That�s for the answer. In that case, with the discussion concerning sending the automatic virus notices, what about the thoughts of sending it to Postmaster and/or abuse at the IP address?
That way, you would have an almost guaranteed way of sending it to correct server. I know we have the mail server IP address in the mail server alias list, as some tests, such as AOL, send messages to postmaster@"IP address". What are other admins out there doing? Is it a requirement to receive e-mail to postmaster@IP? John Tolmachoff IT Manager, Network Engineer 211 E. Imperial Hwy., Suite 106 Fullerton, CA� 92835 714-578-7999, ext. 104 [EMAIL PROTECTED] www.reliancesoft.com � -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] On Behalf Of R. Scott Perry Sent: Monday, April 22, 2002 7:17 AM To: [EMAIL PROTECTED] Subject: Re: [IMail Forum] Forged Headers >Although I know the header can be forged, what about the from IP address >on the top line of the header? > >That line is added by the receiving mail server, which takes the IP >directly from the connection communication, correct? > >Or do I not completely understand how headers are forged? Probably! :( It sounds like you do understand. :) There are two levels of trust involved. One is trusting the header (IE that it was added by a trusted source), the other is trusting the information within the header. The only headers that you can trust are the ones that your mailserver adds. However, the information within those headers may or may not be trustable. In *most* cases, you can only trust the first Received: header, and the only (useful) information in there that you can trust is the IP address. Specifically, you can not always trust the domain name that is listed (since it comes from the remote mailserver, which you can not always trust). The IP address in the first Received: header should be correct about 99.9999% of the time. It's possible to spoof an IP address, but it is *very* difficult with TCP/IP connection (not only does the hacker have to enter an invalid IP address, they have to predict sequence numbers and server responses). The hacker will not know if his mail was sent if he uses a spoofed IP address. However, it can happen. There is a lot of information you can get (or guess) from the other headers, but the accuracy of the information varies. -Scott --- Declude: Anti-virus, Anti-spam and Anti-hijacking solutions for IMail. http://www.declude.com --- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)] Please visit http://www.ipswitch.com/support/mailing-lists.html to be removed from this list. An Archive of this list is available at: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Please visit the Knowledge Base for answers to frequently asked questions: http://www.ipswitch.com/support/IMail/ Please visit http://www.ipswitch.com/support/mailing-lists.html to be removed from this list. An Archive of this list is available at: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Please visit the Knowledge Base for answers to frequently asked questions: http://www.ipswitch.com/support/IMail/
