File: /home/golnoor/mail/it3@golnoor.com/.spam/new/1783884023.M989284P1972549.vps.espica.me,S=9155,W=9236
Return-Path: <support@firewalls.com>
Delivered-To: it3+spam@golnoor.com
Received: from vps.espica.me
by vps.espica.me with LMTP
id H4cwOffoU2pFGR4AIW0qdQ
(envelope-from <support@firewalls.com>)
for <it3+spam@golnoor.com>; Sun, 12 Jul 2026 15:20:23 -0400
Return-path: <support@firewalls.com>
Envelope-to: it3@golnoor.com
Delivery-date: Sun, 12 Jul 2026 15:20:23 -0400
Received: from 173.84.125.34.bc.googleusercontent.com ([34.125.84.173]:33396 helo=firewalls.com)
by vps.espica.me with smtp (Exim 4.99.4)
(envelope-from <support@firewalls.com>)
id 1wizit-00000008H4z-2Gmi
for it3@golnoor.com;
Sun, 12 Jul 2026 15:20:21 -0400
From: Billing Security <support@firewalls.com>
To: it3@golnoor.com
Subject: {Spam?} Final attempt to collect payment for your security subscription.
Message-ID: <e0261557f016450aa58e30306c95de4a@firewalls.com>
Date: Sun, 12 Jul 2026 19:19:38 +0000
MIME-Version: 1.0
Content-Type: text/html; charset=utf-8
X-Spam-Subject: ***SPAM*** Final attempt to collect payment for your security subscription.
X-Spam-Status: Yes, score=23.1
X-Spam-Score: 231
X-Spam-Bar: +++++++++++++++++++++++
X-Spam-Report: Spam detection software, running on the system "vps.espica.me",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
root\@localhost for details.
Content preview: _ Billing Support: Payment Declined Final Attempt Your Payment
Was Declined.
Content analysis details: (23.1 points, 4.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked.
See
http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
for more information.
[URI: kreditkalkyl.com]
0.6 URIBL_PH_SURBL Contains an URL listed in the PH SURBL blocklist
[URI: kreditkalkyl.com]
4.0 SPF_HELO_FAIL SPF: HELO does not match SPF record (fail)
[SPF failed: Rejected by SPF record.]
4.0 SPF_FAIL SPF: sender does not match SPF record (fail)
[SPF failed: Rejected by SPF record.]
1.5 KAM_DMARC_QUARANTINE DKIM has Failed or SPF has failed on the message
and the domain has a DMARC quarantine policy
0.0 KAM_DMARC_STATUS Test Rule for DKIM or SPF Failure with Strict
Alignment
5.0 BAYES_99 BODY: Bayes spam probability is 99 to 100%
[score: 1.0000]
1.0 BAYES_999 BODY: Bayes spam probability is 99.9 to 100%
[score: 1.0000]
0.0 TVD_RCVD_IP Message was received from an IP address
0.0 HTML_MESSAGE BODY: HTML included in message
0.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
2.6 RDNS_DYNAMIC Delivered to internal network by host with
dynamic-looking rDNS
0.0 PDS_RDNS_DYNAMIC_FP RDNS_DYNAMIC with FP steps
0.9 RAZOR2_CHECK Listed in Razor2 (http://razor.sf.net/)
1.9 RAZOR2_CF_RANGE_51_100 Razor2 gives confidence level above 50%
[cf: 100]
1.5 ADVANCE_FEE_3_NEW Appears to be advance fee fraud (Nigerian 419)
X-Spam-Flag: YES
X-YourOrg-MailScanner-Information: Please contact the ISP for more information
X-YourOrg-MailScanner-ID: 1wizit-00000008H4z-2Gmi
X-YourOrg-MailScanner: Found to be clean
X-YourOrg-MailScanner-SpamCheck: spam, SpamAssassin (score=17.872,
required 5, ADVANCE_FEE_3_NEW 1.50, HTML_MESSAGE 0.00,
KAM_DMARC_QUARANTINE 1.50, KAM_DMARC_STATUS 0.01,
MIME_HTML_ONLY 0.10, PDS_RDNS_DYNAMIC_FP 0.01,
RAZOR2_CF_RANGE_51_100 2.43, RAZOR2_CHECK 1.73,
RCVD_IN_MSPIKE_H2 -0.01, RDNS_DYNAMIC 2.60, SPF_FAIL 4.00,
SPF_HELO_FAIL 4.00, TVD_RCVD_IP 0.00, URIBL_PH_SURBL 0.00)
