CAA Emergency kit phish from Google Gmail
Posted by Dave Yadallee on
Return-path:
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Sat, 13 Sep 2025 13:03:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from)
id 1uxVVg-00000000ImH-3Tzc
for dave@doctor.nl2k.ab.ca;
Sat, 13 Sep 2025 13:02:08 -0600
Resent-From: The Doctor
Resent-Date: Sat, 13 Sep 2025 13:02:08 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mail-il1-f181.google.com ([209.85.166.181]:60840)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256
(Exim 4.98.2 (FreeBSD))
(envelope-from)
id 1uxVPO-00000000HlC-3oal
for sales@nk.ca;
Sat, 13 Sep 2025 12:55:47 -0600
Received: by mail-il1-f181.google.com with SMTP id e9e14a558f8ab-403a893fb99so15291845ab.1
for; Sat, 13 Sep 2025 11:54:52 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=owa-prostaffing-services-com.20230601.gappssmtp.com; s=20230601; t=1757789686; x=1758394486; darn=nk.ca;
h=message-id:content-disposition:reply-to:list-unsubscribe:precedence
:to:date:subject:mime-version:from:from:to:cc:subject:date
:message-id:reply-to;
bh=x7HvqZ7LO+eXxnbg50JCG4DTzMFG798OPMH+nfEGH0Q=;
b=vz4uCeH9fdyHD/RvvsrgS2bMxC9tsG3dt0TAa+f5+wxXI6klidnbPGHDEvvsuOenQp
55bZCyVeQVoCRVjXuUDuGUc4qTxWvsT4ymGoRsvOWQLTLYA/7Goyw1UtNuHJXad8Llo3
It7+HEoW5vq05htY3YOL6tFoGYmNQYOtCmSwIY/iaoEmVUZ6SjK/Px4jgFrEFLAddj2c
GzgMGW02Kk0dxj9pxEkwrw4cNnMUlHQUIDdsmn1T/U1hcjqVwen4R63LkObNQmy3YVKO
cL+B4c39RyKy24VXgGKPZhwPNSQQbWFOkXEz9awHGt1jnwPIjvO1BOUradHduU8lAb3j
rChQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20230601; t=1757789686; x=1758394486;
h=message-id:content-disposition:reply-to:list-unsubscribe:precedence
:to:date:subject:mime-version:from:x-gm-message-state:from:to:cc
:subject:date:message-id:reply-to;
bh=x7HvqZ7LO+eXxnbg50JCG4DTzMFG798OPMH+nfEGH0Q=;
b=fQjXF7uol9WekK4zHwURCjiLyD1KpW2jM5TEi6LkX8HjA5wl4w+rZ1uAF9VFg5qKVY
OcZ18GG/sLzcAy38QOQqLJkDLR28l2/FqZma/sAkLB6zrNqmFnq1+XUK+J1pdsMSXKTL
41Kcg0iF51ygshP6qirMlyqeOfO6pqcU8R3zEfR/QAjkJPbUz8R7tgQIJa0zPAnA7tZp
tZVD8TSZERWjat8vDSgbZrna4wnAMzUPZimpYFICyQNLUHyFOn3cOOQgs6C0IDIG3L+o
GXmJkqX6I1s9jnpSK/cNLDNFaJO6sz56XcCVRBCxaJVAB1vfNw+03j/VN+4ziFkAfVQq
V9gg==
X-Gm-Message-State: AOJu0YwYoCmldJw9ARoRTWA3/qP3b9JrmtMfsgEG/Zx4VMCuWZY0zGVH
TDnKbeLkzNSOBw5q31nptGMVaq2z01G4IyolBCpnDQW8zqht+TO6/MRlYA8k2tCw8kGoX5cimTs
gB2gueM5l5o7R
X-Gm-Gg: ASbGnct+hHKy4gWFLfibC2iQg0MvNg3tFDST/ZWOP6wNaT6cee5FGBxQeCpLj0WCARs
4P+AkiewjIPPjdyPSeusao/LYsVQO4B3ZNPSmI3HbKIXuUBm721KJuAGMt++itS7cR8nfJKWViF
Lwf2hIn8JWreaWvhVBZ4yoKz4Jj/XMm6iW5Z0S72Swh11fdl2/MaLz7JeEKVV9uIpIkocNksGx+
18YCOqYI79b/8FU4beYRwRDp75Fx9kstyllpgWy/gXGzirbgUcOKh1+FulYT6OoHqAVIqJeC7Mu
5PcAJi3x9FYaspPlWn2VHExbj3Zew+LOXmyH9JiOZHArZZFWG40Je3UInm16lKTrCNm/LumoK+Y
=
X-Google-Smtp-Source: AGHT+IEgTYJ1RhV15QqzuRKD6ZaTROov4aCUYP1y0ihoiemh2sjHxff+Ak1SozNQnITmxDuHoFLadg==
X-Received: by 2002:a05:6e02:b4c:b0:3fe:12b9:4883 with SMTP id e9e14a558f8ab-4209dabe79bmr102803105ab.3.1757789686563;
Sat, 13 Sep 2025 11:54:46 -0700 (PDT)
Received: from wwszgwsvwz.fr ([52.165.144.11])
