McAfee Phish from Google GMail Part 1
Posted by Dave Yadallee onX-Mozilla-Status2: 00000000
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Tue, 19 May 2026 07:39:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.99.3 (FreeBSD))
(envelope-from
id 1wPKet-00000000N29-1iwE
for dave@doctor.nl2k.ab.ca;
Tue, 19 May 2026 07:38:55 -0600
Resent-From: The Doctor
Resent-Date: Tue, 19 May 2026 07:38:55 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mail-pj1-f70.google.com ([209.85.216.70]:46367)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256
(Exim 4.99.3 (FreeBSD))
(envelope-from
id 1wPKZI-00000000I31-0srb
for root@doctor.nl2k.ab.ca;
Tue, 19 May 2026 07:33:18 -0600
Received: by mail-pj1-f70.google.com with SMTP id 98e67ed59e1d1-3663d5e9bf4so3132769a91.1
for
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=google.com; s=20251104; t=1779197537; x=1779802337; darn=doctor.nl2k.ab.ca;
h=to:from:subject:date:message-id:sender:reply-to:mime-version:from
:to:cc:subject:date:message-id:reply-to;
bh=aj1/Of3xydDnqEpxl26sCUZqYHa35/wDtOOTqSLbNvA=;
b=M6QdcAamwwLR44gPkbLiqU9Y5+FYRN86aIv1ft9tIAQcCKCFy+aF787aoszfN8HMBO
CY4qSdU7JGGyOv73eoJBCTcpOqtj0t12WAmBVJfIdUKmOheNROs68WLCYcnt/TNNGOGd
0ze4WNpJjaXr1FCaOxvsQ0I/V3ZzX/7Yr2skbndf5cCo8J/TgFW7WBcM/Vj9HvBzAJ/V
ApAF4YVw/XdjidaPMECEu82N8U1CHJijtBATw/Y7XF/32wk8lvkWHX8kAsAttbWHAPCy
DkfgxzQ3zmjnN0iC8jt3rp2YuLNsNSP11r0f0mEJfhzC4iD8Edkhi6wMOXbZBDyimv0l
R6oQ==
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=inrvsa-com.20251104.gappssmtp.com; s=20251104; t=1779197537; x=1779802337; darn=doctor.nl2k.ab.ca;
h=to:from:subject:date:message-id:sender:reply-to:mime-version:from
:to:cc:subject:date:message-id:reply-to;
bh=aj1/Of3xydDnqEpxl26sCUZqYHa35/wDtOOTqSLbNvA=;
b=b25OAhHXeo5kusUrVWI03iCuAGjfQk+HdSzjoJikI4pV/l8LSohYJALDYrgzWsNPIg
8DOw5YD/mHTRb5cHuIWpr0DytNg07qDxAyJ4zGsMXT5YM/WDlH+IrdRZgA9Nue0zJuz4
bYiAewkaf+ecwl3NH9A/06ld7tTLqv49WZOWlVr8wx70dkAH9W9Wi+cPJYWKJdiWH83K
BMx+5pk6XD1oOi7GzIA80tye7Qvn/nNZ71Nnz+yYvqCgxNpoP5ShiLpMHM82GGpV03jE
x1z77isJzV4/8dzw7NpSOukAZbHdjVZkQBawwUljreZovM32BNwW3DRn0Jb1oQzyoX+n
Xitw==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20251104; t=1779197537; x=1779802337;
h=to:from:subject:date:message-id:sender:reply-to:mime-version
:x-gm-message-state:from:to:cc:subject:date:message-id:reply-to;
bh=aj1/Of3xydDnqEpxl26sCUZqYHa35/wDtOOTqSLbNvA=;
b=muWciAvMyLaOMuuBsuXMNRlsJPaBDPS8Dx/G0NUqOYf87Mec0OsxQakEdBQs/0Sh4W
+Yr0GWdRg4eLcymy9JGQ5d+ul0C0wI76vhsRX37an9FVbQqpCm0/Dss+M643bIjDftDq
2cFokkpHlNZlidauvmDxKO1DaNRTRy7OERd4BCXs1dInmcQw8eUCaE4DIdgf7z47CgUy
8Yd3OJt2nUvPw80oRdgy2xCLcBqm5DmZ1VVzLpZ1ZUmVfDqrU0Hn3r2z/uTXCH9etIrU
VRrzp+H9jTwH25dxaZrNAdDfhIlayFWc09CLXKxNhUZ+nBTVnSnVqILvQp/m5035ZQaa
1YRw==
X-Gm-Message-State: AOJu0Yxly36EKqDcYHJvycs3PeehHHjjLIM7GgN+Ctg7+Rwo/c7Kvq89
Rs9/6Waf96cBj+usjrWAl/0MzW+Oc9KbSV03SnjJsJewlaHMu9cBkHAwDZIlJU9bPAKISnW+gL2
E0ijrtearlld0dEB7ZlsUIqF6KVDU06hShoP6AfqZzyKhs4Ae1G9hKA==
MIME-Version: 1.0
X-Received: by 2002:a17:90b:5407:b0:36a:9d7:859f with SMTP id
