PPRuNe Forums - View Single Post - Email sending out spam
View Single Post
Old 31st Mar 2014, 14:22
  #17 (permalink)  
Keef

Official PPRuNe Chaplain
 
Join Date: Apr 2001
Location: Witnesham, Suffolk
Age: 80
Posts: 3,498
Likes: 0
Received 0 Likes on 0 Posts
Depending which mail client you use, there will be something you can click to display the whole message.

If you see something that just says "From: [email protected] To: [email protected]", maybe with a date and time, then you can't tell anything from that.

What you are looking for will be something like this:
From - Fri Mar 28 14:08:30 2014
X-Account-Key: account11
X-UIDL: UID7993-1219148700
X-Mozilla-Status: 0001
X-Mozilla-Status2: 00000000
X-Mozilla-Keys:
Return-Path: <[email protected]>
Delivered-To: [email protected]
Received: from Postfix-filter-42a77884ce2a0a03efc6bb50a6dcdb21 (localhost [127.0.0.1])
by smtp-in-75.livemail.co.uk (Postfix) with SMTP id B620565420D
for <[email protected]>; Fri, 28 Mar 2014 14:04:21 +0000 (GMT)
Received: from smtp-in-110.livemail.co.uk (smtp-in-110.livemail.co.uk [213.171.216.171])
by smtp-in-75.livemail.co.uk (Postfix) with ESMTP id 28174654205
for <[email protected]>; Fri, 28 Mar 2014 14:04:18 +0000 (GMT)
Received: from Postfix-filter-42a77884ce2a0a03efc6bb50a6dcdb21 (localhost.localdomain [127.0.0.1])
by smtp-in-110.livemail.co.uk (Postfix) with SMTP id A59CBD8193
for <[email protected]>; Fri, 28 Mar 2014 14:04:18 +0000 (GMT)
Received: from 110.Red-80-37-212.staticIP.rima-tde.net (110.Red-80-37-212.staticIP.rima-tde.net [80.37.212.110])
by smtp-in-110.livemail.co.uk (Postfix) with ESMTP id 5FA11D8195
for <[email protected]>; Fri, 28 Mar 2014 14:04:18 +0000 (GMT)
Received: from 192.168.0.250 ([192.168.0.250])
Message-ID: <F2CE492568CC4D2D8AEDFAC3716F68BF@home-jjkol10>
From: "Gabriel Marlow" <[email protected]>
To: "Benjamin Davidson" <[email protected]>
Subject: Check vacancies in our company
Date: Fri, 28-Mar-2014 14:07:06 GMT
The chain starts at the bottom and works up: the IP addresses are the easiest clue.

You can see from that one that it started at 192.168.0.250 which is an address on someone's local network. If your message had that, and if don't have a local network, or if yours isn't 192.169.0.something, then you'd know already that the message didn't come from you.

The local network sent it through 80.37.212.110 - although there is no indication of the transfer from local network to mail server. "Whois" reveals where 80.37.212.110 is located. If the equivalent on your address isn't at the server address, then it's not yours.

if the problem IS in your PC, then you need to get it seen to immediately if not sooner.

If you can't decipher the headers, post them here or PM them to me and the sleuthing will begin...
Keef is offline