Академический Документы
Профессиональный Документы
Культура Документы
Email Investigations
Learning Objectives
stephen1622@yahoo.com
HEADER
BODY
Email Body
Text
Photo
Program/applications
Files
Email Header
E-mail header = blocks of text that contain routing information
used to determine the actual origin of a message and the path it
took to reach your inbox.
CAUTION:
It is important to know that when reading an email header every
line can be forged, so only the Received: lines that are created by
your service or computer should be completely trusted.
Email Protocols and Services
Client
--srm-alternative-e67cef107a8420cbfd705b118a082deb
Content-Type: text/plain; charset=iso-8859-1
Received: (from sacoor@localhost)
by molly.sacoor.com (8.13.8/8.13.8/Submit) id s6U22gYj037145;
Wed, 30 Jul 2014 03:02:42 +0100
DATE WHEN MESSAGE WAS COMPOSED AND SENT FROM COMPOSER PC TO FIRST MAIL SERVER
Date: Wed, 30 Jul 2014 03:02:42 +0100
A UNIQUE STRING ASSIGNED BY THE MAIL SYSTEM WHEN THE MESSAGE IS FIRST CREATED
THESE CAN EASILY BE FORGED
Message-Id: <201407300202.s6U22gYj037145@molly.sacoor.com>
RECIPIENTS EMAIL ADDRESS
To: someone.someone@gmail.com
MESSAGE SUBJECT
Subject: Thank you for your visit
MIME-Version: 1.0
THE MAIL CLIENT (MAIL PROGRAM) USED TO SEND THE MESSAGE
X-Mailer: SACOOR Resources Management (External)
SENDER EMAIL ADDRESS
From: "Patricia A Silva [Sacoor Brothers Group]" <customercare@sg.sacoor.com>
Content-Type: multipart/alternative; boundary=srm-alternative-
e67cef107a8420cbfd705b118a082deb
--srm-alternative-e67cef107a8420cbfd705b118a082deb
Content-Type: text/plain; charset=iso-8859-1
MESSAGE CONTENT
Dear Someone Someone,
RECIPIENT`S EMAIL ADDRESS
Delivered-To: someone.someone@gmail.com
First Email Server
Received: by 10.50.246.15 with SMTP id xs15csp141599igc;
Tue, 29 Jul 2014 19:02:43 -0700 (PDT)
X-Received: by 10.50.138.11 with SMTP id qm11mr2440613igb.18.1406685763289;
Tue, 29 Jul 2014 19:02:43 -0700 (PDT)
The email address which should be used for bounces. The mail server will send a message to the
specified email address if the message cannot be delivered
Return-Path: <srm@molly.sacoor.com>
Gmail
Microsoft
Gmail service omits the sender IP address information from all
headers.
Only the IP address of Gmail's mail server is shown in
Received: from.
Its impossible to find a sender's true IP address in a received
Gmail.
Microsoft's Hotmail service provides an extended header line
called "X-Originating-IP" that contains the sender's actual IP
address.
Emails from Yahoo contain the sender's IP address in the last
Received: entry.
Time Zone
UTC Coordinated Universal Time
http://mxtoolbox.com/EmailHeaders.aspx
ipTRACKERonline.com
m
http://whatismyipaddress.com/trace-email
https://toolbox.googleapps.com/apps/messageheader/
Fake mail
Fake mail
c.ion@interpol.int