[Novalug] [Ma-linux] Forged email header

Mark Smith mark at winksmith.com
Tue Jan 6 15:08:33 EST 2009


On Tue, Jan 06, 2009 at 01:13:05PM -0500, Jay Hart wrote:
> I assume it is possible to forge an email header.  What is the probability
> that this was forged?  I've copied the entire header below:

it's very typical for spammers to use some of the addresses for
delivery and then some of them for the return address.  they do
this so that there is a valid email address on the from line.
this will ensure two things:

1. many (if not all) MTA's will check the return address to kill
   spam.  if it's not from a valid domain (and/or recipient if
   possible to check) it will reject the mail.

2. that spammers don't get those pesky bounce emails

-- 
Mark Smith
mark at winksmith.com
mark at tux.org



More information about the Novalug mailing list