Forum Moderators: phranque

Message Too Old, No Replies

2 e-mail addresses coming from same IP address?

         

daz_razor

9:36 pm on Feb 16, 2004 (gmt 0)



Im a small business that is losing money due to hoax e-mails who are placing orders & failing to pay....
All are different e-mail addresses, but all are AOL.

Im new to all this IP address stuff.
I wanted to know if these two different parts of headers in the e-mails are from the same person...

Received: from imo-m26.mx.aol.com ([64.12.137.7]) by mc12-f8.hotmail.com with Microsoft SMTPSVC(5.0.2195.6824); Mon, 16 Feb 2004 09:30:40 -0800

Received: from imo-m26.mx.aol.com ([64.12.137.7]) by mc9-f14.hotmail.com with Microsoft SMTPSVC(5.0.2195.6824); Mon, 16 Feb 2004 09:38:32 -0800

( I see that the ([64.12.137.7]) is the same, but one of the same e-mail addresses had a different number in brackets the other day...(Below)..but I did notice that this (5.0.2195.6824); was identical in all.

Received: from imo-r03.mx.aol.com ([152.163.225.99]) by mc2-f38.hotmail.com with Microsoft SMTPSVC(5.0.2195.6824); Wed, 4 Feb 2004 13:20:16 -0800

"HOW DO I FIND OUT IN THE FULL HEADERS, IF THEY ARE FROM THE SAME PERSON?

Im not sure which parts are trhe IP address.
Any help would be much appreciated.
Thanks

Zaphod Beeblebrox

11:09 am on Feb 17, 2004 (gmt 0)

10+ Year Member



What you pasted says that an AOL mailserver received a message from a Hotmail server, nothing more.

Finding the actual sender requires you to find the last IP number listed as 'received from' and see who that may be. You should read the header from bottom to top chronologically.

Abdelrhman Fahmy

11:03 pm on Feb 17, 2004 (gmt 0)

10+ Year Member



Received: from imo-m26.mx.aol.com ([64.12.137.7])

imo-m26.mx.aol.com is the name server for the MX record which point to the mail server at AOL which recived your email and the IP is the resolve ip for this server.
mc12-f8.hotmail.com

is Hotmail mail server . both AOL and Hotmail has a lot of mail servers attached to the same domain to handle the huge number of emails per day
imo-r03.mx.aol.com ([152.163.225.99])

it's another one of AOL mail servers with it's IP
(5.0.2195.6824);

the current Version for the installed mail server software
then as you can see all the email shown here are related to the mail servers for both AOL and Hotmail ,
and that shown that you got the both emails from an email accounts at hotmail.