Document phish from sendgrid
Posted by Dave Yadallee on
X-Mozilla-Status: 0001
X-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Sun, 21 Jun 2026 05:32:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.99.3 (FreeBSD))
(envelope-from)
id 1wbGOh-00000000LNK-2tI1
for dave@doctor.nl2k.ab.ca;
Sun, 21 Jun 2026 05:31:31 -0600
Resent-From: The Doctor
Resent-Date: Sun, 21 Jun 2026 05:31:31 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from wrqvcftr.outbound-mail.sendgrid.net ([149.72.207.117]:36028)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256
(Exim 4.99.3 (FreeBSD))
(envelope-from)
id 1wbE5M-000000006ii-2qAr
for sales@nk.ca;
Sun, 21 Jun 2026 03:03:33 -0600
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=p3-i.com;
h=content-type:mime-version:from:subject:date:to:cc:content-type:date:
from:subject:to;
s=s1; t=1782032551;
bh=RRkDnOi0P2tMynw2T1RybKdX/x0KHqMvT3WgsDj6c0E=;
b=SZhOxbwJyFOPxxJzRQEaiezKmDpKj4oPuMeLQuaCjtTmir8WDhD2c/TYDzq7n13uNfKz
OmR1bMeIkvgufOEbVl3QqWlrhqLKyYFRn/osKcLUosrEi6eYGeM0wVNUXlBuQBeJ8bszQi
Y2CYCdg+6aQYtxd1MqZr/jDAMuL63YtLp6PBuINHUz33pUORB8C+G+pWD0ES7wghiHs5xn
OmxJq/FqxMG+x1x5w/O9pjW+aeATcjgCVYMp4KTc+7p3I7U5w9TTrtq5RNuQODXqBLNLKH
FIYbR8Ne7FAqPJg0ptkf8onXZXgDAmAU4gLg5NACQaq2L96kaLwyHNYr8kHcYaDA==
Received: by recvd-75586bd7d8-d4kqx with SMTP id recvd-75586bd7d8-d4kqx-1-6A37A8A7-6
2026-06-21 09:02:31.046117084 +0000 UTC m=+378627.690296285
Received: from [154.38.165.235] (unknown)
by geopod-ismtpd-25 (SG)
with ESMTP id G8LNT4TtSImDJiJN_Mo1JA
for;
Sun, 21 Jun 2026 09:02:30.914 +0000 (UTC)
Content-Type: multipart/alternative; boundary="===============7540931904844975849=="
MIME-Version: 1.0
From: Docusend
Subject: You Have a New Secured Document
Date: Sun, 21 Jun 2026 09:02:31 +0000 (UTC)
Message-ID: <178203255046.14396.4451825813358312601@vmi2857862>
X-Mailer: Mailer-4985
X-SG-EID:
=?us-ascii?Q?u001=2Es9z3FKz3theG7asXgt6ElAca8kF7UH1zSPQkdebr12z1S4ULEooo0QM4q?=
=?us-ascii?Q?+52j8OhsDOMjRDtkxywGhq+PSF4dKdsXa=2FUYXIy?=
=?us-ascii?Q?KdF+0Y95d1mrun6=2FOwUEPGooaBBRNeH1n5xiN0O?=
=?us-ascii?Q?X=2FdKvQpQHuWMXon10DFJ5AbTvU4EK+chr0eTd9r?=
=?us-ascii?Q?RezDV6O7xrqPnIf5gIxmpYK7PcUORuSp4AQw7r1?=
=?us-ascii?Q?=2F1XpXZpMbWLgAljo14XEy8=3D?=
To: sales@nk.ca
X-Entity-ID: u001.imBUo2waVNFQ1splhTmG4A==
X-Spam_score: 39.2
X-Spam_score_int: 392
X-Spam_bar: +++++++++++++++++++++++++++++++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Shared Document Hello,
Content analysis details: (39.2 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[154.38.165.235 listed in will-spam-for-food.eu.org]
[154.38.165.235 listed in will-spam-for-food.eu.org]
[154.38.165.235 listed in will-spam-for-food.eu.org]
[154.38.165.235 listed in will-spam-for-food.eu.org]
[154.38.165.235 listed in will-spam-for-food.eu.org]
[154.38.165.235 listed in will-spam-for-food.eu.org]
[154.38.165.235 listed in will-spam-for-food.eu.org]
[154.38.165.235 listed in will-spam-for-food.eu.org]
[149.72.207.117 listed in will-spam-for-food.eu.org]
[149.72.207.117 listed in will-spam-for-food.eu.org]
[149.72.207.117 listed in will-spam-for-food.eu.org]
[149.72.207.117 listed in will-spam-for-food.eu.org]
[149.72.207.117 listed in will-spam-for-food.eu.org]
[149.72.207.117 listed in will-spam-for-food.eu.org]
[149.72.207.117 listed in will-spam-for-food.eu.org]
[149.72.207.117 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[149.72.207.117 listed in dnsbl.ahbl.org]
[149.72.207.117 listed in dnsbl.ahbl.org]
[149.72.207.117 listed in dnsbl.ahbl.org]
[149.72.207.117 listed in dnsbl.ahbl.org]
[154.38.165.235 listed in dnsbl.ahbl.org]
[154.38.165.235 listed in dnsbl.ahbl.org]
[154.38.165.235 listed in dnsbl.ahbl.org]
[154.38.165.235 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[149.72.207.117 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[149.72.207.117 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[149.72.207.117 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[149.72.207.117 listed in dnsbl.ahbl.org]
1.7 URIBL_CT_SURBL Contains an URL listed in the CT SURBL blocklist
[URI: u56462072.ct.sendgrid.net]
