14 April 2008

Tracking the source of an email

Here is nice little tutorial on tracking the source IP of an email (this only works when the source of the email was Microsoft Outlook/Outlook Express as they encode the IP in the Message ID field).

1. View the header data and find the Message-ID field:
Message-ID: <000701c89564$0115a292$cc4fb2bc@kagscc>
2. Break out the important portion (bolded between last $ and @):
3. Reverse by octet and convert from hex:
bc = 188
b2 = 178
4f = 79
cc = 204
Source IP address is

Unless the message ID or original IP was spoofed (possible), this is the IP of the computer that originally sent the email.
