check to see where the page they're sending you to is located. if its a US based host thats allowing someone to host bank scams on their network, it shouldnt be too hard to get the sites pulled.
if they're in some crazy third world country, there probably isnt shit you can do about it short of configuring your mail stuff to use that SPF shit.
|