by smtp.gmail.com with ESMTPSA id 8926c6da1cb9f-5121607c279sm674622173.32.2025.09.13.11.54.44
for
(version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128);
Sat, 13 Sep 2025 11:54:44 -0700 (PDT)
From: Claim Your Free Mastercraft Tool Set
X-Google-Original-From: Claim Your Free Mastercraft Tool Set
Received: by wwszgwsvwz.fr for; Sat, 13 Sep 2025 19:54:44 +0100 (envelope-from <>)
X-Google-Original-Sender: info_izfhcqytkr@uses-quality.namecheap.com
MIME-Version: 1.0
subject:Your name appeared for a CAA Car Emergency Kit Set
date:Sat, 13 Sep 2025 11:54:43 -0700
to:sales@nk.ca
Precedence: bulk
X-Mailer-id:<486760726-sales@CzyAlFWD.com>
List-Unsubscribe:,
reply-to:
Content-Disposition: inline
Message-Id:<232380-486760726-104567-oZMDCK@CzyAlFWD.com>
X-Rival-Recipient: X0u8OG2L5u3p9958uCF848k0a6tQF81cJ4Y6qBt35o19H6yuV7t2194kifTS
X-Gm-Features: 4H80R2T63PrZlr17Y32q2pO58898qJU53T5w835W_n28YR5e8078ID09l_-W1155
Content-Type: multipart/alternative;
boundary="==00000000000041oB50M6pG48676072641oB50M6pG"
X-Spam_score: 12.7
X-Spam_score_int: 127
X-Spam_bar: ++++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Home Depot Unsubscribe from this list
Content analysis details: (12.7 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[52.165.144.11 listed in will-spam-for-food.eu.org]
[52.165.144.11 listed in will-spam-for-food.eu.org]
[52.165.144.11 listed in will-spam-for-food.eu.org]
[52.165.144.11 listed in will-spam-for-food.eu.org]
[52.165.144.11 listed in will-spam-for-food.eu.org]
[52.165.144.11 listed in will-spam-for-food.eu.org]
[52.165.144.11 listed in will-spam-for-food.eu.org]
[52.165.144.11 listed in will-spam-for-food.eu.org]
[209.85.166.181 listed in will-spam-for-food.eu.org]
[209.85.166.181 listed in will-spam-for-food.eu.org]
[209.85.166.181 listed in will-spam-for-food.eu.org]
[209.85.166.181 listed in will-spam-for-food.eu.org]
[209.85.166.181 listed in will-spam-for-food.eu.org]
[209.85.166.181 listed in will-spam-for-food.eu.org]
[209.85.166.181 listed in will-spam-for-food.eu.org]
[209.85.166.181 listed in will-spam-for-food.eu.org]
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[209.85.166.181 listed in list.dnswl.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[52.165.144.11 listed in dnsbl.ahbl.org]
[52.165.144.11 listed in dnsbl.ahbl.org]
[52.165.144.11 listed in dnsbl.ahbl.org]
[52.165.144.11 listed in dnsbl.ahbl.org]
[209.85.166.181 listed in dnsbl.ahbl.org]
[209.85.166.181 listed in dnsbl.ahbl.org]
[209.85.166.181 listed in dnsbl.ahbl.org]
[209.85.166.181 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[52.165.144.11 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[52.165.144.11 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[52.165.144.11 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[52.165.144.11 listed in dnsbl.ahbl.org]
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[209.85.166.181 listed in wl.mailspike.net]
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.7 HTML_IMAGE_ONLY_20 BODY: HTML: images with 1600-2000 bytes of words
0.0 HTML_MESSAGE BODY: HTML included in message
0.7 MPART_ALT_DIFF BODY: HTML and text parts are different
0.8 SARE_FROM_SPAM_WORD3 I don't know people named this!
0.0 MIME_HTML_ONLY_MULTI Multipart message only has text/html MIME parts
2.5 HDRS_MISSP Misspaced headers
0.0 NO_RDNS2 Sending MTA has no reverse DNS
0.3 HTML_SHORT_LINK_IMG_3 HTML is very short with a linked image
1.8 COMBO_IMAGEONLY1 Appears to be an image only message
Subject: {SPAM?} Your name appeared for a CAA Car Emergency Kit Set
--==00000000000041oB50M6pG48676072641oB50M6pG
Content-Type:text/html; charset=UTF-8
Home Depot
--==00000000000041oB50M6pG48676072641oB50M6pG--
Envelope-to: dave@doctor.nl2k.ab.ca
Delivery-date: Sat, 13 Sep 2025 13:03:00 -0600
Received: from doctor by doctor.nl2k.ab.ca with local (Exim 4.98.2 (FreeBSD))
(envelope-from
id 1uxVVg-00000000ImH-3Tzc
for dave@doctor.nl2k.ab.ca;
Sat, 13 Sep 2025 13:02:08 -0600
Resent-From: The Doctor
Resent-Date: Sat, 13 Sep 2025 13:02:08 -0600
Resent-Message-ID:
Resent-To: Dave Yadallee
Received: from mail-il1-f181.google.com ([209.85.166.181]:60840)
by doctor.nl2k.ab.ca with esmtps (TLS1.3) tls TLS_AES_128_GCM_SHA256
(Exim 4.98.2 (FreeBSD))
(envelope-from
id 1uxVPO-00000000HlC-3oal
for sales@nk.ca;
Sat, 13 Sep 2025 12:55:47 -0600
Received: by mail-il1-f181.google.com with SMTP id e9e14a558f8ab-403a893fb99so15291845ab.1
for
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=owa-prostaffing-services-com.20230601.gappssmtp.com; s=20230601; t=1757789686; x=1758394486; darn=nk.ca;
h=message-id:content-disposition:reply-to:list-unsubscribe:precedence
:to:date:subject:mime-version:from:from:to:cc:subject:date
:message-id:reply-to;
bh=x7HvqZ7LO+eXxnbg50JCG4DTzMFG798OPMH+nfEGH0Q=;
b=vz4uCeH9fdyHD/RvvsrgS2bMxC9tsG3dt0TAa+f5+wxXI6klidnbPGHDEvvsuOenQp
55bZCyVeQVoCRVjXuUDuGUc4qTxWvsT4ymGoRsvOWQLTLYA/7Goyw1UtNuHJXad8Llo3
It7+HEoW5vq05htY3YOL6tFoGYmNQYOtCmSwIY/iaoEmVUZ6SjK/Px4jgFrEFLAddj2c
GzgMGW02Kk0dxj9pxEkwrw4cNnMUlHQUIDdsmn1T/U1hcjqVwen4R63LkObNQmy3YVKO
cL+B4c39RyKy24VXgGKPZhwPNSQQbWFOkXEz9awHGt1jnwPIjvO1BOUradHduU8lAb3j
rChQ==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=1e100.net; s=20230601; t=1757789686; x=1758394486;
h=message-id:content-disposition:reply-to:list-unsubscribe:precedence
:to:date:subject:mime-version:from:x-gm-message-state:from:to:cc
:subject:date:message-id:reply-to;
bh=x7HvqZ7LO+eXxnbg50JCG4DTzMFG798OPMH+nfEGH0Q=;
