by Watchingwolf
Fri Dec 11, 2009 2:26 pm
I've looked all over the site, but cannot find exact information on how to trace IPs via the email headers. The header is posted below from the first email received. I'm trying to figure out the actual location and am stuck. I searched the IPs via http://whatismyipaddress.com
Any help is appreciated. In case its needed, this was sent from a yahoo email to a yahoo email.
What I Am Looking ForTuesday, November 17, 2009 9:27 AM
From Billy Rivers Tue Nov 17 15:27:41 2009
X-RocketMail: 00000001;R---S-----------;5138
X-RocketUID: 0000000000
X-RocketYMUMID: AMfGtEQAAOQsSwLA8QnyRB3Blx4
X-RocketMIF: 1258471665;8852;
X-Apparently-To: REMOVED
X-RocketRCL: 5847;1;1460831792;5945
Return-Path: <[email protected]>
X-RocketTIP: 68.142.206.160 ; yahoo.com:s1024
X-RocketSRV: showStationery=; ;s_ip=68.142.206.160;d_t=1258471665;url=yimg.com,http://mail.yimg.com/us.yimg.com/i/mesg/tsmileys2/40.gif;Retro=Y;SgrnP=N
X-Rocket-Track: cat=UK; info=dkv:GD;dmcu:UK<token=NO_MATCH>;ip:NN<ip=68.142.206.160,policy=n-w0,n100,g0,s>;ipsh:UK<ip=68.142.206.160,policy=P=-1,X=-1,S=-1>;ipst:GD<ip=68.142.206.160>;cmsgbl:UK<s=30,m=1>;cmsgbk:UK<s=30,m=7>;cmsgob:UK<s=30,m=1>;mip:UK<p=not_run>;cptron:UK<prob=0.97>;ipsp:GD;csubbl:UK;csubbk:UK;url2db:GD<url=yimg.com>
X-YMailISG: JO2kBTcWLDvHYMUIwIn8g5EiMsZHyyOxXVECiJ5oGXJvpsoYh0TVtR61KkczbNZRSCgN.zRjSZJg5CNbOyikpfP5oWZhJ8su0.skLBkRC5D1OuvguQQS.6xAGmt6b59xjsVNqRjh7MgL3f0i1ENn5SrBye60aRpYo5x2Aw9JCBvsa5edZ3AoItUapahhTMmRopZ3R9vwZjR1Rl8EJOEWvIW2bnfXUwrO..mhHwMDQgTldcGJgD_n15rwRmgAuht_gQ4DjpG8ctbtaQk81sdlauviANC4OC4q.VyqhgPDB3jtMrG_o0LOeBOIyYHmMpVK3FwzM2SUw.hujxpnsZRDtVSbL8PAqlBclPFw0qEWLFM_J1GhA4b7pIsR5mOGnZtgb9aGJVzu4TeFwX9ol0mXAwMSYUWWacNyBdwX8GuTgwEAOPHTsP9Glbe2LQ3CYkr8_zt8G2gjvmck3acNSYo.kIUE
X-RocketHELO: n21.bullet.mail.mud.yahoo.com
X-RocketMAILFROM: [email protected]
X-RocketRCPTTO: REMOVED
X-RocketMSGID: [email protected]#0
X-Originating-IP: [68.142.206.160]
Authentication-Results: mta110.mail.ac4.yahoo.com from=yahoo.com; domainkeys=pass (ok); from=yahoo.com; dkim=pass (ok)
Received: from 127.0.0.1 (HELO n21.bullet.mail.mud.yahoo.com) (68.142.206.160) by mta110.mail.ac4.yahoo.com with SMTP; Tue, 17 Nov 2009 07:27:45 -0800
Received: from [209.191.108.96] by n21.bullet.mail.mud.yahoo.com with NNFMP; 17 Nov 2009 15:27:42 -0000
Received: from [68.142.201.247] by t3.bullet.mud.yahoo.com with NNFMP; 17 Nov 2009 15:27:42 -0000
Received: from [127.0.0.1] by omp408.mail.mud.yahoo.com with NNFMP; 17 Nov 2009 15:27:42 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: [email protected]
