False Positive: Why Is This Email In Spam?

Jun 10, 2021
33
5
8
Maryland, USA
I do not understand why this email is going to Spam. Everything looks good. Spam score is 0, spf, dkim and dmarc all ok.



----
Delivered-To: user1@domain.com,user2@domain.com,user3@domain.com

Return-Path: sender@senderdomain.com

Received-SPF: pass (senderdomain.com: Sender is authorized to use 'sender@senderdomain.com' in 'mfrom' identity (mechanism 'include:spf.protection.outlook.com' matched)) receiver=titan.gams.biz; identity=mailfrom; envelope-from="sender@senderdomain.com"; helo=nam10-dm6-obe.outbound.protection.outlook.com; client-ip=40.107.93.63

Received-SPF: pass (senderdomain.com: Sender is authorized to use 'sender@senderdomain.com' in 'mfrom' identity (mechanism 'include:spf.protection.outlook.com' matched)) receiver=titan.gams.biz; identity=mailfrom; envelope-from="sender@senderdomain.com"; helo=nam10-dm6-obe.outbound.protection.outlook.com; client-ip=40.107.93.63

Received-SPF: pass (senderdomain.com: Sender is authorized to use 'sender@senderdomain.com' in 'mfrom' identity (mechanism 'include:spf.protection.outlook.com' matched)) receiver=titan.gams.biz; identity=mailfrom; envelope-from="sender@senderdomain.com"; helo=nam10-dm6-obe.outbound.protection.outlook.com; client-ip=40.107.93.63

Received: from NAM10-DM6-obe.outbound.protection.outlook.com (mail-dm6nam10on2063.outbound.protection.outlook.com [40.107.93.63])

(using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))

(No client certificate requested)

by smtp.domain.com (Proxmox) with ESMTPS id 0409CAC1D88;

Fri, 27 Aug 2021 17:59:35 -0400 (EDT)

ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;

b=bAnKwzWD5sAQJmyIKIHvOP42NOTb564VizfGHIIv3rK780GvHMAgSje/MEu+D+XBBv+ra98WLwlxL/bbBPIGXEi0qhhcMO7X3j4cI0E5+qhR71RGcVy6pTsIpzrUXkVoQZHZ5YGrWAnvdi/HdmOC1i9kAR5lFQc/ZG66t5ECpVuihtIhlZBR2j7nwUvyAAsy81UxLtTov4cIG+xNh1Gk5+KYd32ql/EQhLvlZV7e49Pwkc1mh1GUYmSCK8pKghSoFTeMqqk+L7cOXgImhroa+pcBAxNHmyZBUKp7rJg8tgKlB4ZLhvOvPeXbkEnIxEAP3Kif4Ss4aRs+myrGcCJLKQ==

ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;

s=arcselector9901;

h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;

bh=mZo+QuETvzUO70GE/h2t53XnM7athOR7wJRffoc0Hmo=;

b=SZ+/S8tqAkPR96m7h0TWI5mYh1VD1wRUVdBrRSrxEV5ubA7n6Yop75edHq0YpJU9BCd7cC+e8+gu2FxeamSNlPpTPlhASSXIBpxqAIHFxbfGnqaumijzSiKtK2YEHl9ZDtHvk39m5M/cGdZxMU0Hp9vkEjknE3b/Lyk0NIVNHaKQmuesUk4i8lJQYCLRaiFp/tcbc8WMGPO8RuUoV1GAWc34byh34NSHUFFQPIsSzPOZs1eSA+eXHQEry1O+e8XbnMrjs+ZBiodcchJeDkWD8oNehYbLQNHY555mWRgBrR0nVhi2W6btUq3tpb8iPjUhVeLgGbZcuW1zarN73zSNCw==

ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass

smtp.mailfrom=senderdomain.com; dmarc=pass action=none

header.from=senderdomain.com; dkim=pass header.d=senderdomain.com;

arc=none

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;

d=tlitech.onmicrosoft.com; s=selector2-tlitech-onmicrosoft-com;

h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;

bh=mZo+QuETvzUO70GE/h2t53XnM7athOR7wJRffoc0Hmo=;

b=fAMayxXHRz4pFvMNTuJwpgfpC+Q3Mt0BhUvJNFjybl3raudqL2TXjf+UFLsPPi09JIPnyYpLyuz8/yC7Tmp9n0ZbSN+szz5A2zi+5Ll0l3DpLMk4+5F9iWnJWf5DQaL2NY4Q7tEGY1Qdm59my/9OOVfpvPbwfb3k6HBnBrhBrEs=

