You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 2 Next »

Tracking where an email came from

We received a suspicious email from someone with a gmail address. Looking at the headers we ascertained the email came from:

Received: from mail-vc0-f179.google.com
(mail-vc0-f179.google.com [209.85.220.179])

There is no DNS record for this host and UDNS (part of RocketFuel) cannot find it.

SatSig (http://www.satsig.net/maps/lat-long-finder.htm)  identifies the host as being near Ankara, Turkey.

GeoIPTools (http://www.geoiptool.com/en/?ip=209.85.220.179), IPLocation (http://www.iplocation.net/click/1), IPLigence (http://www.iplocation.net/click/2), IPFinger (http://www.ipfingerprints.com/) and GeoPlugin (http://www.geoplugin.com/) identify it at Google HQ in Mountain View California

using TULIP we find it probably located in 

  • No labels