SCANNING PST'S FOR HEADER INFO

M

Mike Cooper

If you get a virus, or rather repeat viruses from a
specific IP, it would be nice to track down who it is
sending it to you.

For example, I get a virus that is To:<me> and From:<my
mom> with sending IP belonging to <someISP>.com. I know
the sender usually is someone that uses <someISP>.com and
has both me and my Mom in their address book. I can
deduce who might be the culprit but not always.

What I would like to do is to scan all email in my inbox
(or PST) and look for the connecting IP in the header
info of all previously received email (or at least the
subnet if they have a dynamic IP). Chances are the
sender has sent me legitimate email before and I can more
easily identify them to ask them to buy some freaking
anti-virus software (but I digress).

I cannot seem to be able to get at the header info in any
way other than using View..options.. which is unworkable
way to look. Any ideas? I have exported the data to CSV
but Internet header info is not exported.

Mike.
 
S

Sue Mosher [MVP-Outlook]

This isn't necessarily the case at all. More than likely, some virus several
generations removed has harvested your and your mom's addresses and is also
using some unrelated ISP to send through. The machine sending the message
you received is unlikely to belong to someone who knows you, and your
chances of identifying the actual infected machine are very slim.

If you want to pursue this goose chase without using Options, you would have
to use CDO or Redemption to programatically retrieve the headers. See
http://www.outlookcode.com/d/forms/headers.htm
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top