Anyone can use your email identity in minutes! Beware!!

I was searching for a email newsletters software to send bulk emails. Searching few minutes on Google I found an appropriate software. The software was good & did what exactly I wanted to. As I do normally, I started checking each & every option of the software.

In Preferences of that software, there was “Sender Options”, where you will give sender’s email ID & name. When I used this first time I used my actual email ID. Just got bit curious about that option, I entered a non real email ID (anything that came to mind) & sent a mail to my gmail. Shocked! in a second I received that mail in gmail with from email ID exactly as entered in “Sender Options” of the software. Here I will show you how exactly it worked with screenshots:

1. As you see in below screenshot, I have given email ID as admin@google.com & name as Google.

Email Identity threat 1 Click to Enlarge

2. I composed a mail & sent it to my gmail & Yahoo IDs

Email Identity threat 3 Click to Enlarge

3. The mail got into my inbox in seconds:

Gmail:

Email Identity threat 4

Email Identity threat 5

Yahoo:

Email Identity threat 6

Email Identity threat 7

I got this email in my gmail inbox & Yahoo! identified it as Spam. But in this email, no way you can find out it is sent by someone else & not Google. This means you can enter whatever you want in “Sender Options” of the software & send mails. You can enter your boss’s ID, your cousin’s, a bank’s…..whatever. I think you already realized how dangerous this could be. Without hacking anything, any password of email accounts you can use other’s email IDs (identity) for whatever kind of emails. But in gmail still there is a way to find out that is a fake email. When you open a mail in gmail, click “Show Details”. You can find “mailed by & “signed by” information there.

Email Identity threat 8 Click to Enlarge

These two info is missing in emails which I sent using that software. But a very less people will look into these options. I am not a hacker & don’t know what’s happening in the background. But I think major email providers should have any algorithm to find out these kind of mails & should block them. Yahoo! even found it as spam, if recipient looks into spam folder & finds sender is known to him, he/she will definitely mark it as “Not a spam”.

Update:

Few more Screenshots

Since many of readers got confused with post, am posting more two screenshots. This time I enter my cousin’s email ID as sender & I will send a mail asking credit card details.

Email Identity threat 9

But my cousin is not aware of this email & sent using a software by anyone (here it’s me) And it can also be made such that reply to this mail could go to some other email ID. Gmail is also showing online/offline status of sender & his profile picture on mouse over!

Email Identity threat 10

Here my cousin could never know somebody sent a mail like this using his identity.

Aw! This post has become too lengthy.

Name & information of the software I used is not disclosed in article for security reasons.

  • shameer

    I guess this is more likely a problem with the SMTP server you are using. Your SMTP server should not allow you to specify arbitrary mail sender ids.

    Inorder to view the original source of an email, you can always view the full headers of the mail

    Correct me if I am wrong.

  • shameer

    I guess this is more likely a problem with the SMTP server you are using. Your SMTP server should not allow you to specify arbitrary mail sender ids.

    Inorder to view the original source of an email, you can always view the full headers of the mail

    Correct me if I am wrong.

  • http://www.techbangalore.com/ Prashanth

    @shameer
    First point is right, anybody can manipulate SMTP server to send these mails. But I don’t know anything about that. I just used this software, it may have inbuilt SMTP.

    Second point, Even though if you view full header, you will not see any source information. In all screenshots here, header is expanded. Check if you can find anything about source.

    You can’t.

  • http://www.techbangalore.com Prashanth

    @shameer
    First point is right, anybody can manipulate SMTP server to send these mails. But I don’t know anything about that. I just used this software, it may have inbuilt SMTP.

    Second point, Even though if you view full header, you will not see any source information. In all screenshots here, header is expanded. Check if you can find anything about source.

    You can’t.

  • Pingback: Tech Bangalore » Blog Archive » How does mail delivery system works?

  • Anon

    What software is this?

  • shameer

    Nope. It should contain the source information. Below is the procedure to see full header.

    1. Open the email message.
    2. Click the down arrow next to Reply, at the top-right of the message pane.
    3. Click Show original.
    4. The message with full headers opens in a new browser window. Select all, copy, paste.

    Read the header from bottom to top, The first
    ‘Received: from’ header will give your machine’s IP or your ISP’s ip.

  • Anon

    What software is this?

  • shameer

    Nope. It should contain the source information. Below is the procedure to see full header.

    1. Open the email message.
    2. Click the down arrow next to Reply, at the top-right of the message pane.
    3. Click Show original.
    4. The message with full headers opens in a new browser window. Select all, copy, paste.

    Read the header from bottom to top, The first
    ‘Received: from’ header will give your machine’s IP or your ISP’s ip.

