Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Mail Headers Question


You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion

Mail Headers Question
Reply
 
Thread Tools
Old 03-04-2008, 21:47   #1
Next: STS-125 -HST Repair
 
LSainsbury's Avatar
 
Join Date: Sep 2003
Location: 127.0.0.1
Services: TV: Sky Digital Phone: BT Mobile: Orange Internet: Twang.net ADSL
Posts: 4,170
LSainsbury has a bronzed appealLSainsbury has a bronzed appeal
LSainsbury has a bronzed appealLSainsbury has a bronzed appealLSainsbury has a bronzed appealLSainsbury has a bronzed appealLSainsbury has a bronzed appealLSainsbury has a bronzed appealLSainsbury has a bronzed appealLSainsbury has a bronzed appealLSainsbury has a bronzed appealLSainsbury has a bronzed appealLSainsbury has a bronzed appealLSainsbury has a bronzed appealLSainsbury has a bronzed appealLSainsbury has a bronzed appealLSainsbury has a bronzed appealLSainsbury has a bronzed appealLSainsbury has a bronzed appeal
Mail Headers Question

When looking at mail headers, where does it say who the senders ISP is?

I'm looking at a a particular email that I have recieved, which has been forwarded through a number of server and a corporate spam solution (MessageLabs)...

Any ideas on what I should look for?

Thanks
Lee
__________________
http://www.leesainsbury.com
LSainsbury is offline   Reply With Quote
Old 04-04-2008, 04:11   #2
cf.member
 
sparky621's Avatar
 
Join Date: Jan 2008
Location: Cheshire
Services: VM B'band "M" Ambit 200 Sky Dig TV
Posts: 33
sparky621 is an unknown quantity at this point
Re: Mail Headers Question

Hi Lee
Take it you're trying to trace some spam to its source?
Have a look here:
http://www.lse.ac.uk/itservices/help/emailheader.htm
it explains quite well.
Some paths can be long (and winding) but the last in the list is where its come from.
Sparky
sparky621 is offline   Reply With Quote
Old 04-04-2008, 17:26   #3
cf.mega poster
 
Join Date: Dec 2004
Posts: 2,386
Toto has reached the bronze age
Toto has reached the bronze ageToto has reached the bronze ageToto has reached the bronze ageToto has reached the bronze ageToto has reached the bronze ageToto has reached the bronze ageToto has reached the bronze ageToto has reached the bronze ageToto has reached the bronze ageToto has reached the bronze ageToto has reached the bronze ageToto has reached the bronze ageToto has reached the bronze age
Re: Mail Headers Question

As per Sparky621's comments.

The bottom most "Received from:" section contains the network IP address that sent the email.

By performing a lookup on that IP address in a regional registrar database, you should be able to find the network abuse contact, which is normally abuse@domain. A good free tool is http://geektools.com/whois.php.

The top most received from section usually contains your networks mail transport address, this will not be the sender of the email.
__________________
Toto

http://www.cableforum.co.uk/board/image.php?u=6881&dateline=1172428039&type=sigpic
Toto is offline   Reply With Quote
Old 04-04-2008, 17:29   #4
Cable Forum Team
 
Rob M's Avatar
 
Join Date: Feb 2004
Location: /root/
Age: 31
Services: netstat -tula > /home/raistlin/netstat.txt
Posts: 8,176
Rob M has a pair of shiny starsRob M has a pair of shiny stars
Rob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny starsRob M has a pair of shiny stars
Re: Mail Headers Question

Don't forget though that even if you can identify the originating IP it might not necessarily belong to the actual sender.
__________________
Formerly known as 'Raistlin'
Pausing Live TV and Eating Wotsits
Rob M is offline   Reply With Quote
Old 07-04-2008, 04:10   #5
cf.geek
 
webcrawler2050's Avatar
 
Join Date: Feb 2008
Location: Gloucester
Services: V+ VM 20MB VM Fixed Line VM Mobiles
Posts: 581
webcrawler2050 is a splendid one to beholdwebcrawler2050 is a splendid one to beholdwebcrawler2050 is a splendid one to beholdwebcrawler2050 is a splendid one to beholdwebcrawler2050 is a splendid one to beholdwebcrawler2050 is a splendid one to beholdwebcrawler2050 is a splendid one to beholdwebcrawler2050 is a splendid one to beholdwebcrawler2050 is a splendid one to behold
Send a message via MSN to webcrawler2050 Send a message via Skype™ to webcrawler2050
Re: Mail Headers Question

