# Is it possible to trace an IP, using an email sent to you?

**URL:** <https://boards.straightdope.com/t/is-it-possible-to-trace-an-ip-using-an-email-sent-to-you/131444>\
**Category:** Factual Questions\
**Created:** [October 8, 2002, 10:57pm UTC](https://boards.straightdope.com/t/is-it-possible-to-trace-an-ip-using-an-email-sent-to-you/131444 "2002-10-08T22:57:06Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![BrentLumkin](https://avatars.discourse-cdn.com/v4/letter/b/9d8465/32.png) [@BrentLumkin](https://boards.straightdope.com/u/BrentLumkin)\
**Post date:** [October 8, 2002, 10:57pm UTC](https://boards.straightdope.com/t/is-it-possible-to-trace-an-ip-using-an-email-sent-to-you/131444/1 "2002-10-08T22:57:06Z")

</div>

Someone sent me an email, and I truly need to trace it back to whoever sent it. This is an individual who has been stealing passwords, account information, etc… from UBID members, and they need to be stoped. They sent me an email, and I really need to find out who they are, somehow. So, is this possible?

---

<div class="post-metadata">

**Author:** ![Mister\_Damage](https://avatars.discourse-cdn.com/v4/letter/m/ba8739/32.png) [@Mister\_Damage](https://boards.straightdope.com/u/Mister_Damage)\
**Post date:** [October 8, 2002, 11:27pm UTC](https://boards.straightdope.com/t/is-it-possible-to-trace-an-ip-using-an-email-sent-to-you/131444/2 "2002-10-08T23:27:34Z")

</div>

It may be possible, depending on the headers included with the email, and whether or not you can access them. You can probably at least trace the individual back to an ISP and work from there.

If you can view the detailed headers of the email message, you should see something like:

Received: from [mailserver.hisisp.com](http://mailserver.hisisp.com) ([1.1.1.1]) by [mailserver.yourisp.com](http://mailserver.yourisp.com) ([2.2.2.2]) with SMTP id RAA25161 for \<[you@yourisp.com](mailto:you@yourisp.com)\>; Tue Oct 8 2002 19:19:30 -400 (EDT)

…if there were mail relays in between, there may be more than one “Received:” line, e.g.:

Received: from [relay.otherisp.com](http://relay.otherisp.com) ([3.3.3.3]) by [mailserver.yourisp.com](http://mailserver.yourisp.com) ([2.2.2.2]) with SMTP id RAA25161 for \<[you@yourisp.com](mailto:you@yourisp.com)\>; Tue Oct 8 2002 19:19:30 -400 (EDT)  
Received: from [mailserver.hisisp.com](http://mailserver.hisisp.com) ([1.1.1.1]) by [relay.otherisp.com](http://relay.otherisp.com) ([3.3.3.3]) with SMTP id RAA25161 for \<[you@yourisp.com](mailto:you@yourisp.com)\>; Tue Oct 8 2002 19:17:45 -400 (EDT)

…the last “Received:” line listed will be as far back as you can trace the mail message, and in theory should be the machine that originated the message.

---

<div class="post-metadata">

**Author:** ![NutWrench](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/nutwrench/32/20193_2.png) [@NutWrench](https://boards.straightdope.com/u/NutWrench)\
**Post date:** [October 8, 2002, 11:34pm UTC](https://boards.straightdope.com/t/is-it-possible-to-trace-an-ip-using-an-email-sent-to-you/131444/3 "2002-10-08T23:34:58Z")

</div>

Yes.

E-mail contains “headers” which show the path the e-mail takes as it is passed from one computer to the next. The header display is normally toggled off in most e-mail programs but you should be able to switch it on. Copy and paste just the headers here (the body of the message isn’t as important) and we can at least tell you which ISP it came from.

---

<div class="post-metadata">

**Author:** ![BrentLumkin](https://avatars.discourse-cdn.com/v4/letter/b/9d8465/32.png) [@BrentLumkin](https://boards.straightdope.com/u/BrentLumkin)\
**Post date:** [October 8, 2002, 11:48pm UTC](https://boards.straightdope.com/t/is-it-possible-to-trace-an-ip-using-an-email-sent-to-you/131444/4 "2002-10-08T23:48:23Z")

</div>

How do I go about seeing the “headers” in AOL mail?