  • http://www.techbangalore.com/ Prashanth

    @shameer

    Yeah!
    It works.
    I found my ip allotted by BSNL on my broadband connection.
    That’s really helpful.
    Thanks a ton. But many don’t know about this. Does Yahoo & other webmail services povide this feature?

  • http://www.techbangalore.com Prashanth

    @shameer

    Yeah!
    It works.
    I found my ip allotted by BSNL on my broadband connection.
    That’s really helpful.
    Thanks a ton. But many don’t know about this. Does Yahoo & other webmail services povide this feature?

  • shameer

    Email headers are always there associated with an e-mail. Usually mail clients/web mail shows the main headers we are interested in. But there would be an option to see the full headers in all cases. Full headers can be used for SMTP debugging & identifying spam sources.
    Quick search returned a link explaining terms related to SMTP.
    http://www.sendmail.org/resources/email-explained.php
    Hope this helps

  • shameer

    Email headers are always there associated with an e-mail. Usually mail clients/web mail shows the main headers we are interested in. But there would be an option to see the full headers in all cases. Full headers can be used for SMTP debugging & identifying spam sources.
    Quick search returned a link explaining terms related to SMTP.
    http://www.sendmail.org/resources/email-explained.php
    Hope this helps

  • http://www.offers4all.co.nr/ Amol

    Hi..
    I have been visiting your BLOG since few days and found it really good. Regarding your this post, I would like to say that, there are many sites which provide this trick/prank. Of course you might be knowing this (not doubting your knowledge :-) . Also in all cases it’s not possible also to trace the original sender. And we obviously can’t do anything in this I think..?!!here one such FREE site: http://www.sendanonymousemail.net/

  • http://www.offers4all.co.nr Amol

    Hi..
    I have been visiting your BLOG since few days and found it really good. Regarding your this post, I would like to say that, there are many sites which provide this trick/prank. Of course you might be knowing this (not doubting your knowledge :-) . Also in all cases it’s not possible also to trace the original sender. And we obviously can’t do anything in this I think..?!!here one such FREE site: http://www.sendanonymousemail.net/

  • http://mp3bravo.com/ Djohn Atanasov

    I can do it… :( I tried and tried and tried…I can`t do it :(

  • http://mp3bravo.com Djohn Atanasov

    I can do it… :( I tried and tried and tried…I can`t do it :(

  • http://www.warcraftriches.com/ WoW Gold Farming

    I think it’s best you don’t say what the program is called or where to get it. It’s obviously already dangerous in the wrong people’s hands.

  • http://www.warcraftriches.com WoW Gold Farming

    I think it’s best you don’t say what the program is called or where to get it. It’s obviously already dangerous in the wrong people’s hands.

  • http://www.rambhai.com/ rambhai

    can you tell me the name of the software you used??

  • http://www.rambhai.com/ rambhai

    can you tell me the name of the software you used??

  • http://adeydas.com/ Abhishek

    Most email systems have filters that doesn’t allow such mails to be sent to the inbox. A few that don’t, people using these services should see the header part. Maybe its hard for a person with no tech experience to understand it but for a geek its as easy as eating a cake!!!

  • http://adeydas.com Abhishek

    Most email systems have filters that doesn’t allow such mails to be sent to the inbox. A few that don’t, people using these services should see the header part. Maybe its hard for a person with no tech experience to understand it but for a geek its as easy as eating a cake!!!

  • Rajesh Dave

    hi hello

  • Rajesh Dave

    hi hello

  • Loggy

    All,

    Is it possible for someone to input your SMTP and get a copy of your e-mails? If so, how do you detect and stop it from happening?

  • Loggy

    All,

    Is it possible for someone to input your SMTP and get a copy of your e-mails? If so, how do you detect and stop it from happening?

  • karthick

    hi
    i’m a college student from chennai.
    for the past two weeks my friends are receiving such kind of fake emails from my classmates itself.
    i really want to find out who that stupid is.
    is there a way to find it out.
    also i want to know abt the software shown in screenshots.pls mail me(email ID is submitted while posting this comment) abt the software.

    thank u

  • karthick

    hi
    i’m a college student from chennai.
    for the past two weeks my friends are receiving such kind of fake emails from my classmates itself.
    i really want to find out who that stupid is.
    is there a way to find it out.
    also i want to know abt the software shown in screenshots.pls mail me(email ID is submitted while posting this comment) abt the software.

    thank u

  • http://mobilegyaan.com/ Deepak

    @ karthick:
    A cyber expert can detect, where the e-mail has originated from.. And about the software I guess Prashant won’t disclose its name keeping security concerns in mind.

