TD Direct Investing phish from Google User
Posted by Dave Yadallee onX-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Fri, 24 Jul 2026 12:59:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.99.3 (FreeBSD))
(envelope-from
id 1wnL6h-000000003to-24zg
for dave@doctor.nl2k.ab.ca;
Fri, 24 Jul 2026 12:58:51 -0600
Resent-From: The Doctor
Resent-Date: Fri, 24 Jul 2026 12:58:51 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from [35.215.3.35] (port=44459 helo=campaigns.arf01.com)
by doctor.nl2k.ab.ca with esmtp (Exim 4.99.3 (FreeBSD))
(envelope-from
id 1wnKzz-000000003E3-02qo
for root@nk.ca;
Fri, 24 Jul 2026 12:52:03 -0600
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; s=default; d=campaigns.arf01.com;
h=Content-Type:MIME-Version:From:To:Subject:Date:Message-ID;
i=notification@kpgzmv.campaigns.arf01.com;
bh=AkVxnPl+VD/dcLdpJ02JcrM3POmFXBP0DleIwOOHcww=;
b=X9H0AcDsRhI+2MHs/Lt2GCQ5rABeMW1m7fETK2xZo6pYW6NJHfCHr0OuySAc/yxGW5Y7+dfUTY5W
MUj0j9GDx///0yhrC60WkAm8WsFdpC48ePO3+wv1yBBRHLAOepkNA5LM4rxJ7RbJL5/lsJy8/pLb
SPCq6GVo9QHzPAlA7OiQOwRz2Vt2DhFRsf7lrfvu6vGJhhhvYDoVx/EonvkZCRM5EZj6AoC6Jz4a
IM/Nry1GaqhOnhrsZEyJRoU0eUHk69R8k0GFFuHsuSf2eN7cRgmIqqiVHvswfTx9UDAQss6kSSuR
HsJoNM//GUmC8Mh+YZ0wkpy8BcDxX7CxU4ALZQ==
Content-Type: multipart/alternative;
boundary="===============4261748735468286487=="
MIME-Version: 1.0
From: TD Direct Investing
To: root@nk.ca
Subject: [TD WebBroker] Security Protocol - Temporary Withdrawal Hold -
Unrecognized Device Access Verification Required
Date: Sat, 25 Jul 2026 03:50:58 +0900
Message-ID:
<178491905818.3307.16470108963559159387@kpgzmv.campaigns.arf01.com>
List-Unsubscribe-Post: List-Unsubscribe=One-Click
X-Auto-Response-Suppress: OOF, DR, RN, NRN
Feedback-ID: campaign:kpgzmv.campaigns.arf01.com:mailer
X-Entity-Ref-ID: 89d69dce-c30b-4844-a03f-14a94d1142fd
X-Spam_score: 17.4
X-Spam_score_int: 174
X-Spam_bar: +++++++++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: [TD WebBroker] Security Protocol: Temporary Withdrawal Hold
— Unrecognized Device Access Verification Required root, The TD Direct
Investing Security Operations Centre has identified one or more access events
associated with your TD WebBroker account that originate from a device, browser
fingerprint, or network endp [...]
Content analysis details: (17.4 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[35.215.3.35 listed in dnsbl.ahbl.org]
[35.215.3.35 listed in dnsbl.ahbl.org]
[35.215.3.35 listed in dnsbl.ahbl.org]
[35.215.3.35 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[35.215.3.35 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[35.215.3.35 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[35.215.3.35 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[35.215.3.35 listed in dnsbl.ahbl.org]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[35.215.3.35 listed in will-spam-for-food.eu.org]
[35.215.3.35 listed in will-spam-for-food.eu.org]
[35.215.3.35 listed in will-spam-for-food.eu.org]
[35.215.3.35 listed in will-spam-for-food.eu.org]
[35.215.3.35 listed in will-spam-for-food.eu.org]
[35.215.3.35 listed in will-spam-for-food.eu.org]
[35.215.3.35 listed in will-spam-for-food.eu.org]
[35.215.3.35 listed in will-spam-for-food.eu.org]
3.6 RCVD_IN_SBL_CSS RBL: Received via a relay in Spamhaus SBL-CSS
[35.215.3.35 listed in zen.spamhaus.org]
1.5 RCVD_IN_SBL_XBL RBL: Received via a relay in Spamhaus SBL+XBL
[35.215.3.35 listed in sbl-xbl.spamhaus.org]
2.5 URIBL_DBL_SPAM Contains a spam URL listed in the DBL blocklist
[URI: arf01.com]
-2.0 RCVD_IN_RP_SAFE RBL: Sender in ReturnPath Safe - Contact
safe-sa@returnpath.net
[Excessive Number of Queries |
-3.0 RCVD_IN_RP_CERTIFIED RBL: Sender in ReturnPath Certified - Contact
cert-sa@returnpath.net
[Excessive Number of Queries |
1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,
https://senderscore.org/blacklistlookup/
[35.215.3.35 listed in bl.score.senderscore.com]
