±×°ÍÀÇ IP ÁÖ¼Ò¸¦ ÅëÇØ ÀüÀÚ ¿ìÆíÀÇ ¿ø·¡ À§Ä¡¸¦ ÃßÀûÇÏ´Â ¹æ¹ý

2007³â10¿ù 9ÀÏ 7:14 AM¿¡ ¿¡ ¹èÄ¡ÇÏ´Â

´ç½ÅÀÌ ¾î¶»°Ô¿¡ ÇÒ ¼ö ÀÖ´ÂÁö °¡À̵å¾î¶»°Ô ¿¡ ºü¸¥ °Í ¿©±â¿¡¼­ ÀÖ´Ù ±×°Í¿¡ ´ëÀ§ ÀüÀÚ ¿ìÆíÀº À§Ä¡¸¦ ±âÀÎÇϰí ÀÖ´Ù ÀüÀÚ ¿ìÆíÀÇ IP ÁÖ¼Ò¸¦ ÆÄ¾ÇÇϰí´Â°ú ã¾Æº¸¾Æ¼­. ³ª´Â °ËÁõ ¸ñÀûÀ» À§ÇØ È®½ÇÈ÷ ³ª°¡ ³ªÀÇ blog ¶§¹®¿¡ ¸ÅÀÏ ÀüÀÚ ¿ìÆíÀÇ Á¦ºñ¸¦ ¹Þ±â ¶§¹®¿¡ À¯¿ëÇϱâ À§ÇÏ¿© À̰ÍÀ» ¿©·¯¹ø ã¾Æ³Â´Ù. ÀüÀÚ ¿ìÆí ¹ß¼ÛÀÎÀÇ IP ÁÖ¼Ò¸¦ ÃßÀûÇÏ´Â °ÍÀº ¸î¸î ±â¼úÀû ¼¼ºÎ»çÇ×ÀÇ º¸¸¦ ¿ä±¸Çϰí, ±×·¡¼­ ´ç½ÅÀÇ ¹ßµÚ²ÞÄ¡¸¦ ¾ÈÀ¸·Î ÆÄ°Ô ÁغñµÇ¾î ÀÖ´Ù!

ÀÇ °úÁ¤¿¡¼­ Æ÷ÇÔµÈ ±âº»ÀûÀ¸·Î 2°³ ´Ü°è°¡ ÀÖ´Ù ÀüÀÚ ¿ìÆí ÃßÀû: ÀüÀÚ ¿ìÆí ¿ìµÎ¸Ó¸® ´Ü¸éµµ¿¡¼­ IP ÁÖ¼Ò¸¦ ã¾Æ³»°í ±× ÈÄ¿¡ IP ÁÖ¼ÒÀÇ À§Ä¡¸¦ ã¾Æº¸½Ê½Ã¿À.

GMail, Yahoo ¿ìÆí¹° ¹× Àü¸Á¿¡ ÀÖ´Â ÀüÀÚ ¿ìÆí ¹ß¼ÛÀÎÀÇ IP ÁÖ¼Ò¸¦ ã¾Æ³»±â

±×µéÀÌ ´ëÁßÀûÀÎ ÀüÀÚ ¿ìÆí Ŭ¶óÀ̾ðÆ®À̱⠶§¹®¿¡ º¸ÀÚ ´ç½Å Google¸¦ À§ÇØ À̰ÍÀ», Yahoo ¹× Àü¸ÁÀÌ ÇÒ ¹æ¹ýÀ» ÃßÁøÇϰí.

GoogleÀÇ Gmail

1. ´ç½ÅÀÇ °èÁ¤À¸·Î Å볪¹«´Â ¹®Á¦ÀÇ ÀüÀÚ ¿ìÆíÀ» ¿¬´Ù.

2. ÀÇ ¿À¸¥ÂÊ¿¡ ÀÎ È­»ìÀ» ¾Æ·¡·Î Ŭ¸¯ÇϽʽÿÀ ´ë´ä ¿¬°á. ¼±ÅÃÇϽʽÿÀ ¼î °íÀ¯ ¸íºÎ¿¡¼­.

