Hello and welcome to CertForums.co.uk, here we host free active certification forums with links to the best free resources for Microsoft's MCSA MCSE MCDBA Cisco's CCNA CCDA and CCNP, and CompTIA's A+ Network+ i-NET+ and Security+ certifications in the UK. If you wish to post or use other advanced features you will need to register first. Registration is absolutely free and takes only a few minutes to complete so sign up today!

If you have any problems with the registration process or your account login, please contact support

Go Back   CertForums > Computing Support Forums > Connectivity, Telecommunications & the Internet
Home Forums Register Search Today's Posts Mark Forums Read

Tracing emails

Post New ThreadReply
 
Thread Tools Display Modes
  #1  
Old 17-Feb-2008, 03:06 PM
Abs Abs is offline
New Member
Posts: 18
Points: 0 Abs has no points
Power: 2
None
Join Date: 15 Sep 2007
Tracing emails

Hi guys....I was wondering is it pssible to find out where the person who sends email to you is. I know the person and he send me an email, can I found out the country he is in when he send that email? Thanks.

 
Reply With Quote
  #2  
Old 17-Feb-2008, 03:16 PM
Sparky's Avatar
Sparky Sparky is offline
Premium Member
Posts: 5,001
Points: 2421 Sparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 points
Power: 79
None
Join Date: 15 Dec 2005
Location: Scotland
Age: 29
Certifications: MSc MCSE MCTS N+ A+
WIP: Server 2008 upgrade & 70-284
If you run nslookup and query the mx record of the domain you can then put the IP into an application such as neotrace. This should give you some more info to where the email is originating from.


Me: You need to buy a couple of servers.
Customer: Whats wrong with the servers I have?
Me: Well, you dont have *any* servers just now.
Customer: WTF! I thought I did!

 
Reply With Quote
  #3  
Old 17-Feb-2008, 03:26 PM
Abs Abs is offline
New Member
Posts: 18
Points: 0 Abs has no points
Power: 2
None
Join Date: 15 Sep 2007
Sparky

Thanks for that answer. Only problem is Im a noob and the answer totally went over my head lool. How do I do NSlookup and query the mx record of the domain? And is neotrace a free application that can be downloaded free from the internet? Thanks

 
Reply With Quote
  #4  
Old 17-Feb-2008, 03:36 PM
UCHEEKYMONKEY's Avatar
UCHEEKYMONKEY UCHEEKYMONKEY is offline
Toto
Posts: 3,467
Points: 1977 UCHEEKYMONKEY has over 1500 pointsUCHEEKYMONKEY has over 1500 pointsUCHEEKYMONKEY has over 1500 pointsUCHEEKYMONKEY has over 1500 pointsUCHEEKYMONKEY has over 1500 pointsUCHEEKYMONKEY has over 1500 pointsUCHEEKYMONKEY has over 1500 pointsUCHEEKYMONKEY has over 1500 pointsUCHEEKYMONKEY has over 1500 pointsUCHEEKYMONKEY has over 1500 pointsUCHEEKYMONKEY has over 1500 points
Power: 57
None
Join Date: 04 May 2006
Quote:
Originally Posted by Abs View Post
Sparky

Thanks for that answer. Only problem is Im a noob and the answer totally went over my head lool. How do I do NSlookup and query the mx record of the domain? And is neotrace a free application that can be downloaded free from the internet? Thanks
Using the command window (MS DOS) then enter the commands shown by sparky!

Also just incase - to get to the command window press windows key and the letter R on the keyboard or select the run command under the start menu. then type the following letting CMD and press enter to get the command window up


Last edited by UCHEEKYMONKEY : 17-Feb-2008 at 03:38 PM.
 
