Donation spam from Russia
Posted by Dave Yadallee onX-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Wed, 21 Jan 2026 05:15:00 -0700
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from
id 1viX6f-00000000DwR-1LJ7
for dave@doctor.nl2k.ab.ca;
Wed, 21 Jan 2026 05:14:41 -0700
Resent-From: The Doctor
Resent-Date: Wed, 21 Jan 2026 05:14:41 -0700
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mx1.rniito.ru ([85.143.162.3]:60845)
by doctor.nl2k.ab.ca with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
(Exim 4.98.2 (FreeBSD))
(envelope-from
id 1viQJJ-00000000I3d-1kzM
for sales@nk.ca;
Tue, 20 Jan 2026 21:59:27 -0700
X-Virus-Scanned: amavisd-new at rniito.ru
Received: from [203.188.171.173] (unknown [203.188.171.173])
(using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits))
(No client certificate requested)
(Authenticated sender: vnlivencov@rniito.ru)
by mx1.rniito.ru (Postfix) with ESMTPSA id EFB362BDA;
Wed, 21 Jan 2026 05:53:23 +0300 (MSK)
Content-Type: multipart/alternative; boundary="===============1038902316=="
MIME-Version: 1.0
Subject: Congratulations you have won.
To: Donation Group
From: "Rafaela Aponte-Diamant"
Date: Wed, 21 Jan 2026 02:52:49 +0000
Reply-To: infoendownment@gmail.com
X-Priority: 1 (High)
Message-Id: <20260121025323.EFB362BDA@mx1.rniito.ru>
X-Spam_score: 11.0
X-Spam_score_int: 110
X-Spam_bar: +++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Congratulations! My name is Rafaela Aponte-Diamant we have
launched a special donation program and your email address has been selected
to receive a donation of AC2.7 million. Kindly reply for more details.
Content analysis details: (11.0 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[85.143.162.3 listed in dnsbl.ahbl.org]
[85.143.162.3 listed in dnsbl.ahbl.org]
[85.143.162.3 listed in dnsbl.ahbl.org]
[85.143.162.3 listed in dnsbl.ahbl.org]
[203.188.171.173 listed in dnsbl.ahbl.org]
[203.188.171.173 listed in dnsbl.ahbl.org]
[203.188.171.173 listed in dnsbl.ahbl.org]
[203.188.171.173 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[85.143.162.3 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[85.143.162.3 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[85.143.162.3 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[85.143.162.3 listed in dnsbl.ahbl.org]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[203.188.171.173 listed in will-spam-for-food.eu.org]
[203.188.171.173 listed in will-spam-for-food.eu.org]
[203.188.171.173 listed in will-spam-for-food.eu.org]
[203.188.171.173 listed in will-spam-for-food.eu.org]
[203.188.171.173 listed in will-spam-for-food.eu.org]
[203.188.171.173 listed in will-spam-for-food.eu.org]
[203.188.171.173 listed in will-spam-for-food.eu.org]
[203.188.171.173 listed in will-spam-for-food.eu.org]
[85.143.162.3 listed in will-spam-for-food.eu.org]
[85.143.162.3 listed in will-spam-for-food.eu.org]
[85.143.162.3 listed in will-spam-for-food.eu.org]
[85.143.162.3 listed in will-spam-for-food.eu.org]
[85.143.162.3 listed in will-spam-for-food.eu.org]
[85.143.162.3 listed in will-spam-for-food.eu.org]
[85.143.162.3 listed in will-spam-for-food.eu.org]
[85.143.162.3 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_SBL_XBL RBL: Received via a relay in Spamhaus SBL+XBL
[203.188.171.173 listed in sbl-xbl.spamhaus.org]
1.5 RCVD_IN_CBL RBL: Received via a relay in cbl.abuseat.org
[Listed by XBL, see
-0.0 SPF_PASS SPF: sender matches SPF record
0.5 NO_RDNS Sending MTA has no reverse DNS (Postfix variant)
-0.0 T_RP_MATCHES_RCVD Envelope sender domain matches handover relay
domain
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 HTML_MESSAGE BODY: HTML included in message
2.5 FREEMAIL_FORGED_REPLYTO Freemail in Reply-To, but not From
Subject: {SPAM?} Congratulations you have won.
You will not see this in a MIME-aware mail reader.
--===============1038902316==
Content-Type: text/plain; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Content-Description: Mail message body
Congratulations!
My name is Rafaela Aponte-Diamant we have launched a special donation progr=
am and your email address has been selected to receive a donation of =20AC2=
.7 million.
Kindly reply for more details.
--===============1038902316==
Content-Type: text/html; charset="utf-8"
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Content-Description: Mail message body
=3Dutf-8"/>
My name i=
s Rafaela Aponte-Diamant we have launched a special donation program and yo=
ur email address has been selected to receive a donation of =E2=82=AC2.7 mi=
llion.
Kindly reply for more details.
--===============1038902316==--