Pelican Parts Forums

Pelican Parts Forums (http://forums.pelicanparts.com/)
-   Off Topic Discussions (http://forums.pelicanparts.com/off-topic-discussions/)
-   -   Email Originating IP Address (http://forums.pelicanparts.com/off-topic-discussions/781527-email-originating-ip-address.html)

dennis in se pa 11-13-2013 11:20 PM

Email Originating IP Address
 
Is there a way to positively identify the origin of an email from the header? I have heard there is, but I don't know how to do it. Your input is appreciated.

drcoastline 11-14-2013 02:47 AM

I would be interested in this answer as well.

id10t 11-14-2013 04:19 AM

Yup, maybe - depends on how exactly the mail servers involved are configured. Can you post the entire headers?

stomachmonkey 11-14-2013 04:27 AM

Do you know how to view the headers?

What email client?

gshase 11-14-2013 06:24 AM

How come I get SPAM Email from my own Email address?

John Rogers 11-14-2013 06:27 AM

Have you ever posted an ad on Craigslist or somewhere else and somebody ask "is this still for sale"? Now they have your email.

dennis in se pa 11-14-2013 06:39 AM

ID10t - I sent the full header to you privately. I appreciate your assistance and education.

respects,
Dennis

Steve Carlton 11-14-2013 06:53 AM

Quote:

Originally Posted by john rogers (Post 7755105)
Have you ever posted an ad on Craigslist or somewhere else and somebody ask "is this still for sale"? Now they have your email.

I thought that was only true if you responded.

id10t 11-14-2013 07:46 AM

Quote:

Originally Posted by gshase (Post 7755099)
How come I get SPAM Email from my own Email address?

The "from" (and date/time stamp you see in your client) are controlled by the sending client configuration. You have to look at the headers to see exactly what mailserver sent it.

Your ISP can stop this by using SPF records and authenticated SMTP

John Rogers 11-14-2013 08:29 AM

Opps, left out the last sentence! Guess I am getting old as you do have to respond to the email.

dennis in se pa 11-15-2013 12:54 AM

id10t - did you get a chance to look at what I sent you? I know the ip address somewhere in the header is supposed to tell you where it came from. But if it came via yahoo or gmail would that carry over? As in - my local internet provider will be easily identified as from what locale, but what about the global providers? And there are a bunch of ip addresses in the header - which one is the important one in this case?

KFC911 11-15-2013 03:02 AM

Quote:

Originally Posted by dennis in se pa (Post 7754834)
Is there a way to positively identify the origin of an email from the header? I have heard there is, but I don't know how to do it. Your input is appreciated.

Not quite that easy, and you might be able to track down a casual email sender, but someone with the desire (to remain anonymous), knowledge, system access, and their ability to "spoof IP/header addresses" will simply lead you on a wild goose chase in your attempt.

Quote:

Originally Posted by id10t (Post 7754963)
Yup, maybe - depends on how exactly the mail servers involved are configured. Can you post the entire headers?

Sounds as if id10t has a good handle on SMPT and how mail servers work, but keep in mind that depending upon the "sender", you might be SOL. For a casual email user (using a common provider), you might be able to track back to their "local access point" (which might not even be an ISP or a common mail server). You're still not likely going to be able to track it back to an "individual" simply based upon the email headers. IP (and TCP, SMTP, et al) are not exactly sophisticated protocols in the scheme of things, and are pretty easy to manipulate for someone with the skill set. I always joked that if I wanted to do something "nefarious", then I would be using my CEO's (or director of security's) email/IP addresses to cover my tracks :D

id10t 11-15-2013 04:14 AM

Quote:

Originally Posted by dennis in se pa (Post 7756672)
id10t - did you get a chance to look at what I sent you? I know the ip address somewhere in the header is supposed to tell you where it came from. But if it came via yahoo or gmail would that carry over? As in - my local internet provider will be easily identified as from what locale, but what about the global providers? And there are a bunch of ip addresses in the header - which one is the important one in this case?

No email or PM with headers....

dennis in se pa 11-15-2013 04:28 AM

OOps. I thought I had sent it. But when I tried to resend it it says it is too long. So I guess it did not really go the first time. I had to cut off the bottom part to fit the character limit. Thanks again for your help with this. This is why this place is SO GREAT! PPOT for ME!


All times are GMT -8. The time now is 10:21 AM.

Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0
Copyright 2025 Pelican Parts, LLC - Posts may be archived for display on the Pelican Parts Website


DTO Garage Plus vBulletin Plugins by Drive Thru Online, Inc.