Received: (qmail 34589 invoked by uid 60001); 17 Nov 2009 15:27:41 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s1024; t=1258471661; bh=2JsiXw6MO6uRCel2eg5zuL9BC51rnXOv/JTHdx90V0k=; h=Message-ID:X-YMail-OSG:Received:X-Mailer:Date:From:Subject:To:MIME-Version:Content-Type; b=1C3A/8aNO0KsSJvLTmUSw+bWhcA+8+zD1XiJOtcgF5PFDBjj/QjszF0YTi60OZsWScZUM0/hh/OwKT6hSX9jUzah5+0Vd3PX2QBnrjsXCOKi/sQKUfav1ZNIwDPO8/Ldj2Ypf8it6WmQtZ2pBYxvRPMCCG8bqhnFLkG0cqdYjUA=
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s1024; d=yahoo.com; h=Message-ID:X-YMail-OSG:Received:X-Mailer:Date:From:Subject:To:MIME-Version:Content-Type; b=T9GerMaJiyeOErsTAJreQg5JumlG9FFbSucqDt1IXNPWOEntnFdhNlZKpJ80h7XWgsKFcUnXjRbS36Y0gqq6c31Ky32piW7jp41RlFYey7NuzsKRVxQoZJVBq35lRymN2HnPmtWe0lnqt9EDOY7GTCjTxOHU6JNIHYAUtssjaYU=;
Message-ID: <[email protected]>
X-YMail-OSG: PYfGQawVM1mWpPDxBSL2hBh9spyEy5scXsSQnbCBYTZ4TyFzRbVGM1ocGLJC8o_uRArct5_DDn2QXunEi144FFpR7zE.c9Cysh5xL8kkcZ8uci7YTAG6QDDHU094OwnmkCIqmJ4yZ.w9lwuugT91SzBlRUS9e7tlKtbxWnvxV4sCXoQ8jZNgeTJz7.hxNkWBSoWggtG3P7cLu5lo4AkjBGbURi3K08fGtM9H19ClFLADnHtbBIaGQFHjYSS9rkEaSdUVlCIcLXFv4Fu3z.eriR9PP.eNzAaQqHZguPCFy4teTt6HkQOwgS8zaID_SZAZV979hmFuVQ--
Received: from [209.73.188.240] by web111914.mail.gq1.yahoo.com via HTTP; Tue, 17 Nov 2009 07:27:41 PST
X-Mailer: YahooMailClassic/8.1.6 YahooMailWebService/0.7.361.4
Date: Tue, 17 Nov 2009 07:27:41 -0800 (PST)
From: This sender is DomainKeys verified Billy Rivers <[email protected]> Add sender to Contacts
Subject: What I Am Looking For
To: REMOVED
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="0-1541397210-1258471661=:54895"
Content-Length: 5847
Any help is appreciated. In case its needed, this was sent from a yahoo email to a yahoo email.
What I Am Looking ForTuesday, November 17, 2009 9:27 AM
From Billy Rivers Tue Nov 17 15:27:41 2009
X-RocketMail: 00000001;R---S-----------;5138
X-RocketUID: 0000000000
X-RocketYMUMID: AMfGtEQAAOQsSwLA8QnyRB3Blx4
X-RocketMIF: 1258471665;8852;
X-Apparently-To: REMOVED
X-RocketRCL: 5847;1;1460831792;5945
Return-Path: <[email protected]>
X-RocketTIP: 68.142.206.160 ; yahoo.com:s1024
X-RocketSRV: showStationery=; ;s_ip=68.142.206.160;d_t=1258471665;url=yimg.com,http://mail.yimg.com/us.yimg.com/i/mesg/tsmileys2/40.gif;Retro=Y;SgrnP=N
X-Rocket-Track: cat=UK; info=dkv:GD;dmcu:UK<token=NO_MATCH>;ip:NN<ip=68.142.206.160,policy=n-w0,n100,g0,s>;ipsh:UK<ip=68.142.206.160,policy=P=-1,X=-1,S=-1>;ipst:GD<ip=68.142.206.160>;cmsgbl:UK<s=30,m=1>;cmsgbk:UK<s=30,m=7>;cmsgob:UK<s=30,m=1>;mip:UK<p=not_run>;cptron:UK<prob=0.97>;ipsp:GD;csubbl:UK;csubbk:UK;url2db:GD<url=yimg.com>