98e67ed59e1d1-36a09d7887fmr2084763a91.14.1779197537304; Tue, 19 May 2026
06:32:17 -0700 (PDT)
Reply-To: Adena Zirngibl
Sender: Google Calendar
Message-ID:
Date: Tue, 19 May 2026 13:32:17 +0000
Subject: Invitation: Current processing progress is now available @ Wed 20 May
2026 10:31am (HKT) (root@doctor.nl2k.ab.ca)
From: Adena Zirngibl
To: root@doctor.nl2k.ab.ca
Content-Type: multipart/mixed; boundary="000000000000324b9606522bb5dc"
X-Spam_score: 5.4
X-Spam_score_int: 54
X-Spam_bar: +++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Current processing progress is now available Wednesday 20
May 2026 ⋅ 10:31am Hong Kong Standard Time McAfee 📄 Receipt Date: Tuesday,
19 May 2026 21:31:38Receipt id: YX53E4GPA8FEVC📞 Customer Support Request:
1856 6206857.Plan continues with confirmed service renewalDear Customer,This
message is [...]
Content analysis details: (5.4 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[209.85.216.70 listed in dnsbl.ahbl.org]
[209.85.216.70 listed in dnsbl.ahbl.org]
[209.85.216.70 listed in dnsbl.ahbl.org]
[209.85.216.70 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[209.85.216.70 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[209.85.216.70 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[209.85.216.70 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[209.85.216.70 listed in dnsbl.ahbl.org]
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[209.85.216.70 listed in will-spam-for-food.eu.org]
[209.85.216.70 listed in will-spam-for-food.eu.org]
[209.85.216.70 listed in will-spam-for-food.eu.org]
[209.85.216.70 listed in will-spam-for-food.eu.org]
[209.85.216.70 listed in will-spam-for-food.eu.org]
[209.85.216.70 listed in will-spam-for-food.eu.org]
[209.85.216.70 listed in will-spam-for-food.eu.org]
[209.85.216.70 listed in will-spam-for-food.eu.org]
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[209.85.216.70 listed in list.dnswl.org]
-2.0 RCVD_IN_RP_SAFE RBL: Sender in ReturnPath Safe - Contact
safe-sa@returnpath.net
[Excessive Number of Queries |
-3.0 RCVD_IN_RP_CERTIFIED RBL: Sender in ReturnPath Certified - Contact
cert-sa@returnpath.net
[Excessive Number of Queries |
0.3 LONGWORD BODY: Uses overlong words
0.6 MEGALONGWORD BODY: Uses really overlong words
0.6 J_CHICKENPOX_84 BODY: 8alpha-pock-4alpha
1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL,
https://senderscore.org/blacklistlookup/
[209.85.216.70 listed in bl.score.senderscore.com]
-0.0 RCVD_IN_MSPIKE_H3 RBL: Good reputation (+3)
[209.85.216.70 listed in wl.mailspike.net]
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 HTML_FONT_SIZE_HUGE BODY: HTML font size is huge
2.0 RATWR8_MESSID Message-ID with excessive dashes and dollars
0.0 T_DKIM_INVALID DKIM-Signature header exists but is not valid
-0.0 RCVD_IN_MSPIKE_WL Mailspike good senders
0.6 LONG_INVISIBLE_TEXT Long block of hidden text - bayes poison?
Subject: {SPAM?} Invitation: Current processing progress is now available @ Wed 20 May 2026 10:31am (HKT) (root@doctor.nl2k.ab.ca)