For instance, Yahoo Mail puts my IP address in a line like this
Received: from [xxx.xxx.xxx.xxx]
For instance, Yahoo Mail puts my IP address in a line like this
Received: from [xxx.xxx.xxx.xxx]
Facebook is a closed system. When you send a message to someone on Facebook, you presume that you are adding that message within Facebook. The notification email that Facebook sends to the recipient is just that, a notification generated by the Facebook system. You, the sender of the message is not part of this notification system, though you your action triggered the notification. There is no reason why the sender's IP should be exposed in this flow under normal circumstances.
Edit: it doesn't show up base64 encoded, either.
Example:
Received: from [x.x.x.x] by web113916.mail.gq1.yahoo.com via HTTP; Fri, 07 May 2010 18:59:00 PDT
In this test case, x.x.x.x is my current IP address, not Yahoo!'s. The HTTP indicates that I used a browser, not POP/IMAP.
They've been doing that for years. It's handy as heck when you need to track an e-mail - you don't have to bother Yahoo with a subpoena - you can go right to the client's ISP.
There is no reason Facebook shouldn't do the same thing.
Edit: Comcast does:
X-Originating-IP: [x.x.x.x]
Google is weird:
Received: by 10.216.27.139 with HTTP; Fri, 7 May 2010 19:34:21 -0700 (PDT)
I'm not on a 10.x address. Hmmm....
They only said they may hide it.