%Start Email Headers Can Tell You About the Origin of Spam GA
S
REGULAR Menu Lifewire Tech for Humans Newsletter! Search Close GO Email, Messaging, & Video Calls > Email
Email Headers Can Tell You About the Origin of Spam
Find out where junk mail is coming from
By Heinz Tschabitscher Heinz Tschabitscher Writer University of Vienna A former freelance contributor who has reviewed hundreds of email programs and services since 1997. lifewire's editorial guidelines Updated on January 25, 2021 Tweet Share Email Tweet Share Email
In This Article
Expand Jump to a Section Complaining About Spam Determining the Source of Spam Email Header and Body Header Forging Received Lines Parsing Received Header Lines Received Lines for Tracing Received Line Forging How to Tell a Forged Received Header Line Example Spam Analyzed and Traced Sender and Subject The Received Lines Spam will end when it is no longer profitable.
thumb_upLike (1)
commentReply (0)
shareShare
visibility258 views
thumb_up1 likes
N
Natalie Lopez Member
access_time
10 minutes ago
Tuesday, 29 April 2025
Spammers will see their profits tumble if nobody buys from them (because you don't even see the junk emails). This is the easiest way to fight spam, and certainly one of the best.
thumb_upLike (13)
commentReply (1)
thumb_up13 likes
comment
1 replies
L
Lily Watson 5 minutes ago
Complaining About Spam
You can affect the expenses side of a spammer's balance sheet,...
L
Lucas Martinez Moderator
access_time
15 minutes ago
Tuesday, 29 April 2025
Complaining About Spam
You can affect the expenses side of a spammer's balance sheet, too. If you complain to the spammer's internet service provider (ISP), they will lose their connection and might have to pay a fine (depending on the ISP's acceptable usage policy).
thumb_upLike (36)
commentReply (1)
thumb_up36 likes
comment
1 replies
L
Liam Wilson 6 minutes ago
Since spammers know and fear such reports, they try to hide. That's why finding the right ISP isn't ...
S
Scarlett Brown Member
access_time
20 minutes ago
Tuesday, 29 April 2025
Since spammers know and fear such reports, they try to hide. That's why finding the right ISP isn't always easy. However, there are tools like SpamCop that simplify reporting spam correctly to the accurate address.
thumb_upLike (46)
commentReply (0)
thumb_up46 likes
C
Chloe Santos Moderator
access_time
15 minutes ago
Tuesday, 29 April 2025
Tim Robberts / Stone / Getty Images
Determining the Source of Spam
How does SpamCop find the right ISP to complain to? It takes a close look at the spam message's header lines.
thumb_upLike (35)
commentReply (0)
thumb_up35 likes
Z
Zoe Mueller Member
access_time
6 minutes ago
Tuesday, 29 April 2025
These headers contain information about the path an email took. SpamCop follows the path until the point from which the spammer sent the email.
thumb_upLike (11)
commentReply (1)
thumb_up11 likes
comment
1 replies
D
Daniel Kumar 4 minutes ago
From this point, also know as an IP address, it can derive the spammer's ISP and send the repor...
S
Sophie Martin Member
access_time
21 minutes ago
Tuesday, 29 April 2025
From this point, also know as an IP address, it can derive the spammer's ISP and send the report to this ISP's abuse department. Let's take a closer look at how this works.
Email Header and Body
Every email message consists of two parts, the body and the header.
thumb_upLike (1)
commentReply (3)
thumb_up1 likes
comment
3 replies
A
Andrew Wilson 1 minutes ago
The header is like the email envelope containing the sender's address, the recipient, the subject, a...
I
Isaac Schmidt 8 minutes ago
Some header information usually displayed by your email program includes: From: The sender's name an...
The header is like the email envelope containing the sender's address, the recipient, the subject, and other information. The body has the text and the attachments.
thumb_upLike (12)
commentReply (2)
thumb_up12 likes
comment
2 replies
M
Mason Rodriguez 10 minutes ago
Some header information usually displayed by your email program includes: From: The sender's name an...
N
Natalie Lopez 7 minutes ago
Date: The date when the message was sent. Subject: The subject line.
Header Forging
...
E
Ella Rodriguez Member
access_time
27 minutes ago
Tuesday, 29 April 2025
Some header information usually displayed by your email program includes: From: The sender's name and email address. To: The recipient's name and email address.
thumb_upLike (24)
commentReply (3)
thumb_up24 likes
comment
3 replies
J
Julia Zhang 21 minutes ago
Date: The date when the message was sent. Subject: The subject line.
Header Forging
...
J
Joseph Kim 7 minutes ago
They are just convenient. Usually, the From line, for example, will be sent to the sender's addr...
