Tip: teach you to find the real sender of spam

  
                  

Spam mail is generally sent by mass-sending software. The sender's address can be arbitrarily forged. Checking the letter header allows you to find the real sender. The way to view the letterhead is:

1) If you are looking at the email on the web page, open the email directly and click on the "original" in the menu above the message to see the letterhead.

2) If you use OutLook Express to receive mail, point to the mail, do not open it, click the right mouse button, look at the attributes of the letter, and then click on the details, you can see the letterhead. If there is a sender, the sender is the real sender; if there is no sender, the last receivedfrom is the ***TP server used by the sender.

The basic expression format of the Receive statement is: fromServerAbyServerB, ServerA is the sending server, and ServerB is the receiving server. For example:

ReturnPath:

Received:fromns.enet.com.cn([202.106.124.167])

bymail.777.net.cn(8.9.3/8.8.7)

with***TPidTAA13043;

Thu,28Oct199919:51:28+0800

Received:(fro civilized term ist@localhost)

byns.enet.com.cn (8.9.3/8.9.0)idRAA19714

forenewsdailylist;Thu,28Oct199917:50:30+0800

Received:fromchinanetweek.com([ ,null,null,3],210.72.235.218])

byns.enet.com.cn(8.9.3/8.9.0)

withE***TPidRAA19690

for;Thu,28Oct199917: 50:28+0800

Received:fromchinanetweek.com([10.1.2.105])

bychinanetweek.com(8.9.3/8.9.0)

withE** *TPidRAA05935

for;Thu,28Oct199917:49:26+0800

(CST) Generally, the last sentence of ServerA in Receive is the address of the sender, and ServerB is the sender server that he uses. It is the starting point of the mail. The first ServerB in Receive is your own mail receiving server. The contents added by various servers in the letterhead are not the same. Sometimes you can't find any IP address or domain name in a row of Receive. In this case, you can ignore it and continue to look up.

From the above example, it is not difficult to see that this letter is sent from 10.1.2.105 (dynamic address), the delivery route is: chinanetweek.com → ns.enet.com.cn → mail.777.net .cn.

Copyright © Windows knowledge All Rights Reserved