# Tracing email

**URL:** <https://boards.straightdope.com/t/tracing-email/699991>\
**Category:** Factual Questions\
**Created:** [September 30, 2014, 6:16pm UTC](https://boards.straightdope.com/t/tracing-email/699991 "2014-09-30T18:16:59Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![dauerbach](https://avatars.discourse-cdn.com/v4/letter/d/c2a13f/32.png) [@dauerbach](https://boards.straightdope.com/u/dauerbach)\
**Post date:** [September 30, 2014, 6:16pm UTC](https://boards.straightdope.com/t/tracing-email/699991/1 "2014-09-30T18:16:59Z")

</div>

If I wanted an email to be essentially untraceable, say I was going to send a “whistle blowing” report on my boss (rather than anything illegal) what is the best way to do that. I know that I can easily create a false email account, but I worry about tracking the IP address.

Can I use TOR as my browser. Would that obscure my IP address?

---

<div class="post-metadata">

**Author:** ![AHarris](https://avatars.discourse-cdn.com/v4/letter/a/bcef8e/32.png) [@AHarris](https://boards.straightdope.com/u/AHarris)\
**Post date:** [September 30, 2014, 6:43pm UTC](https://boards.straightdope.com/t/tracing-email/699991/2 "2014-09-30T18:43:46Z")

</div>

The easiest way to do this would be to go to an internet cafe or library with public internet access. If for some reason you needed to use your own computer, you could use a proxy service or the Tor browser like you suggested.

In theory anything else could be tracked back to your computer given someone willing to invest sufficient time, effort and money into it.

Realistically as long as you didn’t use your work computer/e-mail, you would probably be fine. Also, you would need to make sure that the authority you are reporting to has a way of contacting you (as they may need more information).

---

<div class="post-metadata">

**Author:** ![jtur88](https://avatars.discourse-cdn.com/v4/letter/j/e9c0ed/32.png) [@jtur88](https://boards.straightdope.com/u/jtur88)\
**Post date:** [September 30, 2014, 6:49pm UTC](https://boards.straightdope.com/t/tracing-email/699991/3 "2014-09-30T18:49:01Z")

</div>

Is the whistle-blowing for a serious enough infraction that it is worth the effort and possibly ruining somebody’s life, or are you just being vindictive? Could you just put a post it note on his desk and say “I know what you’re doing”?

---

<div class="post-metadata">

**Author:** ![dauerbach](https://avatars.discourse-cdn.com/v4/letter/d/c2a13f/32.png) [@dauerbach](https://boards.straightdope.com/u/dauerbach)\
**Post date:** [October 1, 2014, 1:26pm UTC](https://boards.straightdope.com/t/tracing-email/699991/4 "2014-10-01T13:26:04Z")

</div>

I am only concerned about a private company being able to trace it.

Many of us have already spoken to her about it. It is serious enough that I need to go above her head.

---

<div class="post-metadata">

**Author:** ![Donnerwetter](https://avatars.discourse-cdn.com/v4/letter/d/b2d939/32.png) [@Donnerwetter](https://boards.straightdope.com/u/Donnerwetter)\
**Post date:** [October 1, 2014, 2:04pm UTC](https://boards.straightdope.com/t/tracing-email/699991/5 "2014-10-01T14:04:17Z")

</div>

Maybe it would be a good idea and go old school: Print out the report, drive to a big town nearby, buy envelopes and stamps there and send the document by (snail) mail.

---

<div class="post-metadata">

**Author:** ![yoyodyne](https://avatars.discourse-cdn.com/v4/letter/y/a9a28c/32.png) [@yoyodyne](https://boards.straightdope.com/u/yoyodyne)\
**Post date:** [October 1, 2014, 2:11pm UTC](https://boards.straightdope.com/t/tracing-email/699991/6 "2014-10-01T14:11:18Z")

</div>

[https://emkei.cz/](https://emkei.cz/) is good. I believe they store your IP in case you threaten to kill the president or something, but it doesn’t show up in the email.

---

<div class="post-metadata">

**Author:** ![chappachula](https://avatars.discourse-cdn.com/v4/letter/c/d2c977/32.png) [@chappachula](https://boards.straightdope.com/u/chappachula)\
**Post date:** [October 1, 2014, 2:17pm UTC](https://boards.straightdope.com/t/tracing-email/699991/7 "2014-10-01T14:17:02Z")

</div>

> [@dauerbach](#):
>
> I am only concerned about a private company being able to trace it.

It may only be a private complaint to a private person in management of a private company.  
But be careful, you never know what might develop in the future, especially if somebody hires a lawyer .

Silly examples, but not impossible if somebody wants revenge:  
Maybe your complaint could be turned against you-- as grounds for a civil lawsuit for defamation. Or maybe your complaint could be turned into grounds for a criminal suit for something that you aren’t aware of (say, stealing company property–did you ever take home a company document, or a “free sample” of something, or even just hijack a pack of paper from the supply room?)

I dont know anything about computer security. But I always work on the assumption that anything you type into a computer can be taken back out of the computer…if somebody is really,really determined to do it.

Send your untraceable email by driving to a library (not the branch nearest your office, or your house.)  
Create a yahoo address with a reasonable name, so it won’t be ignored as spam.  
And then periodically check the email account to see if somebody has contacted you—but check it only by physically going go back to the same library branch. If you get lazy and log into Yahoo from your computer at home , you’ve created a traceable link.

---

<div class="post-metadata">

**Author:** ![Chronos](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chronos/32/134_2.png) [@Chronos](https://boards.straightdope.com/u/Chronos)\
**Post date:** [October 1, 2014, 3:09pm UTC](https://boards.straightdope.com/t/tracing-email/699991/8 "2014-10-01T15:09:47Z")

</div>

While we’re at it, this thread itself is also traceable. You may have already said too much.

---

<div class="post-metadata">

**Author:** ![CookingWithGas](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cookingwithgas/32/485_2.png) [@CookingWithGas](https://boards.straightdope.com/u/CookingWithGas)\
**Post date:** [October 1, 2014, 5:34pm UTC](https://boards.straightdope.com/t/tracing-email/699991/9 "2014-10-01T17:34:00Z")

</div>

> [@Chronos](#):
>
> …this thread itself is also traceable.

By whom? I would guess only by board administrators.

---

<div class="post-metadata">

**Author:** ![Chronos](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chronos/32/134_2.png) [@Chronos](https://boards.straightdope.com/u/Chronos)\
**Post date:** [October 1, 2014, 6:19pm UTC](https://boards.straightdope.com/t/tracing-email/699991/10 "2014-10-01T18:19:47Z")

</div>

Depends on how much work you’re willing to put in, and what other resources you have available. If the OP posted from his place of work, then the company’s computer guys potentially already have a record of him visiting this site, and it wouldn’t take many clues to identify him as the OP of this particular thread.

---

<div class="post-metadata">

**Author:** ![Lemur866](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lemur866/32/434_2.png) [@Lemur866](https://boards.straightdope.com/u/Lemur866)\
**Post date:** [October 1, 2014, 6:42pm UTC](https://boards.straightdope.com/t/tracing-email/699991/11 "2014-10-01T18:42:49Z")

</div>

There’s a couple of levels here. If it’s “We think dauerbach sent this letter, how do we prove it?”, then he’s screwed by things like posting here on the Dope. They can focus on all sorts of things that tie you to the letter.

If it’s “somebody at the company sent this letter, who was it?” then you’re much more protected.

---

<div class="post-metadata">

**Author:** ![Chronos](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chronos/32/134_2.png) [@Chronos](https://boards.straightdope.com/u/Chronos)\
**Post date:** [October 1, 2014, 10:11pm UTC](https://boards.straightdope.com/t/tracing-email/699991/12 "2014-10-01T22:11:31Z")

</div>

And the difference between those two cases depends on how many people there are at the company. If the company is small enough or has enough resources, then they can go through the “We think \_\_\_\_\_ sent this letter” process for every employee.

---

<div class="post-metadata">

**Author:** ![Senegoid](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/senegoid/32/6606_2.png) [@Senegoid](https://boards.straightdope.com/u/Senegoid)\
**Post date:** [October 2, 2014, 12:39am UTC](https://boards.straightdope.com/t/tracing-email/699991/13 "2014-10-02T00:39:31Z")

</div>

Many libraries require patrons to sign up for a time slot to use their public-access terminals, often using their library card. And there may even be a record of which card-holders used which terminals.

In one city where I lived, for example, there was an automated sign-up process: You logged in at one specific terminal, where you get to see a grid showing all time slots, and which are available. You pick an available time slot. Then it prints out a slip showing your appointment time and which terminal you’re assigned to.

If your library makes any sort of record of who is using the terminals, you might want to find some other place to send your report.

---

<div class="post-metadata">

**Author:** ![Simplicio](https://avatars.discourse-cdn.com/v4/letter/s/c37758/32.png) [@Simplicio](https://boards.straightdope.com/u/Simplicio)\
**Post date:** [October 2, 2014, 12:54am UTC](https://boards.straightdope.com/t/tracing-email/699991/14 "2014-10-02T00:54:46Z")

</div>

> [@dauerbach](#):
>
> If I wanted an email to be essentially untraceable, say I was going to send a “whistle blowing” report on my boss (rather than anything illegal) what is the best way to do that. I know that I can easily create a false email account, but I worry about tracking the IP address.
> 
> Can I use TOR as my browser. Would that obscure my IP address?

The IP address of your computer isn’t attached to the email. So if you make a dummy gmail account, the only way for your work to find out\* it was you is for them to get Google to tell them what IP addresses were used to log on to that account. They’re only likely to be able to do this if they get a court order, which doesn’t sound very likely, but if you want to be extra cautious, you can get a VPN service for a couple bucks to cover your IP address, or just log-in from a local Starbucks.

(and to state the obvious, don’t send the email account from work. Even than, you’d probably be safe, since if its a large work place there are probably a lot of people signed into gmail at any given time, but still, its not impossible they might compare the time of your log-on to the time the email was sent and figure it out.)

---

<div class="post-metadata">

**Author:** ![jharvey963](https://avatars.discourse-cdn.com/v4/letter/j/54ee81/32.png) [@jharvey963](https://boards.straightdope.com/u/jharvey963)\
**Post date:** [October 2, 2014, 5:25pm UTC](https://boards.straightdope.com/t/tracing-email/699991/15 "2014-10-02T17:25:26Z")

</div>

> [@yoyodyne](#):
>
> [https://emkei.cz/](https://emkei.cz/) is good. I believe they store your IP in case you threaten to kill the president or something, but it doesn’t show up in the email.

Web of Trust reports this as a malicious website, and blocked access to it, so I’m not sure I’d try to use it.

On Edit: sorry, it’s not Web of Trust, it’s the security software on my machine.

J.
