I am brand new to the email headers (not talking about spam), but I would like and need to have some knowledge for it now. I list two email headers below, they are (assumed) from the same sender with the same machine, is this correct and how can I tell that from the headers? BTW, the emails are from China, how can I tell where is the sender's system is? What is the info I should look to find the above items?
QUOTE
From =?gb2312?B?zv3B1rjfzd64383e?= Fri May 22 17:10:04 2009
Return-Path: <[b]replaced@live.cn>
Authentication-Results: mta130.mail.cnb.yahoo.com from=live.cn; domainkeys=neutral (no sig); from=live.cn; dkim=neutral (no sig)
Received: from 65.55.116.84 (EHLO blu0-omc3-s9.blu0.hotmail.com) (65.55.116.84) by mta130.mail.cnb.yahoo.com with SMTP; Fri, 22 May 2009 17:10:07 +0800
Received: from BLU142-W6 ([65.55.116.72]) by blu0-omc3-s9.blu0.hotmail.com with Microsoft SMTPSVC(6.0.3790.3959); Fri, 22 May 2009 02:10:05 -0700
Message-ID: <BLU142-W61D9CB9D64971BCBF26E7C4560[at]phx.gbl>
Return-Path: replaced@live.cn
Content-Type: multipart/alternative; boundary="_95acf702-5617-4f95-828f-9bbaeb83ee81_"
From: =?gb2312?B?zv3B1rjfzd64383e?= <replaced@live.cn> 查看联系人资料
To: <replaced@yahoo.com.cn>
Subject: =?gb2312?B?u9i4tA==?=
Date: Fri, 22 May 2009 09:10:04 +0000
Importance: Normal
MIME-Version: 1.0
Content-Length: 829
Return-Path: <[b]replaced@live.cn>
Authentication-Results: mta130.mail.cnb.yahoo.com from=live.cn; domainkeys=neutral (no sig); from=live.cn; dkim=neutral (no sig)
Received: from 65.55.116.84 (EHLO blu0-omc3-s9.blu0.hotmail.com) (65.55.116.84) by mta130.mail.cnb.yahoo.com with SMTP; Fri, 22 May 2009 17:10:07 +0800
Received: from BLU142-W6 ([65.55.116.72]) by blu0-omc3-s9.blu0.hotmail.com with Microsoft SMTPSVC(6.0.3790.3959); Fri, 22 May 2009 02:10:05 -0700
Message-ID: <BLU142-W61D9CB9D64971BCBF26E7C4560[at]phx.gbl>
Return-Path: replaced@live.cn
Content-Type: multipart/alternative; boundary="_95acf702-5617-4f95-828f-9bbaeb83ee81_"
From: =?gb2312?B?zv3B1rjfzd64383e?= <replaced@live.cn> 查看联系人资料
To: <replaced@yahoo.com.cn>
Subject: =?gb2312?B?u9i4tA==?=
Date: Fri, 22 May 2009 09:10:04 +0000
Importance: Normal
MIME-Version: 1.0
Content-Length: 829
From =?gb2312?B?zv3B1rjfzd64383e?= Tue May 26 16:15:19 2009
Return-Path: <[b]replaced@live.cn>
Authentication-Results: mta128.mail.cnb.yahoo.com from=live.cn; domainkeys=neutral (no sig); from=live.cn; dkim=neutral (no sig)
Received: from 65.55.116.104 (EHLO blu0-omc3-s29.blu0.hotmail.com) (65.55.116.104) by mta128.mail.cnb.yahoo.com with SMTP; Tue, 26 May 2009 16:16:23 +0800
Received: from BLU142-W14 ([65.55.116.72]) by blu0-omc3-s29.blu0.hotmail.com with Microsoft SMTPSVC(6.0.3790.3959); Tue, 26 May 2009 01:15:20 -0700
Message-ID: <BLU142-W14E5BA21777E0A83388373C4520[at]phx.gbl>
Return-Path: replaced@live.cn
Content-Type: multipart/alternative; boundary="_2e821a2a-bc19-4feb-a1cc-9cb691bfbf08_"
From: =?gb2312?B?zv3B1rjfzd64383e?= <replaced@live.cn> 查看联系人资料
To: =?gb2312?B?sc8g0cex8g==?= <replaced@yahoo.com.cn>
Subject:
Date: Tue, 26 May 2009 08:15:19 +0000
Importance: Normal
MIME-Version: 1.0
Content-Length: 872 [/b]
Thanks
P.S. I replaced the USER IDs for the sender and receiver.