1.5 MR_STRANGE_QUESTION URI: No description available.
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
1.3 RDNS_NONE Delivered to internal network by a host with no rDNS
1.5 VOWEL_FROM_6 Impronouncable from header (6 consecutive vowels)
0.8 SARE_FROM_SPAM_WORD3 I don't know people named this!
1.5 TVD_PH_BODY_ACCOUNTS_PRE The body matches phrases such as "accounts
suspended", "account credited", "account
verification"
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
2.0 TVD_PH_BODY_META No description available.
Subject: {SPAM?} [TD WebBroker] Security Protocol - Temporary Withdrawal Hold -
Unrecognized Device Access Verification Required
X-Mozilla-Status: 0001
X-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Fri, 24 Jul 2026 12:59:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.99.3 (FreeBSD))
(envelope-from
id 1wnL6h-000000003to-24zg
for dave@doctor.nl2k.ab.ca;
Fri, 24 Jul 2026 12:58:51 -0600
Resent-From: The Doctor
Resent-Date: Fri, 24 Jul 2026 12:58:51 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from [35.215.3.35] (port=44459 helo=campaigns.arf01.com)
by doctor.nl2k.ab.ca with esmtp (Exim 4.99.3 (FreeBSD))
(envelope-from
id 1wnKzz-000000003E3-02qo
for root@nk.ca;
Fri, 24 Jul 2026 12:52:03 -0600
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; s=default; d=campaigns.arf01.com;
h=Content-Type:MIME-Version:From:To:Subject:Date:Message-ID;
i=notification@kpgzmv.campaigns.arf01.com;
bh=AkVxnPl+VD/dcLdpJ02JcrM3POmFXBP0DleIwOOHcww=;
b=X9H0AcDsRhI+2MHs/Lt2GCQ5rABeMW1m7fETK2xZo6pYW6NJHfCHr0OuySAc/yxGW5Y7+dfUTY5W
MUj0j9GDx///0yhrC60WkAm8WsFdpC48ePO3+wv1yBBRHLAOepkNA5LM4rxJ7RbJL5/lsJy8/pLb
SPCq6GVo9QHzPAlA7OiQOwRz2Vt2DhFRsf7lrfvu6vGJhhhvYDoVx/EonvkZCRM5EZj6AoC6Jz4a
IM/Nry1GaqhOnhrsZEyJRoU0eUHk69R8k0GFFuHsuSf2eN7cRgmIqqiVHvswfTx9UDAQss6kSSuR
HsJoNM//GUmC8Mh+YZ0wkpy8BcDxX7CxU4ALZQ==
Content-Type: multipart/alternative;
boundary="===============4261748735468286487=="
MIME-Version: 1.0
From: TD Direct Investing
To: root@nk.ca
Subject: [TD WebBroker] Security Protocol - Temporary Withdrawal Hold -
Unrecognized Device Access Verification Required
Date: Sat, 25 Jul 2026 03:50:58 +0900
Message-ID:
<178491905818.3307.16470108963559159387@kpgzmv.campaigns.arf01.com>
List-Unsubscribe-Post: List-Unsubscribe=One-Click
X-Auto-Response-Suppress: OOF, DR, RN, NRN
Feedback-ID: campaign:kpgzmv.campaigns.arf01.com:mailer
X-Entity-Ref-ID: 89d69dce-c30b-4844-a03f-14a94d1142fd
X-Spam_score: 17.4
X-Spam_score_int: 174
X-Spam_bar: +++++++++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: [TD WebBroker] Security Protocol: Temporary Withdrawal Hold
— Unrecognized Device Access Verification Required root, The TD Direct
Investing Security Operations Centre has identified one or more access events
associated with your TD WebBroker account that originate from a device, browser
fingerprint, or network endp [...]
