Loan spam from Google Gmail Part 1
Posted by Dave Yadallee onX-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Sun, 25 Jan 2026 05:22:00 -0700
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from
id 1vjz7u-00000000CNW-1qI9
for dave@doctor.nl2k.ab.ca;
Sun, 25 Jan 2026 05:21:58 -0700
Resent-From: The Doctor
Resent-Date: Sun, 25 Jan 2026 05:21:58 -0700
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mail-pl1-f227.google.com ([209.85.214.227]:57495)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256
(Exim 4.98.2 (FreeBSD))
(envelope-from
id 1vjvjQ-000000006Zf-24mL
for root@nk.ca;
Sun, 25 Jan 2026 01:44:37 -0700
Received: by mail-pl1-f227.google.com with SMTP id d9443c01a7336-2a1022dda33so20822855ad.2
for
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20230601; t=1769330615; x=1769935415;
h=thread-index:thread-topic:mime-version:subject:message-id:reply-to
:from:date:dkim-signature:dkim-filter:x-gm-gg:x-gm-message-state
:from:to:cc:subject:date:message-id:reply-to;
bh=xyiAz+qFQFRgJleyuroZKT/FG0rie6dGemrPIhufYM0=;
b=j373JC4SiWs5e6C/4/5yd2xqoVcwO7Ga0rP1FalRzznX4UQ/NiLaapmmSjy7AfwLlC
b+enwFm6pSydQIEUVGrh2FeiNbMUq+VaZJ9QWaziyaG092AJ5XVVzdZ59ME8NEBuLcO0
+3iQAUKft/qjvMyuEvLBplKVQOaMM0A5TOREbvYomJGN1BuvOMjAAo8814897XBiyJAL
kYNX9/3BjsilYZwChyvWdvB4NQ3ONc4Zm/hWiwXz+z9guXMbI0n7qCWlRq9+iEtIg8OK
C3QJL/JbE7vADyEp9vI1oIsybC29PaRjX+uPFLpnCjy5imSNzEXTGB+MO2SvTEQOiOxo
+HcQ==
X-Forwarded-Encrypted: i=1; AJvYcCWli4ASqYRqpl1x29krpdn8mZkVFf+wIDMv/3t6pXnWYGpRq82ZMhsEcHGia+vaAtwW+WTp@nk.ca
X-Gm-Message-State: AOJu0YwRQtBi7BwQhgiH4kd29bEbzQGAgjhwhucqRKjtsvNgRzmN5eOL
GKd8SvdpEnHjAnzkRobTDXChSCUKeF5I6iQm8KPcrP2J8OXPZrjxKdkgSKa3mrsqfm0nV9lw9sw
BTjMGc9Qye83nKCI87EqvtzalcDGV1/bMYYLo
X-Gm-Gg: AZuq6aLDBIoylD6b4qohxcuQRzXtzcT06X3CyvKs9SwenmhXC5xtKulbg9nLoq5nQ7H
z0MuvtVuZH4kezARjTYlx8jCnut1+qP6kc+YdEIJPIp7XQI9jv/FF+nPmDHk4IUddZUnKudSX9X
tikeI5z8ujleCIGHnYFEm9M5qhiQwPlYXLTGfiMEdC56wDR5fsXPcl38KYFONr9mBghZ03zv1Jr
W0LLaxAbM/xyXKiMcszmz4p9smbZcd0CGD0Z5DXJSnK+feHT88pmJ93Tg3TgMkYd63csVOqzhUP
yUUpwytVPuCiLFdxLq5VCooL3ILCn80ZHeKpWQuQB3lytCYmLvaseEESLxYFNihww/XrFexxn26
l
X-Received: by 2002:a17:902:e892:b0:29f:2734:6ffb with SMTP id d9443c01a7336-2a84523ad24mr10420565ad.22.1769330614933;
Sun, 25 Jan 2026 00:43:34 -0800 (PST)
Received: from mail.activos.com.co ([190.216.205.98])
by smtp-relay.gmail.com with ESMTPS id d9443c01a7336-2a804bef6a3sm6685675ad.42.2026.01.25.00.43.34
(version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128);
Sun, 25 Jan 2026 00:43:34 -0800 (PST)
X-Relaying-Domain: activos.com.co
Received: from mail.activos.com.co (localhost [127.0.0.1])
by mail.activos.com.co (Postfix) with ESMTPS id 06A0F1752093;
Sun, 25 Jan 2026 03:40:38 -0500 (-05)
Received: from localhost (localhost [127.0.0.1])
by mail.activos.com.co (Postfix) with ESMTP id 21953175208A;
Sun, 25 Jan 2026 03:40:37 -0500 (-05)
DKIM-Filter: OpenDKIM Filter v2.9.2 mail.activos.com.co 21953175208A
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=activos.com.co;
s=3617E2B2-E791-11E8-974D-5040C871AF00; t=1769330437;
bh=fEAiQJpJ/ZkXYaZJ5ERIvobQemAsK9z57oDRa26LTjs=;
h=Date:From:Reply-To:Message-ID:Subject:MIME-Version:Content-Type;
b=SzP/z03VE7o+Ca1ISWDkyyWiX99km9ZQilM8EElQB6cVbQE5Ji9CDxFjswmitdsbd
nUD1+SJnTuqO+qBvvI/elGkUMhGezNoMt9D2Fyhqw2tVmRu/hoDDPXilSp+2b88Fct
uEErswEYr4hf6F6lrjbxatBTSBw0q1Dfom6KE6jU=
X-Amavis-Modified: Mail body modified (using disclaimer) - mail.activos.com.co
Received: from mail.activos.com.co ([127.0.0.1])
by localhost (mail.activos.com.co [127.0.0.1]) (amavisd-new, port 10026)
with ESMTP id SgJUA-Qizg5f; Sun, 25 Jan 2026 03:40:36 -0500 (-05)
Received: from mail.activos.com.co (localhost [127.0.0.1])
by mail.activos.com.co (Postfix) with ESMTP id 9DA27175209C;
Sun, 25 Jan 2026 03:40:32 -0500 (-05)
Date: Sun, 25 Jan 2026 03:40:32 -0500 (COT)
From: QIA
Reply-To: QIA
Message-ID: <1799386315.4973921.1769330432525.JavaMail.zimbra@activos.com.co>
Subject: We provide funding for projects....
