Thanks for the clarification about headers. I've had a related question for some time: I don't understand the IP notation in the header in the example below. In the example below the IP is bracketed by parentheses and brackets ([IP]). I'm used to only seeing the IP with brackets not parentheses as well. What does this mean?
Unfortunately, while the Received: header has a general format, it is fairly flexible -- so you may see various methods of including IPs, HELO hostnames, and/or reverse DNS entries.
Anything in parentheses in a Received: header is designed to be a human readable comment. So:
Received: from W2KAESB040 ([192.192.100.50])
by ntw40mailsvr.jaring.my (InternetNow! MailNow! 3.495);
Sat, 17 Jul 2004 10:43:08 +0800
In this case, the mailserver that processed this E-mail (ntw40mailsvr.jaring.my) received the E-mail from a mailserver (or mail client) identifying itself as just "W2KAESB040", and the mailserver added a comment of "[192.192.100.50]" which implies that the E-mail was received from the IP 192.192.100.50 (but in theory might not be).
FWIW, if Declude JunkMail were to see this header, it would assume that the 192.192.100.50 was the IP that the E-mail was received from.
The reason I am asking is that one of our clients recently moved to their own in-house Exchange server (formerly hosted on our Imail server). Because they are running on a DSL line they are still using our Imail server as a store and forward to their Exchange. We are trying (in vain) to configure their Exchange server to only accept incoming SMTP connections from Imail. However, this is proving difficult because their firewall is re-writing the received IP to a private IP (as in the example below) the hostname is unchanged, but there's parenthesis around the IP as below.
Ouch. If the firewall is *changing* the IP address in the Received: header (actually altering the Received: header), the firewall is broken. If it is just reporting the IP as an internal IP instead of an external IP, it may not be broken, but behaving in a very odd way.
-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers since 2000.
Declude Virus: Ultra reliable virus detection and the leader in mailserver vulnerability detection.
Find out what you've been missing: Ask for a free 30-day evaluation.
--- [This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]
To Unsubscribe: http://www.ipswitch.com/support/mailing-lists.html List Archive: http://www.mail-archive.com/imail_forum%40list.ipswitch.com/ Knowledge Base/FAQ: http://www.ipswitch.com/support/IMail/
