Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

How do I trace an email that is from an unknown sender

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » The DU Lounge Donate to DU
 
merh Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Feb-25-05 10:09 AM
Original message
How do I trace an email that is from an unknown sender
that advises the sender has "heard_all_about you..."

Thanks for any help you can give!
Printer Friendly | Permalink |  | Top
Mabus Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Feb-25-05 10:14 AM
Response to Original message
1. Check the header
If you're using Netscape go to "Views", "Headers" and click "all".

Look at the originating IP number. Google "DNS lookup" and plug in the originating IP number and then you at least find out where it is coming from but not WHO send it.
Printer Friendly | Permalink |  | Top
 
merh Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Feb-25-05 10:16 AM
Response to Reply #1
2. He is using a email service provided on a website out of
argentina.
Printer Friendly | Permalink |  | Top
 
ken-in-seattle Donating Member (195 posts) Send PM | Profile | Ignore Fri Feb-25-05 10:40 AM
Response to Reply #2
5. maybe.. maybe not
headers have to be read correctly. the From: line and other lines can be forged easily. The mail server, if it is unix sendmail other unix based (mac osx is actually based on bsd unix) then there should be a line that looks like:
-----------------------------------------------
Received: from skydiver.de (<213.13.209.23>)
(my ip deleted) with SMTP id j1OJc8100501xx;
Thu, 24 Feb 2005 11:38:11 -0800 (PST)
(envelope-from iqecjt@skydiver.de)
Message-ID: <12fc01c51aa5$4235df40$ff9767db@iqecjt>
Reply-To: "ComputerCasiino" <iqecjt@skydiver.de>
From: "ComputerCasiino" <iqecjt@skydiver.de>
-----------------------------------------------

The "Received from" line is also forged, but the number in parens and brackets (<213.13.209.23>) is the actual ip address of the sending/injecting machine. If you look up the ip address in the ARIN database (google for it, WHOIS ARIN) then you see it is assigned to an address space used by RIPE (european NIC registry) http://www.ripe.net/whois?form_type=simple&full_query_string=&searchtext=213.13.209.23&do_search=Search
which tells us that it is actually registered to a portugese company in Lisbon. This still may not be the originator of the message, but it was sent from a residential DSL line and the Abuse adress listed in on this page could be contacted to further narrow it down. However most serious spams now come from China via their safe harbor spammer datacenters.
Printer Friendly | Permalink |  | Top
 
ken-in-seattle Donating Member (195 posts) Send PM | Profile | Ignore Fri Feb-25-05 10:43 AM
Response to Reply #5
6. in case you mis understand,
The above is an example pulled from my own spam in the last 10 min. Example is meant to show you which line to look at which is unlikely to be forged. Note the original email indicated germany yet the machine it was sent from is in portugal.
Printer Friendly | Permalink |  | Top
 
merh Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Feb-25-05 12:13 PM
Response to Reply #5
9. I am in outlook, how do I view the header?
:shrug:
Printer Friendly | Permalink |  | Top
 
pauliedangerously Donating Member (843 posts) Send PM | Profile | Ignore Fri Feb-25-05 12:17 PM
Response to Reply #9
10. Click on View and select "options"
The full header will appear in the bottom half of the new window that opens.
Printer Friendly | Permalink |  | Top
 
merh Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Feb-25-05 12:31 PM
Response to Reply #5
12. This is what I get
Return-Path:
Received: from cnospg.it (<209.233.197.130>) by imf10aec.mail.bellsouth.net
(InterMail vM.5.01.06.11 201-253-122-130-111-20040605) with ESMTP
id <20050225065708.GTBC2220.imf10aec.mail.bellsouth.net@cnospg.it>
for ; Fri, 25 Feb 2005 01:57:08 -0500
Received: from icon.com.ar (mx.icon.com.ar <200.69.193.15>)
by cnospg.it with esmtp
id 4D809F7413 for ; Thu, 24 Feb 2005 22:56:56 -0800
Message-ID: <000001c51b07$2ce4845c$0bdfbdd3@icon.com.ar>
From: "Acosta I. Roquefort"
To: XXXXXX
Subject: Unbelievable :)
Date: Thu, 24 Feb 2005 22:56:56 -0800
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_NextPart_000_0036_5B6A8765.6124405D"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2800.1437
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1081
X-RAV-AntiVirus: This message has been scanned for viruses on cnospg.it
Printer Friendly | Permalink |  | Top
 
merh Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Feb-25-05 10:25 AM
Response to Reply #1
3. Actually it looks like a business in Argentina
Printer Friendly | Permalink |  | Top
 
merh Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Feb-25-05 10:30 AM
Response to Reply #1
4. Then there is this
http://www.icongrouponline.com/countries.asp?sid=817382777&country=Argentina



Managers need up-to-date and comprehensive information to better plan and implement strategies in a global economy. ICON Group International is the world’s single largest publisher of global market research and business intelligence. It does so with the heavy use of econometric models and techniques, which produce high value international research and reports. These high-end reports and exportable spreadsheets cover 2,000 product categories across some 200 countries, 2,000 cities and over 16,000 companies.
Printer Friendly | Permalink |  | Top
 
RebelOne Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Feb-25-05 10:47 AM
Response to Original message
7. Here's a good tool for checking headers.
Printer Friendly | Permalink |  | Top
 
merh Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Feb-25-05 11:38 AM
Response to Reply #7
8. I'm using Outlook - how do I get the header?
Thanks for the help.
Printer Friendly | Permalink |  | Top
 
da_chimperor Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Feb-25-05 12:22 PM
Response to Reply #8
11. There should be some sort of 'show header' or 'view header' option
Edited on Fri Feb-25-05 12:23 PM by da_chimperor
Printer Friendly | Permalink |  | Top
 
merh Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Feb-25-05 12:32 PM
Response to Reply #11
13. Thanks!
:hi:
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Fri Dec 27th 2024, 09:09 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » The DU Lounge Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC