{"success":true,"data":{"id":"private-ip-origin","label":"X-Originating-IP / X-Sender-IP is a private address — local-machine injection (compromised host / spam relay)","description":"The `X-Originating-IP` or `X-Sender-IP` header — which records the client IP that submitted the message to its first mail server — contains a PRIVATE IP address from one of the RFC 1918 / loopback / link-local ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, 127.0.0.0/8, IPv6 fc00::/7, fe80::/10, ::1). Legitimate internet mail ALWAYS comes from a public IP — a home broadband, corporate NAT egress, cloud function, or marketing platform server. A private IP in these headers almost universally means either (1) a compromised web app running on the same host as the receiving MTA (the exact shape of a hacked-WordPress spam relay), or (2) a misconfigured internal tool leaking into outbound traffic. Weighted at +3 — strong but not solo-decisive, because a tiny long-tail of corporate mail flows through split-horizon NAT could theoretically expose a private IP in this header.","tier":"danger","category":"other","isThin":false}}