Live data from Hacker News

Don't verify email addresses by sending spam to them

milek7.pl

11–20 of 67 posts

Re: Don't verify email addresses by sending spam to them

#11
post #3
post #2

the actual base64 email itself is an HTML document, with a bunch of filler text about metal magnets! > Hi there, A magnetic domain is a region within a magnetic material in which the magnetization is in a uniform direction. This means that the individual magnetic moments of the atoms are aligned with one another and they point in the same direction [...] they sign off the email with a zero-width space set to "font-si…

Also, the magnet text is not visible: style="position: absolute; left: -9999px; top:-9999px;display: none" maybe they try to warm up those emails to use them for other "campaigns" later on...

The text is added to get around bayesian filters. The spammer doesn't want the text to be displayed to the end user though typically.

Re: Don't verify email addresses by sending spam to them

#12

I just did a signup on a brand new email address and was not able to recreate. No random spam emails reported. Just a normal verification email. It's likely that the email the author received is pure coincidence. Especially if they are using a client that downloads emails in batches. FWIW it looks like their validation email is sent by Customer.IO via Mailgun. Both have squeaky clean service agreements so it's unlike…

Maybe they don't do that for larger destination providers. But definitely no coincidences here. (in the post I replaced address with example.com because I'm curious if I will ever get other spam onto it, but here's another one unmodified)

  curl --request POST --data '{"email": "pangramdemo@milek7.pl"}' https://www.pangram.com/api/validate-email
https://milek7.pl/mailverifyspam/another.txt

Re: Don't verify email addresses by sending spam to them

#13

I just did a signup on a brand new email address and was not able to recreate. No random spam emails reported. Just a normal verification email. It's likely that the email the author received is pure coincidence. Especially if they are using a client that downloads emails in batches. FWIW it looks like their validation email is sent by Customer.IO via Mailgun. Both have squeaky clean service agreements so it's unlike…

I just tried with a new email at my domain. I'm excited to see what I get.

Re: Don't verify email addresses by sending spam to them

#14

I just did a signup on a brand new email address and was not able to recreate. No random spam emails reported. Just a normal verification email. It's likely that the email the author received is pure coincidence. Especially if they are using a client that downloads emails in batches. FWIW it looks like their validation email is sent by Customer.IO via Mailgun. Both have squeaky clean service agreements so it's unlike…

[deleted]

Re: Don't verify email addresses by sending spam to them

#15
post #3

Earlier quoted context omitted.

Also, the magnet text is not visible: style="position: absolute; left: -9999px; top:-9999px;display: none" maybe they try to warm up those emails to use them for other "campaigns" later on...

The text is added to get around bayesian filters. The spammer doesn't want the text to be displayed to the end user though typically.

A smart bayesian filter would catch email with invisible text. Legitimate email shouldn't have any, but I have seen it more than once in spam

Re: Don't verify email addresses by sending spam to them

#16

Can it be that Pangram doesn't send any spam itself but instead (intentionally or not) leaks your email address to some spammer who then does the sending?

Spamming, leaking, or selling. Either way, I now know that I want nothing to do with Pangram.

Re: Don't verify email addresses by sending spam to them

#17
I would make even stronger advice.

If you want to verify an email, send me a one-time code with several hours expiry that I have to resubmit through my logged in web identity at your site.

It drives me batty that a financial provider (retirement vendor from previous employer) won't seem to let my "paperless" setting remain active. Only because I don't ping their abusive email tracking pixels etc.

To me, paperless means I can log in and download my quarterly PDF statements and related documents, and they won't be left in a mailbox on the street. It doesn't mean I have to subject myself to reading your silly emails with a promiscuous client.

Re: Don't verify email addresses by sending spam to them

#18

I would make even stronger advice. If you want to verify an email, send me a one-time code with several hours expiry that I have to resubmit through my logged in web identity at your site. It drives me batty that a financial provider (retirement vendor from previous employer) won't seem to let my "paperless" setting remain active. Only because I don't ping their abusive email tracking pixels etc. To me, paperless mea…

I really wish you could provide a PGP public key to your bank and have them just email the damn pdf every month.

Re: Don't verify email addresses by sending spam to them

#19
Interesting business model.

Sell verification services to one set of clients, and use the harvested email addresses to sell spam delivery to another set of clients.

It's like having a space in a big building downtown with storefronts on two opposite streets. Babysitting/childcare services here; rent a child to go the park with and help you pick up chicks there.

The similar playing-both-sides against the middle that I'm struggling with right now: companies sell (physical) mail addresses to other companies for beaucoup bucks. But if you want to correctly report that your wife has been dead for 9 years because you're tired of getting her USPS spam, they want to charge you to add you to their profitable database.

Re: Don't verify email addresses by sending spam to them

#20

I would make even stronger advice. If you want to verify an email, send me a one-time code with several hours expiry that I have to resubmit through my logged in web identity at your site. It drives me batty that a financial provider (retirement vendor from previous employer) won't seem to let my "paperless" setting remain active. Only because I don't ping their abusive email tracking pixels etc. To me, paperless mea…

[deleted]
Post reply on HN