Reply With Quote
  #5  
Old 17-Feb-2008, 03:40 PM
Sparky's Avatar
Sparky Sparky is offline
Premium Member
Posts: 5,001
Points: 2421 Sparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 points
Power: 79
None
Join Date: 15 Dec 2005
Location: Scotland
Age: 29
Certifications: MSc MCSE MCTS N+ A+
WIP: Server 2008 upgrade & 70-284
Start>run

Type cmd and then the command window should appear. Type nslookup.

Then type ‘set type=mx’ and then type in the domain you are trying to query (e.g hotmail.com). It should come back with the IP address of where mail records are pointing to. If it displays something like mail.hotmail.com then type ‘set type=a’ and then type mail.hotmail.com (or whatever the A record is) and that will give you the IP address.

It is worth noting that the MX records might be pointing to a completely different server to where the email is actually originating from. In some cases the email can go to separate server to be scanning for viruses and then forwarded to the mail server.

You have to pay for neotrace (I think!) but you may be able to get a trial version.


Me: You need to buy a couple of servers.
Customer: Whats wrong with the servers I have?
Me: Well, you dont have *any* servers just now.
Customer: WTF! I thought I did!

 
Reply With Quote
  #6  
Old 17-Feb-2008, 03:58 PM
Fergal1982's Avatar
Fergal1982 Fergal1982 is offline CertForums News Posting Member
Linux Àihǎozhě: bù zàihū!
Posts: 2,803
Points: 3860 Fergal1982 has over 3000 pointsFergal1982 has over 3000 pointsFergal1982 has over 3000 pointsFergal1982 has over 3000 pointsFergal1982 has over 3000 pointsFergal1982 has over 3000 pointsFergal1982 has over 3000 pointsFergal1982 has over 3000 pointsFergal1982 has over 3000 pointsFergal1982 has over 3000 pointsFergal1982 has over 3000 points
Power: 74
None
Join Date: 04 May 2004
Location: Aberdeen, UK
Age: 25
Certifications: ITIL Foundation
WIP: 70-536,70-294,(A+), Procastination+
ummm. that doesnt really work. That will tell you the IP address of the mailserver the domain in question uses. But it doesnt tell you where the user actually sends it from. For example, my work mail server is based in Aberdeen, if I use pop3 on my laptop to connect to that server, and send an email from my account whilst im in nigeria, Sparky's method will tell you im in Aberdeen.

The mail server in question likely records the ip address of the sender, but im not entirely sure if that is captured in the email headers to be honest.


"Im Nerdy in the extreme and whiter than sour cream"


ObsidianPhoenix - my development blog



 
Reply With Quote
  #7  
Old 17-Feb-2008, 04:10 PM
Sparky's Avatar
Sparky Sparky is offline
Premium Member
Posts: 5,001
Points: 2421 Sparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 pointsSparky has over 2000 points
Power: 79
None
Join Date: 15 Dec 2005
Location: Scotland
Age: 29
Certifications: MSc MCSE MCTS N+ A+
WIP: Server 2008 upgrade & 70-284
Yeah, it’s based on the assumption that the user is located in the same office as the mail server. I just thought the OP was asking where the email was originating from (the actual domain that is).

There are other points to consider as well, the mail server might use a smarthost therefore the email will originate from the ISPs IP address and not the IP of the mail server.


Me: You need to buy a couple of servers.
Customer: Whats wrong with the servers I have?
Me: Well, you dont have *any* servers just now.
Customer: WTF! I thought I did!

 
Reply With Quote
  #8  
Old 17-Feb-2008, 04:28 PM
UCHEEKYMONKEY's Avatar
UCHEEKYMONKEY UCHEEKYMONKEY is offline
Toto
Posts: 3,467
Points: 1977 UCHEEKYMONKEY has over 1500 pointsUCHEEKYMONKEY has over 1500 pointsUCHEEKYMONKEY has over 1500 pointsUCHEEKYMONKEY has over 1500 pointsUCHEEKYMONKEY has over 1500 pointsUCHEEKYMONKEY has over 1500 pointsUCHEEKYMONKEY has over 1500 pointsUCHEEKYMONKEY has over 1500 pointsUCHEEKYMONKEY has over 1500 pointsUCHEEKYMONKEY has over 1500 pointsUCHEEKYMONKEY has over 1500 points
Power: 57
None
Join Date: 04 May 2006
I think he wanted to know which country the emailer was from.