b=fQjXF7uol9WekK4zHwURCjiLyD1KpW2jM5TEi6LkX8HjA5wl4w+rZ1uAF9VFg5qKVY
OcZ18GG/sLzcAy38QOQqLJkDLR28l2/FqZma/sAkLB6zrNqmFnq1+XUK+J1pdsMSXKTL
41Kcg0iF51ygshP6qirMlyqeOfO6pqcU8R3zEfR/QAjkJPbUz8R7tgQIJa0zPAnA7tZp
tZVD8TSZERWjat8vDSgbZrna4wnAMzUPZimpYFICyQNLUHyFOn3cOOQgs6C0IDIG3L+o
GXmJkqX6I1s9jnpSK/cNLDNFaJO6sz56XcCVRBCxaJVAB1vfNw+03j/VN+4ziFkAfVQq
V9gg==
X-Gm-Message-State: AOJu0YwYoCmldJw9ARoRTWA3/qP3b9JrmtMfsgEG/Zx4VMCuWZY0zGVH
TDnKbeLkzNSOBw5q31nptGMVaq2z01G4IyolBCpnDQW8zqht+TO6/MRlYA8k2tCw8kGoX5cimTs
gB2gueM5l5o7R
X-Gm-Gg: ASbGnct+hHKy4gWFLfibC2iQg0MvNg3tFDST/ZWOP6wNaT6cee5FGBxQeCpLj0WCARs
4P+AkiewjIPPjdyPSeusao/LYsVQO4B3ZNPSmI3HbKIXuUBm721KJuAGMt++itS7cR8nfJKWViF
Lwf2hIn8JWreaWvhVBZ4yoKz4Jj/XMm6iW5Z0S72Swh11fdl2/MaLz7JeEKVV9uIpIkocNksGx+
18YCOqYI79b/8FU4beYRwRDp75Fx9kstyllpgWy/gXGzirbgUcOKh1+FulYT6OoHqAVIqJeC7Mu
5PcAJi3x9FYaspPlWn2VHExbj3Zew+LOXmyH9JiOZHArZZFWG40Je3UInm16lKTrCNm/LumoK+Y
=
X-Google-Smtp-Source: AGHT+IEgTYJ1RhV15QqzuRKD6ZaTROov4aCUYP1y0ihoiemh2sjHxff+Ak1SozNQnITmxDuHoFLadg==
X-Received: by 2002:a05:6e02:b4c:b0:3fe:12b9:4883 with SMTP id e9e14a558f8ab-4209dabe79bmr102803105ab.3.1757789686563;
Sat, 13 Sep 2025 11:54:46 -0700 (PDT)
Received: from wwszgwsvwz.fr ([52.165.144.11])
by smtp.gmail.com with ESMTPSA id 8926c6da1cb9f-5121607c279sm674622173.32.2025.09.13.11.54.44
for
(version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128);
Sat, 13 Sep 2025 11:54:44 -0700 (PDT)
From: Claim Your Free Mastercraft Tool Set
X-Google-Original-From: Claim Your Free Mastercraft Tool Set
Received: by wwszgwsvwz.fr for
X-Google-Original-Sender: info_izfhcqytkr@uses-quality.namecheap.com
MIME-Version: 1.0
subject:Your name appeared for a CAA Car Emergency Kit Set
date:Sat, 13 Sep 2025 11:54:43 -0700
to:sales@nk.ca
Precedence: bulk
X-Mailer-id:<486760726-sales@CzyAlFWD.com>
List-Unsubscribe:
reply-to:
Content-Disposition: inline
Message-Id:<232380-486760726-104567-oZMDCK@CzyAlFWD.com>
X-Rival-Recipient: X0u8OG2L5u3p9958uCF848k0a6tQF81cJ4Y6qBt35o19H6yuV7t2194kifTS
X-Gm-Features: 4H80R2T63PrZlr17Y32q2pO58898qJU53T5w835W_n28YR5e8078ID09l_-W1155
Content-Type: multipart/alternative;
boundary="==00000000000041oB50M6pG48676072641oB50M6pG"
X-Spam_score: 12.7
X-Spam_score_int: 127
X-Spam_bar: ++++++++++++
X-Spam_report: Spam detection software, running on the system "doctor.nl2k.ab.ca",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
@@CONTACT_ADDRESS@@ for details.
