Difference between revisions of "Email spoofing"

Ben (Talk | contribs)
Ben (Talk | contribs)
 
Line 16: Line 16:
  
 
Delivered-To: dmitri@vitaliev.info<br>
 
Delivered-To: dmitri@vitaliev.info<br>
Received: by 10.220.151.69 with SMTP id b5csp114879vcw;
+
Received: by 10.220.151.69 with SMTP id b5csp114879vcw;<br>
Sun, 28 Oct 2012 20:05:50 -0700 (PDT)
+
Sun, 28 Oct 2012 20:05:50 -0700 (PDT)<br>
Received: by 10.14.216.193 with SMTP id g41mr47392166eep.37.1351479949985;
+
Received: by 10.14.216.193 with SMTP id g41mr47392166eep.37.1351479949985;<br>
Sun, 28 Oct 2012 20:05:49 -0700 (PDT)
+
Sun, 28 Oct 2012 20:05:49 -0700 (PDT)<br>
Return-Path: <joe.average@webmail.com>
+
Return-Path: <joe.average@webmail.com><br>
Received: from emkei.cz ([2a01:5e0:36:5001::20])
+
Received: from emkei.cz ([2a01:5e0:36:5001::20])<br>
by mx.google.com with ESMTP id z46si13229132eeo.136.2012.10.28.20.05.49;
+
by mx.google.com with ESMTP id z46si13229132eeo.136.2012.10.28.20.05.49;<br>
Sun, 28 Oct 2012 20:05:49 -0700 (PDT)
+
Sun, 28 Oct 2012 20:05:49 -0700 (PDT)<br>
Received-SPF: neutral (google.com: 2a01:5e0:36:5001::20 is neither permitted nor denied by best guess record for domain of joe.average@webmail.com) client-ip=2a01:5e0:36:5001::20;
+
Received-SPF: neutral (google.com: 2a01:5e0:36:5001::20 is neither permitted nor denied by best guess record for domain of joe.average@webmail.com) client-ip=2a01:5e0:36:5001::20;<br>
Authentication-Results: mx.google.com; spf=neutral (google.com: 2a01:5e0:36:5001::20 is neither permitted nor denied by best guess record for domain of joe.average@webmail.com) smtp.mail=joe.average@webmail.com
+
Authentication-Results: mx.google.com; spf=neutral (google.com: 2a01:5e0:36:5001::20 is neither permitted nor denied by best guess record for domain of joe.average@webmail.com) smtp.mail=joe.average@webmail.com<br>
Received: by emkei.cz (Postfix, from userid 33)
+
Received: by emkei.cz (Postfix, from userid 33)<br>
id 8423ED5A2D; Mon, 29 Oct 2012 04:05:48 +0100 (CET)
+
id 8423ED5A2D; Mon, 29 Oct 2012 04:05:48 +0100 (CET)<br>
To: dmitri@vitaliev.info
+
To: dmitri@vitaliev.info<br>
Subject: long time no see
+
Subject: long time no see<br>
From: "Joe Average" <joe.average@webmail.com>
+
From: "Joe Average" <joe.average@webmail.com><br>
X-Priority: 3 (Normal)
+
X-Priority: 3 (Normal)<br>
Importance: Normal
+
Importance: Normal<br>
Errors-To: joe.average@webmail.com
+
Errors-To: joe.average@webmail.com<br>
Reply-To: joe.average@webmail.com
+
Reply-To: joe.average@webmail.com<br>
Content-Type: text/plain; charset=utf-8
+
Content-Type: text/plain; charset=utf-8<br>
Message-Id: <20121029030548.8423ED5A2D@emkei.cz>
+
Message-Id: <20121029030548.8423ED5A2D@emkei.cz><br>
Date: Mon, 29 Oct 2012 04:05:48 +0100 (CET)
+
Date: Mon, 29 Oct 2012 04:05:48 +0100 (CET)<br>
  
 
Reading the message from the bottom up, look for telling signs of the real server where the message was sent from. You will see right away that this particular email is being sent from the @emkei.cz domain and not webmail.com
 
Reading the message from the bottom up, look for telling signs of the real server where the message was sent from. You will see right away that this particular email is being sent from the @emkei.cz domain and not webmail.com

Latest revision as of 20:08, 27 May 2014

Last modified 11 years ago
Cancel

Help improve this page!

Cancel

Keep track of this page and all changes to it.