
[202.88.64.59 listed in dnsbl.ahbl.org]
[202.88.64.59 listed in dnsbl.ahbl.org]
[216.131.80.80 listed in dnsbl.ahbl.org]
[216.131.80.80 listed in dnsbl.ahbl.org]
[216.131.80.80 listed in dnsbl.ahbl.org]
[216.131.80.80 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[202.88.64.59 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[202.88.64.59 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[202.88.64.59 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[202.88.64.59 listed in dnsbl.ahbl.org]
0.7 SPF_NEUTRAL SPF: sender does not match SPF record (neutral)
0.0 NSL_RCVD_FROM_USER Received from User
1.6 SUBJ_ALL_CAPS Subject is all capitals
1.2 MISSING_HEADERS Missing To: header
1.0 HTML_IMAGE_ONLY_16 BODY: HTML: images with 1200-1600 bytes of words
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.0 HTML_IMAGE_RATIO_06 BODY: HTML has a low ratio of text to image area
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
0.0 FORGED_OUTLOOK_HTML Outlook can't send HTML message only
2.0 WINDOWS_7BITS Windows charset announced as 7 bit
0.6 FSL_NEW_HELO_USER Spam's using Helo and User
1.5 TVD_PH_BODY_ACCOUNTS_PRE The body matches phrases such as "accounts
suspended", "account credited", "account
verification"
1.2 AXB_XMAILER_MIMEOLE_OL_1ECD5 Yet another X header trait
0.6 FORGED_OUTLOOK_TAGS Outlook can't send HTML in this format
1.0 ZMIde_OutlookExpress Outlook Express should not be used anymore
2.0 MIXED_HREF_CASE Has href in mixed case
2.8 FORGED_MUA_OUTLOOK Forged mail pretending to be from MS Outlook
2.5 TO_NO_BRKTS_MSFT To: misformatted and supposed Microsoft tool
Subject: {SPAM?} : TELNET EMAIL SERVICE SUSPENSION :
This is a multi-part message in MIME format.
------=_NextPart_000_0028_01C2AA85.5E07EFC2
Content-Type: text/html;
charset="Windows-1251"
Content-Transfer-Encoding: 7bit

For failure to Revalidate Your Telnet email account - Your Telnet Account will be SUSPENDED by 14th March 2026.
Telnet Communications.
http://www.telnetcommunications.com/
X-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Thu, 12 Mar 2026 11:57:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from
id 1w0kH3-000000000Sc-0zk2
for dave@doctor.nl2k.ab.ca;
Thu, 12 Mar 2026 11:56:41 -0600
Resent-From: The Doctor
Resent-Date: Thu, 12 Mar 2026 11:56:41 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mx.ite.net ([202.88.64.59]:47218 helo=mail.ite.net)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384
(Exim 4.98.2 (FreeBSD))
(envelope-from
id 1w0fbo-00000000PMs-1zYp
for sales@nk.ca;
Thu, 12 Mar 2026 06:57:58 -0600
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=mail.ite.net;
s=smtp1dkim; t=1773320210;
bh=586i8RmFghXM+yWFZvYT783fnu9CNZDVNfj+lf5YtLk=;
h=From:Subject:Date:From;
b=DsYsgtcCI8jmPhEZPmNMRviSsavmuTHa0+ksx322LECAVcHGx9a9A5p42VM1NM+1p
+Q4m+IuhyhY6/sHOzLSJr6eHt1hopvFc8unf6QNiYV6Yf6JXsa9+vuu7Y47FuyfxgZ
i4Y9/EZYZ5AD7Dl6I4kK26uF59XVXvaXGlOELKDA=
Received: from User (216-131-80-80.lax.as62651.net [216.131.80.80])
by mail.ite.net (Postfix) with ESMTPA id A1BA38CCAC40;
Thu, 12 Mar 2026 22:56:22 +1000 (ChST)
From:
Subject: : TELNET EMAIL SERVICE SUSPENSION :
Date: Thu, 12 Mar 2026 07:56:49 -0500
MIME-Version: 1.0
Content-Type: multipart/related;
boundary="----=_NextPart_000_0028_01C2AA85.5E07EFC2"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2800.1081
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1081
X-Virus-Scanned: clamav-milter 1.4.3 at av01.ite.net
X-Virus-Status: Clean
X-Spam_score: 25.0
X-Spam_score_int: 250
X-Spam_bar: +++++++++++++++++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: For failure to Revalidate Your Telnet email account - Your
Telnet Account will be SUSPENDED by 14th March 2026. If you wish to continue
using the Telnet email services - CLICK HERE TO REVALIDATE
Content analysis details: (25.0 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
0.1 MISSING_MID Missing Message-Id: header
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[216.131.80.80 listed in will-spam-for-food.eu.org]
[216.131.80.80 listed in will-spam-for-food.eu.org]
[216.131.80.80 listed in will-spam-for-food.eu.org]
[216.131.80.80 listed in will-spam-for-food.eu.org]
[216.131.80.80 listed in will-spam-for-food.eu.org]
[216.131.80.80 listed in will-spam-for-food.eu.org]
[216.131.80.80 listed in will-spam-for-food.eu.org]
[216.131.80.80 listed in will-spam-for-food.eu.org]
[202.88.64.59 listed in will-spam-for-food.eu.org]
[202.88.64.59 listed in will-spam-for-food.eu.org]
[202.88.64.59 listed in will-spam-for-food.eu.org]
[202.88.64.59 listed in will-spam-for-food.eu.org]
[202.88.64.59 listed in will-spam-for-food.eu.org]
[202.88.64.59 listed in will-spam-for-food.eu.org]
[202.88.64.59 listed in will-spam-for-food.eu.org]
[202.88.64.59 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[202.88.64.59 listed in dnsbl.ahbl.org]
[202.88.64.59 listed in dnsbl.ahbl.org]
[202.88.64.59 listed in dnsbl.ahbl.org]
[202.88.64.59 listed in dnsbl.ahbl.org]
[216.131.80.80 listed in dnsbl.ahbl.org]
[216.131.80.80 listed in dnsbl.ahbl.org]
[216.131.80.80 listed in dnsbl.ahbl.org]
[216.131.80.80 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[202.88.64.59 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[202.88.64.59 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[202.88.64.59 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[202.88.64.59 listed in dnsbl.ahbl.org]
0.7 SPF_NEUTRAL SPF: sender does not match SPF record (neutral)
0.0 NSL_RCVD_FROM_USER Received from User
1.6 SUBJ_ALL_CAPS Subject is all capitals
1.2 MISSING_HEADERS Missing To: header
1.0 HTML_IMAGE_ONLY_16 BODY: HTML: images with 1200-1600 bytes of words
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.0 HTML_IMAGE_RATIO_06 BODY: HTML has a low ratio of text to image area
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
0.0 FORGED_OUTLOOK_HTML Outlook can't send HTML message only
2.0 WINDOWS_7BITS Windows charset announced as 7 bit
0.6 FSL_NEW_HELO_USER Spam's using Helo and User
1.5 TVD_PH_BODY_ACCOUNTS_PRE The body matches phrases such as "accounts
suspended", "account credited", "account
verification"
1.2 AXB_XMAILER_MIMEOLE_OL_1ECD5 Yet another X header trait
0.6 FORGED_OUTLOOK_TAGS Outlook can't send HTML in this format
1.0 ZMIde_OutlookExpress Outlook Express should not be used anymore
2.0 MIXED_HREF_CASE Has href in mixed case
2.8 FORGED_MUA_OUTLOOK Forged mail pretending to be from MS Outlook
2.5 TO_NO_BRKTS_MSFT To: misformatted and supposed Microsoft tool
Subject: {SPAM?} : TELNET EMAIL SERVICE SUSPENSION :
This is a multi-part message in MIME format.
------=_NextPart_000_0028_01C2AA85.5E07EFC2
Content-Type: text/html;
charset="Windows-1251"
Content-Transfer-Encoding: 7bit
For failure to Revalidate Your Telnet email account - Your Telnet Account will be SUSPENDED by 14th March 2026.
Telnet Communications.
http://www.telnetcommunications.com/
