SCAMS | EMAIL | PHONE | MAP | TAGS | EMAIL ANALYSIS | IP LOCATOR
Click to go to Scammed.by homepage
Forward scams to - remove your name and email address first! TO CONTACT US CLICK HERE INSTEAD


Scam email #229369 - COMPLIMENTS OF THE DAY!!

Email info

The email was sent on 2017-05-19 13:47:47 and appeared to be from foreignremittancedepartment33@gmail.com but this address could have been spoofed.
If you replied to this email, your reply would have been sent to dr.robot_williams@yahoo.com which was the scammer's actual email address.
It was probably sent from 77.238.177.90 in Unknown, United Kingdom

Email header

Explains what each bit of the header means, and shows the journey the email took. Click here to show or hide it

Your content is below the advert

The scam


SpamAssassin Report (spam score: 10.4)


 pts rule name               description
---- ---------------------- --------------------------------------------------
 0.0 TVD_RCVD_IP4           Message was received from an IPv4 address
 0.0 TVD_RCVD_IP            Message was received from an IP address
 0.0 FREEMAIL_FROM          Sender email is commonly abused enduser mail provider
                            (foreignremittancedepartment33[at]gmail.com)
-0.0 RCVD_IN_DNSWL_NONE     RBL: Sender listed at http://www.dnswl.org/, no
                            trust
                            [77.238.177.90 listed in list.dnswl.org]
 0.5 RCVD_IN_SORBS_SPAM     RBL: SORBS: sender is a spam source
                            [77.238.177.90 listed in dnsbl.sorbs.net]
 0.0 DKIM_ADSP_CUSTOM_MED   No valid author signature, adsp_override is
                            CUSTOM_MED
 1.0 SPF_SOFTFAIL           SPF: sender does not match SPF record (softfail)
 1.6 SUBJ_ALL_CAPS          Subject is all capitals
 0.2 FREEMAIL_ENVFROM_END_DIGIT Envelope-from freemail username ends in
                            digit
                            (foreignremittancedepartment33[at]gmail.com)
 1.2 MISSING_HEADERS        Missing To: header
 0.1 DKIM_SIGNED            Message has a DKIM or DK signature, not necessarily valid
 1.9 REPLYTO_WITHOUT_TO_CC  REPLYTO_WITHOUT_TO_CC
 0.0 T_DKIM_INVALID         DKIM-Signature header exists but is not valid
 1.6 FORGED_MUA_MOZILLA     Forged mail pretending to be from Mozilla
 1.0 FREEMAIL_REPLYTO       Reply-To/From or Reply-To/body contain different
                            freemails
 1.2 NML_ADSP_CUSTOM_MED    ADSP custom_med hit, and not from a mailing list



Please be careful with the links in the above email - Scammed.by strongly suggests that you do not click on any links in the above message
The email above is most likely a scam but every now and then legitimate emails do come through, as do spam emails which are not attempting to defraud, so please use your judgement
You can contact ScamSearch at help at scammed.by for any information, help, or if you have spotted a legitimate email. Please link to the email you think is legitimate.
ScamSearch does not accept any responsibility for visitors enduring any issues as a result of following links in the above email and/or contacting the sender
Please do not contact the sender unless you know what you are doing (i.e. experienced scambaiters)

Comments

Where the scam probably came from



theScamBaiter freight bait archive, theFailure Cole baits   theFAILURE freight bait from theScamBaiter - Cole v2.0   theFAILURE freight bait from theScamBaiter - Rebait at Cole's   theFAILURE freight bait from theScamBaiter - the Martins Cole saga   theFAILURE Butch Driveshaft telemarketer phone baiting   theFAILURE freight bait from theScamBaiter - Anus Laptops commercial made by scammer   theFAILURE freight bait from theScamBaiter - script of Anus Laptops commercial made by scammer