Live data from Hacker News

A little trick to spam the spammers (2021)

misc.l3m.in

151–160 of 231 posts

Re: A little trick to spam the spammers (2021)

#151

I run marketing email databases. This is cute, but it doesn't actually do anything in most systems - either the employees all already get the marketing emails or there is a system-wide rule to suppress against the email domain. If you actually want to (potentially) break something, try submitting some obscure characters or malformed html into some fields. Blank spaces in emails can particularly be a nuisance. And if…

The extended version where he sends signs up his list of other spammers for each other's newsletters should get around that problem.

If it's an public email address we actually care about, it's likely flooded with OOFs or noise anyway.

There's a product we use called SiftRock that automatically sorts through noisy inboxes and detects real human responses so we know which ones a service person actually needs to respond to.

Re: A little trick to spam the spammers (2021)

#152
Heh, you could also do the other usuals

all@domain.com allstaff@domain.com support@domain.com legal@domain.com careers@domain.com refunds@domain.com

If you really don't like them keep adding those addresses to other subscriptions.

If all goes well they'll end up on black lists really quickly.

Re: A little trick to spam the spammers (2021)

#154

I used to get spam from a Chinese exporter who conveniently included their actual address in the emails. One day I happened to be visiting their city and went to their office and asked them to unsubscribe me in person. The lady was very confused and first thought I wanted to buy something. I showed her the spam on my phone and she agreed but didn't bother actually removing me. Just seemed to think I was a bit stupid…

There's no better motivater than having an upset customer in your presence. I have camped outside the office of someone until a situation was resolved.

Agreed. Great motivator. Slightly different twist is if you have kids - rambunctious kids are even better. We had an issue with a home renovation project that was not completed (we had stupidly paid the final invoice on time, lesson learned- always hold back 10% until you’re 100% satisfied)

My wife got pissed at their lack of response. She took our two boys to their office, sat down, and instructed them to feel free to touch and play with everything (tile, wood samples, etc.) Salesperson notices and approaches “can I help you?” She explained the situation and the salesperson said no problem we will send someone next week.

Unsatisfied with this answer- we had already experienced many weeks of “soon” - she said ok no problem, we will just sit here until someone shows up at our house to finish the job.

Sure enough a worker showed up later that day and installed the three punch list items we had identified. Worked like a charm!

Re: A little trick to spam the spammers (2021)

#155
post #17

I wonder if most sites maintain any of the following addresses or not for externally incoming mail: hostmaster@ postmaster@ webmaster@ dns-admin@ info@ contact@ root@ (And if they do, if anyone is actually reading the mail coming to those addresses.) I used to but I got so much spam and 0 actually legit mails to these addresses on my own domains so I stopped accepting externally incoming mails for those names/aliases…

Every email to legal@ has to be read by any legitimate site, thanks to GDPR/CCPA. Not that you'll get a response.

How can this possibly be enforced? What if there’s no email service on that domain? What if the business has no email address at all?

Re: A little trick to spam the spammers (2021)

#156

https://news.ycombinator.com/item?id=12951917 DonHopkins on Nov 14, 2016 | parent | context | favorite | on: The NHS's 1.2M employees are trapped in a 'reply-a... Back in the days of ARPANET mailing lists, there used to be an "educational" mailing list called "please-remove-me", that was for people who asked an entire mailing list to remove them, instead of removing themselves, or sending email to the administrative…

In more modern times, within the last couple months, there was the Epic/Unreal Engine Github Email Storm[0][1] at minium 60m emails, because a few hundred thousand people were getting over a hundred emails within a minute or so thanks to a user trying to get a minor patch pulled in so they could get some credit/resume line/who knows. They "@"tted the whole membership of the organization. There was a few repeats of th…

The person who @'d the Epic org owns very little of the blame, in my opinion. If you have a button that causes 60m+ emails to be sent, and you leave it in a public place with no warnings and no confirmation dialogs, that's your bad choice. The person who presses the button is incidental; someone was going to.

Re: A little trick to spam the spammers (2021)

#157

I wonder if most sites maintain any of the following addresses or not for externally incoming mail: hostmaster@ postmaster@ webmaster@ dns-admin@ info@ contact@ root@ (And if they do, if anyone is actually reading the mail coming to those addresses.) I used to but I got so much spam and 0 actually legit mails to these addresses on my own domains so I stopped accepting externally incoming mails for those names/aliases…

I will often provide the email address postmaster@hashbang.com for people insisting they need an email address who have no legitimate reason doing so. (hashbang.com resolves to localhost. Thanks twocows...)

Anyone know why I would get some "random" addresses if I run `nslookup hashbang.com`, but if I run `nslookup hashbang.com.` I get localhost?

Re: A little trick to spam the spammers (2021)

#158

I run marketing email databases. This is cute, but it doesn't actually do anything in most systems - either the employees all already get the marketing emails or there is a system-wide rule to suppress against the email domain. If you actually want to (potentially) break something, try submitting some obscure characters or malformed html into some fields. Blank spaces in emails can particularly be a nuisance. And if…

I think Log4shell was about the closest we got to this. It’s still crazy to me you could exploit an unknown machine by leaving a string of text somewhere and waiting for a vulnerable client to process it. I imagine many spammers are running a lot of insecure PHP and Perl scripts to support their operation. That was certainly the case back in ~2006, and I imagine most “new entrant” spammers are not using email but rat…

So, for the email industry (both marketers and client developers) "Spam" is used to specify emails that are not compliant with the CAN-SPAM act - they don't have a way to unsubscribe or report abuse.

ITT people are using Spam to cover all sorts of junk email, but in my mind there is a difference between companies engaging in annoying methods to get your consent and organizations engaging in bad faith breaches of CAN-SPAM.

Re: A little trick to spam the spammers (2021)

#160

Earlier quoted context omitted.

I think Log4shell was about the closest we got to this. It’s still crazy to me you could exploit an unknown machine by leaving a string of text somewhere and waiting for a vulnerable client to process it. I imagine many spammers are running a lot of insecure PHP and Perl scripts to support their operation. That was certainly the case back in ~2006, and I imagine most “new entrant” spammers are not using email but rat…

So, for the email industry (both marketers and client developers) "Spam" is used to specify emails that are not compliant with the CAN-SPAM act - they don't have a way to unsubscribe or report abuse. ITT people are using Spam to cover all sorts of junk email, but in my mind there is a difference between companies engaging in annoying methods to get your consent and organizations engaging in bad faith breaches of CAN-…

I’m not sure if your comment is meant to defend the practices of the companies I’m referring to - maybe you work at one of these spam houses, I won’t judge - but frankly, I don’t care what the definition of CAN-SPAM is. Clearly everyone thinks they CAN-SPAM me and I’ve never heard of anyone actually being fined under any anti-spam law except at the highest, most absurdly industrial volumes of spam.

If my email is public because it’s in a Git commit or a Gravatar or even an intentionally public “email” field in my profile, that is not consent to send me unsolicited, automated messages followed by a multi-day campaign of emails guilt-tripping me for not responding to the first one. Maybe they have an unsubscribe link at the bottom. I don’t know, because I don’t open unsolicited emails that may contain malicious zero-days targeting my device. But if they do include the unsubscribe link, it doesn’t make me think any better of them and it doesn’t absolve them of any moral wrong-doing.

If you’re a founder or employee of a company that revolves around sending automated emails to non-customers, just be aware that your target market is a group of self-anointed “hustlers” who send unsolicited email messages to people who slowly grow to rightfully despise them. If your “marketing database” is a scraped list of emails, you should delete it and shut down the company. In the future, consider using your skills to work on problems that have a positive impact on the world.

Post reply on HN