  • http://mobilegyaan.com Deepak

    @ karthick:
    A cyber expert can detect, where the e-mail has originated from.. And about the software I guess Prashant won’t disclose its name keeping security concerns in mind.

  • karthick

    hi
    isnt there anyother way to find it out?

  • karthick

    hi
    isnt there anyother way to find it out?

  • http://mobilegyaan.com/ Deepak

    @ Karthick:

    There are many other ways of doing it. It would be better if you find it out of your own :P

  • http://mobilegyaan.com Deepak

    @ Karthick:

    There are many other ways of doing it. It would be better if you find it out of your own :P

  • http://www.yahoomail.com/ bhaskar

    any one teach me abot how to hack the web site
    and give the websites name which help me to hack the website
    i have some knowledge about the c,&c++ language but not good knowledge about this sector and also tell me that how to improve myself programing language . if you have notes upon hackin then send to my e mail id
    thankyou sir

  • http://www.yahoomail.com bhaskar

    any one teach me abot how to hack the web site
    and give the websites name which help me to hack the website
    i have some knowledge about the c,&c++ language but not good knowledge about this sector and also tell me that how to improve myself programing language . if you have notes upon hackin then send to my e mail id
    thankyou sir

  • http://yobangalore.com/full-timepass/ Yo Bangalore

    Wonderful.. I have added your blog to my bookmarks and share it with all my colleagues and friends..

  • http://yobangalore.com/full-timepass/ Yo Bangalore

    Wonderful.. I have added your blog to my bookmarks and share it with all my colleagues and friends..

  • http://digg.com/celebrity/Alessandra_Ambrosio_nude_pictures_naked_video_sextape_3 hnEydo

    Full sex tape video whith Alessandra Ambrosio
    click here Alessandra Ambrosio nude gallary sextape or just follow the link http://digg.com/celebrity/Alessandra_Ambrosio_nude_pictures_naked_video_sextape_3
    You MUST SEE it, this girl really beautifull!!!

  • http://digg.com/celebrity/Alessandra_Ambrosio_nude_pictures_naked_video_sextape_3 hnEydo

    Full sex tape video whith Alessandra Ambrosio
    click here Alessandra Ambrosio nude gallary sextape or just follow the link http://digg.com/celebrity/Alessandra_Ambrosio_nude_pictures_naked_video_sextape_3
    You MUST SEE it, this girl really beautifull!!!

  • http://digg.com/celebrity/Tara_Reid_nude_pictures_naked_video_sextape piniko

    The best scenes whith Tara Reid (hot and sexy)!
    click here Tara Reid nude gallery sextape or just follow the link http://digg.com/celebrity/Tara_Reid_nude_pictures_naked_video_sextape
    You MUST SEE it, this chik really beautifull!!!

  • http://digg.com/celebrity/Tara_Reid_nude_pictures_naked_video_sextape piniko

    The best scenes whith Tara Reid (hot and sexy)!
    click here Tara Reid nude gallery sextape or just follow the link http://digg.com/celebrity/Tara_Reid_nude_pictures_naked_video_sextape
    You MUST SEE it, this chik really beautifull!!!

  • http://clifornia-primier-repairs.info/ca/ Hankibboneefe

    I watch this guy for year, yea he do a lot of crazy stuff, but I know he is a really good and nice person. My boyfriend got his all best fights and we probably going to pray today and watch his in ring – so sad love you Mike.

  • http://clifornia-primier-repairs.info/ca/ Hankibboneefe

    I watch this guy for year, yea he do a lot of crazy stuff, but I know he is a really good and nice person. My boyfriend got his all best fights and we probably going to pray today and watch his in ring – so sad love you Mike.

  • Leo

    some one minpulated my work e mail and made it sound we exchanged e mails , he even changed my work title in my e mail signature, my company chowed me copies of the e mails and thought I wrote them which I had no knowledge of. could he possibly using this software? any advice..

  • Leo

    some one minpulated my work e mail and made it sound we exchanged e mails , he even changed my work title in my e mail signature, my company chowed me copies of the e mails and thought I wrote them which I had no knowledge of. could he possibly using this software? any advice..

  • Saurabhchauhan73

    Sir someone send me Emails on my I.D. , the person who send me emails is my friend’s I.D. but when i discuss with my friend then she tell me that “I don’t send u Emails, i don’t know how it’s possible.” So, sir how can i find who is he/she who send me Emails.
    Sir please send me details by which I find who send me Emails on my I.D. “saurabhchauhan73@gmail.com”, it’s my I.D. sir please send it immediately.

Do like us!

Subscribe via Email

Enter your email address:

Email will be used only to send updates, we hate spam ourselves!

Switch to our mobile site