Skippy is correct - 4/5 - almost certainly spoofing.
There is specific data within the original email that can be inspected to determine what the source was of the email was. This may help determine if it was a bot/malware locally or a spoof (most likely), or a password issue.
|