Return-Path:
Delivered-To: oxcpoxcp+spam@server.oxoserver.com
Received: from server.oxoserver.com
by server.oxoserver.com with LMTP
id jMs/AuVZNGopVBMApFFIGg
(envelope-from )
for ; Thu, 18 Jun 2026 20:49:41 +0000
Return-path:
Envelope-to: admin@oxoserver.com
Delivery-date: Thu, 18 Jun 2026 20:49:41 +0000
Received: from [188.247.39.134] (port=59454 helo=lsu.edu)
by server.oxoserver.com with esmtp (Exim 4.99.4)
(envelope-from )
id 1waJgE-00000005JUf-0rLE
for admin@oxoserver.com;
Thu, 18 Jun 2026 20:49:40 +0000
From: "American Express"
To: admin@oxoserver.com
Date: 18 Jun 2026 23:48:59 +0300
Message-ID: <20260618234859.FD9C82ECE32DDD55@lsu.edu>
MIME-Version: 1.0
Content-Type: text/html;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
X-Spam-Status: Yes, score=24.6
X-Spam-Score: 246
X-Spam-Bar: ++++++++++++++++++++++++
X-Spam-Report: Spam detection software, running on the system "server.oxoserver.com",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
root\@localhost for details.
Content preview: See details inside Account ending: 37XXX00
Content analysis details: (24.6 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked.
See
http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
for more information.
[URI: bhartionline.com]
[URI: aexp-static.com]
[URI: americanexpress.com]
0.0 URIBL_DBL_BLOCKED_OPENDNS ADMINISTRATOR NOTICE: The query to
dbl.spamhaus.org was blocked due to usage of an
open resolver. See
https://www.spamhaus.org/returnc/pub/
[URI: cdaas.americanexpress.com]
[URI: bhartionline.com]
[URI: www.americanexpress.com]
[URI: www.aexp-static.com]
[URI: global.americanexpress.com]
[URI: americanexpress.com]
1.5 SPF_HELO_SOFTFAIL SPF: HELO does not match SPF record (softfail)
1.5 SPF_SOFTFAIL SPF: sender does not match SPF record (softfail)
0.0 KAM_DMARC_STATUS Test Rule for DKIM or SPF Failure with Strict
Alignment
0.2 KAM_DMARC_NONE DKIM has Failed or SPF has failed on the message and
the domain has no DMARC policy
0.0 HTML_MESSAGE BODY: HTML included in message
0.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.5 RCVD_IN_HOSTKARMA_BR RBL: Sender listed in HOSTKARMA-BROWN
[188.247.39.134 listed in hostkarma.junkemailfilter.com]
0.5 KAM_REALLYHUGEIMGSRC RAW: Spam with image tags with ridiculously huge
http urls
2.0 RDNS_NONE Delivered to internal network by a host with no rDNS
0.0 TVD_PH_SUBJ_META1 Email has a Phishy looking subject line
1.5 KAM_GOOGLE_REDIR Use of Google redir
1.5 GOOG_REDIR_HTML_ONLY Google redirect to obscure spamvertised website
+ HTML only
1.5 GOOG_REDIR_NORDNS Google redirect to obscure spamvertised website +
no rDNS
2.0 HTML_FONT_TINY_NORDNS Font too small to read, no rDNS
2.0 TO_NO_BRKTS_NORDNS_HTML To: lacks brackets and no rDNS and HTML only
2.8 VFY_ACCT_NORDNS Verify your account to a poorly-configured MTA -
probable phishing
5.0 URI_WP_HACKED URI for compromised WordPress site, possible malware
2.0 KAM_SENDGRID2 Sendgrid being exploited by scammers
X-Spam-Flag: YES
Subject: ***SPAM*** We've temporarily flagged your account.
See details inside
<=
/P>
Account en=
ding: 37XXX00
=
We couldn’t approve a recent purchase on you=
r Account
<=
/TABLE>
What happened
We noticed that you or one of your employees recen=
tly attempted to make a purchase with an Employee Card on your account. We =
couldn’t approve that purchase because we believe is unauthorize=
d
Your account has been flagged to prevent new&=
nbsp;transcation unstill this is resloved
=
TBODY>
What we need from you
We strongly suggest, that you try to do the follow=
ing
*Patriot Act Notice: <=
/SPAN>Federal law requires all financial institutions to obtain, verify and=
record information that identifies each person who opens an account, inclu=
ding your name, address, date of birth and other information that will allo=
w us to verify your identity.
Your account information is included above to help=
you recognize this as a customer care email from American Express. To lear=
n more about email security or report a suspicious email, please visit us a=
tameric=
anexpress.com/phishing. We kindly ask you not to reply to this email bu=
t instead contact us viaCustomer Care=
A>.