It is sometimes possible to backtrack this activity using the full headers
associated with the SMTP traffic. That will at least get you to the
machine or port that originated the message. With server addressing that's
pretty much useless unless you're keeping some pretty detailed logs, but
with static addressing it can be valuable information. If you have static
addresses and sign-in logs, you may be able to catch your spoofer.
On the other hand, there's always the old looking over the shoulder
method... *heh*.
-- Bruce Carter, Instructional Software Designer (208)385-1851@voice Boise State University, Boise, ID 83725 (208)385-1856@fax http://mentor.idbsu.edu/BruceCarter/home.html bcarter@mentor.idbsu.edu