PDA

View Full Version : Suspicious Email Forwarding - Readnotify.com service.



JRMcIntee
2013-12-18, 00:24
Good afternoon - newbie here, so please bear with.

I've been utilizing Readnotify.com for a number of years, and lately emails that I've sent are being forwarded as follows:

Forwarded/opened on different computer
Opened 15-Dec-13 at 17:22:15pm (UTC -7:00) - 1day2hours26mins1sec after sending
Location Mountain View, California, United States (86% likelihood)
Opened on google-proxy-66-249-84-107.google.com (66.249.84.107:43866)
Browser used by recipient: Moz/5.0 (Win; U; Windows NT 5.1; de; rv:1.9.0.7) Gecko/2009021910 Firefox/3.0.7 (via ggpht.com)

Neither myself nor the people that I send emails to have any contacts in Mountain View, California. Most are emails just around the city of Calgary, Alberta, Canada - I do understand that servers are not always physically located from the point of origin - but if the Readnotify service is correct, my emails are being forwarded and opened at that location.

I'm a fully paid subscriber of Spybot and have run everything you have - nothing jumps out. The deepscan function for rootkits didn't come up with anything out of the ordinary. Any thoughts as to what's going on would be appreciated, as it's a bit concerning that someone's apparently reading my/our emails without permission. Not dealing in state secrets or anything, so I have to wonder what's going on.

Thanks,
J. R. McIntee.

tashi
2013-12-18, 01:19
Hello JRMcIntee,

Have you contacted Readnotify (http://www.readnotify.com/) and posed your inquiry there?

You can trace route here: http://whois.domaintools.com/readnotify.com

Edit
Google (http://whois.domaintools.com/google.com) is located in Mountain View, perhaps people are using gmail?



Forwarded/opened on different computer
Opened 15-Dec-13 at 17:22:15pm (UTC -7:00) - 1day2hours26mins1sec after sending
Location Mountain View, California, United States (86% likelihood)
Opened on google-proxy-66-249-84-107.google.com (66.249.84.107:43866)

Neither myself nor the people that I send emails to have any contacts in Mountain View, California.


Best regards. :)

aposford
2014-05-29, 05:34
:o ok, speaking of hasard; exact same thing happened to me with readnotify.

heres the answer i found.





Since December 3, 2013 the Gmail web client started doing something behind the scenes that got a lot of people screaming that the sky is falling!

(...)

What’s the big change?

Gmail implemented some changes which impacts the way images are loaded within the web-based email client. What they have done is applied a proxy that wraps the image URL and downloads the image from a Mountain View, California Mountain View, CAserver that caches the image, so that it never downloads it again. This does a few things for the end user of Gmail (Gmail Official Blog Announcement):

Senders can’t use image loading to get information like your IP address or location.
Senders can’t set or read cookies in your browser.
Gmail checks your images for known viruses or malware.


http://www.emaildirect.com/blog/2013/12/gmail-now-shows-images-by-defaultbut-theres-a-catch/



oh, and yeah. the sky IS falling.