Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 origin of this email, can anyone tell from email header

views
     
TScmleow
post Jul 28 2015, 09:22 PM, updated 11y ago

New Member
*
Junior Member
33 posts

Joined: Dec 2006
good day,
wondering if any expert here can tell me where is the origin/sender base on the email header below? I am getting unstoppable spam from this sender.

-------------------------------------
Delivered-To: flxoffice@gmail.com
Received: by 10.112.173.68 with SMTP id bi4csp2281042lbc;
Tue, 28 Jul 2015 05:55:43 -0700 (PDT)
X-Received: by 10.60.37.166 with SMTP id z6mr33410485oej.63.1438088143188;
Tue, 28 Jul 2015 05:55:43 -0700 (PDT)
Return-Path: <felxcofficesvr26@server26.dns-server-ip.net>
Received: from server26.dns-server-ip.net (119.81.1.194-static.reverse.softlayer.com. [119.81.1.194])
by mx.google.com with ESMTPS id fp17si791851pac.179.2015.07.28.05.55.42
for <flxoffice@gmail.com>
(version=TLSv1.2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128);
Tue, 28 Jul 2015 05:55:43 -0700 (PDT)
Received-SPF: neutral (google.com: 119.81.1.194 is neither permitted nor denied by best guess record for domain of felxcofficesvr26@server26.dns-server-ip.net) client-ip=119.81.1.194;
Authentication-Results: mx.google.com;
spf=neutral (google.com: 119.81.1.194 is neither permitted nor denied by best guess record for domain of felxcofficesvr26@server26.dns-server-ip.net) smtp.mail=felxcofficesvr26@server26.dns-server-ip.net
Received: by server26.dns-server-ip.net (Postfix, from userid 10177)
id 6EDA96D5C28; Fri, 24 Jul 2015 08:38:44 +0800 (MYT)
To: flxoffice@gmail.com
Subject: 线上支付尽享 1%贴心回馈,资金更有保障; æ¾³é—¨å¾ˆæ¼‚äº®ï¼Œæ‚¨ä¸æƒ³æ¥é€›é€›å—ï¼Ÿå¦‚æžœå› ä¸ºæ²¡é’±ï¼Œé‚£å°±æ¥æ¾³é—¨é‡‘æ²™é›†å›¢ www.919991.com淘金吧!0门槛0风险0成本,简单注册成功就能免费成为高级会员。 ã€Šæ¾³é—¨é‡‘æ²™é›†å›¢ã€‹è®©æ‚¨è¶³ä¸å‡ºæˆ·ä½“éªŒæ¾³é—¨çŽ°åœºè èœæ¿€æƒ…ã€‚ 首存送30%最高礼金高达300000元,只要您敢来,我们就敢送。天天返水1.2ï¼…æ— ä¸Šé™ï¼Œäºšæ´²é¡¶çº§ä¿¡èª‰ï¼Œå¤§é¢æ— å¿§ï¼Œå•ç¬”ææ¬¾1000万元,即时到帐,也可在澳门取现! 即使道路坎坷不平,车轮也要前进;即使江河波涛汹涌,船只也航行。 recommend website Office Supplies Sdn Bhd to huaqianshu002@126.com
X-PHP-Originating-Script: 10177:classEmailV1e.php
X-Mailer: entertopPHP-Mailer
MIME-Version: 1.0
Content-type: text/html; charset=iso-8859-1
Message-Id: <20150724003844.6EDA96D5C28@server26.dns-server-ip.net>
Date: Fri, 24 Jul 2015 08:38:44 +0800 (MYT)
From: felxcofficesvr26@server26.dns-server-ip.net
----------------------------------

thank you.

This post has been edited by cmleow: Jul 30 2015, 09:01 PM
baka.bakashi
post Aug 19 2015, 03:23 PM

Getting Started
**
Junior Member
53 posts

Joined: Oct 2011
you should check this line

Received: from server26.dns-server-ip.net (119.81.1.194-static.reverse.softlayer.com. [119.81.1.194])

but from my observation there could be more behind it...

This post has been edited by baka.bakashi: Aug 19 2015, 03:32 PM
Melton
post Sep 15 2015, 03:51 AM

New Member
*
Validating
38 posts

Joined: Sep 2015


from Singapore.

But other domains might have been resolved to that IP address as well.

This post has been edited by Melton: Sep 15 2015, 04:25 AM

 

Change to:
| Lo-Fi Version
0.0150sec    0.60    5 queries    GZIP Disabled
Time is now: 20th December 2025 - 04:05 AM