procmail
[Top] [All Lists]

Re: How does mail not addressed to me get to me?

2004-12-14 08:07:13
On Tue, 14 Dec 2004 07:07:05 -0700 Justin Gombos wrote:

* Eric Wood <eric(_at_)interplas(_dot_)com> [2004-12-14 08:59]:

An spam email addressed to Bonnie but comes in my box.  But my
address nowhere in the email header.  Sometimes I see my address
after the "for" in the Received block which explains how the email
gets to me.  But certain emails make it to me without the "for".  Is
this a fluke with sendmail-8.12.10 not inserting the "for" clause in
some conditions?

Believe it or not, the TO field is purely for your information, and
can contain anything, or nothing at all.  Message routing is dependant
on the 'envelope header', which is transparent to you as a recipient.
What you see in the end is the 'body header'.
Ultimately the message gets routed based on the SMTP command "RCPT
TO".  


And to complete that statement.
RCPT TO is built based on information retrieved from "To", "Cc", "Bcc", and
possibly local MTA only headers (though I've never actually seen that, only
read about it years ago).

"To" and "Cc" are normally left intact by the MTA as body headers so you
can see them. "Bcc" is stripped at the MTA level after generating "RCPT TO"
so you can't see all of the addresses that the message was delivered to,
including your own.

Spammers use "Bcc" a lot. I've taught my friends and family who like to
send info/jokes/whatever to several people with a single message to address
it to themselves and use "Bcc" for the other addresses they are sending to.
They get a copy to make sure it went out (as most use their ISP's remote
MTA) and everyone else who gets a copy doesn't get a list of 20 addresses
showing in the "To" header for viruses/spam proxies to feed from if they
ever get infected.

The messages you get that don't show you in the basic headers were most
likely sent to you as a "Bcc". If your MTA/MUA doesn't leave the "Rcpt To"
intact at final delivery you can't even find your address in the raw view
of the message.

Gerald


____________________________________________________________
procmail mailing list   Procmail homepage: http://www.procmail.org/
procmail(_at_)lists(_dot_)RWTH-Aachen(_dot_)DE
http://MailMan.RWTH-Aachen.DE/mailman/listinfo/procmail

<Prev in Thread] Current Thread [Next in Thread>