False Positive: Why Is This Email In Spam?

Jun 10, 2021
33
5
8
Maryland, USA
I do not understand why this email is going to Spam. Everything looks good. Spam score is 0, spf, dkim and dmarc all ok.



----
Delivered-To: user1@domain.com,user2@domain.com,user3@domain.com

Return-Path: sender@senderdomain.com

Received-SPF: pass (senderdomain.com: Sender is authorized to use 'sender@senderdomain.com' in 'mfrom' identity (mechanism 'include:spf.protection.outlook.com' matched)) receiver=titan.gams.biz; identity=mailfrom; envelope-from="sender@senderdomain.com"; helo=nam10-dm6-obe.outbound.protection.outlook.com; client-ip=40.107.93.63

Received-SPF: pass (senderdomain.com: Sender is authorized to use 'sender@senderdomain.com' in 'mfrom' identity (mechanism 'include:spf.protection.outlook.com' matched)) receiver=titan.gams.biz; identity=mailfrom; envelope-from="sender@senderdomain.com"; helo=nam10-dm6-obe.outbound.protection.outlook.com; client-ip=40.107.93.63

Received-SPF: pass (senderdomain.com: Sender is authorized to use 'sender@senderdomain.com' in 'mfrom' identity (mechanism 'include:spf.protection.outlook.com' matched)) receiver=titan.gams.biz; identity=mailfrom; envelope-from="sender@senderdomain.com"; helo=nam10-dm6-obe.outbound.protection.outlook.com; client-ip=40.107.93.63

Received: from NAM10-DM6-obe.outbound.protection.outlook.com (mail-dm6nam10on2063.outbound.protection.outlook.com [40.107.93.63])

(using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits))

(No client certificate requested)

by smtp.domain.com (Proxmox) with ESMTPS id 0409CAC1D88;

Fri, 27 Aug 2021 17:59:35 -0400 (EDT)

ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none;

b=bAnKwzWD5sAQJmyIKIHvOP42NOTb564VizfGHIIv3rK780GvHMAgSje/MEu+D+XBBv+ra98WLwlxL/bbBPIGXEi0qhhcMO7X3j4cI0E5+qhR71RGcVy6pTsIpzrUXkVoQZHZ5YGrWAnvdi/HdmOC1i9kAR5lFQc/ZG66t5ECpVuihtIhlZBR2j7nwUvyAAsy81UxLtTov4cIG+xNh1Gk5+KYd32ql/EQhLvlZV7e49Pwkc1mh1GUYmSCK8pKghSoFTeMqqk+L7cOXgImhroa+pcBAxNHmyZBUKp7rJg8tgKlB4ZLhvOvPeXbkEnIxEAP3Kif4Ss4aRs+myrGcCJLKQ==

ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com;

s=arcselector9901;

h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;

bh=mZo+QuETvzUO70GE/h2t53XnM7athOR7wJRffoc0Hmo=;

b=SZ+/S8tqAkPR96m7h0TWI5mYh1VD1wRUVdBrRSrxEV5ubA7n6Yop75edHq0YpJU9BCd7cC+e8+gu2FxeamSNlPpTPlhASSXIBpxqAIHFxbfGnqaumijzSiKtK2YEHl9ZDtHvk39m5M/cGdZxMU0Hp9vkEjknE3b/Lyk0NIVNHaKQmuesUk4i8lJQYCLRaiFp/tcbc8WMGPO8RuUoV1GAWc34byh34NSHUFFQPIsSzPOZs1eSA+eXHQEry1O+e8XbnMrjs+ZBiodcchJeDkWD8oNehYbLQNHY555mWRgBrR0nVhi2W6btUq3tpb8iPjUhVeLgGbZcuW1zarN73zSNCw==

ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass

smtp.mailfrom=senderdomain.com; dmarc=pass action=none

header.from=senderdomain.com; dkim=pass header.d=senderdomain.com;

arc=none

DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;

d=tlitech.onmicrosoft.com; s=selector2-tlitech-onmicrosoft-com;

h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck;

bh=mZo+QuETvzUO70GE/h2t53XnM7athOR7wJRffoc0Hmo=;

b=fAMayxXHRz4pFvMNTuJwpgfpC+Q3Mt0BhUvJNFjybl3raudqL2TXjf+UFLsPPi09JIPnyYpLyuz8/yC7Tmp9n0ZbSN+szz5A2zi+5Ll0l3DpLMk4+5F9iWnJWf5DQaL2NY4Q7tEGY1Qdm59my/9OOVfpvPbwfb3k6HBnBrhBrEs=

Received: from SN7PR14MB4336.namprd14.prod.outlook.com (2603:10b6:806:108::9)

by SN6PR14MB2254.namprd14.prod.outlook.com (2603:10b6:805:4c::12) with

Microsoft SMTP Server (version=TLS1_2,

cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.4457.23; Fri, 27 Aug

2021 21:59:27 +0000

Received: from SN7PR14MB4336.namprd14.prod.outlook.com

([fe80::c15a:7bf7:a322:a914]) by SN7PR14MB4336.namprd14.prod.outlook.com

([fe80::c15a:7bf7:a322:a914%8]) with mapi id 15.20.4436.027; Fri, 27 Aug 2021

21:59:27 +0000

From: sender <sender@senderdomain.com>

To: user1 <user1@domain.com>, user2 <user2@domain.com>, user3 <user3@domain.com>

Subject: Blah Blah Blah
Thread-Topic: Blah Blah Blah

Thread-Index: Adebi+pDp4GPNhUSQ+KEJD8iQnG7kAAAuNce

Date: Fri, 27 Aug 2021 21:59:27 +0000

Message-ID: <8B3E0717-39F6-494E-8105-3C6DA70ED383@senderdomain.com>

References: <202108272156.17RK56Fr030863@mx0a-001e6701.pphosted.com>

In-Reply-To: <202108272156.17RK56Fr030863@mx0a-001e6701.pphosted.com>

Accept-Language: en-US

Content-Language: en-US

X-MS-Has-Attach: yes

X-MS-TNEF-Correlator:

authentication-results: domain.com; dkim=none (message not signed)

header.d=none;domain.com; dmarc=none action=none

header.from=senderdomain.com;

x-ms-publictraffictype: Email

x-ms-office365-filtering-correlation-id: e077dda3-4123-4051-45ce-08d969a5f04d

x-ms-traffictypediagnostic: SN6PR14MB2254:

x-microsoft-antispam-prvs:

<SN6PR14MB2254E859EEDB69F30EE31B4BD8C89@SN6PR14MB2254.namprd14.prod.outlook.com>

x-ms-oob-tlc-oobclassifiers: OLM:2201;

x-ms-exchange-senderadcheck: 1

x-ms-exchange-antispam-relay: 0

x-microsoft-antispam: BCL:0;

x-microsoft-antispam-message-info:

dUbDX9j+AKQANnSWBEdWy7fdnlAgCxrlP0E7ovBk4De1ejUg/OrOJ5XdQlnYFcIGy7Mygs6gi+4H3TadVXjSfZYMqAO5VWi7/903RICAesm/DZrKYc+x0sWo9uF5zGP4BfdS67Ivb1DJe5giqzALuclLVyMTADT1K9A9VLoM4mLkH97JlQwHQktpVC75gzf0eyLE/axaU4Py82X2S3BBpA+LieSOURjeVI++i9XbhPa2l7EnzGSPHEpu6Anugq5rQRZROsbWtVdlnHd4O8NAWAuyeQXzcr8w68AMdXysLkAv+Hjj03lG6TJGu/HTgrT15gsGPkpg2sj6jKCcH1RqIKLw7J7Tv5qtcMKRT3ywFRVWUObqwSkX6l31M8BBq/FCHlcM2omaXfmRQkJtYQSRsFPckdRy1AKu04nq6blN3OVLrE6pkwrvBlGizQlTtVoAnqb8ZRitc/rVj9uRD9SGW/fJW6keRX5oDhMyIRps+HSi0NRuMIKgygLuJcquesKM4TOXOHmHpi1dihNiPHIxFo4rJwym46Ae0Q1+RXF8WWsYjcsFoBSqMuzuYPMdSb3gw/pR7okCiRjghEAtY4vJ4NtD+tNutl1uCRyPk6n9/ZvHemiDmYBmtHEgSCE/2dk1JKnAfaYmLbJXAgIghJGMV8d/k2z0YrkLRpk/dvD7xv66Kg3FrXgFzIfVBFASCvc6

x-forefront-antispam-report:

