www.hay-scams.com
(  Use your "back" button or return to Submit )

How to find the message "headers" of a Hay Scam message when using Thunderbird mail program

The simplest way is,  with the message on screen, go to "View" slide down to "Headers" then over to the right and click on "All"

Thunderbird-headers4.jpg (19225 bytes)

Then simply click on "Forward" and the entire message with headers included will open in a new message ready to address and send:

Thunderbird-headers5.jpg (21108 bytes)

If you don't click on 'Headers> All' before forwarding, the message will only include the brief headers.

The second more complicated way is as follows:

With the message opened, click on "View" then down to and click "Message Source"
(see the picture below)

Thunderbird-headers.jpg (20882 bytes)

A new window will open up.
Then click on "Edit" and then click on "Select All" at which point the headers and message will turn blue.

Thunderbird-headers2.jpg (27453 bytes)

Then click on "Edit" and slide down and click on "Copy"

Thunderbird-headers3.jpg (18073 bytes)

You will now have all the information ready to 'paste' into an e-mail

It will look similar to this when you paste it into your e-mail:

pinkfade.gif (2115 bytes)

From - Thu Mar 06 18:57:01 2008
X-Account-Key: account3
X-UIDL: GmailId11886f3c32f35b41
X-Mozilla-Status: 0001
X-Mozilla-Status2: 10000000
Delivered-To: XXXXX@gmail.com
Received: by 10.142.157.10 with SMTP id f10cs490297wfe;
Thu, 6 Mar 2008 17:56:07 -0800 (PST)
Received: by 10.86.60.15 with SMTP id i15mr658229fga.36.1204854965396;
Thu, 06 Mar 2008 17:56:05 -0800 (PST)
Return-Path: < XXXXX@gmail.com>
Received: from py-out-1112.google.com (py-out-1112.google.com [64.233.166.183])
by mx.google.com with ESMTP id f19si5686020fka.18.2008.03.06.17.56.03;
Thu, 06 Mar 2008 17:56:05 -0800 (PST)
Received-SPF: pass (google.com: domain of  XXXXX@gmail.com designates 64.233.166.183 as permitted sender) client-ip=64.233.166.183;
Authentication-Results: mx.google.com; spf=pass (google.com: domain of  XXXXX@gmail.com designates 64.233.166.183 as permitted sender) smtp.mail= XXXXX@gmail.com; dkim=pass (test mode) header.i=@gmail.com
Received: by py-out-1112.google.com with SMTP id u52so255028pyb.1
for < XXXXX@gmail.com>; Thu, 06 Mar 2008 17:56:03 -0800 (PST)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=gmail.com; s=gamma;
h=domainkey-signature:received:received:message-id:from:to:subject:date:mime-version:content-type:x-priority:x-msmail-
priority:x-mailer:x-mimeole;
bh=parm+N++fCIxh1YCHnftEZu74cqRlOC37S+BOYG/wcM=;
b=wjW5TXgrLkNL3ca2YuD6JD5ThuB5N+AY3AMIBqM5H7IpekHia8CAJ3kbcIOkrcw+5k8AcmahaXE1N6vhOHB
2bBEr4HYTYZ/GHTkU3f2piVQR8PosgnvZahmltRlt0KxPlJhjF9sZFMk/lkmx+bjsbDJKvcvA3ZiAiaYwhLSq/go=
DomainKey-Signature: a=rsa-sha1; c=nofws;
d=gmail.com; s=gamma;
h=message-id:from:to:subject:date:mime-version:content-type:x-priority:x-msmail-priority:x-mailer:x-mimeole;
b=a64ZbNE387d0E2XPPi3iMIO0Hb267lCNX2hycpNnxmidME2XfBJDRzheGCG0WqBPO5CtEh8cuBNW3VLN0iU
cZiw4LCXlnN17VUVlZ+wX1ULi55q4MF6y6oQ+C1RQ0Eu3XjsyzZyeJHZn96MLL5VAHKJDhFLxEHG8Qa7Z0Sni
2go=
Received: by 10.35.27.1 with SMTP id e1mr946563pyj.57.1204854963159;
Thu, 06 Mar 2008 17:56:03 -0800 (PST)
Return-Path: < XXXXX@gmail.com>
Received: from 093487U512H45F ( [12.10.254.1])
by mx.google.com with ESMTPS id w67sm10239646pyg.20.2008.03.06.17.55.51
(version=SSLv3 cipher=RC4-MD5);
Thu, 06 Mar 2008 17:55:52 -0800 (PST)
Message-ID: <000d01c87ff6$576eca20$6e01a8c0@093487U512H45F>
From: " XXXXX" < XXXXX@gmail.com>
To: < XXXXX@gmail.com>
Subject:
Date: Thu, 6 Mar 2008 14:19:49 -0700

 

pinkfade.gif (2115 bytes)

Home page Submit a hay-scam e-mail
Recent and Current hay scam message and List of scammer's e-mail addresses
"Common Traits" and "Red flags" Typical contact  'messages'
Images of Counterfeit funds (dial-up) Images of Counterfeit funds (high speed)
Fight back! +44..... phone numbers

 

 

 

www.hay-scams.com

page hit counter