´ëÀ§ ÀüÀÚ ¿ìÆí

³ª°¡ ¸ÕÀú¿¡ °üÇÏ¿© ´ç½Å¿¡°Ô ¸»Çϰí ÀÖ´ø ±â¼úÀûÀÎ ºÎºÐÀº ¿©±â¿¡¼­ Áö±Ý ÀÖ´Ù! ´ç½ÅÀº "½ÃÀÛÇϽʽÿÀ ÅØ½ºÆ® ÇàÀ» ãÀ» Çʿ䰡 ÀÖ´Ù¹Þ´Â: ¿¡¼­¡°. °£´ÜÇÏ°Ô ´©¸£´Â °ÍÀÌ ½¬¿ï °ÍÀÌ Áöµµ ¸ð¸£´Ù ÅëÁ¦ + F ±×¸®°í Àú ´Ü°è¸¦ À§ÇÑ ¼ö»öÀ» ½ÇÇàÇϽʽÿÀ. ´ç½ÅÀº ¸Þ½ÃÁö ¼­µÎ¿¡¼­¿¡¼­ ÁÖ¾îÁø ¸î¸îÀÌ ´Ù´Â °ÍÀ» ÁÖÀÇÇÒ °ÍÀÌ´Ù. À̰ÍÀº ¸Þ½ÃÁö ¼­µÎ°¡ ´ç½Å¿¡°Ô ¿©Á¤¿¡¼­ Àú ÀüÀÚ ¿ìÆí Æ÷ÇԵDZ⠼­¹ö ÀüºÎÀÇ IP ÁÖ¼Ò¸¦ Æ÷ÇÔÇϱ⠶§¹®ÀÌ´Ù.

¸Þ½ÃÁö ¼­µÎ

¿ø·¡ ÀüÀÚ ¿ìÆíÀ» º¸³½ ù¹øÂ° ÄÄÇ»Å͸¦ ã¾Æ³»±â À§ÇÏ¿©´Â, ´ç½ÅÀº °¡Àå ¸Ö´Ù Àú°Í¿¡¼­ ÁÖ¾îÁö ã¾Æ³»¾ß ÇÒ °ÍÀÌ´Ù ¾Æ·¡·Î. ´ç½ÅÀÌ À§ ½É»ó¿¡¼­ º¼ ¼ö ÀÖ´ø ´ë·Î, óÀ½ °ÍÀº ºÒ¸° ÄÄÇ»ÅÍ¿¡¼­ ÀÌ´Ù "aseem" IP ÁÖ¼Ò 72.204.154.191. ±× ¶§ ±×°ÍÀº ³ªÀÇ ISPÀÇ ¼­¹ö¿¡¿¡ ¼ö¼ÛµÇ¾ú´Ù eastrmmtao104.cox.net µîµî ±×°ÍÀÌ ´ç½ÅÀÇ ÀüÀÚ ¿ìÆí ¼­¹ö¿¡ ¾òÀ» ¶§±îÁö µîµî.

ÄÄÇ»ÅÍ aseem ³ªÀÇ °³ÀÎ °¡Á¤¿ë ÄÄÇ»ÅÍ´Â À̰í Àú°ÍÀº ³ªÀÇ ÁýÀ» À§ÇÑ ³ªÀÇ °øÁß IP ÁÖ¼ÒÀÌ´Ù! ³ª´Â Yahoo¿Í Àü¸ÁÀ» ÅëÇØ Àú IP ÁÖ¼ÒÀÇ À§Ä¡ ÃßÀû¿¡ ´ëÇØ¼­ À̾߱âÇϱâ Àü¿¡ °¥ °ÍÀÌ´Ù.

beta Yahoo ¿ìÆí¹°

1. ´ç½ÅÀÇ °èÁ¤À¸·Î Å볪¹«´Â »õ·Î¿î ÅÇ¿¡¼­ ¿¬´Ù ±×·¡¾ß ÀüÀÚ ¿ìÆíÀ» ¿­°í (´ç½ÅÀÌ »õ·Î¿î ½Ã»ç °ø¿ë¿µ¿ª¿¡ beta Yahoo ¿ìÆí¹°À» ÀÌ¿ëÇÏ´Â °æ¿ì¿¡, È®ÀÎÇÑ´Ù ´ç½ÅÀ» ÀüÀÚ ¿ìÆí¿¡ double-click)