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_Part_4973920_1697717932.1769330432521"
X-Mailer: Zimbra 8.6.0_GA_1153 (zclient/8.6.0_GA_1153)
Thread-Topic: We provide funding for projects....
Thread-Index: AKBKMd5N/WghFKajlqACJx00A+lALg==
X-Spam_score: 7.4
X-Spam_score_int: 74
X-Spam_bar: +++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Hello, If you are currently seeking financial assistance,
our organization offers funding support to individuals and enterprises for
a wide range of projects. If you would like more information about this op
[...]
Content analysis details: (7.4 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[209.85.214.227 listed in dnsbl.ahbl.org]
[209.85.214.227 listed in dnsbl.ahbl.org]
[209.85.214.227 listed in dnsbl.ahbl.org]
[209.85.214.227 listed in dnsbl.ahbl.org]
[190.216.205.98 listed in dnsbl.ahbl.org]
[190.216.205.98 listed in dnsbl.ahbl.org]
[190.216.205.98 listed in dnsbl.ahbl.org]
[190.216.205.98 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[209.85.214.227 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[209.85.214.227 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[209.85.214.227 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[209.85.214.227 listed in dnsbl.ahbl.org]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[190.216.205.98 listed in will-spam-for-food.eu.org]
[190.216.205.98 listed in will-spam-for-food.eu.org]
[190.216.205.98 listed in will-spam-for-food.eu.org]
[190.216.205.98 listed in will-spam-for-food.eu.org]
[190.216.205.98 listed in will-spam-for-food.eu.org]
[190.216.205.98 listed in will-spam-for-food.eu.org]
[190.216.205.98 listed in will-spam-for-food.eu.org]
[190.216.205.98 listed in will-spam-for-food.eu.org]
[209.85.214.227 listed in will-spam-for-food.eu.org]
[209.85.214.227 listed in will-spam-for-food.eu.org]
[209.85.214.227 listed in will-spam-for-food.eu.org]
[209.85.214.227 listed in will-spam-for-food.eu.org]
[209.85.214.227 listed in will-spam-for-food.eu.org]
[209.85.214.227 listed in will-spam-for-food.eu.org]
[209.85.214.227 listed in will-spam-for-food.eu.org]
[209.85.214.227 listed in will-spam-for-food.eu.org]
0.0 RCVD_IN_VALIDITY_CERTIFIED_BLOCKED RBL: ADMINISTRATOR NOTICE: The
query to Validity was blocked. See
https://knowledge.validity.com/hc/en-us/articles/20961730681243
for more information.
[209.85.214.227 listed in sa-trusted.bondedsender.org]
-3.0 RCVD_IN_RP_CERTIFIED RBL: Sender in ReturnPath Certified - Contact
cert-sa@returnpath.net
[Excessive Number of Queries |
-2.0 RCVD_IN_RP_SAFE RBL: Sender in ReturnPath Safe - Contact
safe-sa@returnpath.net
[Excessive Number of Queries |
0.0 RCVD_IN_VALIDITY_SAFE_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to
Validity was blocked. See
https://knowledge.validity.com/hc/en-us/articles/20961730681243
for more information.
[209.85.214.227 listed in sa-accredit.habeas.com]
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[209.85.214.227 listed in wl.mailspike.net]
0.0 RCVD_IN_VALIDITY_RPBL_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to
Validity was blocked. See
https://knowledge.validity.com/hc/en-us/articles/20961730681243
for more information.
[209.85.214.227 listed in bl.score.senderscore.com]
1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,
https://senderscore.org/blacklistlookup/
[209.85.214.227 listed in bl.score.senderscore.com]
-0.0 SPF_PASS SPF: sender matches SPF record
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid
0.1 DKIM_INVALID DKIM or DK signature exists, but is not valid
0.2 MR_NOT_ATTRIBUTED_IP Beta rule: an non-attributed IPv4 found in
headers
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[209.85.214.227 listed in list.dnswl.org]
1.2 MISSING_HEADERS Missing To: header
0.2 FREEMAIL_REPLYTO_END_DIGIT Reply-To freemail username ends in digit
[qia7625331(at)gmail.com]
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 NO_RDNS2 Sending MTA has no reverse DNS
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
1.9 REPLYTO_WITHOUT_TO_CC No description available.
2.5 FREEMAIL_FORGED_REPLYTO Freemail in Reply-To, but not From
Subject: {SPAM?} We provide funding for projects....