View Single Post
Old 05-24-2006, 06:18 AM  
rowan
Too lazy to set a custom title
 
Join Date: Mar 2002
Location: Australia
Posts: 17,393
In general you cannot trust SMTP headers, apart from the ones that the receiving system creates (assuming you do trust that )

This means that the only IP which is pretty much guaranteed to be accurate is the one that your server marks as delivering the mail. Anything else, including lines like

Received: from [80.87.84.30] by web35905.mail.mud.yahoo.com via HTTP; Tue, 23 May 2006 11:48:56 PDT

... can be forged.
rowan is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote