Download presentation
Presentation is loading. Please wait.
Published byTyler Holmes Modified over 9 years ago
1
Tracing an Email by Etienne Takougang by Etienne Takougang
2
Introduction Do you hate Spam? Of course, we all do! Have you ever wondered just who was hiding behind those anonymous emails that keep finding their way into your Inbox? Well, this manual will help you detect and identify the origin of these anonymous emails. The most convenient way of achieving this goal is to use the program eMailTrackerPro. A free trial version is available at http://www.visualware.com/. Do you hate Spam? Of course, we all do! Have you ever wondered just who was hiding behind those anonymous emails that keep finding their way into your Inbox? Well, this manual will help you detect and identify the origin of these anonymous emails. The most convenient way of achieving this goal is to use the program eMailTrackerPro. A free trial version is available at http://www.visualware.com/. http://www.visualware.com/
3
The first step is to use an e-mail analysis tool like eMailTrackerPro, which will automatically analyze an e-mail and its headers and provide graphical results similar to the following: Using eMailTrackerPro
5
n If you do not have an actual e-mail, but only have an e-mail address, you can use the eMailTracker tool in VisualRoute to track the user to their e-mail server. n An added benefit is that you are able to see what SMTP software the mail server is running (many times with version information as well). n In most cases, using an e-mail tracking tool like eMailTrackerPro is your best option. But, if you want to understand how these tracking tools work, continue reading...
6
e-mail Internet Headers Every received e-mail has Internet Headers. Using Microsoft Outlook as an example (other mail programs are very similar), just follow these steps to view the headers: Every received e-mail has Internet Headers. Using Microsoft Outlook as an example (other mail programs are very similar), just follow these steps to view the headers: n
7
n 1. Right-click on the mail message that is still in your Outlook that is still in your Outlook Inbox Inbox n 2. Select 'Options...' from the resulting popup menu resulting popup menu n 3. Examine the 'Internet Headers’ in the resulting ‘Message in the resulting ‘Message Options’ dialog box Options’ dialog box
8
When your full header is not visible on your email: n Some email programs like Hotmail or Yahoo have their full headers hidden by default. n In order to view the full header, you must specifically turn on that option.
9
Yahoo n 1. Click Options n 2. Click Mail Preferences n 3. Click “Show Headers” n 4. Click “All” n 5. Click Save
10
Hotmail n 1. Click Options n 2. Click Mail Display Headings (under “Additional Options”) “Additional Options”) n 3. Click “Message Headers” n 4. Click “Full” n 5. Click OK
11
Example Example What you see when you view the message headers will be very similar to the following:
12
1: Received: from tes1a623.OneMail.com.sg ([203.127.89.129]) 1: Received: from tes1a623.OneMail.com.sg ([203.127.89.129]) by visualroute.com (8.11.6) id f9CIVSk24480; Fri, 12 Oct by visualroute.com (8.11.6) id f9CIVSk24480; Fri, 12 Oct 2001 12:31:29 -0600 (MDT) 2001 12:31:29 -0600 (MDT) 2: Message- 2: Message- Id: Id: 3: Received: from drb.com (IIM1608 [203.127.89.138]) by 3: Received: from drb.com (IIM1608 [203.127.89.138]) by tes1a623.OneMail.com.sg with SMTP (Microsoft Exchange tes1a623.OneMail.com.sg with SMTP (Microsoft Exchange Internet Mail Service Version 5.5.2448.0) Internet Mail Service Version 5.5.2448.0) 4: id 4XNK9ATR; Sat, 13 Oct 2001 01:19:10 +0800 4: id 4XNK9ATR; Sat, 13 Oct 2001 01:19:10 +0800 5: From: paylesslongdistance@somedomain.com 5: From: paylesslongdistance@somedomain.com 6: To: <> 6: To: <> 7: Subject: Long Distance - 4.9 cents per min - NO FEES! 7: Subject: Long Distance - 4.9 cents per min - NO FEES! 8: Date: Fri, 12 Oct 2001 13:24:26 -0400 8: Date: Fri, 12 Oct 2001 13:24:26 -0400 9: X-Sender: paylesslongdistance@yahoo.com 9: X-Sender: paylesslongdistance@yahoo.com 10: X-Mailer: QUALCOMM Windows Eudora Pro Version 4.1 10: X-Mailer: QUALCOMM Windows Eudora Pro Version 4.1 11: Content-Type: text/plain; charset="us-ascii" 11: Content-Type: text/plain; charset="us-ascii" 12: X-Priority: 3 12: X-Priority: 3 13: X-MSMail-Priority: Normal 13: X-MSMail-Priority: Normal 14: X-UIDL: 8`Y!!0GR!!"?H"!k:O!! 14: X-UIDL: 8`Y!!0GR!!"?H"!k:O!! 15: Status: U 15: Status: U
13
‘Received’ Header The most important header field for tracking purposes is the Received header field, which usually has a syntax similar to: The most important header field for tracking purposes is the Received header field, which usually has a syntax similar to: Received: Received: from ? by ? via ? with ? id ? id ? for ? date-time
14
Sender’s IP Address What is crucial for tracking, is to pay attention to the trail of IP-address in the from tokens and not necessarily the host name provided to us in the by tokens: What is crucial for tracking, is to pay attention to the trail of IP-address in the from tokens and not necessarily the host name provided to us in the by tokens: Received: Received: n from tes1a623.OneMail.com.sg ([203.127.89.129]) n by visualroute.com (8.11.6) n id f9CIVSk24480; n Fri, 12 Oct 2001 12:31:29 -0600 (MDT)
15
Track the IP Address n Use eMailTrackerPro to track the IP Address! Track down the person! The resulting trace will look somewhat like the following generic trace:
17
Conclusion As a result, by using eMailTrackerPro and analyzing email message headers, you are fully capable of tracing that mysterious email. You can now take action and rest easy. As a result, by using eMailTrackerPro and analyzing email message headers, you are fully capable of tracing that mysterious email. You can now take action and rest easy.
18
Merry Christmas and Happy New Year! Merry Christmas and Happy New Year!
19
THE END
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.