你收到了一封电子邮件,你想知道它来自哪里。乍一看,这似乎是不可能的。只有一个电子邮件地址(email address),它可能来自世界任何地方。没有邮票、邮资标记或像(postage mark)信件邮件(letter mail)那样的回邮街道地址。
电子邮件确实具有与我们大多数人从未见过的信件类似的功能。(letter mail)其中之一是一个类似于街道地址的(street address)IP(IP address)地址。挑战是从电子邮件 中跟踪IP 地址。(IP address)
让我们先看看如何查看和阅读电子邮件标题(email header)。这也是判断电子邮件是假的、欺骗性的还是垃圾邮件的好方法。
如何阅读电子邮件标题(How To Read An Email Header)
每封电子邮件都有一个电子邮件标题。把它想象成一种随邮件一起旅行的信封。它具有发件人和收件人信息(sender and recipient information),以及沿途拾取的信息。标题是否存在并不明显,并且可能难以阅读。
如何在 Gmail 中查看电子邮件标题(How To View An Email Header In Gmail)
- 在电子邮件的右上角,单击三个垂直点。在打开的菜单中,单击Show Original。
- 在打开的页面上,您会在底部看到电子邮件的纯文本版本。直到电子邮件内容(email content)开始的所有奇怪的文本都是标题。
如何在 Yahoo Mail 中查看电子邮件标题(How To View An Email Header In Yahoo Mail)
- 在电子邮件的顶部和中间附近,单击三个水平点。在打开的菜单中,单击查看原始消息(View raw message)。
- 打开的窗口将包含电子邮件的纯文本版本。直到消息正文的所有内容都是标题。
如何在 Outlook.com 中查看电子邮件标题(How To View An Email Header In Outlook.com)
- 在电子邮件的右上角,单击三个水平点。然后单击查看(View),然后单击查看消息详细信息(View message details)。
- 消息详细信息(Message details)窗口将打开,仅显示电子邮件的标题。
如何在 Outlook 中查看电子邮件标题(How To View An Email Header In Outlook)
- 首先,在它自己的窗口中打开消息。然后点击左上角的文件。(File)
- 在打开的窗口中,单击“属性(Properties )”按钮。
- 查看“属性(Properties )”窗口打开时的底部,查看Internet 标题(Internet headers)部分。框中的文本是标题。
如何阅读电子邮件标题(How To Read An Email Header)
阅读电子邮件标题的最简单方法是使用在线标题分析器(header analyzer)。一些选择包括 Google 的GSuite Toolbox Messageheader或MX Toolbox 的标头分析器(MX Toolbox’s header analyzer)。我们将使用谷歌的。
- 将标题粘贴到Messageheader 工具(Messageheader tool) (a)中,然后单击分析上面的标题(Analyze the Header Above) (b)。
- 结果将按 Internet 上的跳数顺序显示,起始点从 0 开始。在下面的示例中,IP 地址(IP address)已被模糊化以保护隐私。要跟踪电子邮件中的IP 地址(IP address),您可以使用该 IP 地址来尝试查找电子邮件的地理来源。它也可能作为域名(domain name)存在。
如何从电子邮件中跟踪 IP 地址位置(How To Track An IP Address Location From An Email)
您可以在多个站点上执行 whois 搜索以追踪IP 地址(IP address)位置。whois 搜索是查找域名(domain name)所有者或IP 地址(IP address)的搜索。搜索您喜欢的,但我们今天将使用Whois.com。
- (Enter)从标头分析(header analysis)结果中输入IP 地址或域名(IP address or domain name),然后单击WHOIS按钮。
- 结果将返回大量信息。Registrant Contact部分可能会列出注册域名(domain name)或拥有IP 地址(IP address)的个人或公司(person or company)的姓名、街道(Street)、城市(City)、State/Province、邮政编码(Postal Code)和国家(Country)/地区。
如果域是 Google、Yahoo 或 Outlook 怎么办?(What If The Domain Is Google, Yahoo Or Outlook?)
当从Google(Google)、Yahoo或Outlook等免费电子邮件服务(email service)发送电子邮件时,它不会携带发件人的IP 地址(IP address)。它只会显示Google(Google)、Yahoo或Outlook的 IP 或域名。当然,这可能距离发件人的实际位置有数千英里。
检查电子邮件域名(Check The Email Domain Name)
@ 符号后面的部分是发件人的域名(domain name)。如果不是@gmail.com、@ yahoo.com或@outlook.com,它可能是该发件人或其组织所独有的。最简单的做法是将域名(domain name)放入网络浏览器,看看它是否会显示一个网站。如果有,请检查该站点是否有邮寄地址(mailing address)。
将域名转换为 IP 地址(Turn A Domain Name Into An IP Address)
如果您有域名(domain name)但没有要查看的网站怎么办?whois 搜索隐藏了他们的实际位置?尝试(Try)将域名(domain name)转换为IP 地址(IP address)并对其进行 whois 搜索。
- 打开 Windows 命令提示符。
- 输入(Enter)命令
ping domain.com
其中 domain.com 是从标头分析中获取的(header analysis)域名(domain name)。按回车(Enter )键。该命令要做的第一件事是将域名(domain name)转换为IP 地址(IP address)。记(Make note)下该IP 地址(IP address)并对其进行whois 搜索(whois search)。
如果我仍然找不到位置怎么办?(What If I Still Can’t Find The Location?)