1.6 RCVD_IN_BRBL_LASTEXT RBL: No description available.
[149.72.207.117 listed in bb.barracudacentral.org]
-3.0 RCVD_IN_RP_CERTIFIED RBL: Sender in ReturnPath Certified - Contact
cert-sa@returnpath.net
[Excessive Number of Queries |]
-2.0 RCVD_IN_RP_SAFE RBL: Sender in ReturnPath Safe - Contact
safe-sa@returnpath.net
[Excessive Number of Queries |]
1.1 URIBL_GREY Contains an URL listed in the URIBL greylist
[URI: sendgrid.net]
-0.0 SPF_PASS SPF: sender matches SPF record
15 GR_DOMAIN_SENDGR1 Received contains spammer id (sendgr)
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[149.72.207.117 listed in wl.mailspike.net]
1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,
https://senderscore.org/blacklistlookup/
[149.72.207.117 listed in bl.score.senderscore.com]
15 GR_DOMAIN_SENDGR6 URI: Body contains known spammer URI (sendgr)
0.7 MPART_ALT_DIFF BODY: HTML and text parts are different
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 MIME_BASE64_TEXT RAW: Message text disguised using base64 encoding
0.0 MIME_HTML_ONLY_MULTI Multipart message only has text/html MIME parts
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
0.0 SARE_FROM_SPAM_WORD4 From address suggests this may be spam
1.8 COMBO_IMAGEONLY1 Appears to be an image only message
Subject: {SPAM?} You Have a New Secured Document
Hello,
A shared document has been made available for your review. Please use the secure access button below to open and view the file.
Shared Document for Review
Access the document securely using the link below.
Review Shared Document
Important
For security and confidentiality, please do not share or forward this access link unless authorized.
Thank you,
Docsend
This email was sent to notify you that a document has been shared for review.
© 2026. All rights reserved.
X-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Sun, 21 Jun 2026 05:32:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.99.3 (FreeBSD))
(envelope-from
id 1wbGOh-00000000LNK-2tI1
for dave@doctor.nl2k.ab.ca;
Sun, 21 Jun 2026 05:31:31 -0600
Resent-From: The Doctor
Resent-Date: Sun, 21 Jun 2026 05:31:31 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from wrqvcftr.outbound-mail.sendgrid.net ([149.72.207.117]:36028)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256
(Exim 4.99.3 (FreeBSD))
(envelope-from
id 1wbE5M-000000006ii-2qAr
for sales@nk.ca;
Sun, 21 Jun 2026 03:03:33 -0600
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=p3-i.com;
h=content-type:mime-version:from:subject:date:to:cc:content-type:date:
from:subject:to;
s=s1; t=1782032551;
bh=RRkDnOi0P2tMynw2T1RybKdX/x0KHqMvT3WgsDj6c0E=;
b=SZhOxbwJyFOPxxJzRQEaiezKmDpKj4oPuMeLQuaCjtTmir8WDhD2c/TYDzq7n13uNfKz
OmR1bMeIkvgufOEbVl3QqWlrhqLKyYFRn/osKcLUosrEi6eYGeM0wVNUXlBuQBeJ8bszQi
Y2CYCdg+6aQYtxd1MqZr/jDAMuL63YtLp6PBuINHUz33pUORB8C+G+pWD0ES7wghiHs5xn
OmxJq/FqxMG+x1x5w/O9pjW+aeATcjgCVYMp4KTc+7p3I7U5w9TTrtq5RNuQODXqBLNLKH
FIYbR8Ne7FAqPJg0ptkf8onXZXgDAmAU4gLg5NACQaq2L96kaLwyHNYr8kHcYaDA==
Received: by recvd-75586bd7d8-d4kqx with SMTP id recvd-75586bd7d8-d4kqx-1-6A37A8A7-6
2026-06-21 09:02:31.046117084 +0000 UTC m=+378627.690296285
Received: from [154.38.165.235] (unknown)
by geopod-ismtpd-25 (SG)
with ESMTP id G8LNT4TtSImDJiJN_Mo1JA
for
Sun, 21 Jun 2026 09:02:30.914 +0000 (UTC)
Content-Type: multipart/alternative; boundary="===============7540931904844975849=="
MIME-Version: 1.0
From: Docusend
Subject: You Have a New Secured Document
Date: Sun, 21 Jun 2026 09:02:31 +0000 (UTC)
Message-ID: <178203255046.14396.4451825813358312601@vmi2857862>
X-Mailer: Mailer-4985
X-SG-EID:
=?us-ascii?Q?u001=2Es9z3FKz3theG7asXgt6ElAca8kF7UH1zSPQkdebr12z1S4ULEooo0QM4q?=
=?us-ascii?Q?+52j8OhsDOMjRDtkxywGhq+PSF4dKdsXa=2FUYXIy?=
=?us-ascii?Q?KdF+0Y95d1mrun6=2FOwUEPGooaBBRNeH1n5xiN0O?=
=?us-ascii?Q?X=2FdKvQpQHuWMXon10DFJ5AbTvU4EK+chr0eTd9r?=