X-YMailISG: JO2kBTcWLDvHYMUIwIn8g5EiMsZHyyOxXVECiJ5oGXJvpsoYh0TVtR61KkczbNZRSCgN.zRjSZJg5CNbOyikpfP5oWZhJ8su0.skLBkRC5D1OuvguQQS.6xAGmt6b59xjsVNqRjh7MgL3f0i1ENn5SrBye60aRpYo5x2Aw9JCBvsa5edZ3AoItUapahhTMmRopZ3R9vwZjR1Rl8EJOEWvIW2bnfXUwrO..mhHwMDQgTldcGJgD_n15rwRmgAuht_gQ4DjpG8ctbtaQk81sdlauviANC4OC4q.VyqhgPDB3jtMrG_o0LOeBOIyYHmMpVK3FwzM2SUw.hujxpnsZRDtVSbL8PAqlBclPFw0qEWLFM_J1GhA4b7pIsR5mOGnZtgb9aGJVzu4TeFwX9ol0mXAwMSYUWWacNyBdwX8GuTgwEAOPHTsP9Glbe2LQ3CYkr8_zt8G2gjvmck3acNSYo.kIUE
X-RocketHELO: n21.bullet.mail.mud.yahoo.com
X-RocketMAILFROM: [email protected]
X-RocketRCPTTO: REMOVED
X-RocketMSGID: [email protected]#0
X-Originating-IP: [68.142.206.160]
Authentication-Results: mta110.mail.ac4.yahoo.com from=yahoo.com; domainkeys=pass (ok); from=yahoo.com; dkim=pass (ok)
Received: from 127.0.0.1 (HELO n21.bullet.mail.mud.yahoo.com) (68.142.206.160) by mta110.mail.ac4.yahoo.com with SMTP; Tue, 17 Nov 2009 07:27:45 -0800
Received: from [209.191.108.96] by n21.bullet.mail.mud.yahoo.com with NNFMP; 17 Nov 2009 15:27:42 -0000
Received: from [68.142.201.247] by t3.bullet.mud.yahoo.com with NNFMP; 17 Nov 2009 15:27:42 -0000
Received: from [127.0.0.1] by omp408.mail.mud.yahoo.com with NNFMP; 17 Nov 2009 15:27:42 -0000
X-Yahoo-Newman-Property: ymail-3
X-Yahoo-Newman-Id: [email protected]
Received: (qmail 34589 invoked by uid 60001); 17 Nov 2009 15:27:41 -0000
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=yahoo.com; s=s1024; t=1258471661; bh=2JsiXw6MO6uRCel2eg5zuL9BC51rnXOv/JTHdx90V0k=; h=Message-ID:X-YMail-OSG:Received:X-Mailer:Date:From:Subject:To:MIME-Version:Content-Type; b=1C3A/8aNO0KsSJvLTmUSw+bWhcA+8+zD1XiJOtcgF5PFDBjj/QjszF0YTi60OZsWScZUM0/hh/OwKT6hSX9jUzah5+0Vd3PX2QBnrjsXCOKi/sQKUfav1ZNIwDPO8/Ldj2Ypf8it6WmQtZ2pBYxvRPMCCG8bqhnFLkG0cqdYjUA=
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s1024; d=yahoo.com; h=Message-ID:X-YMail-OSG:Received:X-Mailer:Date:From:Subject:To:MIME-Version:Content-Type; b=T9GerMaJiyeOErsTAJreQg5JumlG9FFbSucqDt1IXNPWOEntnFdhNlZKpJ80h7XWgsKFcUnXjRbS36Y0gqq6c31Ky32piW7jp41RlFYey7NuzsKRVxQoZJVBq35lRymN2HnPmtWe0lnqt9EDOY7GTCjTxOHU6JNIHYAUtssjaYU=;
Message-ID: <[email protected]>
X-YMail-OSG: PYfGQawVM1mWpPDxBSL2hBh9spyEy5scXsSQnbCBYTZ4TyFzRbVGM1ocGLJC8o_uRArct5_DDn2QXunEi144FFpR7zE.c9Cysh5xL8kkcZ8uci7YTAG6QDDHU094OwnmkCIqmJ4yZ.w9lwuugT91SzBlRUS9e7tlKtbxWnvxV4sCXoQ8jZNgeTJz7.hxNkWBSoWggtG3P7cLu5lo4AkjBGbURi3K08fGtM9H19ClFLADnHtbBIaGQFHjYSS9rkEaSdUVlCIcLXFv4Fu3z.eriR9PP.eNzAaQqHZguPCFy4teTt6HkQOwgS8zaID_SZAZV979hmFuVQ--
Received: from [209.73.188.240] by web111914.mail.gq1.yahoo.com via HTTP; Tue, 17 Nov 2009 07:27:41 PST
X-Mailer: YahooMailClassic/8.1.6 YahooMailWebService/0.7.361.4
Date: Tue, 17 Nov 2009 07:27:41 -0800 (PST)
From: This sender is DomainKeys verified Billy Rivers <[email protected]> Add sender to Contacts
Subject: What I Am Looking For
To: REMOVED
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="0-1541397210-1258471661=:54895"
Content-Length: 5847