I received this morning a very good phishing attempts in my mailbox. The email is almost perfectly crafted to match the usual Bank of America communications, except for two details:
  1. BoA-Phishing-20130611.pngThere is no DKIM signature. It shows right away because of the little icon on the "From" line, displayed by my DKIMStatus plugin for roundcube.
  2. The link below "To get start" (with a spelling mistake that I didn't notice at first) point to http://oncu*****.com/bura****.com.tr/index4.html, which is obviously not the BoA website...

Still, this phishing is one of the most dangerously well crafted I've seen in a long time... Stay sharp, and don't click on these links!