Could you post the header here -

With headers, you are suppost to read them bottom to top - Bottom being the start

I.E:

Microsoft Mail Internet Headers Version 2.0
Received: from GLOSFW0003.gloucester.serco.com ([192.168.50.6]) by glosex0001.internal-x.serco.com with Microsoft SMTPSVC(6.0.3790.3959);
Mon, 7 Apr 2008 00:40:16 +0100
Received: from coremtaexm04.core.serco.com (unknown [217.22.1.162])
by GLOSFW0003.gloucester.serco.com (BorderWare MXtreme Mail Firewall) with SMTP id C7B3D1F26A
for <richard.copestake@gloucester.serco.com>; Mon, 7 Apr 2008 00:17:02 +0100 (BST)
X-Spam-Checker-Version: SpamAssassin 3.2.3 (2007-08-08) on
coremtaexm04.core.serco.com
X-Spam-Level:
X-Spam-Status: No, score=-6.6 required=4.0 tests=BAYES_00,RCVD_IN_DNSWL_MED
autolearn=ham version=3.2.3
Received: from mail188.messagelabs.com ([85.158.139.163]:48246)
by coremtaexm04.core.serco.com with esmtps (TLSv1:AES256-SHA:256)
(Exim 4.50)
id 1JieT6-00050j-81
for richard.copestake@serco.com; Mon, 07 Apr 2008 00:40:12 +0100
X-VirusChecked: Checked
X-Env-Sender: email.bounces@mobilefun.co.uk
X-Msg-Ref: server-12.tower-188.messagelabs.com!1207525202!6333335!1 <<- Here is the message labs sending spam servers
X-StarScan-Version: 5.5.12.14.2; banners=-,-,-
X-Originating-IP: [62.89.145.108]
Received: (qmail 26880 invoked from network); 6 Apr 2008 23:40:02 -0000
Received: from mail.mobilefun.co.uk (HELO mail.mobilefun.co.uk) (62.89.145.108) These few lines are the sending servers and IPs

by server-12.tower-188.messagelabs.com with AES256-SHA encrypted SMTP; 6 Apr 2008 23:40:02 -0000
Received: from 62-89-145-109.pool.free.th.hotchilli.net ([62.89.145.109] helo=www.mobilefun.co.uk)
by mail.mobilefun.co.uk with esmtp (Exim 4.63) << Heres the Sending Server
id 1JieSw-0008KI-FB
for richard.copestake@serco.com; Mon, 07 Apr 2008 00:40:02 +0100
To: richard.copestake@serco.com
From: order.system@mobilefun.co.uk
Subject: Mobile Fun Order Acknowledgement - MF1325379
Message-Id: <E1JieSw-0008KI-FB@mail.mobilefun.co.uk>
Date: Mon, 07 Apr 2008 00:40:02 +0100
X-Processed-ID: 85.158.139.163
X-STA-Metric: 0 (engine=028)
X-STA-NotSpam: 0870 acknowledgement by: subject:Acknowledgem -------------
X-STA-Spam: 6pm url:customer account, sim cost:
X-BTI-AntiSpam: score:0,sta:0/028,dcc:passed,dnsbl:passed,sw:off,bsn:50/passed,spf:off,dk:off,pbmf:none,ipr:none,trusted:n o,ts:no,bs:no,ubl:passed
Return-Path: email.bounces@mobilefun.co.uk
X-OriginalArrivalTime: 06 Apr 2008 23:40:16.0459 (UTC) FILETIME=[911679B0:01C8983F]
__________________
Richard Copestake
Bionic Hosting Ltd
Company No: 6604305
Tel: 0800 756 1189: 24/7 Telephone Support | Fax: 01452 357971 - UK Web Hosting
webcrawler2050 is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 02:34.


Links
Google
 
Web www.cableforum.co.uk


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0
Copyright © 2003 - 2008, Cable Forum.
(s204569790.onlinehome.info)