iSnare.com - Free Content Articles Directory
Authors Contents [Advanced Search][Add OpenSearch][Job Search]
Distribute your articles to thousands of article sites for only $2 and below! Read more...

Index  Internet
 

How To Determine The Origin Of Spam?

 
[ Contact the Author] [ Send to a Friend] [ Article Publisher] [Make PDF] [ Print] [ Bookmark & Share]
 
Read our Terms of Service before reprinting this article. The submitter specified above has claimed the rights to this article.
Julia Gulevich

Spam will continue spreading as far as it makes profit. If nobody buys from spammers or acts upon their scams, spam will end. This is the obvious and easiest way to fight spam. You can ignore and delete spam emails you receive. But you can also take vengeance on the spammer by complaining to the spammer's Internet Service Provider (ISP). The ISP will block their connection and maybe impose a fine (depending on the ISP's acceptable usage policy). Spammers beware of such complaints and try to disguise their messages. That's why finding the right ISP is not always easy.

Let’s look inside a spam message. Every email message includes two parts, the body and the header. The body is the actual message text and attachments. The header is a kind of the envelope of the message. The header shows the address of the message sender, the address of the message recipient, the message subject and other information. Email programs usually display these header fields:

From: shows the sender's name and email address.
To: shows the recipient's name and email address.
Date: shows the date when the message was sent.
Subject: shows the message subject.

The From: field usually contains the sender's email address. This lets you know who sent the message and allows you easily reply. Spammers, of course, don’t want you to reply and don’t want you to know who they are. Therefore, they put forged email addresses into the From: lines of their emails. So the From: field won’t help you if you want to determine where the spam email comes from.

Tip! With G-Lock SpamCombat you can easily preview not only the message text but also all the fields of the message header . You can choose the preview format by yourself. You can view the message as HTML, decoded message, or message source.There are also several Received: fields in the header of every message. Email programs don’t usually display the Received: lines but the Received: lines can be very helpful in tracing the spam origin.

Just like a postal letter goes through a number of post offices before it’s delivered to the recipient, an email message is processed by several mail servers. Each mail server adds a line to the message header – a Received: line – which contains

- the server name and IP address of the machine the server received the message from and
- the name of the mail server itself.

Each Received: line is inserted at the top of the message header. If we want to reproduce the message’s path from sender to recipient, we start from the topmost Received: line and walk down until the last one, which is where the email originated.

Just like the From: field the Received: lines may contain forged information to fool those who would want to trace the spammer. Because every mail server inserts the Received: line at the top of the header, we start the analysis from the top.

The Received: lines forged by spammers usually look like normal Received: fields. We can hardly tell whether the Received: line is forged or not at first sight. We should analyze all the Received: lines chain to find out a forged Received: field.

As we mentioned above, every mail server registers not only its name but also the IP address of the machine it got the message from. We simply need to look what name a server puts and what the next server in the chain says. If the servers don’t match, the earlier Received: line is forged.

The origin of the email is what the server immediately after the forged Received: line says about where it received the message from.

Let's see how determining of the spam email origin works in real life. Here is the header of a spam message we’ve recently received:

**************************************************
Return-Path:
Delivered-To: press@mydomain.com
Received: from unknown (HELO 60.17.139.96) (221.200.13.158) by mail1.myserver.xx with
SMTP; 7 Nov 2006 10:54:16 -0000
Received: from 164.145.240.209 by 60.17.139.96; Tue, 07 Nov 2006 05:53:35 -0500
Date: Tue, 07 Nov 2006 12:48:35 +0200
From: Pharmacy

Reply-To: umceqhzjmndfy
X-Priority: 3 (Normal)
Message-ID: <15216897.20061108040652@hawaiicity.com>
To: press@mydomain.com
Subject: Cheap Med*s V!agra Many Med_s QnNXpRy9
MIME-Version: 1.0
Content-Type: text/html; charset=us-ascii
Content-Transfer-Encoding: quoted-printable
**************************************************

At first, look at the forged From: field. The email address in the From: and Reply-To: lines doesn’t exist. So, the spammer took care about directing bounced messages and all the indignant replies people may send to a non-existing email account.

Secondly, the Subject: line. It contains the variations of the “Meds” and “Viagra” words that are known to be met in spam messages. Plus, the subject contains a range of random characters. It’s obvious that the subject line is skillfully tailored to fool anti-spam filters.