---

<div class="post-metadata">

**Author:** ![BrentLumkin](https://avatars.discourse-cdn.com/v4/letter/b/9d8465/32.png) [@BrentLumkin](https://boards.straightdope.com/u/BrentLumkin)\
**Post date:** [October 8, 2002, 11:49pm UTC](https://boards.straightdope.com/t/is-it-possible-to-trace-an-ip-using-an-email-sent-to-you/131444/5 "2002-10-08T23:49:50Z")

</div>

Nevermind, is this what you need?

**Return-Path: \<[customerservice@ubld.com](mailto:customerservice@ubld.com)\>  
Received: from [rly-xd02.mx.aol.com](http://rly-xd02.mx.aol.com) ([rly-xd02.mail.aol.com](http://rly-xd02.mail.aol.com) [172.20.105.167]) by [air-xd01.mail.aol.com](http://air-xd01.mail.aol.com) (v89.10) with ESMTP id MAILINXD11-1007165659; Mon, 07 Oct 2002 16:56:58 -0400  
Received: from [web102.bizmail.yahoo.com](http://web102.bizmail.yahoo.com) ([web102.bizmail.yahoo.com](http://web102.bizmail.yahoo.com) [216.136.172.122]) by [rly-xd02.mx.aol.com](http://rly-xd02.mx.aol.com) (v89.10) with ESMTP id MAILRELAYINXD26-1007165636; Mon, 07 Oct 2002 16:56:36 2000  
Message-ID: \<[20021007205635.71773.qmail@web102.bizmail.yahoo.com](mailto:20021007205635.71773.qmail@web102.bizmail.yahoo.com)\>  
Received: from [62.231.66.127] by [web102.bizmail.yahoo.com](http://web102.bizmail.yahoo.com) via HTTP; Mon, 07 Oct 2002 13:56:35 PDT  
Date: Mon, 7 Oct 2002 13:56:35 -0700 (PDT)  
From: “uBid Inc.” \<[customerservice@ubld.com](mailto:customerservice@ubld.com)\>  
Subject: Security Check  
To: [lumkinsc98@aol.com](mailto:lumkinsc98@aol.com)  
MIME-Version: 1.0  
Content-Type: multipart/alternative; boundary="0-2015247683-1034024195=:71165"**

---

<div class="post-metadata">

**Author:** ![BrentLumkin](https://avatars.discourse-cdn.com/v4/letter/b/9d8465/32.png) [@BrentLumkin](https://boards.straightdope.com/u/BrentLumkin)\
**Post date:** [October 8, 2002, 11:51pm UTC](https://boards.straightdope.com/t/is-it-possible-to-trace-an-ip-using-an-email-sent-to-you/131444/6 "2002-10-08T23:51:51Z")

</div>

By the way, I got the above by clicking on “details” in the header.

---

<div class="post-metadata">

**Author:** ![Giraffe](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/giraffe/32/129_2.png) [@Giraffe](https://boards.straightdope.com/u/Giraffe)\
**Post date:** [October 8, 2002, 11:57pm UTC](https://boards.straightdope.com/t/is-it-possible-to-trace-an-ip-using-an-email-sent-to-you/131444/7 "2002-10-08T23:57:21Z")

</div>

I once got an email from Bill Gates, who was developing an email tracing program. He was offering $5000 to anyone who forwarded to everyone they know, which I of course did. I never got a check, though, so it may not be available yet. Probably needs more testing.

---

<div class="post-metadata">

**Author:** ![NotMrKnowItAll](https://avatars.discourse-cdn.com/v4/letter/n/6bbea6/32.png) [@NotMrKnowItAll](https://boards.straightdope.com/u/NotMrKnowItAll)\
**Post date:** [October 9, 2002, 12:26am UTC](https://boards.straightdope.com/t/is-it-possible-to-trace-an-ip-using-an-email-sent-to-you/131444/8 "2002-10-09T00:26:43Z")