Received: from SN7PR14MB4336.namprd14.prod.outlook.com (2603:10b6:806:108::9)

by SN6PR14MB2254.namprd14.prod.outlook.com (2603:10b6:805:4c::12) with

Microsoft SMTP Server (version=TLS1_2,

cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4457.23; Fri, 27 Aug

2021 21:59:27 +0000

Received: from SN7PR14MB4336.namprd14.prod.outlook.com

([fe80::c15a:7bf7:a322:a914]) by SN7PR14MB4336.namprd14.prod.outlook.com

([fe80::c15a:7bf7:a322:a914%8]) with mapi id 15.20.4436.027; Fri, 27 Aug 2021

21:59:27 +0000

From: sender <sender@senderdomain.com>

To: user1 <user1@domain.com>, user2 <user2@domain.com>, user3 <user3@domain.com>

Subject: Blah Blah Blah
Thread-Topic: Blah Blah Blah

Thread-Index: Adebi+pDp4GPNhUSQ+KEJD8iQnG7kAAAuNce

Date: Fri, 27 Aug 2021 21:59:27 +0000

Message-ID: <8B3E0717-39F6-494E-8105-3C6DA70ED383@senderdomain.com>

References: <202108272156.17RK56Fr030863@mx0a-001e6701.pphosted.com>

In-Reply-To: <202108272156.17RK56Fr030863@mx0a-001e6701.pphosted.com>

Accept-Language: en-US

Content-Language: en-US

X-MS-Has-Attach: yes

X-MS-TNEF-Correlator:

authentication-results: domain.com; dkim=none (message not signed)

header.d=none;domain.com; dmarc=none action=none

header.from=senderdomain.com;

x-ms-publictraffictype: Email

x-ms-office365-filtering-correlation-id: e077dda3-4123-4051-45ce-08d969a5f04d

x-ms-traffictypediagnostic: SN6PR14MB2254:

x-microsoft-antispam-prvs:

<SN6PR14MB2254E859EEDB69F30EE31B4BD8C89@SN6PR14MB2254.namprd14.prod.outlook.com>

x-ms-oob-tlc-oobclassifiers: OLM:2201;

x-ms-exchange-senderadcheck: 1

x-ms-exchange-antispam-relay: 0

x-microsoft-antispam: BCL:0;

x-microsoft-antispam-message-info:

dUbDX9j+AKQANnSWBEdWy7fdnlAgCxrlP0E7ovBk4De1ejUg/OrOJ5XdQlnYFcIGy7Mygs6gi+4H3TadVXjSfZYMqAO5VWi7/903RICAesm/DZrKYc+x0sWo9uF5zGP4BfdS67Ivb1DJe5giqzALuclLVyMTADT1K9A9VLoM4mLkH97JlQwHQktpVC75gzf0eyLE/axaU4Py82X2S3BBpA+LieSOURjeVI++i9XbhPa2l7EnzGSPHEpu6Anugq5rQRZROsbWtVdlnHd4O8NAWAuyeQXzcr8w68AMdXysLkAv+Hjj03lG6TJGu/HTgrT15gsGPkpg2sj6jKCcH1RqIKLw7J7Tv5qtcMKRT3ywFRVWUObqwSkX6l31M8BBq/FCHlcM2omaXfmRQkJtYQSRsFPckdRy1AKu04nq6blN3OVLrE6pkwrvBlGizQlTtVoAnqb8ZRitc/rVj9uRD9SGW/fJW6keRX5oDhMyIRps+HSi0NRuMIKgygLuJcquesKM4TOXOHmHpi1dihNiPHIxFo4rJwym46Ae0Q1+RXF8WWsYjcsFoBSqMuzuYPMdSb3gw/pR7okCiRjghEAtY4vJ4NtD+tNutl1uCRyPk6n9/ZvHemiDmYBmtHEgSCE/2dk1JKnAfaYmLbJXAgIghJGMV8d/k2z0YrkLRpk/dvD7xv66Kg3FrXgFzIfVBFASCvc6

x-forefront-antispam-report:

CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:SN7PR14MB4336.namprd14.prod.outlook.com;PTR:;CAT:NONE;SFS:(396003)(136003)(366004)(376002)(39830400003)(346002)(66556008)(64756008)(99936003)(2906002)(86362001)(66446008)(38100700002)(83380400001)(66946007)(450100002)(36756003)(122000001)(6486002)(6512007)(110136005)(5660300002)(38070700005)(478600001)(6506007)(2616005)(33656002)(186003)(66476007)(8676002)(71200400001)(76116006)(66616009)(316002)(8936002)(45980500001)(559001)(579004);DIR:OUT;SFP:1101;
 
Last edited:
Check out your Tracking Center and look for that particular email info. It should mention which rules that proceed the delivery.

Code:
Aug 29 08:29:18 pmg postfix/smtpd[82743]: connect from outbound-147-160-155-132.pinterestmail.com[147.160.155.132]
Aug 29 08:29:19 pmg postfix/smtpd[82743]: NOQUEUE: client=outbound-147-160-155-132.pinterestmail.com[147.160.155.132]
Aug 29 08:29:20 pmg pmg-smtp-filter[81864]: 40056612AD4E0147B9: new mail message-id=<DE.FC.27891.CC4DA216@ag.mta4vrest.cc.prd.sparkpost>#012
Aug 29 08:29:28 pmg pmg-smtp-filter[81864]: 40056612AD4E0147B9: SA score=0/5 time=7.779 bayes=0.00 autolearn=no autolearn_force=no hits=AWL(-0.529),BAYES_00(-1.9),CLICK_BAIT(1),DKIMWL_WL_HIGH(-0.746),DKIM_SIGNED(0.1),DKIM_VALID(-0.1),DKIM_VALID_AU(-0.1),HTML_FONT_LOW_CONTRAST(0.001),HTML_IMAGE_RATIO_02(0.001),HTML_MESSAGE(0.001),KAM_LOTSOFHASH(0.25),LIST_UNSUB(1),MPART_ALT_DIFF_COUNT(1.112),RCVD_IN_DNSWL_NONE(-0.0001),RDNS_DYNAMIC(0.982),SPF_HELO_NONE(0.001),SPF_PASS(-0.001),SUBJ_SPAM1(1),USER_IN_DEF_DKIM_WL(-7.5),USER_IN_DEF_SPF_WL(-7.5)
Aug 29 08:29:28 pmg pmg-smtp-filter[81864]: 40056612AD4E0147B9: notify <admin@mydomain.com> (rule: Quarantine bad mail subject, 0A3B541D66)
Aug 29 08:29:28 pmg pmg-smtp-filter[81864]: 40056612AD4E0147B9: moved mail for <user1@mydomain.com> to spam quarantine - 41D6D612AD4E80BF5B (rule: Quarantine bad mail subject)
Aug 29 08:29:28 pmg pmg-smtp-filter[81864]: 40056612AD4E0147B9: processing time: 7.967 seconds (7.779, 0.148, 0)
Aug 29 08:29:28 pmg postfix/smtpd[82743]: proxy-accept: END-OF-MESSAGE: 250 2.5.0 OK (40056612AD4E0147B9); from=<bounces-1113304107793270639@explore.pinterest.com> to=<user1@mydomain.com> proto=ESMTP helo=<outbound-147-160-155-132.pinterestmail.com>
Aug 29 08:29:33 pmg postfix/smtpd[82743]: disconnect from outbound-147-160-155-132.pinterestmail.com[147.160.155.132] ehlo=1 mail=1 rcpt=1 data=1 quit=1 commands=5
 

About

The Proxmox community has been around for many years and offers help and support for Proxmox VE, Proxmox Backup Server, and Proxmox Mail Gateway.
We think our community is one of the best thanks to people like you!

Get your subscription!

The Proxmox team works very hard to make sure you are running the best software and getting stable updates and security enhancements, as well as quick enterprise support. Tens of thousands of happy customers have a Proxmox subscription. Get yours easily in our online shop.

Buy now!