Forum Discussion
Scary Email Scams...
There's all kinds of info in the message source, but one thing you see (I haven't looked at a message source in a long time, but I imagine they haven't changed much) is where the email comes from (gmail, for instance). Sometimes there are IP addresses there too. Most of the rest makes no sense to me, but I'll be happy to send it to the Feds.
GabeU wrote:
The only thing I could figure out to do in order to see anything more than the sender email address is to "View Message Source", and it shows a huge amount of info, all of which is foreign to me. I don't know what it is I'm supposed to be looking for or seeing.
The trick is to always look for the first "Received From" then there will be an IP in square brakets. That is the IP of the server that HELO'd your email server before it sent it. Everything else can be forged, including the servername that's supposed to be associated with the IP. Not likely the IP itself was was forged during a HELO handshake.
Edit: Looks like this:
Received: from APC01-SG2-obe.outbound.protection.outlook.com (mail-sg2apc01hn0245.outbound.protection.outlook.com [104.47.125.245])
- maratsade8 years agoDistinguished Professor IV
That part's missing from Gmail emails, right? I thought Gmail didn't include the sender's IP in the header.
MarkJFine wrote:The trick is to always look for the first "Received From" then there will be an IP in square brakets. That is the IP of the server that HELO'd your email server before it sent it.
- MarkJFine8 years agoProfessor
maratsade wrote:That part's missing from Gmail emails, right? I thought Gmail didn't include the sender's IP in the header.
Hmmm. Haven't noticed, tbh.
- maratsade8 years agoDistinguished Professor IV
They may have changed this -- I remember a long time ago reading that Google did not include the sender's IP address in the headers. I haven't really checked, as my knowledge of this is extremely basic.
Related Content
- 6 years ago
- 5 years ago
- 5 years ago