ABS - you could use a program called track and trace or use the Email Internet Headers


Right-click on the mail message that is still in your Outlook Inbox
Select 'Options...' from the resulting popup menu
Examine the 'Internet Headers' in the resulting 'Message Options' dialog
TIP: Right-click in the 'Internet Headers' field and click on 'Select All' in the popup menu (or type ctrl-A). Then right-click again and click on 'Copy' in the popup menu (or type ctrl-C). Finally, paste all the Internet Headers into your favorite text editor for full examination (such as 'Notepad', included with Windows).

Source:Email tracer

 
Reply With Quote
  #9  
Old 17-Feb-2008, 06:39 PM
JonnyMX's Avatar
JonnyMX JonnyMX is offline
Lifetime Member
Posts: 2,390
Points: 1505 JonnyMX has over 1500 pointsJonnyMX has over 1500 pointsJonnyMX has over 1500 pointsJonnyMX has over 1500 pointsJonnyMX has over 1500 pointsJonnyMX has over 1500 pointsJonnyMX has over 1500 pointsJonnyMX has over 1500 pointsJonnyMX has over 1500 pointsJonnyMX has over 1500 pointsJonnyMX has over 1500 points
Power: 44
None
Join Date: 28 Apr 2005
Location: Newport
Age: 36
Certifications: MCSD, i-Net+, Master CIW Designer
WIP: Hmmm...
The non-technical answer is 'why do you want to know?' and 'isn't there an easier way of finding out?'.

The first things that come to mind are:

1) Your boyfriend/girlfriend etc have gone on a business trip and you want to make sure they really HAVE gone to Slough and aren't with their ex down the road.

2) You're a 419 scammer who had been baited and wants to send someone around to kick the culprit's head in.

3) Er, stuck now.




'To err is human, but to really foul things up you need a computer' Anon, 1978
 
Reply With Quote
  #10  
Old 17-Feb-2008, 09:01 PM
hbroomhall hbroomhall is offline
Premium Member
Posts: 5,976
Points: 2032 hbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 pointshbroomhall has over 2000 points
Power: 85
None
Join Date: 08 Sep 2005
Location: Tunbridge Wells, Kent
Certifications: ECDL A+ Network+ i-Net+
WIP: Server+
The first port of call in deciding where an email has come from is in the headers of that email.

That will tell you (perhaps - but see below) the route it took to get you you. Nothing else will get close to that info.

*BUT*

There are well known ways of 'preloading' the headers, and spoofing info.

What you have to do is decide where the spoof ends and the real info begins. Not easy, and takes experience.

Harry.

 
Reply With Quote
Post New ThreadReply Spread this thread: Submit this thread to digg Submit this thread to del.icio.us


Go Back   CertForums > Computing Support Forums > Connectivity, Telecommunications & the Internet


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Differences Between Rich Text and HTML Emails Arroryn Software 1 30-Aug-2007 05:13 PM
Nuisance emails - configuring hotmail limey Connectivity, Telecommunications & the Internet 10 20-Jul-2007 06:58 AM
Microsoft's antivirus deletes users' emails tripwire45 News 6 12-Mar-2007 03:22 PM
# of virus laden emails lately ffreeloader Security & Viruses 3 20-Aug-2005 07:50 PM
Outlook "not responding" when opening emails. madrob Software 6 03-Dec-2003 05:22 PM


All times are GMT. The time now is 08:35 AM.

Powered by vBulletin® Version 3.6.10
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
CertForums.co.uk (C) copyright 2003-2007 All Rights Reserved. Content published on CertForums.co.uk requires permission for reprint.
Hosted by Lunarpages