I have received the following alarming emaii:
Return-Path: <email@example.com> Received: from compute5.internal (compute5.nyi.internal [10.202.2.45]) by sloti27t02 (Cyrus fastmail-fmjessie44416-15275-git-fastmail-15275) with LMTPA; Wed, 05 Jul 2017 20:05:18 -0400 X-Cyrus-Session-Id: sloti27t02-1847331-1499299518-2-7902621334515718164 X-Sieve: CMU Sieve 3.0 X-Spam-known-sender: no X-Spam-score: 5.9 X-Spam-hits: BAYES_00 -1.9, DCC_CHECK 1.1, RCVD_IN_BRBL_LASTEXT 1.449, RCVD_IN_INVALUEMENT24 2, RCVD_IN_SBL_CSS 3.335, SPF_HELO_PASS -0.001, SPF_PASS -0.001, T_RP_MATCHES_RCVD -0.01, LANGUAGES en, BAYES_USED global, SA_VERSION 3.4.0 X-Spam-source: IP='188.8.131.52', Host='nestpensions52.top', Country='CN', FromHeader='top', MailFrom='top' X-Spam-charsets: plain='windows-1251' X-Attached: SecureMessageNEST.doc X-Resolved-to: [redacted] X-Delivered-to: [redacted] X-Mail-from: firstname.lastname@example.org Received: from mx4 ([10.202.2.203]) by compute5.internal (LMTPProxy); Wed, 05 Jul 2017 20:05:18 -0400 Received: from mx4.messagingengine.com (localhost [127.0.0.1]) by mailmx.nyi.internal (Postfix) with ESMTP id 3A237C865A for <[redacted]>; Wed, 5 Jul 2017 20:05:18 -0400 (EDT) Received: from mx4.messagingengine.com (localhost [127.0.0.1]) by mx4.messagingengine.com (Authentication Milter) with ESMTP id 0F871A439AE; Wed, 5 Jul 2017 20:05:18 -0400 Authentication-Results: mx4.messagingengine.com; dkim-adsp=pass (ADSP policy from nestpensions52.top); dkim=pass (1024-bit rsa key) header.d=nestpensions52.top email@example.com header.b=gmZf+wD3; dmarc=pass header.from=nestpensions52.top; spf=pass firstname.lastname@example.org smtp.helo=nestpensions52.top Received-SPF: pass (nestpensions52.top: 184.108.40.206 is authorized to use 'email@example.com' in 'mfrom' identity (mechanism 'ip4:220.127.116.11' matched)) receiver=mx4.messagingengine.com; identity=mailfrom; envelope-from="firstname.lastname@example.org"; helo=nestpensions52.top; client-ip=18.104.22.168 Received: from nestpensions52.top (nestpensions52.top [22.214.171.124]) by mx4.messagingengine.com (Postfix) with ESMTP for <[redacted]>; Wed, 5 Jul 2017 20:05:16 -0400 (EDT) DKIM-Signature: v=1; a=rsa-sha1; c=relaxed/relaxed; s=key1; d=nestpensions52.top; h=Message-ID:From:To:Subject:Date:MIME-Version:Content-Type; email@example.com; bh=IwyE9/XNOjUwIUfUXoZbDXNKyMg=; b=gmZf+wD3Mvi9pF9UAMV2FYjieiZqYw5D1DN9LhQf24LHUxhlMjBzf6WGX1jxJMvNdbKwI01dvDZw pQZ6k3qHokOGSayVCrrHgzV+TWfkKfOBmapiVDkGXrI3a/pCFxak6/J8pfS8L/exQfIAzeXWiyzi sHH6151X/FaKiBXpXC8= DomainKey-Signature: a=rsa-sha1; c=nofws; q=dns; s=key1; d=nestpensions52.top; b=d9eb5262Skvh+m8vBl12AWlZXBmMjs+E1Kv85Fe2mHvLIW54fOhP6kHWZs6QBZfPWpoE8wMqHmDp gyjPb6Bvkac57H2fc31XfFJA7pRl+5/gp4lt2K2aNyjYNLZt/ACLBWXJwreiZg05NZf1GdVxFmuD q+V2qe2GC2qzhGPpw0E=; Message-ID: <3AC0B8D55286A80BD7D29B25F1B91D8F@nestpensions52.top> From: "firstname.lastname@example.org" <email@example.com> To: <[redacted]> Subject: You've got a new message in your NEST mailbox Date: Thu, 6 Jul 2017 02:05:05 +0200 MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="549852d9c89408885e72dcb50b0a" This is a multi-part message in MIME format. --549852d9c89408885e72dcb50b0a Content-Type: text/plain; charset="windows-1251" Content-Transfer-Encoding: quoted-printable There's a new message in your NEST mailbox. We're confirming that payment of 1479.67 will be taken by Direct Debit in= accordance with your agreed terms.=20 Please see the details in attached file. [rest of message omitted]
NEST Pensions are (as the fake "From" address, which is the real address of the real organization, indicates) a pension-scheme provider in the UK, but the X-Spam-Source header seems to indicate that the true sender (firstname.lastname@example.org, the real "From" address) is in China.
Unfortunately, I don't have a NEST account (which is one "this is phishing" indicator, another is that a message from an unknown source is asking me to open an attachment), hence I have no way to inform NEST of this spammer as their site doesn't list a contact email address for urgent enquiries such as this, which is why I'm posting it to here instead of sending it to them. (I hope posting this isn't against the rules.)