Firstly as some have already pointed out it is relatively trivial to spoof email headers. The name and address are the easiest to do. Most of the sapm eminates from large automated botnets. You can tell this usually if you look through the headers of the hops that the mail has made from the source I/P through to yourself or whoever it has gone too. Frequently you will find that these tend to eminate from somewhere like China where there are large numbers of compromised machines that are then operated remotely possibly within China or wherever. A genuine message would have a different set of message headers where the message will eminate from a rouces that is regonisably apropriate for that message. Those who operate these botnets do so for money by giving an organisation the ability to reach (spam) a large group of people, for this the botnet owner gets money. In prractice there is very little one can do about this sort of thing because email is NOT secure and the ecobonic incentive too high. Unless one uses extra measures like digital signatures it is next to impossible to vouch for absolute verasity of the email. Regards. Tristram Llewellyn Sight and Sound Technology Technical Support www.sightandsound.co.uk Mail: Tristram: tristram.llewellyn@xxxxxxxxxxxxxxxxxxx Technical: Support@xxxxxxxxxxxxxxxxxxx General - info@xxxxxxxxxxxxxxxxxxx Phone: Support line: 0845 634 7979 Sight and Sound Technology Limited is a company registered in England and Wales, with company number 1408275. Sight and Sound Technology Welton House North Wing Summerhouse Road Moulton Park Northampton NN3 6WD VAT Number - GB 860 2121 66. ________________________________ From: access-uk@xxxxxxxxxxxxx [mailto:access-uk@xxxxxxxxxxxxx] On Behalf Of DEREK HACKETT Sent: 03 July 2009 10:58 To: access Subject: [access-uk] E-mail Address Spoofed Hi Folks Is there any way I can find out how my e-mail address has been spoofed, I keep recieving spam e-mails that have been sent from my e-mail account. Both ESet smart Security and Malware Bytes can not find any mailware or spyware on my Pc. Thank you for any advice given to me so that I can resolve my problem. Regards Derek __________ Information from ESET Smart Security, version of virus signature database 4212 (20090703) __________ The message was checked by ESET Smart Security. part000.txt - is OK part001.htm - is OK http://www.eset.com ______________________________________________________________________ This email has been scanned by the MessageLabs Email Security System. For more information please visit http://www.messagelabs.com/email ______________________________________________________________________ ** To leave the list, click on the immediately-following link:- ** [mailto:access-uk-request@xxxxxxxxxxxxx?subject=unsubscribe] ** If this link doesn't work then send a message to: ** access-uk-request@xxxxxxxxxxxxx ** and in the Subject line type ** unsubscribe ** For other list commands such as vacation mode, click on the ** immediately-following link:- ** [mailto:access-uk-request@xxxxxxxxxxxxx?subject=faq] ** or send a message, to ** access-uk-request@xxxxxxxxxxxxx with the Subject:- faq