LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Non-*NIX Forums > General
User Name
Password
General This forum is for non-technical general discussion which can include both Linux and non-Linux topics. Have fun!

Notices


Reply
  Search this Thread
Old 01-29-2004, 09:10 AM   #1
WeNdeL
Member
 
Registered: Oct 2002
Location: At my desk...
Distribution: RedHat, Fedora, Ubuntu
Posts: 344

Rep: Reputation: 30
Question Mail Headers


As I am sure you all know, or at least most of you, virus activity has been through the roof lately. I've been dealing with a large volume of emails that are spoofing domains and basically brute forcing their way into my system (not very successfully I might add).

What I was hoping you could help me with is to tell me if I am interpreting this correctly. Dig this header:

Code:
Received: from mail-hub.mydomain.com (rrcs-midsouth-24-172-75-161.biz.rr.com [24.172.75.161])
        by ms-smtp-01-eri0.southeast.rr.com (8.12.10/8.12.7) with ESMTP id i0SMbSjF019486
        for <brian@openssl.org>; Wed, 28 Jan 2004 17:37:28 -0500 (EST)
Message-Id: <200401282237.i0SMbSjF019486@ms-smtp-01-eri0.southeast.rr.com>
From: david@mail-hub.my-domain.com
To: brian@openssl.org
The first line says that the email was received from mail-hub.mydomain.com and then lists a hostname and an ip (in brackets). Is the hostname/IP combo where it was REALLY received from? This email did NOT originate from my mail server as it is not used as an smtp gateway. I have another machine that does this for my clients...

So is it safe to say that someone is attempting to trick someone into thinking that this email is from my domain but in reality, it is coming from the hostname/IP listed in the part of the received field delimited by brackets?

Edit: and what RFC describes email headers?

Last edited by WeNdeL; 01-29-2004 at 09:12 AM.
 
Old 01-29-2004, 10:09 AM   #2
trickykid
LQ Guru
 
Registered: Jan 2001
Posts: 24,149

Rep: Reputation: 269Reputation: 269Reputation: 269
Moved: Not necessarily Linux related, more suitable in General.
 
Old 01-29-2004, 10:14 AM   #3
WeNdeL
Member
 
Registered: Oct 2002
Location: At my desk...
Distribution: RedHat, Fedora, Ubuntu
Posts: 344

Original Poster
Rep: Reputation: 30
didn't I post this in general?
 
Old 01-29-2004, 10:59 AM   #4
trickykid
LQ Guru
 
Registered: Jan 2001
Posts: 24,149

Rep: Reputation: 269Reputation: 269Reputation: 269
Quote:
Originally posted by WeNdeL
didn't I post this in general?
You posted in Linux - General, not General. Regards.
 
Old 01-29-2004, 11:25 AM   #5
WeNdeL
Member
 
Registered: Oct 2002
Location: At my desk...
Distribution: RedHat, Fedora, Ubuntu
Posts: 344

Original Poster
Rep: Reputation: 30
ahsoh... ^_^

sorry!
 
Old 01-31-2004, 05:28 AM   #6
fr0zen
Member
 
Registered: Nov 2003
Location: 127.0.0.1
Distribution: xubuntu
Posts: 217

Rep: Reputation: 30
Email headers are defined by several RFC's, namely 821 (or 2821) and 2076.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Logging mail subject headers in Postfix timjames Linux - Software 1 03-20-2009 02:07 PM
headers displayed when new mail arrives while logged in... plisken Linux - General 2 07-02-2006 07:45 AM
Sending mail from shell: how to define custom headers? ricky_ds Linux - Software 3 06-22-2005 07:58 AM
Editing mail headers with nail Berhanie Linux - General 2 11-30-2004 07:08 PM
read mail headers from command line plisken Linux - General 5 04-13-2003 01:53 PM

LinuxQuestions.org > Forums > Non-*NIX Forums > General

All times are GMT -5. The time now is 05:01 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration