Question about tracing emails

(For a work of fiction)

How exactly would authorities (police, government) trace emails? How fast could they do it? Is there a way to make emails untraceable? is there a way for regular folks to make them harder to trace with minimal (read no) geekologistic equipment?

Who are you planning on “offing?” Anyone I know?

Without going into specifics, I’ve always kind of had my eye on Daleforce One.

Jeez, FJohn. All you had to do was ask. But, I’m telling you, the jet fuel is killing me.

FJohn,

select any email
View/Source
the routing is in the header

milliseconds

yes

There are various ways to “Spoof” an email - to make it appear that it came from somewhere else.

Try a Googlesearch on “Spoof Email” and you should get a few forums that will give you more details.

Incidentally if someone was going to go to the bother of making it hard to figure out where an email came from then chances are they would go to the bother of encrypting the email as well.

With regards to spoofing email addresses you can easily download tools from hacker sites like astalavista that will let you send an email from any address you want. We used to do it to wind people up in college :smiley:

The other way to do it would be to use an anonymous proxy to surf the net (these are commonly available and usually used for illegal file sharing) and create a webmail account on gmail or hotmail. As long as the proxy is always used to access the account then it would be very hard to trace who created the account.

But once they had the routing they still have to trace it to an actual person.

Assuming the IP address/email isn’t obviously linked to an individual then they would use standard

http://www.visualware.com/resources/tutorials/email.html
http://www.usus.org/elements/tracing.htm

Once you have the IP address of the email server/person who sent it you will have to trace that as well

http://www.wikihow.com/Trace-an-IP-Address

It’s easy to do a lookup and a traceroute on an IP address to find out who it’s registered to, the authorities will then get a court order to find out who was using that address at the time the email was sent.

I suggest drinking something a bit less potent.

There are also a number of sites that allow you to generate a temporary email address. The idea is to by-pass security on sites that send out a password by email. At the end of the day, the address disappears. I expect you could send an email from one of these temporary sources.

Agreed, it’s script kiddie stuff. Very, very easy to spoof senders. I could
make it look like an email came from you. Wouldn’t hold up as evidence in
any court.
Not just that, but I could go to a public library or internet cafe, create a new
Yahoo account with false info, and send an email, and there’s no way in the
world you could figure out who sent it. There’s just no real trail.

not many fiction writers that don’t ignore the last few yards of it though :laughing:

I’m a nice quiet applications programmer that wouldn’t actually know anything about any of this.

Thank you,

Okay, great, thank you. Now, what about the ability to intercept emails from one party to another. If one person sent an email to another person and neither one turned theirs in to the police, could they still somehow find them? For example, could the government find and read emails between terrorist cells if they had no idea who the senders and receivers are?

Yup, and they do.

http://en.wikipedia.org/wiki/ECHELON

Encryption would obviously make this more difficult.

Maybe more specifically to email:

http://en.wikipedia.org/wiki/Carnivore_(software)