Ip address identificactions

goodole1

Member
Nov 17, 2003
72
0
0
Sometimes I receive emails etc that are just downright not right. Is there software to read the header and tell you who the host is and possible sender information?
 

elcamino74ss

Senior member
Jun 6, 2005
215
0
0
depending on your mail client but all that info is already in the original email and you do not need another piece of software. check the help on your mail client.
 

goodole1

Member
Nov 17, 2003
72
0
0
Yes the info is there but to interpret the info is another thing. All the letters and number are great, but if you can't understand the acronyms it's kind of a lost cause.

Thanks
 

engineereeyore

Platinum Member
Jul 23, 2005
2,070
0
0
If you're just looking for the source IP address, you should only need to look at the received items. These are usually listed in descending order, newest to oldest, I believe. So the first entry should tell you who gave it to your computer and from whom they got it. Follow that all the say down and you should see the IP address of the computer it came from. This may be the address of the mail server though and not the actual computer, depending on how they were connected.
 

bsobel

Moderator Emeritus<br>Elite Member
Dec 9, 2001
13,346
0
0
Originally posted by: engineereeyore
If you're just looking for the source IP address, you should only need to look at the received items. These are usually listed in descending order, newest to oldest, I believe. So the first entry should tell you who gave it to your computer and from whom they got it. Follow that all the say down and you should see the IP address of the computer it came from. This may be the address of the mail server though and not the actual computer, depending on how they were connected.

Unfortunately you can only 'trust' the last header you can verify. For most users that is the first received header. Anything up stream may simply have been forged. Spammers will often inject bogus received headers to make fake sources (trust me on this, I've seen plenty, we scan about 1/4 of the overall global email traffic)

And frankly, if it's spam we are talking about, it's most likely overseas or from a bot. There are few true 'spamming' server left in the US. Most email bots send only a few spams per day (I've seen numbers from 3-20 for smart bot nets). Meaning you can spend a week shutting down a bot, but you've killed 3 emails, not the botnet which is generating millions.
 

engineereeyore

Platinum Member
Jul 23, 2005
2,070
0
0
Originally posted by: bsobel
Unfortunately you can only 'trust' the last header you can verify. For most users that is the first received header. Anything up stream may simply have been forged. Spammers will often inject bogus received headers to make fake sources (trust me on this, I've seen plenty, we scan about 1/4 of the overall global email traffic)

And frankly, if it's spam we are talking about, it's most likely overseas or from a bot. There are few true 'spamming' server left in the US. Most email bots send only a few spams per day (I've seen numbers from 3-20 for smart bot nets). Meaning you can spend a week shutting down a bot, but you've killed 3 emails, not the botnet which is generating millions.

Very true. It is possible that you'll occasionally actually catch someone using their home computer to send out such messages and don't know how to cover their tracks, but most of the time what you see is bogus. We had to write our own email client while I was in college and it's nuts how easy it is to forge all that information. I would think that placing a few more restrictions on outgoing mail servers would help fix this, but how do you implement that world-wide?
 

engineereeyore

Platinum Member
Jul 23, 2005
2,070
0
0
Originally posted by: bsobel
but how do you implement that world-wide?

Slowly over time e.g. SPF, domain keys, etc...

Very true. I haven't done a lot with mail server specifications in a while. Have they started mandating any of this yet or it is still left to the service provider to decide if they want to use it?
 

bsobel

Moderator Emeritus<br>Elite Member
Dec 9, 2001
13,346
0
0
Originally posted by: engineereeyore
Originally posted by: bsobel
but how do you implement that world-wide?

Slowly over time e.g. SPF, domain keys, etc...

Very true. I haven't done a lot with mail server specifications in a while. Have they started mandating any of this yet or it is still left to the service provider to decide if they want to use it?

Its not mandated, what your seeing is the larger providers enabling it and using it as part of spam scoring. The smaller providers have to support it to ensure their mail flows properly to the 'big boys' (hotmail, gmail, yahoo, etc...) Not ideal but is helping and can only improve matters over time.
 

goodole1

Member
Nov 17, 2003
72
0
0
Well I can tell you it's not a spam issue, I just block most of them with software, it's more or less a fraudulent situation. I've tried to ping most of the address's in the header only to find two of maybe 6 valid. I just thought there was an easier way out of China town so to speak.

Thanks for your comments.

 

SunnyD

Belgian Waffler
Jan 2, 2001
32,674
146
106
www.neftastic.com
Originally posted by: goodole1
Well I can tell you it's not a spam issue, I just block most of them with software, it's more or less a fraudulent situation. I've tried to ping most of the address's in the header only to find two of maybe 6 valid. I just thought there was an easier way out of China town so to speak.

Thanks for your comments.

Ping? Keep in mind that a lot of servers will outright block ICMP requests. Definitely not a good test to see if something is alive.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |