Track "Spoofed Email" Tutorial


If you feel that your email address is being spoofed or you are receiving unwanted mail there are steps that you can take to try and locate the sending ISP.


The first step is to open and view the header of the email in question.

Start by highlighting the message you want to investigate. In Outlook Express it would look something like this:


Next “right click” the message and click properties.

A window will open up, click the details tab.


Search the text and find the first IP address starting from the bottom up. An example would look like this:


The next step will be to take this number and look up the information associated with it.

Go to the www.dnsstuff.com.


Scroll down to the box that is labeled "NEW! IP information"

Enter the IP address you found from the steps above.

Click "Lookup"


A list of general information will populate. Note the "verified" entry next to the IP address.

At the bottom there will be an entry labeled "Link for WHOIS" follow this link.


This will give you a list of all the pertinant information (sometimes including phone number). You will now be able to contact the responsible party.


NOTE! the above will only work if the IP address comes up as "verified". If you receive any other entry, follow the steps below.


Take the domain name from the offending message and go back to www.dnsstuff.com.


Place the domain name in the upper most right text field labeled "DNS Lookup" from the drop down menu select MX.


This will populate a list of information about the domain. It may contain additional domains that can be used to contact the sending party (by browsing to those domains and using their contact information).


Additional and more detailed information in regards to email headers can be found at www.stopspam.org/email/headers.html.