Date: The date when the message was sent. Subject: The subject line.
Header Forging
The actual delivery of emails doesn't depend on any of these headers.
thumb_upLike (21)
commentReply (1)
thumb_up21 likes
comment
1 replies
S
Sebastian Silva 10 minutes ago
They are just convenient. Usually, the From line, for example, will be sent to the sender's addr...
V
Victoria Lopez Member
access_time
55 minutes ago
Tuesday, 29 April 2025
They are just convenient. Usually, the From line, for example, will be sent to the sender's address so you know who the message is from and can reply quickly. Spammers want to make sure you cannot reply easily, and certainly don't want you to know who they are.
thumb_upLike (37)
commentReply (3)
thumb_up37 likes
comment
3 replies
J
Julia Zhang 25 minutes ago
That's why they insert fictitious email addresses in the From lines of their junk messages.
...
A
Aria Nguyen 13 minutes ago
You don't need to rely on it. The headers of every email message also contain Received lines....
That's why they insert fictitious email addresses in the From lines of their junk messages.
Received Lines
The From line is useless in determining the real source of an email.
thumb_upLike (18)
commentReply (2)
thumb_up18 likes
comment
2 replies
D
David Cohen 12 minutes ago
You don't need to rely on it. The headers of every email message also contain Received lines....
B
Brandon Kumar 7 minutes ago
Email programs do not usually display these, but they can be beneficial in tracing spam.
Parsin...
V
Victoria Lopez Member
access_time
26 minutes ago
Tuesday, 29 April 2025
You don't need to rely on it. The headers of every email message also contain Received lines.
thumb_upLike (32)
commentReply (1)
thumb_up32 likes
comment
1 replies
S
Sophia Chen 1 minutes ago
Email programs do not usually display these, but they can be beneficial in tracing spam.
Parsin...
L
Liam Wilson Member
access_time
70 minutes ago
Tuesday, 29 April 2025
Email programs do not usually display these, but they can be beneficial in tracing spam.
Parsing Received Header Lines
Just like a postal letter will go through several post offices on its way from sender to recipient, an email message is processed and forwarded by several mail servers. Imagine every post office putting a unique stamp on each letter.
thumb_upLike (22)
commentReply (3)
thumb_up22 likes
comment
3 replies
M
Madison Singh 50 minutes ago
The stamp would say exactly when the mail was received, where it came from, and where it was forward...
S
Sebastian Silva 54 minutes ago
Received Lines for Tracing
As a mail server processes a message, it adds a part...
The stamp would say exactly when the mail was received, where it came from, and where it was forwarded to by the post office. If you got the letter, you could determine the exact path taken by the letter. This is precisely what happens with email.
thumb_upLike (46)
commentReply (1)
thumb_up46 likes
comment
1 replies
E
Emma Wilson 6 minutes ago
Received Lines for Tracing
As a mail server processes a message, it adds a part...
W
William Brown Member
access_time
64 minutes ago
Tuesday, 29 April 2025
Received Lines for Tracing
As a mail server processes a message, it adds a particular line to the message's header. The Received line contains the server name and IP address of the machine the server received the message from, and the name of the mail server.
thumb_upLike (33)
commentReply (2)
thumb_up33 likes
comment
2 replies
J
Jack Thompson 48 minutes ago
The Received line is always at the top of the message header. To reconstruct an email's journey ...
S
Scarlett Brown 29 minutes ago
They might insert forged Received lines that point to somebody else sending the message to fool the ...
E
Ella Rodriguez Member
access_time
68 minutes ago
Tuesday, 29 April 2025
The Received line is always at the top of the message header. To reconstruct an email's journey from sender to a recipient, start at the topmost Received line and go down to the last one, which is where the email originated.
Received Line Forging
Spammers know that people apply this procedure to uncover their whereabouts.
thumb_upLike (0)
commentReply (2)
thumb_up0 likes
comment
2 replies
S
Scarlett Brown 57 minutes ago
They might insert forged Received lines that point to somebody else sending the message to fool the ...
S
Sofia Garcia 53 minutes ago
This is why you should start your analysis at the top and not just derive the point where an email o...
D
Daniel Kumar Member
access_time
90 minutes ago
Tuesday, 29 April 2025
They might insert forged Received lines that point to somebody else sending the message to fool the intended recipient. Since every mail server will always put its Received line at the top, the spammers' forged headers can only be at the bottom of the Received line chain.
thumb_upLike (10)
commentReply (3)
thumb_up10 likes
comment
3 replies
S
Sofia Garcia 80 minutes ago
This is why you should start your analysis at the top and not just derive the point where an email o...
N
Noah Davis 87 minutes ago
By itself, you can't tell a forged Received line from a genuine one, which is where one distinct...
This is why you should start your analysis at the top and not just derive the point where an email originated from the first Received line (at the bottom).
How to Tell a Forged Received Header Line
The forged Received lines inserted by spammers look like all the other Received lines (unless they make an obvious mistake).
thumb_upLike (11)
commentReply (3)
thumb_up11 likes
comment
3 replies
G
Grace Liu 28 minutes ago
By itself, you can't tell a forged Received line from a genuine one, which is where one distinct...
C
Chloe Santos 38 minutes ago
Compare what a server claims to be with what the server one notch up in the chain says it is. If the...
By itself, you can't tell a forged Received line from a genuine one, which is where one distinct feature of Received lines comes into play. Every server notes who it is and where it got the message from (in IP address form).
thumb_upLike (23)
commentReply (2)
thumb_up23 likes
comment
2 replies
C
Charlotte Lee 31 minutes ago
Compare what a server claims to be with what the server one notch up in the chain says it is. If the...
E
Elijah Patel 37 minutes ago
In this case, the email's origin is what the server placed immediately after the forged Received...
M
Mia Anderson Member
access_time
63 minutes ago
Tuesday, 29 April 2025
Compare what a server claims to be with what the server one notch up in the chain says it is. If the two don't match, the earlier is a forged Received line.
thumb_upLike (17)
commentReply (0)
thumb_up17 likes
L
Luna Park Member
access_time
66 minutes ago
Tuesday, 29 April 2025
In this case, the email's origin is what the server placed immediately after the forged Received says.
Example Spam Analyzed and Traced
Now that we know the theoretical underpinning, let's analyze a junk email to identify its origin in real life.
thumb_upLike (8)
commentReply (2)
thumb_up8 likes
comment
2 replies
J
Julia Zhang 27 minutes ago
We've just received an exemplary piece of spam that we can use for exercise. Here are the header...
I
Isabella Johnson 10 minutes ago
The spammer wants to make it look like the message came from a Yahoo! Mail account. With the Reply...
H
Henry Schmidt Member
access_time
92 minutes ago
Tuesday, 29 April 2025
We've just received an exemplary piece of spam that we can use for exercise. Here are the header lines: Received: from unknown (HELO 38.118.132.100) (62.105.106.207) by mail1.infinology.com with SMTP; 16 Nov 2003 19:50:37 -0000 Received: from [235.16.47.37] by 38.118.132.100 id ; Sun, 16 Nov 2003 13:38:22 -0600 Message-ID: From: "Reinaldo Gilliam" Reply-To: "Reinaldo Gilliam" To: ladedu@ladedu.com Subject: Category A Get the meds u need lgvkalfnqnh bbk Date: Sun, 16 Nov 2003 13:38:22 GMT X-Mailer: Internet Mail Service (5.5.2650.21) MIME-Version: 1.0 Content-Type: multipart/alternative; boundary="9B_9.._C_2EA.0DD_23" X-Priority: 3 X-MSMail-Priority: Normal Can you tell the IP address where the email originated?
Sender and Subject
First, look at the forged From line.
thumb_upLike (19)
commentReply (3)
thumb_up19 likes
comment
3 replies
B
Brandon Kumar 34 minutes ago
The spammer wants to make it look like the message came from a Yahoo! Mail account. With the Reply...
E
Elijah Patel 1 minutes ago
Mail account. Next, the Subject is a curious accumulation of random characters....
The spammer wants to make it look like the message came from a Yahoo! Mail account. With the Reply-To line, this From address aims to direct all bouncing messages and angry replies to a non-existing Yahoo!
thumb_upLike (18)
commentReply (1)
thumb_up18 likes
comment
1 replies
W
William Brown 21 minutes ago
Mail account. Next, the Subject is a curious accumulation of random characters....
M
Mia Anderson Member
access_time
75 minutes ago
Tuesday, 29 April 2025
Mail account. Next, the Subject is a curious accumulation of random characters.
thumb_upLike (34)
commentReply (0)
thumb_up34 likes
A
Audrey Mueller Member
access_time
130 minutes ago
Tuesday, 29 April 2025
It is barely legible and designed to fool spam filters (every message gets a slightly different set of random characters). Still, it is also quite skillfully crafted to get the message across despite this.
thumb_upLike (17)
commentReply (2)
thumb_up17 likes
comment
2 replies
E
Ethan Thomas 117 minutes ago
The Received Lines
Finally, the Received lines. Let's begin with the oldest, Receive...
E
Emma Wilson 19 minutes ago
There are no hostnames in it, but two IP addresses: 38.118.132.100 claims to have received the messa...
C
Charlotte Lee Member
access_time
108 minutes ago
Tuesday, 29 April 2025
The Received Lines
Finally, the Received lines. Let's begin with the oldest, Received: from [235.16.47.37] by 38.118.132.100 id ; Sun, 16 Nov 2003 13:38:22 -0600.
thumb_upLike (45)
commentReply (2)
thumb_up45 likes
comment
2 replies
W
William Brown 74 minutes ago
There are no hostnames in it, but two IP addresses: 38.118.132.100 claims to have received the messa...
C
Chloe Santos 71 minutes ago
Let's see if the next (and in this case last) server in the chain confirms the first Received li...
A
Alexander Wang Member
access_time
28 minutes ago
Tuesday, 29 April 2025
There are no hostnames in it, but two IP addresses: 38.118.132.100 claims to have received the message from 235.16.47.37. If this is correct, 235.16.47.37 is where the email originated, and we'd find out which ISP this IP address belongs to, then send an abuse report to them.
thumb_upLike (1)
commentReply (3)
thumb_up1 likes
comment
3 replies
A
Audrey Mueller 6 minutes ago
Let's see if the next (and in this case last) server in the chain confirms the first Received li...
W
William Brown 21 minutes ago
So far, this is in line with what the previous Received line said. Now let's see where our mail ...
Let's see if the next (and in this case last) server in the chain confirms the first Received line's claims: Received: from unknown (HELO 38.118.142.100) (62.105.106.207) by mail1.infinology.com with SMTP; 16 Nov 2003 19:50:37 -0000. Since mail1.infinology.com is the last server in the chain and indeed "our" server, we know that we can trust it. It has received the message from an "unknown" host claiming to have the IP address 38.118.132.100 (using the SMTP HELO command).
thumb_upLike (8)
commentReply (2)
thumb_up8 likes
comment
2 replies
J
James Smith 66 minutes ago
So far, this is in line with what the previous Received line said. Now let's see where our mail ...
Z
Zoe Mueller 2 minutes ago
This is the IP address the connection was established from, and it is not 38.118.132.100. No, 62.105...
A
Ava White Moderator
access_time
90 minutes ago
Tuesday, 29 April 2025
So far, this is in line with what the previous Received line said. Now let's see where our mail server did get the message from. To find out, look at the IP address in brackets immediately before by mail1.infinology.com.
thumb_upLike (23)
commentReply (0)
thumb_up23 likes
D
Daniel Kumar Member
access_time
31 minutes ago
Tuesday, 29 April 2025
This is the IP address the connection was established from, and it is not 38.118.132.100. No, 62.105.106.207 is where this piece of junk mail was sent from. With this information, you can now identify the spammer's ISP and report the unsolicited email to them to kick the spammer off the net.
thumb_upLike (7)
commentReply (0)
thumb_up7 likes
S
Scarlett Brown Member
access_time
128 minutes ago
Tuesday, 29 April 2025
Was this page helpful? Thanks for letting us know!
thumb_upLike (1)
commentReply (1)
thumb_up1 likes
comment
1 replies
A
Aria Nguyen 20 minutes ago
Get the Latest Tech News Delivered Every Day
Subscribe Tell us why! Other Not enough details Hard to...
C
Christopher Lee Member
access_time
66 minutes ago
Tuesday, 29 April 2025
Get the Latest Tech News Delivered Every Day
Subscribe Tell us why! Other Not enough details Hard to understand Submit More from Lifewire How to View Full Message Headers in Mozilla Thunderbird How to Forward an Email as an Attachment in Outlook How to Find the IP Address of an Email Sender How to Send Email From a PHP Script How to Use AOL Mail Through an Email Client How to Send Email to Bcc Recipients in iPhone Mail What You Need to Know About Mailer Daemon Spam Ignore Delivery Failures of Messages You Did Not Send How to View the Source of a Message in Gmail How to Send Email From a PHP Script Using SMTP Authentication How to See Full Email Headers in Outlook.com How to Search Mail in iPhone Mail The 5 Best Secure Email Services for 2022 How to Send Spam to the Spam Folder in Yahoo Mail How to Access an Email Message Source in Outlook.com Differences Between the Email Body and the Header Newsletter Sign Up Newsletter Sign Up Newsletter Sign Up Newsletter Sign Up Newsletter Sign Up By clicking “Accept All Cookies”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts. Cookies Settings Accept All Cookies
thumb_upLike (10)
commentReply (1)
thumb_up10 likes
comment
1 replies
M
Madison Singh 22 minutes ago
Email Headers Can Tell You About the Origin of Spam GA
S
REGULAR Menu Lifewire Tech for Humans Newsl...