Hi, This message passes DKIM for adobespark.com and hits the sendgrid SPBL rule, but also USER_IN_DEF_SPF_WL. I'm trying to understand how this message was not caught and how it was allowed to apparently manipulate these services.
What is the attachment included in the email? https://pastebin.com/mm2JiT3L Thanks, Alex