Content preview: Home Depot Unsubscribe from this list
Content analysis details: (12.7 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
1.0 RCVD_IN_WSFF RBL: Received via a relay in will-spam-for-food.eu.org
[52.165.144.11 listed in will-spam-for-food.eu.org]
[52.165.144.11 listed in will-spam-for-food.eu.org]
[52.165.144.11 listed in will-spam-for-food.eu.org]
[52.165.144.11 listed in will-spam-for-food.eu.org]
[52.165.144.11 listed in will-spam-for-food.eu.org]
[52.165.144.11 listed in will-spam-for-food.eu.org]
[52.165.144.11 listed in will-spam-for-food.eu.org]
[52.165.144.11 listed in will-spam-for-food.eu.org]
[209.85.166.181 listed in will-spam-for-food.eu.org]
[209.85.166.181 listed in will-spam-for-food.eu.org]
[209.85.166.181 listed in will-spam-for-food.eu.org]
[209.85.166.181 listed in will-spam-for-food.eu.org]
[209.85.166.181 listed in will-spam-for-food.eu.org]
[209.85.166.181 listed in will-spam-for-food.eu.org]
[209.85.166.181 listed in will-spam-for-food.eu.org]
[209.85.166.181 listed in will-spam-for-food.eu.org]
-0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no
trust
[209.85.166.181 listed in list.dnswl.org]
1.5 RCVD_IN_AHBL RBL: AHBL: sender is listed in dnsbl.ahbl.org
[52.165.144.11 listed in dnsbl.ahbl.org]
[52.165.144.11 listed in dnsbl.ahbl.org]
[52.165.144.11 listed in dnsbl.ahbl.org]
[52.165.144.11 listed in dnsbl.ahbl.org]
[209.85.166.181 listed in dnsbl.ahbl.org]
[209.85.166.181 listed in dnsbl.ahbl.org]
[209.85.166.181 listed in dnsbl.ahbl.org]
[209.85.166.181 listed in dnsbl.ahbl.org]
1.5 RCVD_IN_AHBL_SPAM RBL: AHBL: Spam Source in dnsbl.ahbl.org
[52.165.144.11 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_SMTP RBL: AHBL: Open SMTP relay in dnsbl.ahbl.org
[52.165.144.11 listed in dnsbl.ahbl.org]
0.5 RCVD_IN_AHBL_PROXY RBL: AHBL: Open Proxy server in dnsbl.ahbl.org
[52.165.144.11 listed in dnsbl.ahbl.org]
0.0 RCVD_IN_AHBL_RTB RBL: AHBL: Real-Time Blocked in dnsbl.ahbl.org
[52.165.144.11 listed in dnsbl.ahbl.org]
-0.2 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2)
[209.85.166.181 listed in wl.mailspike.net]
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
1.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.7 HTML_IMAGE_ONLY_20 BODY: HTML: images with 1600-2000 bytes of words
0.0 HTML_MESSAGE BODY: HTML included in message
0.7 MPART_ALT_DIFF BODY: HTML and text parts are different
0.8 SARE_FROM_SPAM_WORD3 I don't know people named this!
0.0 MIME_HTML_ONLY_MULTI Multipart message only has text/html MIME parts
2.5 HDRS_MISSP Misspaced headers
0.0 NO_RDNS2 Sending MTA has no reverse DNS
0.3 HTML_SHORT_LINK_IMG_3 HTML is very short with a linked image
1.8 COMBO_IMAGEONLY1 Appears to be an image only message
Subject: {SPAM?} Your name appeared for a CAA Car Emergency Kit Set
--==00000000000041oB50M6pG48676072641oB50M6pG
Content-Type:text/html; charset=UTF-8
--==00000000000041oB50M6pG48676072641oB50M6pG--