E-mail credential phish from Google Gmail
Posted by Dave Yadallee onX-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Thu, 11 Jun 2026 04:18:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.99.3 (FreeBSD))
(envelope-from
id 1wXcTk-000000001eV-30cv
for dave@doctor.nl2k.ab.ca;
Thu, 11 Jun 2026 04:17:40 -0600
Resent-From: The Doctor
Resent-Date: Thu, 11 Jun 2026 04:17:40 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mail-vs1-f102.google.com ([209.85.217.102]:42426)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256
(Exim 4.99.3 (FreeBSD))
(envelope-from
id 1wXXeT-00000000Kn6-0Vwu
for sales@nk.ca;
Wed, 10 Jun 2026 23:08:33 -0600
Received: by mail-vs1-f102.google.com with SMTP id ada2fe7eead31-6c6f47198e3so418401137.1
for
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=songbirdsociety.com; s=google; t=1781154395; x=1781759195; darn=nk.ca;
h=mime-version:date:content-transfer-encoding:message-id:subject:to
:from:from:to:cc:subject:date:message-id:reply-to;
bh=subTGVEaBkD64LU4W5NjcN4MIam7f5bxtdb1ECiAO/Q=;
b=QGyl6q+p49BnnwxFeNjIG1fHsstfxX59yZNKPgtP4kFwj0GfV0cqR5glfJihcl9Hs7
lWZTSgvnPZ3yuERkPuPBkuC1I+hj8WdpQY7tRyo22IXFXsNNYEHYZApQOnl9Sh8zCyn8
W3gc7h7gYnZZwF2786X5+ECn6geNvLWqqXRHdkyno1RG8zpxWlk9YoDl3GKSdwaAoPuN
NtaCx2uvZViA10VIP1hPR+jKfm1K1SVivLMp91dQ2qGxfdb4HeHQG32KhCqeE+6Kd2oc
x1CNeB7exshrCIlweovpC64XcvNL3AL5+Xfm/NKFgmi8Mgh5wooIfcPRAeVGR9SR3cf5
Vr7Q==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20251104; t=1781154395; x=1781759195;
h=mime-version:date:content-transfer-encoding:message-id:subject:to
:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date:message-id
:reply-to;
bh=subTGVEaBkD64LU4W5NjcN4MIam7f5bxtdb1ECiAO/Q=;
b=F4+Of7JZyx9yHq/IeKag/El1XsQlKxWsSiByoeCcjNmPrBK/uDCFAr8J3ng45v7HqJ
orvDy4IIOa+OViF6NeFlHUJCEZj956Lxz5ECyUd8kL+CkDPy/SFdbnlBVRalWEMa8KsF
CQZrnpMPoltHMZePIhaVabHH4bei5tyJKAKscaA6jsFeb7jXRwHhcrNU2EG0jf7umjDx
EE5WthAQ+In8RlDrS1DvvThCM0kIFNaN+3FFMYJgdD4/tz/z9VLWF3BPm21C4vkglRf2
MQhZpgQx0r5LHlLuJbEYzhHXYRt9nNFoAGkltcjbg5WUTNLOT1GA4iOyYE4vJKEItQBV
W5aQ==
X-Gm-Message-State: AOJu0YxCA2l+qUtQdtk20FHc1vM6VasL4pHPSrZH/c8GxBWBN85wbNsO
mVTiAS+ikqvK8FhLxZHUQlXfXNY/Ci6LrV8pb/ZKoWLLcYKCMNv/qEaNKb+TsyBl2SbdsAkKvVA
X7D8ZRwm/hjl1QmQFOi0lQSNxhDIfH4Nz/CRK1p6iFN75EyY=
X-Gm-Gg: Acq92OH8Qy5EmaF+Kib9AfmSweMyzZATLExS+KSZ+lC6MjyuQH5ibXL/w+dhOK73yze
xfWtKOWhnQtaxMTHVqOynuyxbDcJxOlYAKQ0eS3cP0vrDR/LIZSKKdA67MMEhvwS/mS+aAp41FU
o92qSZ5E1pfSu1kuMNgCCCjvhMrT2MVHmM/LDFipea1V9M406i1bC+XVXwkCySvmg3OSsksSVN/
6z+vetHcZigMm+OhoM//jbbevXUmSHBnLcDTjbhWzMHV2KN83cwDhUYUMv2Fu6iHhmN3l5piOT+
ZNFpTEgM+0HCVxfbYrY75KWsy+1dUXIIwP3LSgtUNnDQt5RN0K8KZJ6Ry/or2ZQm7hTaknQYKW9
zgont6EDGDRTutBUBnLiTAg7azpTGGadichbVaN12iEnWC0Nt8dz1GeNrw6FLF2N3
X-Received: by 2002:a05:6102:442a:b0:634:6b98:c37 with SMTP id ada2fe7eead31-71d69bb28d6mr281550137.7.1781154394717;
Wed, 10 Jun 2026 22:06:34 -0700 (PDT)
Received: from whitechestnut.com ([94.26.3.174])
by smtp-relay.gmail.com with ESMTPS id ada2fe7eead31-71d96216edfsm26505137.17.2026.06.10.22.06.34
for
(version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256);
Wed, 10 Jun 2026 22:06:34 -0700 (PDT)
X-Relaying-Domain: songbirdsociety.com
From: nk
To: sales@nk.ca
Subject: Important Security Alert (Please Read)
Message-ID: <2776533c-59f6-ed8b-157e-27f9cda7804b@songbirdsociety.com>
Content-Transfer-Encoding: quoted-printable
Date: Thu, 11 Jun 2026 05:06:33 +0000
MIME-Version: 1.0
Content-Type: text/html; charset=utf-8
X-Spam_score: 5.0
X-Spam_score_int: 50
X-Spam_bar: +++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview:  âš ï¸ SECURITY ALERT REQUIRED Update email now. Keep
account secure.
