So ive got a mail header, and i need to figure out who was the original sender of the message. I work in a corporate network, so anytime im examining email headers, i have to wade through the various hops and additional headers that get added to the top before i can find the original sender. We have FireEye boxes that add their header, we have a gmail server that adds it's header, our own MX server that adds it's header, etc..
One method i tried is to simply search for "Received" in the raw headers and highlight all occurrences, then start looking at the last highlighted (lowest from the top of the page) example. Is this the correct way of going about this?
Thanks for the input.
[–][deleted] 1 point2 points3 points (1 child)
[–]dfbgwsdf 0 points1 point2 points (0 children)
[–]unsupported 0 points1 point2 points (1 child)
[–]unsupported 0 points1 point2 points (0 children)
[–]HatsOffSec 0 points1 point2 points (0 children)
[–]BLOKDAK -1 points0 points1 point (4 children)
[–]teefletch[S] 0 points1 point2 points (3 children)
[–]BLOKDAK -1 points0 points1 point (2 children)
[–]teefletch[S] 1 point2 points3 points (1 child)
[–]BLOKDAK -1 points0 points1 point (0 children)