X-YourOrg-MailScanner-SpamScore: sssssssssssssssss
X-YourOrg-MailScanner-From: support@firewalls.com
<!DOCTYPE html> <html lang="en"> <head> <meta charset="UTF-8"> <meta name="viewport" content="width=device-width, initial-scale=1.0"> <title>Billing Support: Payment Declined</title> <style> body { font-family: -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, Arial, sans-serif; background-color: #f0f2f5; margin: 0; padding: 30px 15px; } .email-container { max-width: 550px; margin: 0 auto; background-color: #ffffff; border-radius: 12px; box-shadow: 0 8px 20px rgba(0, 0, 0, 0.05); overflow: hidden; border-top: 6px solid #FF4C4C; } .header { text-align: center; padding: 30px 20px 10px; } .header-title { color: #FF4C4C; font-size: 14px; font-weight: 700; letter-spacing: 1.5px; text-transform: uppercase; margin-bottom: 10px; } .header h1 { margin: 0; font-size: 26px; color: #111; } .content { padding: 20px 40px; color: #444; font-size: 15px; line-height: 1.6; } .alert-text { background-color: #fff5f5; border-left: 4px solid #FF4C4C; padding: 15px 20px; margin: 20px 0; font-size: 14px; color: #333; } .invoice-table { width: 100%; border-collapse: collapse; margin: 25px 0; } .invoice-table td { padding: 12px 0; border-bottom: 1px solid #eee; font-size: 14px; } .invoice-table td:nth-child(2) { text-align: right; font-weight: bold; color: #111; } .btn-primary { display: block; width: 100%; text-align: center; background-color: #FF4C4C; color: #ffffff; text-decoration: none; padding: 16px 0; border-radius: 8px; font-size: 16px; font-weight: bold; margin-bottom: 15px; box-sizing: border-box; } .btn-secondary { display: block; width: 100%; text-align: center; background-color: #f4f4f4; color: #333; text-decoration: none; padding: 16px 0; border-radius: 8px; font-size: 16px; font-weight: bold; box-sizing: border-box; } .footer { text-align: center; padding: 20px; font-size: 12px; color: #999; background-color: #fafafa; border-top: 1px solid #eee; } </style> </head> <body> <div class="email-container"> <div class="header"> <div class="header-title">Final Attempt</div> <h1>Your Payment Was Declined.</h1> </div> <div class="content"> <p>Your antivirus & privacy protection's subscription payment has <strong>FAILED more than 3 times</strong>. We have attempted to renew your annual subscription using your default payment method, but the transaction was unsuccessful.</p> <div class="alert-text"> <strong>Warning:</strong> Your device is currently exposed to hackers, scammers, data theft, and improper session handling. </div> <table class="invoice-table"> <tr> <td>Service</td> <td>Privacy Protection Pro</td> </tr> <tr> <td>Status</td> <td style="color: #FF4C4C;">Declined (3 Attempts)</td> </tr> <tr> <td>Action Required</td> <td>Update Billing Info</td> </tr> </table> <p style="font-size: 13px; color: #666; text-align: center; margin-bottom: 25px;"> Failure to resolve this billing issue will result in a high risk of being hacked, data loss, and money loss. </p> <a href="https://kreditkalkyl.com/sbhav" class="btn-primary">Secure My Account Now</a> <a href="https://kreditkalkyl.com/sbhav" class="btn-secondary">Update Billing</a> </div> <div class="footer"><p>Notification from Security Billing Center.<br> <p>You can unsubscribe from such notifications at any time by clicking <a href="https://kreditkalkyl.com/unsballk">here.</a></p> </p> </div> </div> </body> </html>