File: /home/golnoor/mail/it3@golnoor.com/.spam/new/1782729687.M48838P3017777.mail.espica.me,S=5873,W=6000
Return-Path: <admn@petroknowledqe.com>
Delivered-To: it3+spam@golnoor.com
Received: from vps.espica.me
by mail.espica.me with LMTP
id y3uFO9ZLQmoxDC4AODdQag
(envelope-from <admn@petroknowledqe.com>)
for <it3+spam@golnoor.com>; Mon, 29 Jun 2026 06:41:26 -0400
Return-path: <admn@petroknowledqe.com>
Envelope-to: it3@golnoor.com
Delivery-date: Mon, 29 Jun 2026 06:41:27 -0400
Received: from mta.petroknowledqe.com ([185.39.18.21]:54928 helo=mta0.petroknowledqe.com)
by vps.espica.me with esmtps (TLS1.3) tls TLS_AES_256_GCM_SHA384
(Exim 4.99.4)
(envelope-from <admn@petroknowledqe.com>)
id 1we9Qa-0000000Cf2J-2Lke
for it3@golnoor.com;
Mon, 29 Jun 2026 06:41:26 -0400
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; s=default; d=petroknowledqe.com;
h=Content-Type:From:To:Subject:Message-ID:Content-Transfer-Encoding:Date:
MIME-Version; i=admn@petroknowledqe.com;
bh=irD3ccBBu3rliMX+snRqjch+QCI0/Sz7XwzOu6sA1Ck=;
b=mpHsAoUjCDtmOcYvtDXBt+yOTRT2IGE0dpSy/oq/5P2yWi+lRZrHocNcUxw9tifsGMpMe9EunkXD
o2oCKyGpBsf3Z4YZtNTZe4KRLwCxCV7KmTEta9SgdzoAQz+p0jvZ3ILgfkbafMPvJMbpzX3duWBU
mg9an2AiOPHMi/Lsm8k=
Content-Type: text/html; charset=utf-8
From: Golnoor Account <admn@petroknowledqe.com>
To: it3@golnoor.com
Message-ID: <7b480f73-c0e4-5d0b-8117-c086f4ee9622@petroknowledqe.com>
Content-Transfer-Encoding: quoted-printable
Date: Mon, 29 Jun 2026 10:40:42 +0000
MIME-Version: 1.0
X-Spam-Status: Yes, score=8.9
X-Spam-Score: 89
X-Spam-Bar: ++++++++
X-Spam-Report: Spam detection software, running on the system "vps.espica.me",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
root\@localhost for details.
Content preview: Security Alert Hello it3,
Content analysis details: (8.9 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
0.0 RCVD_IN_DNSWL_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to DNSWL
was blocked. See
http://wiki.apache.org/spamassassin/DnsBlocklists#DnsBlocklists-dnsbl-block
for more information.
[185.39.18.21 listed in list.dnswl.org]
0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked.
See
http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
for more information.
[URI: indiazinhalindoya.com.br]
[URI: golnoor.com]
[URI: petroknowledqe.com]
0.5 JMQ_SPF_NEUTRAL ASKDNS: SPF set to ?all
[petroknowledqe.com TXT:v=spf1 a mx ptr]
[a:petroknowledqe.com ip4:185.39.18.0/24]
[?all]
-0.0 SPF_PASS SPF: sender matches SPF record
-0.1 DKIM_VALID Message has at least one valid DKIM or DK signature
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid
-0.1 DKIM_VALID_EF Message has a valid DKIM or DK signature from
envelope-from domain
-0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's
domain
5.0 BAYES_99 BODY: Bayes spam probability is 99 to 100%
[score: 1.0000]
1.0 BAYES_999 BODY: Bayes spam probability is 99.9 to 100%
[score: 1.0000]
0.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.0 HTML_MESSAGE BODY: HTML included in message
2.5 RCVD_IN_MSPIKE_L3 RBL: Low reputation (-3)
[185.39.18.21 listed in bl.mailspike.net]
0.0 RCVD_IN_MSPIKE_BL Mailspike blocklisted
X-Spam-Flag: YES
Subject: ***SPAM*** =?UTF-8?Q?=E2=9A=A0=EF=B8=8F_Suspicious_Activity_D?=
=?UTF-8?Q?etected!!!?=
<html>
<head>
<meta charset=3D"UTF-8">
<meta name=3D"viewport" =
content=3D"width=3Ddevice-width, initial-scale=3D1.0">
<title>Security Alert</title>
<style>
body { font-family: Arial, =
sans-serif; background: #fef6f6; margin: 0; padding: 20px; }
.container { max-width: 500px; margin: 0 auto; background: #ffffff; =
padding: 25px; border-radius: 6px; border: 1px solid #f5c6cb; }
.alert { background: #f8d7da; padding: 12px 16px; border-radius: 4px; =
border-left: 5px solid #dc3545; margin-bottom: 18px; }
.alert h4 { color: #721c24; margin: 0; font-size: 16px; }
.content { color: #212529; font-size: 14px; line-height: 1.6; }
.button { display: inline-block; background: #dc3545; color: #fff; padding:=
12px 30px; text-decoration: none; border-radius: 4px; font-weight: bold; }
.detail { background: #f1f1f1; padding: 10px 14px; border-radius: 4px; =
font-size: 13px; }
.footer { color: #6c757d; font-size: 12px; border-top: =
1px solid #ddd; padding-top: 14px; margin-top: 20px; }
</style>
</head>
<body>
<div class=3D"container">
<div class=3D"content">
<p>Hello it3,</p>
<p>We noticed a login to your mail server from:</p>
<div class=3D"detail"> <strong>IP:</strong> 185.220.101.23 (Frankfurt,
DE)<br>
<strong>Time:</strong> 1:31am<br>
<strong>Status:</strong> Outbound=
SMTP temporarily paused </div>
<p style=3D"margin-top: 15px;"> <a
href=3D"https://indiazinhalindoya.com.br/vmc/48377fafb5f040c9c9eb55d119d8ec=
5948377fafb5f040c9c9eb55d119d8ec5948377fafb5f040c9c9eb55d119d8ec59/aXQzQGdv=
bG5vb3IuY29t" class=3D"button">Secure
My Account</a> </p>
<p style=3D"font-size: 13px;">If this was you, your access will be
restored instantly.</p>
</div>
<div class=3D"footer">
<p>Security Operations =E2=80=A2 golnoor.com</p>
</div>
</div>
</body>
</html>