试图从电子邮件中跟踪IP 地址是一项侦探工作。(IP address)工作是这句话的重要组成部分。您投入多少工作取决于您想知道电子邮件的来源。
继续尝试我们所经历的不同组合。尝试不同的电子邮件标题站点和 whois 搜索站点。尝试只搜索整个电子邮件地址(email address),看看它是否与网站上某人的个人资料相关联。那可能有他们的位置。也许您会在论坛中找到它的帖子。有时(Sometimes)论坛会显示一个人来自哪个国家/地区。发挥创意,你(Get)就是侦探!
How to Track the Original Location of an Email via its IP Address
You’ve received an email and you want to figure out where it came from. At first glance, it seems impossible. There’s just an emaіl аddress and that coυld have come from anywhere in the world. There’s no stamp, postage mark, or return street address like letter mail.
Email does have similar features to letter mail that most of us never see. One of them is an IP address that’s sort of like a street address. The challenge is to track an IP address from an email.
Let’s look at how to view and read an email header first. This is also a good way to tell if an email is fake, spoofed, or spam.
How To Read An Email Header
With every email, there is an email header. Think of this as a sort of envelope that travels with the mail. It has the sender and recipient information, as well as information picked up along the way. It’s not obvious that the header is there and it can be difficult to read.
How To View An Email Header In Gmail
- At the top-right corner of the email, click on the three vertical dots. In the menu that opens, click on Show Original.
- On the page that opens, you’ll see the plain text version of the email at the bottom. All the odd text up to where the email content begins is the header.
How To View An Email Header In Yahoo Mail
- Near the top and middle of the email, click on the three horizontal dots. In the menu that opens, click View raw message.
- The window that opens will have the plain text version of the email. Everything right up to the body of the message is the header.
How To View An Email Header In Outlook.com
- At the top-right corner of the email, click on the three horizontal dots. Then click on View and then View message details.
- The Message details window will open, showing only the header of the email.
How To View An Email Header In Outlook
- First, open the message in its own window. Then click on File in the top-left corner.
- In the window that opens, click on the Properties button.
- Look at the bottom part of the Properties window when it opens, for the Internet headers section. The text in the box is the header.
How To Read An Email Header
The easiest way to read an email header is to use an online header analyzer. Some choices include Google’s GSuite Toolbox Messageheader or MX Toolbox’s header analyzer. We’ll use Google’s.
- Paste the header into the Messageheader tool (a) and click on Analyze the Header Above (b).
- The results will be displayed in order of hops through the internet, starting at 0 for the point of origin. In the example below, the IP address has been blurred out for privacy. To track an IP address from an email, this is the IP you would use to try to find the geographical origin of the email. It might also be there as a domain name.
How To Track An IP Address Location From An Email
There are several sites on which you can perform a whois search to track down an IP address location. A whois search is a search to find out who the owner of the domain name is or the IP address. Search for one that you like, but we’ll use Whois.com today.
- Enter the IP address or domain name from the header analysis results, and click on the WHOIS button.
- The results will come back with a lot of information. The Registrant Contact section will likely list the Name, Street, City, State/Province, Postal Code, and Country of the person or company that registered the domain name or owns the IP address.
What If The Domain Is Google, Yahoo Or Outlook?
When an email is sent from a free email service like Google, Yahoo, or Outlook, it won’t carry the IP address of the sender. It’ll just show the IP or domain name of Google, Yahoo, or Outlook. Of course, that could be thousands of miles from the sender’s actual location.
Check The Email Domain Name
The part after the @ symbol is the domain name of the sender. If it’s not @gmail.com, or @yahoo.com, or @outlook.com, it’s probably unique to that sender or their organization. The easiest thing to do is to put the domain name into a web browser and see if it shows you a website. If it does, check to see if that site has a mailing address on it.
Turn A Domain Name Into An IP Address
What if you have a domain name but no website to check? And the whois search hides their actual location? Try turning the domain name into an IP address and doing a whois search on that.
- Open the Windows Command Prompt.
- Enter the command <pre>ping domain.com</pre> where domain.com is the domain name taken from the header analysis. Press the Enter key. The first thing the command will do is convert the domain name into an IP address. Make note of that IP address and do a whois search on that.
What If I Still Can’t Find The Location?
Trying to track an IP address from an email is detective work. Work being the important part of that phrase. How much work you put into it depends on how much you want to know where the email came from.
Keep trying different combinations of what we’ve gone through. Try different email header sites and whois search sites. Try just searching the entire email address and see if it’s associated with someone’s profile on a website. That might have their location. Maybe you’ll find a post from it in a forum. Sometimes forums will show what country a person is from. Get creative, you’re the detective!