Is it possible to forge email receipts?

The_Unbeliever

Honorary Master
Joined
Apr 19, 2005
Messages
103,193
Reaction score
10,233
Location
Nkaaaaandla
On some email systems you (the user) or the Administrator, can set things up so that whenever any email is opened, deleted or whatever, a return receipt is sent to the originator of said email.

Now, is it possible to forge this return receipt?

Can you prove that your network did NOT sent out such a receipt?

How can you prove that somebody did indeed sent out an receipt, although they will deny it?

Interesting questions... let's hear it from the guys! :D
 
i am sure it is possible although i have no idea how one would do it.

to the normal user it might come across as good forgery but i am sure to the advanced tech head kind they can investigate an prove it a forgery.

but yeah would be intersting to hear wot some of the tech dudes say
 
@ TIAL - no.

Merely preparing for such an eventuality. (Besides, trying to forge something might not always be successful, and you (the forger) will be left with even bigger problems...)

Let's say, suppose you've sent email to Horrible-big-mess-kom to let them know two months in advance that they have to stop their debit orders on your savings/credit card account. (Yes, this is a possibility and might just as well happen).

The recipient at the other side haven't opened the mail, but just deleted it. (For this type of event you also get a notofication). Or it was opened and never responded or attended to, and you have got the original email and the notification you received to show that it was opened.

Two months down the line the debit orders still goes off, and you open a case of fraud with the police. :D

Horriblekom's lawyers then counter, saying that their system did NOT sent that receipt, neither did their client ever received such mail. :rolleyes:

(FYI : there was a recent SA case where a customer was notified by email about his new insurance policy clause, but his company's spam filters blocked this email as spam, and he did received a notification but never bothered to retrieve said email. When he put in his claim, it was successfully disputed because he never adhered to his new insurance policy clauses. He went to court over this, and the court ruled in favor of the insurance company.)

So, yes, there will be a time and place when this might land up in court - and it won't be me.
 
Last edited:
@ TIAL - no.

Merely preparing for such an eventuality. (Besides, trying to forge something might not always be successful, and you (the forger) will be left with even bigger problems...)

Let's say, suppose you've sent email to Horrible-big-mess-kom to let them know two months in advance that they have to stop their debit orders on your savings/credit card account. (Yes, this is a possibility and might just as well happen).

The recipient at the other side haven't opened the mail, but just deleted it. (For this type of event you also get a notofication). Or it was opened and never responded or attended to, and you have got the original email and the notification you received to show that it was opened.

Two months down the line the debit orders still goes off, and you open a case of fraud with the police. :D

Horriblekom's lawyers then counter, saying that their system did NOT sent that receipt, neither did their client ever received such mail. :rolleyes:

(FYI : there was a recent SA case where a customer was notified by email about his new insurance policy clause, but his company's spam filters blocked this email as spam, and he did received a notification but never bothered to retrieve said email. When he put in his claim, it was successfully disputed because he never adhered to his new insurance policy clauses. He went to court over this, and the court ruled in favor of the insurance company.)

So, yes, there will be a time and place when this might land up in court - and it won't be me.

So it would be a backup of all your users e-mail... clever
 
Yes, you can forge return and sender receipt within an Exchange/POP3 environment.
 
paste the headers here. you can forge the senders email pretty easly. not to sure how easy it is to forge a recipients address.

If I send out an email, it IS going to have the originating SMTP server in the headers. From that I can figure out how legit the email is. If for instance it was sent through smtp.telkomsa.net, then I know that SMTP has logs of the email, and all the people it was sent to.

By getting those logs, I can tell which person sent it (because most smtp servers require authentication these days), and who that person sent that email to.

I can however, send you a very legit looking email from your email address of choice. Give me an email address, and I will send you one that looks like Bill Gates sent it. The easiest way to do this would be to simply change your email address, and return email address in any email client.
 
Last edited:
I can however, send you a very legit looking email from your email address of choice. Give me an email address, and I will send you one that looks like Bill Gates sent it. The easiest way to do this would be to simply change your email address, and return email address in any email client.

:D

Now I get very nasty thoughts in my little head... :D but won't mention them here... *snigger* :D
 
Top
Sign up to the MyBroadband newsletter
X