2. ¿À¸¥ÂÊ ²À´ë±â¿¡, ´ç½ÅÀº º¼ °ÍÀÌ´Ù µå·Ó´Ù¿î ¼±ÅñÇÀÌ Àִ ǥÁØ ¿ìµÎ¸Ó¸® ºÎÀü½ÂÀ¸·Î ¼±Á¤µÈ´Ù.

3. ±×°ÍÀ» Ŭ¸¯ÇÏ°í ¼±ÅÃÇϽʽÿÀ °¡µæ Â÷ÀÖ´Â ¿ìµÎ¸Ó¸®.

yahoo ¿ìµÎ¸Ó¸®

Again, you¡¯ll see the same information as before, just in a different window:

message headers

Microsoft Outlook

1. Open the email in Outlook by double-clicking on it

2. Go to View at the top menu (the menu options for the email, not the main Outlook window) and choose Options.

outlook message headers

You¡¯ll get a dialog box where you can set the message options and at the bottom you¡¯ll see the Internet Headers box. For some silly reason, the box is very small and you have to scroll a lot, so it¡¯s best to simply copy and paste the text into Notepad to view it more easily.

internet headers

Tracking the location of an IP address

Now that we have our originating IP address of 72.204.154.191, let¡¯s find out where that is! You can do this by perform a location lookup on the IP address. My favorites are IP2Location and GeoBytes IP Locator.

GeoBytes gave me a big map of New Orleans, LA along with a bunch of other information about the location itself.

find ip address location

IP2Location also gave me the same information pretty much, including the ISP (Cox Communications). Of course, this is correct since I live in New Orleans!

If you want more information, you can do a WHOIS database search also. My favorite one is the ARIN WHOIS Database Search. This will give you information on who hosts that IP address and their registration information. You can always contact them to try and find more information on that particular IP address.

Have fun tracking down those emails! Questions, comments, or suggestions? Post a comment!

Technorati Tags: , , , , , ,


If you enjoyed this post, make sure you subscribe to my RSS feed!

» Filed Under Computer Tips

Related Posts

30 Responses to ¡°How to track the original location of an email via its IP address¡±

  1. ReviewSaurus said on :

    Congrats aseem for getting dugged! And hey that¡¯s a nice and informative guide :)


  2. Apostrophe Police said on :

    ¡°It¡¯s¡± is always a contraction; the possessive form of ¡°it¡± has no apostrophe.


  3. beno said on :

    but thats only if the sender used a mail client on his own computer. if the sender uses gmail.com web interface to send the mail, u¡¯ll just see googles server in the ¡°recieved: from¡± section. not useful!


  4. akishore said on :

    Hi Beno,

    I agree it¡¯s not useful if the email is sent from Gmail via a web browser. However, there are tons of people who send emails from their office computers (Outlook, etc) and in those cases, tracking the location would be useful!

    Aseem


  5. beno said on :

    agreed, for such scenarios! i thought more people used the web interface than local clients. anyways, have a great day!


  6. Lexx said on :

    The IP shown isn¡¯t necessarily the originating IP. I could quite easily use someones else IP range and send emails.


  7. Markus Diersbock said on :

    This isn¡¯t always the case with webmail.

    If you are in Europe getting your mail, it will still
    look like you are in the US.

    Their¡¯s some good news with mail like HotMail, you
    can check one of the X-headers like:

    X-Originating-IP: [38.99.194.90]


  8. Markus Diersbock said on :

    new_msg = replace(old_msg, ¡°their¡¯s¡±,¡±there¡¯s¡±)


  9. TRaef06 said on :

    Lexx - ¡°In fact, the only part of the email header that can¡¯t be faked is the Received: line, which references your mail server. Spammers often add spoofed Received: headers to try to hide the true origin of the unwanted email, but modern mail transfer programs record the sender¡¯s correct IP address. So even if the sender uses a fictitious or false name when contacting the receiving server, you can determine the origin of the spoofed message.¡±
    http://searchsecurity.techtarg.....58,00.html

    The three way handshake that is part of every TCP communication prevents IP spoofing.


  10. sadasd said on :

    Not useful: the LAST Received: line may be private IP, you have to look up the last non-private IP.


  11. NotSoFast said on :

    Be careful when relying on this information. Spoofing IP¡¯s in emails is trivial.


  12. TRaef06 said on :

    You can¡¯t spoof the originating IP address. Its part of the three way handshake. All the others are easily spoofed.

    That¡¯s how SPAM filters check reverse DNS.

    His article does state to use the bottom IP address, which is the only one you can rely on.

    Nice article!


  13. Doug Woodall said on :

    Well done!
    This may not work all the time as others have said. But Ive had success in using these procedures in tracking down businesses who have gotten my email from other websites, such as when you use a directory submittal site.


  14. akishore said on :

    TRaef06 and Doug,

    Thanks for the positive comments! I wasn¡¯t meaning this to be a super comprehensive guide to detect the location of spam email. Mostly I¡¯ve used this to track down emails from malicious businesses or individuals. Most of them don¡¯t even know how to spoof an IP address!

    Thanks!


  15. Russ @ bombay potatoes said on :

    IP in email is too easy to fake. Nice article though, well done.


  16. Keith said on :

    Sounds cool¡¦ Like it was being said above, it is not always the case whereby you can trace the mail from the originating server; as a single server can be shared by many hosts.


  17. Sunil Thaha said on :

    Do you have any idea on how to traceback a mail sent from a gmail id ?


  18. Chris said on :

    I had a quick question. Is there any way that you know of to track the IP address for mail coming to just Hotmail?


  19. Nirmal said on :

    This is a great tip. Stumbled.


  20. HASSAN' said on :

    What a wonderful post.


  21. Shahid Khattak said on :

    Hi,
    Any idea how would it work for Outlook Express 6.0, please?
    Cheers,
    Shahid.


    Pingbacks
  1. Chat Marchet News Digest » How to track the originating location of an email via it¡¯s IP address Says:

    [¡¦] Full story This entry was posted on Sunday, October 14th, 2007 at 11:07 pm and is filed under le Chat Marchet. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site. [¡¦]

  2. Pingbacks
  3. How to track the original location of an email via its IP address « ICT NEWS Says:

    [¡¦] details¡¦ [¡¦]

  4. Pingbacks
  5. » How to track the originating location of an email via it¡¯s IP address Says:

    [¡¦] read more | digg story Uncategorized [¡¦]

  6. Pingbacks
  7. How to track the originating location of an email via it¡¯s IP address « digg the wordz Says:

    [¡¦] read more | digg story [¡¦]

  8. Pingbacks
  9. Tracking An Emails Location | Technology Blog by Colbert Low Says:

    [¡¦] tip on how to find out the IP address on the spam emails and do something about blocking them. via Here¡¯s a quick how-to guide on how you can track email to it¡¯s originating location by figuring [¡¦]

  10. Pingbacks
  11. Technogab | Technology News Podcast with a touch of Rock Says:

    [¡¦] How to track the original location of an email via its IP address [¡¦]

  12. Pingbacks
  13. Monday morning links serving: The October 22nd edition | [Geeks Are Sexy] Technology News Says:

    [¡¦] -How to track the original location of an email via its IP address Here¡¯s a quick how-to guide on how you can track email to its originating location by figuring out the email¡¯s IP address and looking it up. [¡¦]

  14. Pingbacks
  15. 5 Ways To Increase The Loading Speed Of A WordPress Blog Says:

    [¡¦] an article of mine entitled ¡°How to track the original location of an email address¡± was Dugg on Digg and got the most Diggs I¡¯ve ever received on an article with over [¡¦]

  16. Pingbacks
  17. How to track down Spam email¡¦ « Kenjun Says:

    [¡¦] http://www.online-tech-tips.co.....its¡¦ [¡¦]

Please post your comments/suggestions!