The email was sent on 2019-03-08 05:31:13 and appeared to be from firstname.lastname@example.org but this address could have been spoofed.
If you replied to this email, your reply would have been sent to email@example.com which was the scammer's actual email address.
It was probably sent from 220.127.116.11 in Shenzhen, China
Explains what each bit of the header means, and shows the journey the email took. Click here to show or hide it
|X-Apparently-To:||Used when there is no 'to' field in the header, does the same thing (says what email address(es) the email is sent to||[email address removed] Fri, 08 Mar 2019 02:31:13 +0000|
|Return-Path:||The address the email was sent from, or at least the one this email should be 'bounced' back to if it can not be delivered. Often spammers and scammers modify the email header to set a different return-path||[email address removed]|
|X-YahooFilteredBulk:||The IP here was blacklisted by Yahoo for sending spam||18.104.22.168|
|Received-SPF:||Returns 'pass' if the email was sent legitimately, 'neutral' if the server thinks nothing is right or wrong, 'soft fail' if it's not a serious issue, 'fail' if the email was sent by an unauthorised user or IP address (often if the mail server is hacked into), 'none' if the server can't tell, 'permerror' if the mail client does not understand what the server is saying, 'temperror' if the client can't connect to the server. More info||none (domain of fndlni.top does not designate permitted sender hosts)|
|X-YMailISG:||A unique ID added by the Yahoo Inbound Spam Guard||JcGrTYYWLDte50PMI4AXMJ.WLDcNQdmHWUGfRWi5bTarO0YK Wpzt7tQHJ8KjI8_UQwCb..6JOmA6O7WKzcumct91qpq4Ap9LWC7oI2wzd9df NbP3tHudtGzsuqyiIAFecfNi4aDQjNUlwXpr.ibM3anJBse7sIZYZuQ9iYy8 nmlhMF6r9U7v5PXNnVYpC_4vCGcPbV3Hs3B0V0rJzIHp0M9b1bIbk5slDG7Y RZz72f9Ag2s_GIZXCgngXKWJtkTejEpxSktMqSuvHLf3JE6tfNftic4Gahf3 Fo5PvQvpzDyWTcJygaKNvCkhJREkDZsOwXo6I4yfb3ZnR4u8CZzMMsmecBKQ dGxXczPTzPfZoyxEhXedn.PUMHDM9XQXf3QX9xjNPiMkSlVvKOkkdQZHDLc4 OT07zFpo2k3.2ZR46sI6pjsurjXwFkYjqfqDgNDExv4VyNCR74aIpGKuAh85 QCCx5T2raB3WkxTZl6FlV2AGklRpTwP5.8cjgf0QNhP3yhOtHjfOx1TUAuYw NvtL7qMX._lQ1BbmQ0hkod3q2JMd2.elAZM8.mArSxAfxFOBZGj2aTvepiQg 0DopM40IJbAr4eB7zXfXhQfPeLY_kL82dtfLwc16X4raMOse8nyVkWdM_9pw fjY39nAMoOjDSwdemKMAcL6pljhPS9LkptLNE8S1Ioha58yLBDrhxVsYMRzc SL_lU89Qu8E0.AbuLTYI4JmauFjCASBaRgAS8Jmfo_bSeDTpzVslvLrny5q7 39ncLjURBvaYSc.A5d5MYDyT4At.vcJGRqjadIFkx2YuH5W4rXEF5202GCgE y1ljtlaOHNB3qWpciXLActvIZc5RtkXFEz4_qFhg51h_CoVsfbLqK7HSkdOr N2c__nYNH.4UtVMfphPHvFUnAx2qsS85MAUjxOyF_D.3Rk7HNkP10djS7j2X eH1D1Qt7Gz3TFzWluKs_M4rm4ozhzq.cruS87z2epAb0MySil8uMokqSG9AX qTbXRTh.2L_CfXon6SXWGkAiYG3sKsoB5uTlnvW4KwTKj0_SNrMPRLRUpTyM YIKufXB7Okf4GImF4nKqGcK5fCZD2WvO0OWnAxAkA8nqI4ycnOfGJ0w2djHJ YTfGHk_T70GHZWAK00hDtUW3h6Usc2znu3cR2.Suc1VIeSB5DRRwnRA-|
|X-Originating-IP:||The IP address the email was originally sent from, sometimes wrong - the bottom 'Received' field in the email header is the most reliable indicator of what IP the email came from||[22.214.171.124]|
|Authentication-Results:||Returns the result given in the Received-SPF field, and says spf=pass if the email passed authentication. Also uses the DKIM signature, and equally returns dkim=pass if the DKIM signature was okay. More info||mta4255.mail.bf1.yahoo.com from=fndlni.top; dkim=neutral (no sig)|
|Received:||Part of the journey the email took to reach us/you, these tend to be in the order bottom-to-top so the first 'Received' is the last step the email took and the last 'Received' is the first step the email took||from 127.0.0.1 (EHLO fndlni.top) (126.96.36.199) by mta4255.mail.bf1.yahoo.com with SMTP; Fri, 08 Mar 2019 02:31:11 +0000|
|Received:||Part of the journey the email took to reach us/you, these tend to be in the order bottom-to-top so the first 'Received' is the last step the email took and the last 'Received' is the first step the email took||from XM01 (unknown [188.8.131.52]) by fndlni.top (Postfix) with ESMTPA id AE416124C6E for [email address removed] Sun, 3 Mar 2019 21:45:25 -0500 (EST)|
|Disposition-Notification-To:||A read-receipt/delivery notification was requested by the sender, and will be sent to this email address (usually the one the email was sent from). The sender was likely notified that this email was read||[email address removed]|
|MIME-Version:||Included, usually 1.0, if the email or header contains any non-ASCII characters or non-text attachments, or if the email is multi-part (contains a plain text version plus an HTML one, lets the user's email client or webmail decide which version to display)||1.0|
|From:||This is the address the email was apparently sent from||=?utf-8?B?S2VsbGVu?= [email address removed]|
|To:||The email address(es) the email was sent to||[email address removed]|
|Reply-To:||This is the email address any reply would be sent to by default||[email address removed]|
|Date:||The date/time the email was sent||4 Mar 2019 10:43:17 +0800|
|Subject:||The subject of the email||=?utf-8?B?44CQRmFjdG9yeSBEaXJlY3TjgJFpbmplY3Rpb24gbW91bGQgd2l0aCBWYXJpb3VzIFN0eWxlcw==?=|
|Content-Type:||What type of content the email usually is, usually text/html, and what character set is used||text/html; charset=utf-8|
|Content-Transfer-Encoding:||How the email has been encoded to comply with regulations (e.g. maximum characters per line)||base64|
|Content-Length:||The size of the email, in bytes||7107|
How are you doing?
We are a venture specializing in the manufacture and export of molding .And export of injection mold more than five years.We have profuse designs with series quality grade, and expressly,our price is very competitive because we are manufactory,we are the source.
Clould you please help to give me reply today?
Shenzhen Qunxingwang Mould Technology Co., Ltd
Add: 1/F Building 126,Shifeng Science and Technology Park,Mashantou Village,
Gongming Town,Guangming New District ,Shenzhen,China.
Tel.: +86 0755 27460423
Mobile: +86 18802584057
pts rule description ---- ---------------------- -------------------------------------------------- 0.0 TVD_RCVD_IP Message was received from an IP address 0.0 TVD_RCVD_IP4 Message was received from an IPv4 address 1.3 RCVD_IN_RP_RNBL RBL: Relay in RNBL, https://senderscore.org/blacklistlookup/ [184.108.40.206 listed in bl.score.senderscore.com] 1.7 DEAR_SOMETHING BODY: Contains 'Dear (something)' 2.0 BASE64_LENGTH_79_INF BODY: base64 encoded email part uses line length greater than 79 characters 0.0 HTML_EXTRA_CLOSE BODY: HTML contains far too many close tags 1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts 0.0 HTML_MESSAGE BODY: HTML included in message 0.0 HTML_NONELEMENT_30_40 BODY: 30% to 40% of HTML elements are non-standard 0.1 FROM_EXCESS_BASE64 From: base64 encoded unnecessarily 0.1 MISSING_MID Missing Message-Id: header 0.6 HTML_MIME_NO_HTML_TAG HTML-only message, but there is no HTML tag
Please be careful with the links in the above email - Scammed.by strongly suggests that you do not click on any links in the above message
The email above is most likely a scam but every now and then legitimate emails do come through, as do spam emails which are not attempting to defraud, so please use your judgement
You can contact ScamSearch at help at scammed.by for any information, help, or if you have spotted a legitimate email. Please link to the email you think is legitimate.
ScamSearch does not accept any responsibility for visitors enduring any issues as a result of following links in the above email and/or contacting the sender
Please do not contact the sender unless you know what you are doing (i.e. experienced scambaiters)