CIP:255.255.255.255;CTRY:;LANG:en;SCL:1;SRV:;IPV:NLI;SFV:NSPM;H:SN7PR14MB4336.namprd14.prod.outlook.com;PTR:;CAT:NONE;SFS:(396003)(136003)(366004)(376002)(39830400003)(346002)(66556008)(64756008)(99936003)(2906002)(86362001)(66446008)(38100700002)(83380400001)(66946007)(450100002)(36756003)(122000001)(6486002)(6512007)(110136005)(5660300002)(38070700005)(478600001)(6506007)(2616005)(33656002)(186003)(66476007)(8676002)(71200400001)(76116006)(66616009)(316002)(8936002)(45980500001)(559001)(579004);DIR:OUT;SFP:1101;
 
Last edited:
Check out your Tracking Center and look for that particular email info. It should mention which rules that proceed the delivery.

Code:
Aug 29 08:29:18 pmg postfix/smtpd[82743]: connect from outbound-147-160-155-132.pinterestmail.com[147.160.155.132]
Aug 29 08:29:19 pmg postfix/smtpd[82743]: NOQUEUE: client=outbound-147-160-155-132.pinterestmail.com[147.160.155.132]
Aug 29 08:29:20 pmg pmg-smtp-filter[81864]: 40056612AD4E0147B9: new mail message-id=<DE.FC.27891.CC4DA216@ag.mta4vrest.cc.prd.sparkpost>#012
Aug 29 08:29:28 pmg pmg-smtp-filter[81864]: 40056612AD4E0147B9: SA score=0/5 time=7.779 bayes=0.00 autolearn=no autolearn_force=no hits=AWL(-0.529),BAYES_00(-1.9),CLICK_BAIT(1),DKIMWL_WL_HIGH(-0.746),DKIM_SIGNED(0.1),DKIM_VALID(-0.1),DKIM_VALID_AU(-0.1),HTML_FONT_LOW_CONTRAST(0.001),HTML_IMAGE_RATIO_02(0.001),HTML_MESSAGE(0.001),KAM_LOTSOFHASH(0.25),LIST_UNSUB(1),MPART_ALT_DIFF_COUNT(1.112),RCVD_IN_DNSWL_NONE(-0.0001),RDNS_DYNAMIC(0.982),SPF_HELO_NONE(0.001),SPF_PASS(-0.001),SUBJ_SPAM1(1),USER_IN_DEF_DKIM_WL(-7.5),USER_IN_DEF_SPF_WL(-7.5)
Aug 29 08:29:28 pmg pmg-smtp-filter[81864]: 40056612AD4E0147B9: notify <admin@mydomain.com> (rule: Quarantine bad mail subject, 0A3B541D66)
Aug 29 08:29:28 pmg pmg-smtp-filter[81864]: 40056612AD4E0147B9: moved mail for <user1@mydomain.com> to spam quarantine - 41D6D612AD4E80BF5B (rule: Quarantine bad mail subject)
Aug 29 08:29:28 pmg pmg-smtp-filter[81864]: 40056612AD4E0147B9: processing time: 7.967 seconds (7.779, 0.148, 0)
Aug 29 08:29:28 pmg postfix/smtpd[82743]: proxy-accept: END-OF-MESSAGE: 250 2.5.0 OK (40056612AD4E0147B9); from=<bounces-1113304107793270639@explore.pinterest.com> to=<user1@mydomain.com> proto=ESMTP helo=<outbound-147-160-155-132.pinterestmail.com>
Aug 29 08:29:33 pmg postfix/smtpd[82743]: disconnect from outbound-147-160-155-132.pinterestmail.com[147.160.155.132] ehlo=1 mail=1 rcpt=1 data=1 quit=1 commands=5