E-Mail header showi...
 
Notifications
Clear all

E-Mail header showing private IP addresses only ?

6 Posts
4 Users
0 Reactions
655 Views
Samuel1
(@samuel1)
Trusted Member
Joined: 14 years ago
Posts: 63
Topic starter  

Hey all,

I am attempting to ascertain how it is possible that an e-mail header I am reviewing in a case only has 10.xxx.xxx.xxx IP addresses in it. This e-mail was coming from a Gmail account. So, perhaps the sender is using POP, but how are they able to completely hide the actual WAN IP address?


   
Quote
 lars
(@lars)
Eminent Member
Joined: 17 years ago
Posts: 31
 

I believe that's typical if the sender is using either the web interface or one of Google's mobile apps. Only if the sender is using a 'fat' client like Outlook, Thunderbird or Apple Mail would I expect to see the WAN address.


   
ReplyQuote
Samuel1
(@samuel1)
Trusted Member
Joined: 14 years ago
Posts: 63
Topic starter  

ah, so you're right! I just checked with other known e-mails. That must make e-mail forensics quite difficult, then. Webmail used to always show the originating IP – I remember with Hotmail it would be quite simple

X-Originating IP XXX.XXX.XXX.XXX

When did this change and get all anonymous?


   
ReplyQuote
(@ddewildt)
Estimable Member
Joined: 17 years ago
Posts: 123
 

X-Originating IP is an optional field and always has been. As far as I am aware GMail has never shown it, in fact they used to explicitly say they wouldn't show it to protect users privacy.


   
ReplyQuote
Samuel1
(@samuel1)
Trusted Member
Joined: 14 years ago
Posts: 63
Topic starter  

aha! well… it certainly seems to be working! )

Thank you.


   
ReplyQuote
(@passager51)
New Member
Joined: 16 years ago
Posts: 2
 

Hi came across a scenario, where a suspect hide his IP by sending an email from Gmail to his same email address, and the target as a secondary receiver in the Cc field
Example
Suspect address susp@gmail.com
Target address targ@gmail.com

From susp@gmail.com to susp@gmail.com
Cc targ@gmail.com


   
ReplyQuote
Share: