Ever wonder if anything before the hop that delivered the message to your server was legit?
Check out this text file attachment, where a spammer's "search and replace" didn't quite work. The first instance of the yahoo section worked, and an extra section leaves his replacement variables... not replaced. The "snip" lines replace the targeted email address, plus two tracking URLs in the body. Andrew 8)
spam.mim
Description: Binary data