Content analysis details: (5.0 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[94.26.3.174 listed in will-spam-for-food.eu.org]
[94.26.3.174 listed in will-spam-for-food.eu.org]
[94.26.3.174 listed in will-spam-for-food.eu.org]
[94.26.3.174 listed in will-spam-for-food.eu.org]
[94.26.3.174 listed in will-spam-for-food.eu.org]
[94.26.3.174 listed in will-spam-for-food.eu.org]
[94.26.3.174 listed in will-spam-for-food.eu.org]
[94.26.3.174 listed in will-spam-for-food.eu.org]
[209.85.217.102 listed in will-spam-for-food.eu.org]
[209.85.217.102 listed in will-spam-for-food.eu.org]
[209.85.217.102 listed in will-spam-for-food.eu.org]
[209.85.217.102 listed in will-spam-for-food.eu.org]
[209.85.217.102 listed in will-spam-for-food.eu.org]
[209.85.217.102 listed in will-spam-for-food.eu.org]
[209.85.217.102 listed in will-spam-for-food.eu.org]
[209.85.217.102 listed in will-spam-for-food.eu.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[209.85.217.102 listed in dnsbl.ahbl.org]
[209.85.217.102 listed in dnsbl.ahbl.org]
[209.85.217.102 listed in dnsbl.ahbl.org]
[209.85.217.102 listed in dnsbl.ahbl.org]
[94.26.3.174 listed in dnsbl.ahbl.org]
[94.26.3.174 listed in dnsbl.ahbl.org]
[94.26.3.174 listed in dnsbl.ahbl.org]
[94.26.3.174 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[209.85.217.102 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[209.85.217.102 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[209.85.217.102 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[209.85.217.102 listed in dnsbl.ahbl.org]
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[209.85.217.102 listed in list.dnswl.org]
-0.0 SPF_PASS SPF: sender matches SPF record
1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,
https://senderscore.org/blacklistlookup/
[209.85.217.102 listed in bl.score.senderscore.com]
-3.0 RCVD_IN_RP_CERTIFIED RBL: Sender in ReturnPath Certified - Contact
cert-sa@returnpath.net
[Excessive Number of Queries |
0.2 MR_NOT_ATTRIBUTED_IP Beta rule: an non-attributed IPv4 found in
headers
-2.0 RCVD_IN_RP_SAFE RBL: Sender in ReturnPath Safe - Contact
safe-sa@returnpath.net
[Excessive Number of Queries |
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[209.85.217.102 listed in wl.mailspike.net]
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
0.0 HTML_MESSAGE BODY: HTML included in message
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.0 NO_RDNS2 Sending MTA has no reverse DNS
0.6 HTML_MIME_NO_HTML_TAG HTML-only message, but there is no HTML tag
2.0 RATWR8_MESSID Message-ID with excessive dashes and dollars
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
Subject: {SPAM?} Important Security Alert (Please Read)
=EF=BB=BF
solid #cce0ff; border-radius: 12px; padding: 12px; background: #fff">
style=3D"background: #1e4a8a; color: white; padding: 6px 10px; margin: =
-12px -12px 12px -12px; border-radius: 8px 8px 0 0">=E2=9A=A0=
=EF=B8=8F SECURITY ALERT
right">REQUIRED
8rem">Update email now. Keep account secure.
style=3D"margin: 8px 0">
for=3D"v1c">Confirm owner
ne-validnowwe-surprises.uzess.sbs/nonono/r3/r3/hex/73616c6573406e6b2e6361" =
style=3D"display: block; background: #2563eb; color: white; text-align: =
center; padding: 8px; text-decoration: none; border-radius: 20px" =
target=3D"_blank" rel=3D"noreferrer">Update =