Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

Tracing origins of an email - Which country was email sent from? Email headers.

Posted on 2014-02-24
6
Medium Priority
?
1,499 Views
Last Modified: 2014-04-03
Hi,

In a UK based legal case we have a situation where an email sender claims an email was sent from a certain country (let’s say Vietnam) however the actual email address is a Hotmail.co.uk

So the person claims the email was sent from Vietnam, using Hotmail.co.uk email address. We highly suspect the account was created as a fraudulent account and the actual email originated from the UK.

I will be analysing the headers of the email (Which I can’t paste here for legal reasons) but I wanted to know the best approach proving with  the best certainty which country the email was sent from. I believe the header should contain the IP address of the sending computer.

Thanks in advance.
0
Comment
Question by:afflik1923
  • 3
  • 3
6 Comments
 
LVL 8

Accepted Solution

by:
Jeff Perry earned 2000 total points
ID: 39882478
If the email was sent from an online hosted email service such as Hotmail then the headers won't help you.
0
 

Author Comment

by:afflik1923
ID: 39882554
I was hoping that it would stamp it with an IP that the browser was in, but I guess not?
Is there anything else that could be done.
0
 
LVL 8

Assisted Solution

by:Jeff Perry
Jeff Perry earned 2000 total points
ID: 39882614
Yes and No.

You are correct that the header will contain an IP.

That IP may or may not be of any use.

Email headers can be completely falsified. IP addresses can be spoofed.

Hopefully you have a criminal that is not that bright and accessed the account from his home pc and signed up to the fraudulent account with his/her real name and address, but I doubt it.
0
Get free NFR key for Veeam Availability Suite 9.5

Veeam is happy to provide a free NFR license (1 year, 2 sockets) to all certified IT Pros. The license allows for the non-production use of Veeam Availability Suite v9.5 in your home lab, without any feature limitations. It works for both VMware and Hyper-V environments

 

Author Comment

by:afflik1923
ID: 39882738
The fraudster is trying to create evidence by saying that correspondence occurred between parties. however we think he created a new email hotmail account and faked this conversation.
We don't think they would be technical enough to fake headers or any kind of spoofing.

The hope we have is that the email was meant to be sent from a person based in another country (South Korea in fact). The potential fraudster is based in the UK, so if we could prove the emails were sent from the UK and not from South Korea, that would be good evidence that they were not actually sent by the person who is supposed to have sent them.

however, looking at the headers so far, the originating server seems to be a hotmail one based in California.

That would likely support the case that we will not be able to prove anything.

Let me know your thoughts.
Thanks again.
0
 
LVL 8

Assisted Solution

by:Jeff Perry
Jeff Perry earned 2000 total points
ID: 39882799
My thoughts from a purely technical standpoint...

Unless you witness the person log onto a site and perform an act, or can prove a person not only "owns" an account but also that no one else can access it, it is nearly impossible to prove anything.

I hope you can find some way to prove the wrong.
0
 

Author Comment

by:afflik1923
ID: 39882812
Probably not, but even circumstantial evidence will be enough to help the case, if it were say, "in most cases it would mean X".
This would be helpful if we can even get to this level.
I've taken the liberty of creating another thread for this where I ask specific questions about South Korea.
http://www.experts-exchange.com/Networking/Protocols/Email/Q_28372773.html

Not expecting miracles, but at least this question is more focused.
Thanks so far for input on this matter.
0

Featured Post

Vote for the Most Valuable Expert

It’s time to recognize experts that go above and beyond with helpful solutions and engagement on site. Choose from the top experts in the Hall of Fame or on the right rail of your favorite topic page. Look for the blue “Nominate” button on their profile to vote.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Unified and professional email signatures help maintain a consistent company brand image to the outside world. This article shows how to create an email signature in Exchange Server 2010 using a transport rule and how to overcome native limitations …
Steps to fix error: “Couldn’t mount the database that you specified. Specified database: HU-DB; Error code: An Active Manager operation fail”
Internet Business Fax to Email Made Easy - With eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, fr…
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Suggested Courses

916 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question