=?us-ascii?Q?RezDV6O7xrqPnIf5gIxmpYK7PcUORuSp4AQw7r1?=
=?us-ascii?Q?=2F1XpXZpMbWLgAljo14XEy8=3D?=
To: sales@nk.ca
X-Entity-ID: u001.imBUo2waVNFQ1splhTmG4A==
X-Spam_score: 39.2
X-Spam_score_int: 392
X-Spam_bar: +++++++++++++++++++++++++++++++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Shared Document Hello,
Content analysis details: (39.2 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[154.38.165.235 listed in will-spam-for-food.eu.org]
[154.38.165.235 listed in will-spam-for-food.eu.org]
[154.38.165.235 listed in will-spam-for-food.eu.org]
[154.38.165.235 listed in will-spam-for-food.eu.org]
[154.38.165.235 listed in will-spam-for-food.eu.org]
[154.38.165.235 listed in will-spam-for-food.eu.org]
[154.38.165.235 listed in will-spam-for-food.eu.org]
[154.38.165.235 listed in will-spam-for-food.eu.org]
[149.72.207.117 listed in will-spam-for-food.eu.org]
[149.72.207.117 listed in will-spam-for-food.eu.org]
[149.72.207.117 listed in will-spam-for-food.eu.org]
[149.72.207.117 listed in will-spam-for-food.eu.org]
[149.72.207.117 listed in will-spam-for-food.eu.org]
[149.72.207.117 listed in will-spam-for-food.eu.org]
[149.72.207.117 listed in will-spam-for-food.eu.org]
[149.72.207.117 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[149.72.207.117 listed in dnsbl.ahbl.org]
[149.72.207.117 listed in dnsbl.ahbl.org]
[149.72.207.117 listed in dnsbl.ahbl.org]
[149.72.207.117 listed in dnsbl.ahbl.org]
[154.38.165.235 listed in dnsbl.ahbl.org]
[154.38.165.235 listed in dnsbl.ahbl.org]
[154.38.165.235 listed in dnsbl.ahbl.org]
[154.38.165.235 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[149.72.207.117 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[149.72.207.117 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[149.72.207.117 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[149.72.207.117 listed in dnsbl.ahbl.org]
1.7 URIBL_CT_SURBL Contains an URL listed in the CT SURBL blocklist
[URI: u56462072.ct.sendgrid.net]
1.6 RCVD_IN_BRBL_LASTEXT RBL: No description available.
[149.72.207.117 listed in bb.barracudacentral.org]
-3.0 RCVD_IN_RP_CERTIFIED RBL: Sender in ReturnPath Certified - Contact
cert-sa@returnpath.net
[Excessive Number of Queries |
-2.0 RCVD_IN_RP_SAFE RBL: Sender in ReturnPath Safe - Contact
safe-sa@returnpath.net
[Excessive Number of Queries |
1.1 URIBL_GREY Contains an URL listed in the URIBL greylist
[URI: sendgrid.net]
-0.0 SPF_PASS SPF: sender matches SPF record
15 GR_DOMAIN_SENDGR1 Received contains spammer id (sendgr)
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[149.72.207.117 listed in wl.mailspike.net]
1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,
https://senderscore.org/blacklistlookup/
[149.72.207.117 listed in bl.score.senderscore.com]
15 GR_DOMAIN_SENDGR6 URI: Body contains known spammer URI (sendgr)
0.7 MPART_ALT_DIFF BODY: HTML and text parts are different
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 MIME_BASE64_TEXT RAW: Message text disguised using base64 encoding
0.0 MIME_HTML_ONLY_MULTI Multipart message only has text/html MIME parts
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
0.0 SARE_FROM_SPAM_WORD4 From address suggests this may be spam
1.8 COMBO_IMAGEONLY1 Appears to be an image only message
Subject: {SPAM?} You Have a New Secured Document
Hello,
A shared document has been made available for your review. Please use the secure access button below to open and view the file.
Shared Document for Review
Access the document securely using the link below.
Review Shared Document
Important
For security and confidentiality, please do not share or forward this access link unless authorized.
Thank you,
Docsend
This email was sent to notify you that a document has been shared for review.
© 2026. All rights reserved.