Just wanted to gain some additional knowledge from the forum on the following. With the Klez virus (among others), it is widely known that the "from" address will most likely be spoofed. However, if you look at the full header, does Klez and the like, also attempt to spoof the IP address in which the request originated from to your (my) server. For example, some headers list Received from 'server name' (IP address) by domain.name with SMTP ID xxxx for email.address on Date Does Klez spoof the server name and IP address from the originator. Thank you for your aid and knowledge!!
_______________________
Keith Johnson, MCP
Network Engineer
Network Advocates, Inc.
Tel: 502.412.1050
Fax: 502.412.1058
Email: [EMAIL PROTECTED]
"Good pings come in small packets"