Lastly, let’s analyze the Received: lines. We start from the oldest one - Received: from 164.145.240.209 by 60.17.139.96; Tue, 07 Nov 2006 05:53:35 -0500. There are two IP addresses in it: 60.17.139.96 says it received the message from 164.145.240.209.

We check if the next (and last in this case) mail server in the chain confirms the state of the first Received: line. In the second Received: field we have: Received: from unknown (HELO 60.17.139.96) (221.200.13.158) by mail1.myserver.xx with SMTP; 7 Nov 2006 10:54:16 -0000.

mail1.myserver.xx is our server and we can trust it. It received the message from an "unknown" host, which says it has the IP address 60.17.139.96. Yes, this confirms what the previous Received: line says.

Now let’s find out where our mail server got the message from. For this purpose, we look at the IP address in brackets before the server name mail1.myserver.xx. It is 221.200.13.15. This is the IP address the connection was established from, and it is not 60.17.139.96. The spam message originates from 221.200.13.15. It’s important to note that it’s not necessarily that the spammer is sitting at the computer 221.200.13.15 and sending spam over the world. It may happen the computer’s owner doesn’t even suspect of being sending spam. The computer may be hijacked by a Trojan, which is spreading spam without the machine’s owner knowing it.

We hope this information will help you identify the spammer's ISP and report them about spam so they can take proper measures.

Important NoticeDISCLAIMER: All information, content, and data in this article are sole opinions and/or findings of the individual user or organization that registered and submitted this article at Isnare.com without any fee. The article is strictly for educational or entertainment purposes only and should not be used in any way, implemented or applied without consultation from a professional. We at Isnare.com do not, in anyway, contribute or include our own findings, facts and opinions in any articles presented in this site. Publishing this article does not constitute Isnare.com's support or sponsorship for this article. Isnare.com is an article publishing service. Please read our Terms of Service for more information.

Author is a technical expert associated with development of computer software like Anti-Spam Software Blocker. More information can be found at AntiSpam Software Resources

Article Tags: message [See Dictionary], received [See Dictionary], spam [See Dictionary]
Got a question about this article? Ask the community!
Article published on November 19, 2006 at Isnare.com
 
Rate this article:

Create And Send Html Email Newsletters
Submitted by: Julia Gulevich

An Introduction To Email Newsletters Email newsletters are being recognized as a great way to enhance sales...

Another Form Of Email Marketing – Permission Based
Submitted by: Julia Gulevich

So, you want to know more about email marketing Here is one type that will really help you out...

Email List Building: How To Get Started Building Your Own Email Mailing List
Submitted by: Julia Gulevich

Email list building is a common marketing practice these days There are very few businesses that you can go into these days that don’t ask for your email address or ask if you want to sign up for special offers or updates through your email...

Email Marketing Success
Submitted by: Julia Gulevich

These days, there are hundreds of ways to market something, and there are a lot of different mediums to choose from...

HTML Email Newsletters – A How To Guide To Creating Them
Submitted by: Julia Gulevich

What is an email newsletter An email newsletter is kind of like a regular newspaper but it delivers news directly to our email electronically...

Simple But Incredibly Important Rules For Successful Email Marketing
Submitted by: Julia Gulevich

You owe an online business and you know that to make money you need a list of people, a list of passionate buyers who are hungry for your offer and will devour it when you send it out...

Responsive Email Is A Key To Successful Email Marketing
Submitted by: Julia Gulevich

Creating and sending a promotional email letter that receives the maximum response rate is at the heart of any successful online business...

Direct Drip Email Marketing Tactic
Submitted by: Julia Gulevich

If you have the products or services that you want to sell on the Internet, you’ll want to create a web site where you’ll advertise what you are offering and you’ll also want to spread a word about your products or services to the world...

Anatomy Of Successful Bulk Email Marketing Campaign
Submitted by: Julia Gulevich

Bulk email marketing is a way to reach prospective customers and to stay in communication with existing clients...

Permission-Based Email Campaign As Important Component Of Email Marketing
Submitted by: Julia Gulevich

The objective of marketing is to spark interest, provoke curiosity for the products and services and generate sales of the goods...

Creating Bulk Email List & Building Strong Relationship With It
Submitted by: Julia Gulevich

Creating Bulk Email List By means of the Internet we have the possibility to connect millions of people from around the world...

Keep Clean Mailing List & Increase Subscriber Response Rate
Submitted by: Julia Gulevich

Have you ever measured what response rate you get from your email campaigns Didn’t you notice that a small mailing list can give you a high response and a huge list can get a very, very low response rate...

What Is Spam? How To Identify And Block It?
Submitted by: Julia Gulevich

Almost everyone who used to communicate via e-mail has ever found in the Inbox the messages from people he doesn’t know proposing some services or products...

Spam – Problem Of Vital Importance On The Internet
Submitted by: Julia Gulevich

Almost everyone who accesses the Internet and uses e-mail knows about spam The common definition of spam is e-mail that is unsolicited, undesired by the recipient...

Spam Scams: How Not To Become A Victim
Submitted by: Julia Gulevich

All spam emails we receive every day in tens or hundreds are annoying and disgusting But the worst of them are scams, hoaxes, and illegal schemes aimed at defrauding you of your money, private information, and even your life...

Protecting Yourself From E-mail Scams
Submitted by: Gregg Housh

A lot of us are already well familiar with the annoyance of spam: unsolicited e-mail advertisements In recent years, unwanted emails have evolved in an attempt to avoid increasingly advanced filters and wary recipients...

Make Extra Money Online
Submitted by: Blanca Ciotoiu

If you are expecting that I'm going to tell you a fast way to make extra money online then, you are wrong...

Web Site Design and Development – Tell a Story to Build Your Credibility and Educate Customers
Submitted by: Daljeet Sidhu

The best way to attract customers to your business is to make them understand what sets you apart from the competition...

Traffic Builder For Free
Submitted by: Dansar Gin

After you decide to have a website and to buy a domain name for your website you will ask a lot of questions like: - What is the right way to start...

5 Ways Verizon FiOS Can Help You Make Money From Home
Submitted by: Russell Blanc

5 Ways Verizon FiOS can Help You Make Money From Home If you are one of the Verizon FiOS New York customers that is looking for a way to make some extra income or to replace a lost job, Verizon FiOS super fast Internet and high quality TV service can help...

What is All About Ebooks?
Submitted by: Roberto Sedycias

Ebook stands for electronic book These are usually in a word processor format or PDF file that can be emailed and delivered anywhere by virtual means...

How Broadband Internet Connections Work
Submitted by: Andy Fullard

We all know that due to inflation and the rising prices of the commodities we can save very little for us...

The Ultimate Hunt For Cheap SEO Packages
Submitted by: Cliff Posey Jr

Cheap SEO packages and SEO services are what most of the website owners are looking for these day as the world has been hit by the global economic recession and many entrepreneurs are now looking for affordable SEO services that would help them save money in some way or the other for their online business...

Enjoy a Glamorous Christmas on a Budget by Buying Online
Submitted by: Vincent Norman

Christmas is a time of giving, but for many it is a time of budgeting Budgeting can be a rather nasty thing around the holiday, especially when you consider the shape that the world economy happens to be in right now...

How to Shop Online For Christmas Presents and Gifts
Submitted by: Derek Rogers

The holiday season is upon us and that can only mean one thing: presents When it comes to presents there are a number of things that you will need to keep in mind...

Kids Toys: Finding the Must Have Christmas Present Online?
Submitted by: Vincent Norman

Shopping for yourself is one thing Shopping for kids...

What Are Meta Tags and Why Are They Important?
Submitted by: Blake Evans

A “meta tag” is a common phrase that new web designers generally have to deal with as soon as they sit down to create a website...

Podcasting
Submitted by: John Taylor

A podcast is a succession of digital media files, audio or video, that are discharged digressively and downloaded through web syndication...

Quick and Simple Overview on Webhosting Services
Submitted by: Ani K

In the present internet world, if we think of something we can get it with in no time It is possible because of the ease of access to the internet where one can search for anything and can get the best result...

Bang For Buck – How to Best Apply Twitter to Your Business and Earn Money Online
Submitted by: Trond Lyngbø

The digital world is growing and changing at an explosive rate As always, change brings both business opportunities and threats...

Isnare.com Footer Divider

© 2004-2009. Isnare Free Articles - An Isnare Online Technologies Free Articles Project. All Rights Reserved.   Privacy Policy