Last updated: July 3, 2022
We have already seen in previous articles the basic methods used by a pentester, and we have seen that the first step used is the collection of information on the target (IP address, operating system, browser version, etc.
These are deployed to detect the faults of a machine on a network in order to better secure the latter.
In this post, we will see together how get a person's IP address when opening the email and other information with a technique called Email Tracking. It's a quick and easy technique.
It consists of using web services that allow you once the sent mail is read, to resend an email to the sender with several information such as:
- The recipient's IP
- Internet browser
- The access provider
- The opening hour of the email
These services can be used within the framework of a company wanting to know if the recipients read the emails sent and if so, for how long. By the way, that's the main purpose of these services, but not for pentesters.
Indeed, there are several services that allow this type of operation such as SpyPig, didtheyreadit and ReadNotify.
Here we will do a demonstration with didtheyreadit.com.
I won't go into too much detail, but after signing up to didtheyreadit.com, just send an email from your email account just adding “didtheyreadit.com” to the end of the recipient's address.
For example, to track an email sent to "target@gmail.com", send it to "target@gmail.com.didtheyreadit.com".
Of course the recipient will not see his email address as such.
Once the email is sent, it will go through the didtheyreadit.com mail server which will add a certain number of codes to your email which will be activated each time the recipient opens the email.
Once the recipient reads your message, a full report will be sent to your email address. You will then obtain information such as the location of the PC, the browser used, theperson's IP address and many others.
Make good use of it!
I have a question
if the person uses proxies or a VPN does it work?
I think not
thank you for the answer
If the person is using a VPN, you'll get the VPN's IP address as the result.
Hello and thank you for your answer, already I really appreciate all the tutorials here!
I tested for me and unfortunately, it gives me an IP address in Holland and not in Belgium where I am
So not not great, I see that your example for you is very clear, maybe there is a trick
Hello katy,
Thank you, it's good to know that you enjoy our articles! Unfortunately, major webmailers like Outlook and Yahoo now load online images through a proxy in an effort to protect their users from malicious content, including trackers. As such, there is no way to know the recipient's IP address when opening the email from these mailboxes.
Thank you very much, that's what I thought I understood by looking a little, too bad, it is sometimes very necessary in certain cases to overcome the barriers. So much good day
One more question on this topic if I may...
Have you tested my email address, because here is what I received.
I'm posting a screenshot so you can see for yourself.
Hi
Me neither, it's not very conclusive.
I followed the procedure correctly and I have the impression that it gives me information from Google
The person is in Italy and that gives me a location here in California.
Well not easy obviously
Hello, I am looking for how to identify the owner of a Gmail address.
hello, I just used the indicated process with two addresses belonging to me.
I test is not very conclusive knowing that I sent myself an email, you will have understood it and that the location locates the sender in Marseilles while I am in Vernon in the 27 ??????
??
Thank you for your answers
dinan
Can you avoid using the term "hacker" when in fact you are referring to a hacker?
In French, a hacker is a resourceful person, a bizouneux, a patenteux, while a pirate is clearly a criminal. Far be it from me that a hacker can become a dangerous hacker, but few hackers are hackers.
I know, moreover, that the mixing of the terms "hacker" and "pirate" began with a letter from William Henry Gates III, published on February 3, 1976, when he was running a startup called Micro-Soft which developed MSDOS 1.0 in 1980 from QDOS, a pirated copy of Digital Research's CP/M purchased for $50,000 from a hacker working for Seattle Computer.
Hello Yves,
According to wikipedia, a computer security hacker is a specialist in mastering computer security and therefore in the means of thwarting this security. Some of them use this know-how within a legal framework (White hat) and others use it outside the law. In the latter case, we speak of hackers or (black hat).
You should know that hackers are classified into several categories according to their objectives and their skills. (black hat, gray hat, white hat and script kiddies).
For more information, I invite you to read this article: http://fr.wikipedia.org/wiki/Hacker_(s%C3%A9curit%C3%A9_informatique)
Are you sure its working? I tried and it told me that the person was in the United States and gave me an ip address from there. I wanted to see if the person I was going to deal with for the future purchase of a phone was indeed where they said they were...
The site has a very easy method to know the recipient's IP address, it has created a Php script in the form of a very small white image, and as soon as you display this image, automatically it will send all the information such as IP , operating system, etc.
If you are curious, you can do a search for images coding in Php 🙂
answer for angel, if your email is gmail boom nothing will be displayed because the gmail client will send the ip of the gmail server (in US) not of the one who sent the email
Hello,
First of all thank you for the clear and precise articles! My question is: does the "Opened on" in your print screen correspond to the IP address of my recipient. I tried the method but the ip in the "Opened on" did not match. to my addressee when I locate it. thank you in advance
Exactly "Opened on" displays your recipient's IP address. I tested it myself and it works great.
You are so good Ahmed, I support you seriously for everything
Thank you very much Adam! 🙂