<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>trace emails Archives - Foster Institute</title>
	<atom:link href="https://fosterinstitute.com/tag/trace-emails/feed/" rel="self" type="application/rss+xml" />
	<link>https://fosterinstitute.com/tag/trace-emails/</link>
	<description>Cybersecurity Experts</description>
	<lastBuildDate>Thu, 21 Jun 2012 04:00:38 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.1</generator>

<image>
	<url>https://fosterinstitute.com/wp-content/uploads/2021/02/Favicon.png</url>
	<title>trace emails Archives - Foster Institute</title>
	<link>https://fosterinstitute.com/tag/trace-emails/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Trace a prank email to the source</title>
		<link>https://fosterinstitute.com/trace-a-prank-email-to-the-source/</link>
		
		<dc:creator><![CDATA[Mike Foster]]></dc:creator>
		<pubDate>Thu, 21 Jun 2012 04:00:38 +0000</pubDate>
				<category><![CDATA[Best Practices]]></category>
		<category><![CDATA[Technology]]></category>
		<category><![CDATA[recommendations]]></category>
		<category><![CDATA[Relating to IT Professionals]]></category>
		<category><![CDATA[trace emails]]></category>
		<guid isPermaLink="false">https://fosterinstitute.com/blog//?p=1361</guid>

					<description><![CDATA[<p>Someone recently asked&#8212;and I’m leaving out the details&#8212;something close to, “Someone just sent a prank email message to our members regarding plans for a party thrown by our organization. Can you help me find out who is the owner of this email address: (name of organization) @aol.com?” How do you find them? Here&#8217;s the answer: [&#8230;]</p>
<p>The post <a href="https://fosterinstitute.com/trace-a-prank-email-to-the-source/">Trace a prank email to the source</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></description>
										<content:encoded><![CDATA[<p>Someone recently asked&mdash;and I’m leaving out the details&mdash;something close to, “Someone just sent a prank email message to our members regarding plans for a party thrown by our organization. Can you help me find out who is the owner of this email address: (name of organization) @aol.com?” How do you find them? Here&#8217;s the answer:<br />
<span id="more-1361"></span><br />
Of course the return address was the name of the head of the organization. The signature line contains “Mrs. Smith” complete with the correct organization’s web site and phone number. It is a wonder the prankster didn’t use the organization’s logo, too.</p>
<p>You already know that the return address is useless. The sender information on email messages can be spoofed&mdash;meaning you don’t know the real sender. Have you ever received an email message from yourself?</p>
<p>The prank e-mail message was sent as a carbon copy to exactly 590 email addresses. 57 of those addresses were duplicates. 31 of them use AOL&mdash;the same source of the prank email&mdash;but that really doesn’t mean much.</p>
<p>Using blind carbon copy (BCC) instead of carbon copy (CC) makes it more difficult for the prankster to learn the 590 email addresses.</p>
<p>So, none of this is useful? How do you track down the results? The answer is headers and log files. Every email message contains headers which usually contain useful information that can sometimes pinpoint the sender and the email program they were using to send the email. Your IT professional can show you how to view the headers.</p>
<p><strong>This blog is dedicated to executives and owners, so it is okay if you skip the following technical information:</strong></p>
<p>To find headers in Outlook 2010, open the email message. Now, click on the <em>File</em> tab, make sure <em>Info</em> is selected in the left-hand column. Then, in the right-hand column of the menu, at the very bottom, is the <em>Properties</em> choice.</p>
<p>Click on <em>Properties</em> and notice the box at the bottom called <em>Internet Headers</em>. You can read the info right there if you want to. I find the small box constraining and elect to click in the box, choose CTRL-A, CTRL-C, then open notepad, and use CTRL-V in Notepad. Now you can expand Notepad to have a better look.</p>
<p>The <em>received: from</em> lines need to be examined and placed in order. Use the time stamps and/or <em>from</em> and <em>by</em> text to get the right order. Now, you are able to see the source unless someone has changed the headers. If you want to learn even more about this process, there is a good write-up at<br />
<a href="http://www.kuro5hin.org/story/2005/9/29/31457/0519" target="_blank" rel="noopener">www.kuro5hin.org/story/2005/9/29/31457/0519</a>.</p>
<p>In case the headers only lead you part of the way, perhaps to the perimeter of an organization, then often the log files (if they are being recorded) inside of an organization will allow identification of the culprit. Log files can be configured to store a great deal of information such as what data goes where in a network, what users are doing, and connections to the Internet.</p>
<p>Contact the <em>last person on the list</em> entity you found in the header and see if they can provide you with more information. Some entities have a privacy policy that won’t allow them to help you from there, while some organizations are more than happy to help you track down the culprit. The other organization will track the date/time and the chronologically first source information you provide them to hopefully find the actual source.</p>
<p>In the case of the organization in this article, the source was tracked down to a specific computer that is owned by the organization.</p>
<p>And just suppose you do catch the prankster. Have you thought of what you’ll do then?</p>
<p>Please post your comments on this blog.</p>
<p>The post <a href="https://fosterinstitute.com/trace-a-prank-email-to-the-source/">Trace a prank email to the source</a> appeared first on <a href="https://fosterinstitute.com">Foster Institute</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
