B
booker@mgt
One of my users asked me to determine where an email originated.
The header is below, but what seems conflicting is that the X originating IP
gives me a reverse lookup to an established citywide ISP, but what am I to
interpret from the bottom Received from header, saying it came from localhost?
(P.s, I changed the domain names for privacy reasons, so don't take the
names at face value
Received: from deliverator3.ecc.domain357.dgz (123.345.185.173) by
aeatlgtrex02.domain125.sfg (123.345.195.46) with Microsoft SMTP Server id
8.1.263.0; Wed, 15 Oct 2008 11:32:36 -0400
Received: from deliverator3.ecc.domain357.dgz (localhost [127.0.0.1])
by
localhost (Postfix) with SMTP id 06E1339C102 for
<[email protected]>; Wed, 15 Oct 2008 11:32:35 -0400 (EDT)
Received: from mail8.domain357.dgz (bigip.ecc.domain357.dgz
[123.345.185.140]) by
deliverator3.ecc.domain357.dgz (Postfix) with ESMTP id B20D139C0EA for
<[email protected]>; Wed, 15 Oct 2008 11:32:35 -0400 (EDT)
Received: from mail8.domain357.dgz (localhost [127.0.0.1]) by
mail8.domain357.dgz
(Postfix) with ESMTP id 9125E5FF5F for
<[email protected]>; Wed,
15 Oct 2008 11:32:35 -0400 (EDT)
Date: Wed, 15 Oct 2008 11:32:35 -0400
From: "Jones, Kristina W" <[email protected]>
To: (e-mail address removed)357.dgz
Message-ID: <[email protected]>
Subject: assignment
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
X-Originating-IP: [21.98.214.90]
X-Mailer: Zimbra 5.0.8_GA_2462.RHEL4_64 (ZimbraWebClient - IE7
(Win)/5.0.8_GA_2462.RHEL4_64)
X-GT-AVAS-Version: 5.4.1.325704, Antispam-Engine: 2.6.0.325393,
Antispam-Data: 2008.10.15.150726
X-GT-Spam-Details: Internal Mail
X-GT-Spam-Rating: (0%)
Return-Path: (e-mail address removed)
The header is below, but what seems conflicting is that the X originating IP
gives me a reverse lookup to an established citywide ISP, but what am I to
interpret from the bottom Received from header, saying it came from localhost?
(P.s, I changed the domain names for privacy reasons, so don't take the
names at face value
Received: from deliverator3.ecc.domain357.dgz (123.345.185.173) by
aeatlgtrex02.domain125.sfg (123.345.195.46) with Microsoft SMTP Server id
8.1.263.0; Wed, 15 Oct 2008 11:32:36 -0400
Received: from deliverator3.ecc.domain357.dgz (localhost [127.0.0.1])
by
localhost (Postfix) with SMTP id 06E1339C102 for
<[email protected]>; Wed, 15 Oct 2008 11:32:35 -0400 (EDT)
Received: from mail8.domain357.dgz (bigip.ecc.domain357.dgz
[123.345.185.140]) by
deliverator3.ecc.domain357.dgz (Postfix) with ESMTP id B20D139C0EA for
<[email protected]>; Wed, 15 Oct 2008 11:32:35 -0400 (EDT)
Received: from mail8.domain357.dgz (localhost [127.0.0.1]) by
mail8.domain357.dgz
(Postfix) with ESMTP id 9125E5FF5F for
<[email protected]>; Wed,
15 Oct 2008 11:32:35 -0400 (EDT)
Date: Wed, 15 Oct 2008 11:32:35 -0400
From: "Jones, Kristina W" <[email protected]>
To: (e-mail address removed)357.dgz
Message-ID: <[email protected]>
Subject: assignment
MIME-Version: 1.0
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: 7bit
X-Originating-IP: [21.98.214.90]
X-Mailer: Zimbra 5.0.8_GA_2462.RHEL4_64 (ZimbraWebClient - IE7
(Win)/5.0.8_GA_2462.RHEL4_64)
X-GT-AVAS-Version: 5.4.1.325704, Antispam-Engine: 2.6.0.325393,
Antispam-Data: 2008.10.15.150726
X-GT-Spam-Details: Internal Mail
X-GT-Spam-Rating: (0%)
Return-Path: (e-mail address removed)