</div>

I got this from a whois search on the ip. email abuse to abuse@rdsnet.ro

WHOIS Query Result for 62.231.66.127:  
inetnum 62.231.66.0 - 62.231.66.255  
Origin RDSNET  
descr Romania Data Systems  
descr Bucharest Branch  
country RO  
Admin. Contact AS1385-RIPE  
Tech. Contact RDS-RIPE  
status ASSIGNED PA  
remarks INFRA-AW  
Notify as-admin@rdsnet.ro  
mnt-by AS8708-MNT  
changed tim@rdsnet.ro 20020809  
source RIPE  
route 62.231.64.0/18  
descr RDSNET  
Origin AS8708  
mnt-by AS8708-MNT  
changed tim@rdsnet.ro 20011123  
source RIPE  
role Romania Data Systems NOC  
address 71-75 Dr. Staicovici  
address Bucharest / ROMANIA  
phone +40 21 30 10 888  
fax-no +40 21 30 10 892  
e-mail tech@rdsnet.ro  
Admin. Contact AS1385-RIPE  
Tech. Contact BS747-RIPE  
NIC Handle RDS-RIPE  
remarks ---------------------------------  
remarks abuse reports: abuse@rdsnet.ro  
remarks NOC Phone 24x7: +40 21 30 10 888  
remarks NOC E-mail: support@rdsnet.ro  
remarks ---------------------------------  
Notify tech@rdsnet.ro  
mnt-by AS8708-MNT  
changed tim@rdsnet.ro 20010507  
source RIPE  
person Andrei Stirbu  
address Romania Data Systems  
address Str. Sf. Vineri nr. 25  
address Bl. 105C sector 3  
address Bucharest, Romania  
phone +40 21 301 0888  
fax-no +40 21 301 0851  
e-mail andii@rdsnet.ro  
NIC Handle AS1385-RIPE  
Notify as-admin@rdsnet.ro  
mnt-by AS8708-MNT  
changed danacorb@rnc.ro 19990212  
changed ciprian@rnc.ro 19990805  
changed root@s2.rnc.ro 20000218  
changed andii@rdsnet.ro 20000220  
source RIPE

---

<div class="post-metadata">

**Author:** ![SCSimmons](https://avatars.discourse-cdn.com/v4/letter/s/e495f1/32.png) [@SCSimmons](https://boards.straightdope.com/u/SCSimmons)\
**Post date:** [October 9, 2002, 3:12am UTC](https://boards.straightdope.com/t/is-it-possible-to-trace-an-ip-using-an-email-sent-to-you/131444/9 "2002-10-09T03:12:02Z")

</div>

I doubt your target is actually posting from Rumania. I’d guess that that server is hosting an open relay. It doesn’t show up in the [Open Relay Database](http://www.ordb.org/) at this time, though … Anyway, if that’s the case, your trail is at a dead-end. (Unless it’s possible that your guy really _is_ in Rumania, in which case you should contact Interpol. Or something.)

---

<div class="post-metadata">

**Author:** ![trader\_of\_shots](https://avatars.discourse-cdn.com/v4/letter/t/aeb1de/32.png) [@trader\_of\_shots](https://boards.straightdope.com/u/trader_of_shots)\
**Post date:** [October 9, 2002, 8:25am UTC](https://boards.straightdope.com/t/is-it-possible-to-trace-an-ip-using-an-email-sent-to-you/131444/10 "2002-10-09T08:25:02Z")

</div>

Why do you think this person has been “stealing” passwords … dealing with cases like this daily - it is just a nerd form of teritorial pissings … stay out of my chat room or i will hack you ect ( AKA nuke ya)

If you are worried about peopel cracking your passwords make a good alphanumeric password

IE

n33ks923m  
mw933nd7  
ba5344j3j

ect

never put real names in and never end a password with the number 1

IE

fred1  
happy1  
gordon1

just too easy to break.

---

<div class="post-metadata">

**Author:** ![BrentLumkin](https://avatars.discourse-cdn.com/v4/letter/b/9d8465/32.png) [@BrentLumkin](https://boards.straightdope.com/u/BrentLumkin)\
**Post date:** [October 9, 2002, 11:11am UTC](https://boards.straightdope.com/t/is-it-possible-to-trace-an-ip-using-an-email-sent-to-you/131444/11 "2002-10-09T11:11:17Z")

</div>

> [@](#):
>
> \*Originally posted by trader\_of\_shots \*  
> \*\*Why do you think this person has been “stealing” passwords … dealing with cases like this daily - it is just a nerd form of teritorial pissings … stay out of my chat room or i will hack you ect ( AKA nuke ya)
> 
> If you are worried about peopel cracking your passwords make a good alphanumeric password
> 
> IE
> 
> n33ks923m  
> mw933nd7  
> ba5344j3j
> 
> ect
> 
> never put real names in and never end a password with the number 1
> 
> IE
> 
> fred1  
> happy1  
> gordon1
> 
> just too easy to break. \*\*

Because they stole mine, and hundreds of other UBID users, that’s why.

