Results 1 to 16 of 16
  1. #1
    My kind of town
    chitown's Avatar
    Join Date
    May 2007
    Last Online
    @
    Posts
    12,520

    Questions about locating an IP address from an email

    Once you open full headers. is senders IP address found in the 1st or 2nd line that says X-Originating-IP

    1st

    X-Apparently-To
    Return-Path
    X-YMailISG
    X-Originating-IP 65.**.***.***

    2nd

    Authentication-Results
    Received
    Received
    Message-ID
    Return-Path:
    Content-Type
    X-Originating-IP 119.**.**.***
    Last edited by chitown; 05-01-2010 at 05:10 PM.

  2. #2
    Banned Muadib's Avatar
    Join Date
    Dec 2005
    Last Online
    @
    Location
    HELL
    Posts
    4,774
    Just look at the header info on the email... Source IP & routing email server will be in the header...

  3. #3
    My kind of town
    chitown's Avatar
    Join Date
    May 2007
    Last Online
    @
    Posts
    12,520
    There are two ip addresses listed. Which one the 1st or 2nd?

  4. #4
    ทำไมคุณแปลนี้
    filch's Avatar
    Join Date
    Aug 2008
    Last Online
    06-11-2022 @ 09:10 PM
    Location
    In yer eyeballs
    Posts
    2,500
    You usually have to locate the button that says view headers, pretty easy to spot if using Hotmail, Yahoo, Gmail etc...

    But if it's in Outlook or Outlook Express right mouse click on the email and choose option>view headers - or something along those lines. Maybe just Options alone will display headers. Can't quite remember now.

  5. #5
    ทำไมคุณแปลนี้
    filch's Avatar
    Join Date
    Aug 2008
    Last Online
    06-11-2022 @ 09:10 PM
    Location
    In yer eyeballs
    Posts
    2,500
    First I believe.

  6. #6
    My kind of town
    chitown's Avatar
    Join Date
    May 2007
    Last Online
    @
    Posts
    12,520
    Of these tow which is it? 65.**.***.*** or 119.**.**.*** ???


    1st

    X-Apparently-To
    Return-Path
    X-YMailISG
    X-Originating-IP 65.**.***.***

    2nd

    Authentication-Results
    Received
    Received
    Message-ID
    Return-Path:
    Content-Type
    X-Originating-IP 119.**.**.***
    Last edited by chitown; 05-01-2010 at 05:10 PM.

  7. #7
    ทำไมคุณแปลนี้
    filch's Avatar
    Join Date
    Aug 2008
    Last Online
    06-11-2022 @ 09:10 PM
    Location
    In yer eyeballs
    Posts
    2,500
    Have a read here Chi:

    Reading email headers

  8. #8
    ทำไมคุณแปลนี้
    filch's Avatar
    Join Date
    Aug 2008
    Last Online
    06-11-2022 @ 09:10 PM
    Location
    In yer eyeballs
    Posts
    2,500
    Generally, in the "Received" section is where you want to look. You may need to run a "whois" to determine if you might have the right IP address (usually you have a good idea of where it should be coming from)... this can be done at this web address:

    http://www.arin.net/index.shtml

  9. #9
    Excommunicated baldrick's Avatar
    Join Date
    Apr 2006
    Last Online
    Today @ 09:22 AM
    Posts
    24,848
    the 65 IP is their reported mail server and the 119 IP is your mail server.

    remember the path is - their machine -> their mail server -> your mail server -> your machine

    their mail server IP is easy spoofed if they want

  10. #10
    Days Work Done! Norton's Avatar
    Join Date
    Oct 2007
    Last Online
    Today @ 06:24 AM
    Location
    Roiet
    Posts
    34,994
    Quote Originally Posted by chitown
    65.55.111.***
    IP is US. Prolly in mid west, Kansas, Nebraska?

  11. #11

    R.I.P.


    dirtydog's Avatar
    Join Date
    Jun 2005
    Last Online
    @
    Location
    Pattaya Jomtien
    Posts
    58,763
    ^They have the internet there?

  12. #12
    Days Work Done! Norton's Avatar
    Join Date
    Oct 2007
    Last Online
    Today @ 06:24 AM
    Location
    Roiet
    Posts
    34,994
    Only the latest and greatest. Voice on data too. Use the same system here in Isaan.


  13. #13
    Excommunicated baldrick's Avatar
    Join Date
    Apr 2006
    Last Online
    Today @ 09:22 AM
    Posts
    24,848
    ^ is that fibre I see there ?

  14. #14
    Days Work Done! Norton's Avatar
    Join Date
    Oct 2007
    Last Online
    Today @ 06:24 AM
    Location
    Roiet
    Posts
    34,994
    Quote Originally Posted by baldrick
    is that fibre I see there ?
    Only the best. Titanium coated fibre. Only thing to have in Isaan. Buffalo can't eat the string.

  15. #15
    Thailand Expat harrybarracuda's Avatar
    Join Date
    Sep 2009
    Last Online
    @
    Posts
    97,374
    the 65 IP is their reported mail server and the 119 IP is your mail server.

    remember the path is - their machine -> their mail server -> your mail server -> your machine

    their mail server IP is easy spoofed if they want
    If it was only always that simple. Send me an email, and it will probably go like this:

    Your machine -> your ISP's Spam and AV filters (if they have them, before or after your mail server) -> Your ISP's mail server -> My ISP's Spam and AV gateways -> My first AV/Spam gateway -> My second content filtering gateway -> My third malware gateway -> My Mail Server -> My machine.

    And all of those add header information.


  16. #16
    Excommunicated baldrick's Avatar
    Join Date
    Apr 2006
    Last Online
    Today @ 09:22 AM
    Posts
    24,848
    ^ come on be gentle with chitown , he only needed the basics

    though as the email starts and originates in the USofA we can add the stop for when the NSA gives it a scan.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •