Hi,
This is the header of a spam that I reported to spamcop:
As you can see the ip address of the last server before our server is 212.52.128.2 but the system actually grabs 212.52.155.35.
The only reliable ip address is 212.52.128.2 because that is the ip address of the sender logged by our server all other ip addresses can be modified by spamer before sending the email.
Return-Path: <cashu[at]service.com>
Delivered-To: XXXX
Received: (qmail 27831 invoked by uid 1006); 2 Jun 2009 23:48:54 -0000
Delivered-To: XXXX
Received: (qmail 27829 invoked by uid 0); 2 Jun 2009 23:48:54 -0000
Received: from mail.cenatrin.bf (HELO koulouba.cenatrin.bf) (212.52.128.2)
by cleanvps.com with SMTP; 2 Jun 2009 23:48:54 -0000
Received: from localhost (localhost [127.0.0.1])
by koulouba.cenatrin.bf (Postfix) with ESMTP id 67D82933197;
Tue, 2 Jun 2009 23:26:15 +0000 (WET)
X-Virus-Scanned: amavisd-new at
X-spam-Flag: NO
X-spam-Score: 4.676
X-spam-Level: ****
X-spam-Status: No, score=4.676 tagged_above=-10 required=6.6
tests=[BAYES_50=0.001, FORGED_MUA_OUTLOOK=3.116,
FORGED_OUTLOOK_HTML=0.001, HTML_MESSAGE=0.001, MIME_HTML_ONLY=1.457,
RDNS_NONE=0.1]
Received: from koulouba.cenatrin.bf ([127.0.0.1])
by localhost (koulouba.cenatrin.bf [127.0.0.1]) (amavisd-new, port 10024)
with ESMTP id rZn2YhhR7OYG; Tue, 2 Jun 2009 23:26:14 +0000 (WET)
Received: from airburki-fatclq.airburkina.local (unknown [212.52.155.35])
by koulouba.cenatrin.bf (Postfix) with ESMTP id 1B9DE932FF0;
Tue, 2 Jun 2009 23:25:38 +0000 (WET)
Received: from User ([217.12.63.26]) by airburki-fatclq.airburkina.local with Microsoft SMTPSVC(6.0.3790.3959);
Tue, 2 Jun 2009 23:41:42 +0000
-------------------------