---

<div class="post-metadata">

**Author:** ![Urban\_Ranger](https://avatars.discourse-cdn.com/v4/letter/u/e9c0ed/32.png) [@Urban\_Ranger](https://boards.straightdope.com/u/Urban_Ranger)\
**Post date:** [October 10, 2002, 8:11am UTC](https://boards.straightdope.com/t/is-it-possible-to-trace-an-ip-using-an-email-sent-to-you/131444/12 "2002-10-10T08:11:54Z")

</div>

How is this person stealing passwords and stuff and why did he e-amil you?

---

<div class="post-metadata">

**Author:** ![handy](https://avatars.discourse-cdn.com/v4/letter/h/b5a626/32.png) [@handy](https://boards.straightdope.com/u/handy)\
**Post date:** [October 10, 2002, 3:14pm UTC](https://boards.straightdope.com/t/is-it-possible-to-trace-an-ip-using-an-email-sent-to-you/131444/13 "2002-10-10T15:14:15Z")

</div>

Its easy to forge headers too. Its probably just a spam scam email.

---

<div class="post-metadata">

**Author:** ![galt](https://avatars.discourse-cdn.com/v4/letter/g/35a633/32.png) [@galt](https://boards.straightdope.com/u/galt)\
**Post date:** [October 10, 2002, 9:12pm UTC](https://boards.straightdope.com/t/is-it-possible-to-trace-an-ip-using-an-email-sent-to-you/131444/14 "2002-10-10T21:12:56Z")

</div>

I would argue that 62.231.66.127 must be more than an open relay – it is actively involved in the forgery. If it were simply an open relay, there would be another “Recieved:” line which looks like this:

Received: from \<some other site\> by 62.231.66.127 …

So either 62.231.66.127 is a relay which conceals sources prior to it (which means it’s a haven for abuse and should be reported) or it’s the guy’s computer which originated the mail. I’d put money on the latter.

**Brent** , here’s how you read these headers. Here they are in a simplified form (note that they’re chronologically backwards):

(1) Received: from [machine2.aol.com](http://machine2.aol.com) by [machine1.aol.com](http://machine1.aol.com)  
(2) Recieved: from [mailserver.yahoo.com](http://mailserver.yahoo.com) by [machine2.aol.com](http://machine2.aol.com)  
(3) Recieved: from 62.231.66.127 by [mailserver.yahoo.com](http://mailserver.yahoo.com)

This boils down to [machine1.aol.com](http://machine1.aol.com) making the following claim:  
“I, [machine1.aol.com](http://machine1.aol.com), received this message from [machine2.aol.com](http://machine2.aol.com).  
[machine2.aol.com](http://machine2.aol.com) _claims_ to have received this message from [mailserver.yahoo.com](http://mailserver.yahoo.com), but I have not verified that. If you trust [machine2.aol.com](http://machine2.aol.com), you can treat this as a verifiable fact.  
Further, [machine2.aol.com](http://machine2.aol.com) claims that [mailserver.yahoo.com](http://mailserver.yahoo.com) claims to have gotten the message from 62.231.66.127. If you trust **both** [machine2.aol.com](http://machine2.aol.com) and [mailserver.yahoo.com](http://mailserver.yahoo.com), then you can treat this as a verifiable fact.”  
So you can see that going further down in the headers involves deciding which servers you trust. It’s probably safe to say that machines handling mail for [aol.com](http://aol.com) and [yahoo.com](http://yahoo.com) are trustworthy enough to accurately record the sources of the messages they handle. Which leaves you suspecting 62.231.66.127 (see **NotMrKnowItAll’s** info).

This seems pretty straightforward: the originating computer is the bad one. Note, however, that the trace _could_ look something like this:

(1) Received: from [machine2.aol.com](http://machine2.aol.com) by [machine1.aol.com](http://machine1.aol.com)  
(2) Received: from [mailserver.yahoo.com](http://mailserver.yahoo.com) by [machine2.aol.com](http://machine2.aol.com)  
(3) Received: from 62.231.66.127 by [mailserver.yahoo.com](http://mailserver.yahoo.com)  
(4) Received: from [machine1.microsoft.com](http://machine1.microsoft.com) from 62.231.66.127  
(5) Received: from [machine2.microsoft.com](http://machine2.microsoft.com) from [machine1.microsoft.com](http://machine1.microsoft.com)

Note that in this case, you can’t trust the lines that claim to come from [x.microsoft.com](http://x.microsoft.com), because the untrustworthy machine (62.231.66.127) could have just fabricated those out of thin air. Once you trace back to a machine you don’t trust, nothing past that point can be trusted.
