TraceyC Posted November 19, 2009 Share Posted November 19, 2009 I've searched the forums, site, and read the FAQs but haven't found a solution to this. I have a number of spam coming to my work address which I am trying to report with the web based tool. The parser seems to identify the next to last IP address in the headers as the originating IP, which is incorrect. It is identifying my company's e-mail server as the injection point, rather than the bottom most IP address in the full headers. An example is here http://www.spamcop.net/sc?id=z3511383452z7...b6e7078c32aed8z Spamcop says 188.8.131.52 (Administrator of network where email originates) The headers say Received: from exprod7mx187.postini.com (HELO psmtp.com) ([184.108.40.206]) by ironport2.chron.com with ESMTP; 19 Nov 2009 04:24:58 -0600 Received: from source ([220.127.116.11]) (using TLSv1) by exprod7mx187.postini.com ([18.104.22.168]) with SMTP; Thu, 19 Nov 2009 10:16:03 GMT Therefore 22.214.171.124 is the originating source. The other spam messages have different originating IPs. The Spamcop parser always thinks they come from 126.96.36.199. What might be causing this problem? Thanks. Link to comment Share on other sites More sharing options...
This topic is now archived and is closed to further replies.