H
hba2pd
How can they fake these email header information?
hba2pd said:How can they fake these email header information?
Peter said:There is information in the headers that you can trust, like the ip
address of the machine that handed off the message to your server,
and anything that happened after that transaction.
hba2pd said:But information before that transaction is unreliable. Therefore,
there is absolutely no information about the origination. But then how
does the police do it?
the said:i have a question here, are we ever going to replace SMTP as the
default mail client? Seems its a bit too trusting and needs some
rethinking for a dishonest world.
hba2pd said:So am I right in concluding that there is absolutely no information
about the origination. If someone wants to fake it on, say, Outlook,
how can he do this?
hba2pd said:I understand. I got an email which looks like a spam but seems to
contain some informations relevant only to insiders. I wanted to
determine whether it is an accident or on purpose.
hba2pd said:I mean the content of this supposedly spam email contains some
specific names which can be suggestive, etc. I am not sure what you
mean.
hba2pd said:here they are. ....snip...
From: "Dawkins Ollie" <[email protected]>
To: "June" <[email protected]>
Subject:
hba2pd said:here they are.Do you have a spam message that you are curious about in particular?
If you do, could you share what part of the header you're concerned
about so that we might be able to help you understand what its for,
how it got there and/or what it means?
Delivered-To: ***@gmail.com
Received: by 10.78.12.19 with SMTP id 19cs1718667hul;
Sun, 25 Mar 2007 17:50:50 -0700 (PDT)
Received: by 10.100.7.18 with SMTP id 18mr4452102ang.1174870249836;
Sun, 25 Mar 2007 17:50:49 -0700 (PDT)
Return-Path: <[email protected]>
Received: from Unknown (24-196-86-114.dhcp.mdsn.wi.charter.com
[24.196.86.114])
by mx.google.com with ESMTP id c37si12687764ana.
2007.03.25.17.50.42;
Sun, 25 Mar 2007 17:50:49 -0700 (PDT)
Received-SPF: fail (google.com: domain of (e-mail address removed) does not
designate 24.196.86.114 as permitted sender)
Message-ID: <025a01c76f40$cce30a90$82e53748@KKHZTU>
From: "Dawkins Ollie" <[email protected]>
To: "June" <[email protected]>
Subject:
Date: Sun, 25 Mar 2007 18:40:17 -0800
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_NextPart_000_0257_01C76F06.20843290"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2900.2180
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
This is a multi-part message in MIME format.