Windows Thread, How to track which IP an email came from - Exchange 2003 in Technical; Any ideas? I thought it might be possible to look at the full header of the email, although it appears ...
-
29th March 2006, 11:37 AM #1
- Rep Power
- 0
How to track which IP an email came from - Exchange 2003
Any ideas? I thought it might be possible to look at the full header of the email, although it appears that apart from the standard to/cc/subject fields, I can't view anything else.
All I'm after is a method of tracking down the source IP of an (internal) email...
TIA
-
-
IDG Tech News
-
29th March 2006, 11:41 AM #2 Re: How to track which IP an email came from - Exchange 2003
Exchange isn't RFC compliant when generating headers. You can work round this by either:
a) make your clients use IMAP/POP3. That way full headers will be generated.
b) make your clients use webmail and use the web server logs.
-
-
29th March 2006, 12:32 PM #3
- Rep Power
- 0
Re: How to track which IP an email came from - Exchange 2003
There's one word for that: b*gger.
-
-
29th March 2006, 12:40 PM #4
- Rep Power
- 14
Re: How to track which IP an email came from - Exchange 2003
You can use message tracking from System Manager, Tools to track messages sent though exchange,
If it is a message which was BCC'd this will still tell you the sender and who it went to as long as you have enabled logging on your server.
Can you not check logs for where the sender was logged on.
-
-
29th March 2006, 12:56 PM #5
- Rep Power
- 0
Re: How to track which IP an email came from - Exchange 2003
I think that's my only alternative. Have enabled message tracking but it appears that it'll only take effect from now, rather than pick up earlier messages (which is what I expected).
Off to do some research.... ;-)
-
-
29th March 2006, 01:41 PM #6 Re: How to track which IP an email came from - Exchange 2003
Message tracking has serious (potentially crippling) performance implications.
-
-
29th March 2006, 01:56 PM #7
- Rep Power
- 0
Re: How to track which IP an email came from - Exchange 2003
That was my other worry, I'll see what I can find out from it overnight, then decide whether to leave it in place or not. I suspect not...
-
-
29th March 2006, 01:59 PM #8 Re: How to track which IP an email came from - Exchange 2003
How about using a real mail server?
-
-
29th March 2006, 01:59 PM #9
- Rep Power
- 0
Re: How to track which IP an email came from - Exchange 2003

Originally Posted by
indiegirl Any ideas? I thought it might be possible to look at the full header of the email, although it appears that apart from the standard to/cc/subject fields, I can't view anything else.
All I'm after is a method of tracking down the source IP of an (internal) email...
TIA
can you not just open the email, file-> properties -> details ?
so you get like:
Code:
Received: from MSFWKC223 [10.133.41.34] by moorlands.staffs.sch.uk
(SMTPD32-5.04) id AA0B3020206; Wed, 29 Mar 2006 12:05:47 +0000
Message-ID: <000801c65320$8510afc0$2229850a@MOORLANDSSIXTH.INTERNAL>
Reply-To: "itassist" <itassist@local>
From: "itassist" <itassist@local>
To: <faultdesk@local>
Subject: Printer credits
Date: Wed, 29 Mar 2006 12:04:16 +0100
Organization: Moorlands Sixthform Centre
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_NextPart_000_0005_01C65328.E6CDEBD0"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2900.2180
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2180
X-RCPT-TO: <faultdesk@local>
X-UIDL: 178
Status: U
or does it not generate those headers at all?
-
-
29th March 2006, 02:02 PM #10 Re: How to track which IP an email came from - Exchange 2003
or does it not generate those headers at all?
Exchange isn't an RFC compliant mail server. It only bothers to generate those headers if you post via IMAP/POP3. ie, if you force the issue.
-
-
29th March 2006, 02:03 PM #11 Re: How to track which IP an email came from - Exchange 2003
have you tried Right click on the email -> options -> internet headers?
-
-
29th March 2006, 02:05 PM #12 Re: How to track which IP an email came from - Exchange 2003
That doesn't work for Internal <-> Internal emails that don't leave the message store.
Those headers are only generated by the SMTP/IMAP/POP3 interfaces, as I've tried to explain.
-
-
29th March 2006, 02:06 PM #13
- Rep Power
- 0
Re: How to track which IP an email came from - Exchange 2003
bloody microsoft why don't they just use the standards like NORMAL PEOPLE gaarr!
-
-
29th March 2006, 02:43 PM #14 Re: How to track which IP an email came from - Exchange 2003
Because they'd have to compete on an even playing field then.
Embrace, extend and extinguish
-
-
29th March 2006, 02:46 PM #15 Re: How to track which IP an email came from - Exchange 2003
I assume it just uses mapi for that and then internal would bypass any normal routes for sending messages. If you have a high use email server would you really want it to do a smtp send and recieve for every internal message? I would guess some other mail servers do the same.
Not that I like exchange, I use mdaemon at home because it doesn't mangle my messages and leaves them in a sensible format than I can import and export via imap, while keeping unmangled headers. I used to use Turnpike which is why I'm a bit picky about these things :P
-
SHARE:
Similar Threads
-
Replies: 4
Last Post: 13th November 2007, 05:39 PM
-
By tosca925 in forum Windows
Replies: 4
Last Post: 8th October 2007, 12:59 PM
-
By timbo343 in forum Windows
Replies: 4
Last Post: 9th May 2007, 02:58 PM
-
By gazankers in forum Networks
Replies: 4
Last Post: 19th December 2006, 11:16 AM
-
By pooley in forum Windows
Replies: 5
Last Post: 4th July 2006, 05:39 PM
Thread Information
Users Browsing this Thread
There are currently 1 users browsing this thread. (0 members and 1 guests)
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules