Moldova, if it was a scam then why is it being triggered on his test emails??? More likely a corrupt mail database which the warning message was stored on..
Dave, the limit is 10Mb, the 9.7 triggered it as a binary (jpg/exe/zip files) have to be encoded into text to allow them to be abled to send via email which is text based, the encoding adds more data hence a 9.7Mb message goes over the 10Mb limit

As asked though can you forward the full header from one of the emails please (taking out your email addies)