Phishing and Yahoo!

I received the following by email:
From - Thu Jun 07 06:20:28 2012
X-Account-Key: account7
X-Mozilla-Status: 0001
X-Mozilla-Status2: 00000000
X-Apparently-To: via 188.
125.83.173; Mon, 04 Jun 2012 08:00:45 +0000
Received-SPF: none (domain of does not designate pe
rmitted sender hosts)
X-Originating-IP: []
Authentication-Results:  from=yaho; domainkeys=neutral (no sig);; dkim=neu
tral (no sig)
Received: from  (EHLO (
  by with SMTP; Mon, 04 Jun 2012 08:00:45 +0000
Received: from (b-bigip1 [])
 by (Postfix) with SMTP id CC23520633CB
 for ; Mon,  4 Jun 2012 08:00:44 +0000 (UTC)
X-Panda: scanned!
X-Spam-Summary: 10,1,0,5655376599ed7ef8,d41d8cd98f00b204,mail,,RULES_HIT:355
0,MSF:not bulk,SPF:fn,MSBL:none,DNSBL:none,Custom_rules:0:0:0
X-Session-Marker: 6F7A6F616B73406875676865732E6E6574
X-Filterd-Recvd-Size: 1378
Received: from ( [])
 (Authenticated sender:
 by (Postfix) with ESMTP
 for ; Mon,  4 Jun 2012 08:00:43 +0000 (UTC)
Date: Mon, 4 Jun 2012 17:00:42 +0900
From: Yahoo 
Subject: Pending Message!
Message-ID: <>
X-Priority: 3
X-Mailer: PHPMailer [version ]
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
Content-Type: text/html; charset="iso-8859-1"

<img alt="" 

<p><FONT face=Verdana size=2>Dear Yahoo User ,<BR></FONT></P>
<P><FONT face=Verdana size=2>your two incoming mails were placed on pending status due to 

the recent upgrade to our database,<P><FONT face=Verdana size=2>In order to recieve the 

       <a class="style1"><A

</span><FONT face=Verdana size=2>Click here</a>.</span>to login and wait for responds from 

yahoo.</span><P><FONT face=Verdana size=2>

We apologise for any inconvenience and appreciate your understanding.<P>

[note - broken img tag (no >), reference to class with no css, horrible markup, equally horrible spelling; I have reformatted some of the ridiculously long lines (X-Spam-Summary, etc) to fit into this article - the original is available upon request...]

As this would appear to be a phishing attempt, I felt perhaps Yahoo! might like to know. I receive mail from Yahoo! by POP into Thunderbird, so I can't report directly from Yahoo! itself.

So I search the website. And I search some more. Eventually, having not found anything like an "abuse at yahoo dot com" reporting facility, I send an email under the heading "Suspicious email from Yahoo" (as none of the other categories are relevant). My message read:

I'm using POP email, and just spent ten minutes going in circles around your site. Is there no "" address I could forward this stuff on to?
Whatever, here's a copy of the email I received with headers. As it claims to be from you, I thought you might like to be aware of it...

[the email as shown above, including headers, pasted here]

I received a prompt reply from Sarah who obviously obviously a customer support operative rather than a techie.
That's probably a bit rough on Sarah, she's probably replying from a set of official cue cards...

Here's what she had to say:

Hello Rick,
Thank you for contacting Yahoo! Mail.
The following Yahoo! Mail Help article should be helpful in resolving your issue. Please use the link below to review the article.
How to report spam to Yahoo!
Thank you again for contacting Yahoo! Mail.

From the help page linked, I quote the relevant paragraphs:

If you don't have a Yahoo! account, but want to report spam from a Yahoo! address
The fastest and most effective way to report spam is to mark the email as spam directly in your inbox, even if you don't have a Yahoo! Mail account -- just look for a "Spam," "Report Spam" or "Junk Mail" button in your inbox. Even though you may be using a different email service, if the spam offender is a Yahoo! user, the report will be sent to us.
Every major email provider has a system for reporting spam or junk mail, and information about spammers is shared across providers. As a result, if a Gmail user marks a message from a Yahoo! user as spam in a Gmail account, the report will be sent to us, and we can take appropriate action when necessary according to our Terms of Service. The fight against spam is much bigger than just Yahoo!, and we partner with other email providers including, but not limited to Gmail, Hotmail, and AOL to identify spammers and prevent them from sending mail to or from our accounts.

Not one single mention of how to tackle spam or suspect messages if you are using your own email client. Is Yahoo! so WEB2.0 that they've forgotten what email actually is and how it works?

Whatever... I feel like I'm chasing phantoms. I won't bother reporting this sort of thing in the future. Instead I'll just mark Sarah's reply as not helpful (sorry Sarah) and provide a link to this article in the "why" box. Maybe, hopefully, somebody higher up the food chain will understand what I'm trying to say here.


Update (twenty eight hiccups later...)

Made a follow-up report to Yahoo!. The screenshot says it all.


Patric, 22nd June 2012, 03:28
I feel with you Rick, my yahoo spam mostly coming from yahoo groups though *sigh* 
Haven't forgotten about your battery btw (in case you've been wondering). Figured you're not desperately in need of it atm since your Beagle appears to be out of service (good excuse for me being lazy).
Stewart, 22nd June 2012, 18:17
After a l-o-n-g break, I've started reporting to Spam-Cop 
again: doubt if it does any good though. 

