[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [cobalt-users] OT Need email header expertise, please?



> 
> This is a bit OT in that it is not really Cobalt-specific. I 
> don't have 
> elsewhere to ask.

Sure you do.

http://groups.google.com/groups?hl=en&lr=&safe=off&group=news.admin.net-
abuse.email

> I am having difficulty interpreting what is going on with 
> this and similar 
> email headers:
> 
> X-Persona: <dnsadmin>
> Return-Path: <deb1615@xxxxxxxxxxxxxxxx>
> Received: from 208.21.174.5 ([200.86.157.128])
> by mail.1bigthink.com (8.9.3/8.9.3) with SMTP id WAA14151;
> Tue, 18 Mar 2003 22:59:54 -0500

208.21.174.5 is fake. It could have said whitehouse.gov if the spammer
wanted.
http://openrbl.org/ip/200/86/157/128.htm
Everything after that is probably fake and can't be trusted.

> Received: from 2zjapui06.2hx [14.85.231.74] by 208.21.174.5 
> with ESMTP id 
> DBJWIVOTC; Tue, 18 Mar 03 19:58:25 +0400

208.21.174.5 is probably the name the spammer gave their PC and
14.85.231.74 is probably a local IP on the spammer's network.

-- 
C2003 Dan Kriwitsky

Please reply to the list only. Off list replies are not read.