Return-Path:
Delivered-To: oxcpoxcp+spam@server.oxoserver.com
Received: from server.oxoserver.com
by server.oxoserver.com with LMTP
id 0TtsM4Y+NGr1xhIApFFIGg
(envelope-from )
for ; Thu, 18 Jun 2026 18:52:54 +0000
Return-path:
Envelope-to: admin@oxoserver.com
Delivery-date: Thu, 18 Jun 2026 18:52:54 +0000
Received: from ip-109-254-107-13.eq.dec.net.ua ([109.254.107.13]:56906 helo=cardmember.com)
by server.oxoserver.com with esmtp (Exim 4.99.4)
(envelope-from )
id 1waHrE-00000005A66-0LZR
for admin@oxoserver.com;
Thu, 18 Jun 2026 18:52:54 +0000
From: "American Express"
To: admin@oxoserver.com
Date: 18 Jun 2026 21:52:11 +0300
Message-ID: <20260618215210.5363F18C14D4FC4E@cardmember.com>
MIME-Version: 1.0
Content-Type: text/html;
charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
X-Spam-Status: Yes, score=12.7
X-Spam-Score: 127
X-Spam-Bar: ++++++++++++
X-Spam-Report: Spam detection software, running on the system "server.oxoserver.com",
has identified this incoming email as possible spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
root\@localhost for details.
Content preview: See details inside Account ending: 37XXX00
Content analysis details: (12.7 points, 5.0 required)
pts rule name description
---- ---------------------- --------------------------------------------------
0.0 URIBL_DBL_BLOCKED_OPENDNS ADMINISTRATOR NOTICE: The query to
dbl.spamhaus.org was blocked due to usage of an
open resolver. See
https://www.spamhaus.org/returnc/pub/
[URI: www.americanexpress.com]
[URI: bhartionline.com]
[URI: americanexpress.com]
[URI: cdaas.americanexpress.com]
[URI: www.aexp-static.com]
[URI: global.americanexpress.com]
0.0 KAM_DMARC_STATUS Test Rule for DKIM or SPF Failure with Strict
Alignment
0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked.
See
http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block
for more information.
[URI: bhartionline.com]
[URI: americanexpress.com]
[URI: aexp-static.com]
0.0 HTML_MESSAGE BODY: HTML included in message
0.1 MIME_HTML_ONLY BODY: Message only has text/html MIME parts
0.5 KAM_REALLYHUGEIMGSRC RAW: Spam with image tags with ridiculously huge
http urls
1.5 KAM_GOOGLE_REDIR Use of Google redir
1.5 GOOG_REDIR_HTML_ONLY Google redirect to obscure spamvertised website
+ HTML only
0.5 GOOG_REDIR_NOTRDNS Google redirect to obscure spamvertised website +
HELO is not rDNS
1.0 KAM_LAZY_DOMAIN_SECURITY Sending domain does not have any
anti-forgery methods
2.6 RDNS_DYNAMIC Delivered to internal network by host with
dynamic-looking rDNS
0.0 TVD_PH_SUBJ_META1 Email has a Phishy looking subject line
5.0 URI_WP_HACKED URI for compromised WordPress site, possible malware
X-Spam-Flag: YES
Subject: ***SPAM*** We've temporarily flagged your account.
See details inside
<=
/P>
Account en=
ding: 37XXX00
=
We couldn’t approve a recent purchase on you=
r Account
<=
/TABLE>
What happened
We noticed that you or one of your employees recen=
tly attempted to make a purchase with an Employee Card on your account. We =
couldn’t approve that purchase because we believe is unauthorize=
d
Your account has been flagged to prevent new&=
nbsp;transcation unstill this is resloved
=
TBODY>
What we need from you
We strongly suggest, that you try to do the follow=
ing
*Patriot Act Notice: <=
/SPAN>Federal law requires all financial institutions to obtain, verify and=
record information that identifies each person who opens an account, inclu=
ding your name, address, date of birth and other information that will allo=
w us to verify your identity.
Your account information is included above to help=
you recognize this as a customer care email from American Express. To lear=
n more about email security or report a suspicious email, please visit us a=
tameric=
anexpress.com/phishing. We kindly ask you not to reply to this email bu=
t instead contact us viaCustomer Care=
A>.