Simple Header

Home
Up
The Right Way
General FAQ
Spam Killer FAQ
Sam Spade
WebTools
AUPs
Glossary
Useful Links
Suggestions
Survey

 

 

 

 

 

TRACING THROUGH A SIMPLE HEADER
Original Header:
Received: from mail.rascal-1-2-3.net ([216.44.69.8])
          by mtiwgwc04.worldnet.att.net (InterMail v03.02.07 118 124)
          with SMTP id <19990514202418.MXAE27324@mail.rascal-1-2-3.net>;
          Fri, 14 May 1999 20:24:18 +0000
From:      <XXXX@XXXXXXX.XXX>
To:        <ZZZ@zzz.zzz>
Date: Fri, 14 May 1999 15:29:11 -0400
Message-ID: <05885312640473202@mail.rascal-1-2-3.net>
Subject: Not-For-Profit Will Help You Pay Debt!
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
 
Relevant Parts of the Header:

 

To Determine the Sender:

Perform an rDNS on the IP address shown:

nslookup 216.44.69.8
No reverse DNS (WSANO_DATA)

Since this IP address is not referenced against a domain name in the DNS server,  the next step is to find the owner of the IP block with an IP lookup:

Trying 216.44.69 at ARIN
New York Net (NETBLK-NYNET-CIDR06) NYNET-CIDR06 216.44.0.0 - 216.44.255.255
Frontline Communications Corporation (NETBLK-FRONTLINE-CIDR02) FRONTLINE-CIDR02  216.44.68.0 - 216.44.71.255

This shows that the IP addresses from 216.44.0.0 through 216.44.255.255 are registered to New York Net.  They have leased IP blocks 216.44.68.0 through 216.44.71.255 to Frontline Communications Corporation.

The IP address which was used to send this UBE is 216.44.68.8.  That falls within Frontline Communications Corporation's IP Block.

The next step is to find out who Frontline Communications Corporation is.

whois -h whois.arin.net !netblk-frontline-cidr02 ...
Frontline Communications Corporation (NETBLK-FRONTLINE-CIDR02)
1 Blue Hill Plaza, 6th floor
Pearl River, NY 10965
US

Netname: FRONTLINE-CIDR02
Netblock: 216.44.68.0 - 216.44.71.255

Coordinator:
Feinberg, Nick (NF39-ARIN) nick@FCC.NET
914-623-8553 ext.101 (FAX) 914-623-8669

Frontline Communications Corporation is fcc.net.  Next, check to see if fcc.net has a registered abuse reporting address:

whois -h whois.abuse.net fcc.net ...
abuse@fcc.net

If it is an ISP that is unfamiliar, it is recommended that you check the website for an AUP.  In this case, the AUP is located at: http://www.fcc.net/policy.htm#acceptable.  This one is a fairly weak policy that states:

"I understand that violation of certain generally accepted guidelines on Internet usage, such as restrictions on mass e-mailings and mass advertising, or posting inappropriately to newsgroups, would be a likely cause for the termination of my account. "

Since there is an AUP and the website indicates that fcc.net is a legitimate ISP and not a spamhaus,  forward the offending mail with complete headers to the abuse address.

 


Questions or problems regarding this web site should be directed to marjie1@att.net
Note: TINW
Copyright © 1999 All rights reserved. 
Last modified: Sunday September 12, 1999.