Content analysis details: (17.4 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[35.215.3.35 listed in dnsbl.ahbl.org]
[35.215.3.35 listed in dnsbl.ahbl.org]
[35.215.3.35 listed in dnsbl.ahbl.org]
[35.215.3.35 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[35.215.3.35 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[35.215.3.35 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[35.215.3.35 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[35.215.3.35 listed in dnsbl.ahbl.org]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[35.215.3.35 listed in will-spam-for-food.eu.org]
[35.215.3.35 listed in will-spam-for-food.eu.org]
[35.215.3.35 listed in will-spam-for-food.eu.org]
[35.215.3.35 listed in will-spam-for-food.eu.org]
[35.215.3.35 listed in will-spam-for-food.eu.org]
[35.215.3.35 listed in will-spam-for-food.eu.org]
[35.215.3.35 listed in will-spam-for-food.eu.org]
[35.215.3.35 listed in will-spam-for-food.eu.org]
3.6 RCVD_IN_SBL_CSS RBL: Received via a relay in Spamhaus SBL-CSS
[35.215.3.35 listed in zen.spamhaus.org]
1.5 RCVD_IN_SBL_XBL RBL: Received via a relay in Spamhaus SBL+XBL
[35.215.3.35 listed in sbl-xbl.spamhaus.org]
2.5 URIBL_DBL_SPAM Contains a spam URL listed in the DBL blocklist
[URI: arf01.com]
-2.0 RCVD_IN_RP_SAFE RBL: Sender in ReturnPath Safe - Contact
safe-sa@returnpath.net
[Excessive Number of Queries |
-3.0 RCVD_IN_RP_CERTIFIED RBL: Sender in ReturnPath Certified - Contact
cert-sa@returnpath.net
[Excessive Number of Queries |
1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,
https://senderscore.org/blacklistlookup/
[35.215.3.35 listed in bl.score.senderscore.com]
1.5 MR_STRANGE_QUESTION URI: No description available.
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
1.3 RDNS_NONE Delivered to internal network by a host with no rDNS
1.5 VOWEL_FROM_6 Impronouncable from header (6 consecutive vowels)
0.8 SARE_FROM_SPAM_WORD3 I don't know people named this!
1.5 TVD_PH_BODY_ACCOUNTS_PRE The body matches phrases such as "accounts
suspended", "account credited", "account
verification"
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
2.0 TVD_PH_BODY_META No description available.
Subject: {SPAM?} [TD WebBroker] Security Protocol - Temporary Withdrawal Hold -
Unrecognized Device Access Verification Required
▶Account Security — Verification Required
Unrecognized Device Access Detected
Temporary Withdrawal Hold Applied
TD WebBroker Security Operations Centre — Automated Threat Detection
root,
The TD Direct Investing Security Operations Centre has identified one or more access events associated with your TD WebBroker account that originate from a device, browser fingerprint, or network endpoint not previously recognized within your established access profile. In accordance with TD Direct Investing’s automated client asset protection protocols, a temporary hold on external fund transfers and third-party withdrawals has been applied to your account pending identity verification.
The access event(s) flagged by our security monitoring systems exhibited the following characteristics:
Access OriginUnrecognized IP Address / Geolocation
Device FingerprintNew / Previously Unseen Client Hash
Browser & Operating SystemUnfamiliar Configuration Profile
Access Time PatternDeviation from Historical Baseline
Account Function AccessedExternal Transfer & Withdrawal Module
Account Security Confidence Score
Requires Verification
Device Trust: Unverified — Account Holder Confirmation Required
TD Direct Investing applies these precautionary measures as a matter of operational security protocol to safeguard client assets against unauthorized access. The temporary hold applies exclusively to external transfer and third-party withdrawal functions. All other account functions—including portfolio viewing, order placement, and internal transfers between your TD accounts—continue to operate normally.
Protective Measure in Effect: External Transfer Hold
The temporary hold on external fund transfers and third-party withdrawals shall remain in effect until the account holder’s identity and control of the account are independently confirmed through the secure verification protocol. This measure is non-negotiable and is applied automatically when unrecognized device access is detected in conjunction with withdrawal-related account functions.
To resolve this matter and lift the temporary hold, please log in to your TD WebBroker account from a previously recognized device where possible, and complete the secure identity verification protocol. The verification process confirms that you are the legitimate account holder and that the flagged access event does not represent an ongoing security concern. If you confirm that the access was indeed initiated by you from a new device or location, the device will be registered to your trusted device profile and the hold will be released.
Log In to Verify Identity & Lift Hold
TD Direct Investing deploys continuous automated security monitoring across all TD WebBroker accounts. All access events are logged and subject to real-time behavioural analytics and anomaly detection. This alert is issued as part of TD Direct Investing’s commitment to the proactive protection of client accounts and assets. If you believe you have received this alert in error or require assistance completing the verification process, please contact the TD Direct Investing Security Operations Centre immediately through the Secure Message Centre upon login or by calling the number on the back of your TD Access Card. Do not reply to this email with sensitive or personal information.
Yours sincerely,
TD Direct Investing
Security Operations Centre
TD Direct Investing is a division of TD Waterhouse Canada Inc., a subsidiary of The Toronto-Dominion Bank. TD Waterhouse Canada Inc. is a Dealer Member of CIRO and a Member of CIPF.
This message is an automated security operations notification.
Please direct all inquiries through the Secure Message Centre within your TD WebBroker account.
TD Bank Group © 2026. All rights reserved.
