I'm new to the forum and I hope you can help.
Basically I suspect someone of being dishonest. I caught them out and I think they are trying to cover up with more lies.
At the bottom I've added the email header details of two separate emails; one was a test by me, the other I'm trying to trace its country of origin.
Said person supposedly sent me an email from inside Taiwan - I am in Taiwan too - but as they haven't been honest I had my doubts.
Their message was sent via yahoo email client on iPhone. The person claimed to be in Taiwan but every ip points to Singapore. When analysing the iPhone xymcookie (at the very bottom of their info) I noticed two ips. One was from this person's mobile provider in Taiwan, and the other was again from Singapore. This suggests that the internal ip of their phone had to reach an external ip to send the message. But why contact Singapore's serves and not Taiwan's? I got very suspicious as said person claimed a friend was going to Singapore while they were at home - I guess some people involuntarily give snippets of the truth. Anyway, I decided to conduct a little test...
I sent myself an email from a yahoo client, to my email - all inside Taiwan. You will see that all the servers are Taiwanese locations, not Singaporean like the other email.
In my mind the evidence is clear, the original email was sent from a location in Singapore, not Taiwan.
Am I correct? I'd appreciate advice on where I may be wrong.
Here are the ips from the possibly dishonest, Singapore email:
sender IP is 220.127.116.11
Received: from [18.104.22.168] by nm33.bullet.mail.sg3.yahoo.com with NNFMP; 30 Mar 2014 15:48:39 -0000
Received: from [22.214.171.124] by tm18.bullet.mail.sg3.yahoo.com with NNFMP; 30 Mar 2014 15:48:39 -0000
Received: from [127.0.0.1] by smtp102.mail.sg3.yahoo.com with NNFMP; 30 Mar
X-Rocket-Received: from [192.168.0.101] email deleted by firstname.lastname@example.org with xymcookie [126.96.36.199]
Here is my test:
sender IP is 188.8.131.52
Received: from [127.0.0.1] by nm38.bullet.mail.ne1.yahoo.com with NNFMP; 01 Apr 2014 06:48:23 -0000
Received: from [184.108.40.206] by nm38.bullet.mail.ne1.yahoo.com with NNFMP; 01 Apr 2014 06:45:23 -0000
Received: from [220.127.116.11] by tm12.bullet.mail.ne1.yahoo.com with NNFMP; 01 Apr 2014 06:45:23 -0000
Received: from [18.104.22.168] by tm5.bullet.mail.tp2.yahoo.com with NNFMP; 01 Apr 2014 06:45:23 -0000
Received: from [127.0.0.1] by omp1009.mail.tp2.yahoo.com with NNFMP; 01 Apr
*My own IP address was here, and it located me to the exact street *
Edited by Bubba72, 01 April 2014 - 07:53 AM.