[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[cobalt-users] OT Need email header expertise, please?



Hello All,

This is a bit OT in that it is not really Cobalt-specific. I don't have elsewhere to ask. I am having difficulty interpreting what is going on with this and similar email headers:

X-Persona: <dnsadmin>
Return-Path: <deb1615@xxxxxxxxxxxxxxxx>
Received: from 208.21.174.5 ([200.86.157.128])
by mail.1bigthink.com (8.9.3/8.9.3) with SMTP id WAA14151;
Tue, 18 Mar 2003 22:59:54 -0500
Received: from 2zjapui06.2hx [14.85.231.74] by 208.21.174.5 with ESMTP id DBJWIVOTC; Tue, 18 Mar 03 19:58:25 +0400 Received: from c1r31e6dmqm4t [30.66.92.64] by 14.85.231.74 with ESMTP id ZHGLZPE; Tue, 18 Mar 03 19:49:25 +0400
Message-ID: <3h-o05a$89pkqy64p$x4$d8@xxxxxxxxxxx>>
From: "Wanda Blue" <deb1615@xxxxxxxxxxxxxxxx>
To: <domainadmin@xxxxxxxxxxxxx>, <dross@xxxxxxxxxxxxx>
Subject: Fwd: Copy DVD's - Instant Download immyii gwsxlzcsa
Date: Tue, 18 Mar 03 19:49:25 GMT
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 5.50.4522.1200
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="DA6_EE0787CC.64DF"
X-MailScanner: Found to be clean
X-UIDL: N9:"!&S3"![3d"!gno"!

No names have been changed because I need a true interpretation. It appears that I have a spammer at 200.86.157.128 forging email headers. But the other received from IPs are DOD 30.66.92.64 and IANA 14.85.231.74 addresses. Is this part of the header forgery or is it really going through DOD and then IANA servers?

Thanks,
Glenn