# Emails being sent by others with my return address?

**URL:** <https://boards.straightdope.com/t/emails-being-sent-by-others-with-my-return-address/191350>\
**Category:** Factual Questions\
**Created:** [July 28, 2003, 1:36am UTC](https://boards.straightdope.com/t/emails-being-sent-by-others-with-my-return-address/191350 "2003-07-28T01:36:47Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![MrTuffPaws](https://avatars.discourse-cdn.com/v4/letter/m/f475e1/32.png) [@MrTuffPaws](https://boards.straightdope.com/u/MrTuffPaws)\
**Post date:** [July 28, 2003, 1:36am UTC](https://boards.straightdope.com/t/emails-being-sent-by-others-with-my-return-address/191350/1 "2003-07-28T01:36:47Z")

</div>

Okay, for a while now, I have been getting emails returned to me from ISPs that say the original message was undeliverable. The problem is that I did not send the emails. Nothing is mine on the returned mail except for the return email address.

Thinking of a virus? Well, I did too, so I went out and got the latest and greatest virus software and low and behold, no viruses. Not a single one. Also none of my normal email correspondents have complained about getting spam from me.

So, should I be looking for something on my machine locally that is sending these mailings out, or can people pull my email address off of news groups and the like and set it up that their spam has my return address?

---

<div class="post-metadata">

**Author:** ![Q.E.D](https://avatars.discourse-cdn.com/v4/letter/q/51bf81/32.png) [@Q.E.D](https://boards.straightdope.com/u/Q.E.D)\
**Post date:** [July 28, 2003, 1:51am UTC](https://boards.straightdope.com/t/emails-being-sent-by-others-with-my-return-address/191350/2 "2003-07-28T01:51:21Z")

</div>

Relax. I had the same thing happen too. It’s someone (or some program) spoofing your email address to progagate the klez worm. If you check the headers, though, you’ll see the originating IP address is nothing like yours.

---

<div class="post-metadata">

**Author:** ![scr4](https://avatars.discourse-cdn.com/v4/letter/s/59ef9b/32.png) [@scr4](https://boards.straightdope.com/u/scr4)\
**Post date:** [July 28, 2003, 1:58am UTC](https://boards.straightdope.com/t/emails-being-sent-by-others-with-my-return-address/191350/3 "2003-07-28T01:58:09Z")

</div>

It’s trivial to send an e-mail with someone else’s address in the FROM line. If it’s the klez worm as QED suggestsed, the worm (virus) is on someone else’s computer, someone who has received e-mail from you in the past. (That’s where it got your address.)

---

<div class="post-metadata">

**Author:** ![SkyBum](https://avatars.discourse-cdn.com/v4/letter/s/a88e57/32.png) [@SkyBum](https://boards.straightdope.com/u/SkyBum)\
**Post date:** [July 28, 2003, 2:01am UTC](https://boards.straightdope.com/t/emails-being-sent-by-others-with-my-return-address/191350/4 "2003-07-28T02:01:06Z")

</div>

I am experiencing the same problem as you have described. As I understand it, a spammer is “spoofing” your e-mail address. Meaning that he has forged your return address to appear in the “from” field. My ISP has advised me to forward these returned emails to their abuse department so that they can investigate further, though they also admit that there is little that they can do to stop the spammer involved. As for your machine being compromised I think you have nothing to worry about.

Posting your e-mail address anywhere on the internet is virtually guaranted to be noticed by these spammers. In fact there are bots, which are programs designed to scour the internet looking for any text string containing @ and harvesting them to a database which is then sold to even more spammers. It really is a no win situation. Your best bet is to cancel your e-mail address and create a new one. Unfortunately for me, my email address is also my domain name from which I sell my art, I am left with no chioce but to continue to be at the mercy of these god forsaken spammers.

---

<div class="post-metadata">

**Author:** ![Hodge](https://avatars.discourse-cdn.com/v4/letter/h/5f9b8f/32.png) [@Hodge](https://boards.straightdope.com/u/Hodge)\
**Post date:** [July 28, 2003, 2:09am UTC](https://boards.straightdope.com/t/emails-being-sent-by-others-with-my-return-address/191350/5 "2003-07-28T02:09:17Z")

</div>

It could be the Klez worm. Or something a whole lot more evil. It’s known as joe-jobbing in the spam industry and it involves forging email headers with other people’s (usually enemies) email addresses. All the bounce-backs get sent to the innocent party as well as a lot of hate mail from people at various sites.

How do I know this? The fuckers did it to me recently. Over the past week I’ve received several hundred bounced back emails advertising Generic Viagra. Their web site is hosted in Guangdong, China and, as you’d probably expect, the company is hardly sympathetic to my complaints. As the headers are forged, I’ve had little luck tracing the emails themselves and the fact that many of these sites truncate the headers in their bounce-back messages doesn’t help, either. I’m seriously considering changing my email address but, as it’s work related, I’m not looking forward to the hassle.

Hopefully, it’s just Klez or one of its variants because then you can just email everybody in your contact list to scan their computers for viruses

---

<div class="post-metadata">

**Author:** ![Markxxx](https://avatars.discourse-cdn.com/v4/letter/m/5daacb/32.png) [@Markxxx](https://boards.straightdope.com/u/Markxxx)\
**Post date:** [July 28, 2003, 2:51am UTC](https://boards.straightdope.com/t/emails-being-sent-by-others-with-my-return-address/191350/6 "2003-07-28T02:51:08Z")

</div>

I wonder as I use WEBTV and a computer. I never had this problem with my computer but my WEBTV has it all the time. I continually get bounced messages (yes from a viagra seller as well).

WebTV is not supposed to be able to get worms and viruses. WebTV doesn’t give headers and I so I just delete it.

---

<div class="post-metadata">

**Author:** ![MLS](https://avatars.discourse-cdn.com/v4/letter/m/919ad9/32.png) [@MLS](https://boards.straightdope.com/u/MLS)\
**Post date:** [July 28, 2003, 12:54pm UTC](https://boards.straightdope.com/t/emails-being-sent-by-others-with-my-return-address/191350/7 "2003-07-28T12:54:41Z")

</div>

I’ve also had a similar problem. My ISP did determine that my account name and password had been stolen. Changing the password (which is something one should do from time to time anyway) cleared up the problem for the time being.

---

<div class="post-metadata">

**Author:** ![Chronos](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chronos/32/134_2.png) [@Chronos](https://boards.straightdope.com/u/Chronos)\
**Post date:** [July 28, 2003, 7:22pm UTC](https://boards.straightdope.com/t/emails-being-sent-by-others-with-my-return-address/191350/8 "2003-07-28T19:22:24Z")

</div>

> [@](#):
>
> WebTV is not supposed to be able to get worms and viruses.

It doesn’t need to. All that needs to happen is for someone else to have an infected computer, and for that computer to have your WebTV e-mail address.

For instance: You sent an e-mail to a friend a while back. Friend’s computer (_not_ WebTV) catches the Klez virus. Klez on friend’s computer looks around for e-mail addresses to steal. Klez finds the e-mail you sent friend, and grabs your address. Klez sends out a bunch of infected e-mails, but lies about where it’s coming from, and uses your address.

It works similarly with the spammers, except that they use some other method to get your address in the first place.

---

<div class="post-metadata">

**Author:** ![ComeToTheDarkSideWeHaveCookies](https://avatars.discourse-cdn.com/v4/letter/c/e9bcb4/32.png) [@ComeToTheDarkSideWeHaveCookies](https://boards.straightdope.com/u/ComeToTheDarkSideWeHaveCookies)\
**Post date:** [July 28, 2003, 8:42pm UTC](https://boards.straightdope.com/t/emails-being-sent-by-others-with-my-return-address/191350/9 "2003-07-28T20:42:42Z")

</div>

I usually advise folks having this problem that one or more of three things is likely responsible:

> [@](#):
>
> 1- Someone is forging your address and using it to send spam.
> 
> The bounces and responses you get to this mail would likely contain  
> unknown user errors, unsubscribe requests, and general anti-spam hate mail.
> 
> 2- Your e-mail address is being stored within someone’s virus infected  
> computer, which provides your address to the virus, which is programmed  
> to forge your address on outbound copies of itself.
> 
> 3- Your system is virus infected. A virus is able to hijack an  
> infected system’s internet connection, at any time (even when you are  
> not using the computer, as long as it is on). The virus is programmed  
> to send copies of itself out from your computer, using various e-mail  
> addresses that it finds stored in your address book, web cache, and  
> other system files. The virus forges these addresses as the From: and  
> To: address on the outbound copies of itself.
> 
> The bounces and responses you get to 2 and 3 above would likely contain  
> virus notifications.

The only way to determine the true point of origin is to interpret the extended headers of the original mail that prompted the bounce, if those headers happen to be included in the body of the bounce.

Sending a complaint to the network responsible for the originating IP will allow the administrators of that network to investigate and determine the responsible account. They are the only entity that will be able to do so, because of the forgery and header manipulation.

There is no way for anyone to proactively prevent their address from being forged by either a spammer or an infected system. Even if you’ve never ever used your address, even if it has never seen the light of day, it can be deduced, guessed, or otherwise frankensteined from parts of similar e-mail addresses, or from folks who have the same address at different domains.

What _can_ be done about address forgery, is reporting it to the network of origin so that appropriate action can be taken against the responsible account. Forging spammers will (hopefully) be warned or their accounts terminated. The forging virus-infected are usually notified of the apparent infection and given instructions for virus-detection and removal.
