Friday, 15 May 2009

FAQ: Suffering Backscatter

Dear Richi, I have about 20-30 returned emails from some entity/person who is somehow using my domain to send out bulk email. How is that even possible?

Sadly, it's trivial for a spammer to forge your address. It's not your Web host's fault.

Some badly configured email servers auto-reply to spam. That's what you're seeing.

If you want to complain to anyone, complain to the people running the servers who are auto-replying to you. Here's a template complaint I've used before...
Hello. You are sending spam to me by bouncing spam to an unrelated person. I did not send the spam to your server: spammers forge the message sender. Hence, your reply goes to an innocent third party.

Perhaps you sent an unsolicited bounce because your mail server is incorrectly configured. Please don't do that. You should *reject* during the SMTP conversation, not *bounce* after accepting the spam message. It is not necessary for your MTA to send a non-delivery DSN -- you should reject at the point of SMTP RCPT with a 553 error or equivalent.

Or perhaps you're auto-replying to spam. Presumably you filter spam before delivering inbound email. In which case, this reply shows that spam is getting through those filters.

It's bad practice to accept a message for a non-existent user. If you accept and then bounce, you're sending spam. For more information, please see http://www.spamcop.net/fom-serve/cache/329.html

If this was an isolated error, there's no need to be concerned that you will be blacklisted as a spam source. It usually takes several complaints to illustrate a pattern of email abuse.

However, I urge you to correctly configure your mail servers.
More info at an old post of mine: I Got 25,000 Spam Messages in Two Days!

Saturday, 2 May 2009

CNN: carbon footprint of spam

Finally, I have the CNN footage.

Amusingly, they mixed up the captions, so Woody got my title...


No video? Click here for the carbon footprint of spam video.

Wednesday, 29 April 2009

A "Monster" Spammer (NYSE:MWW)

Update May 1 3.30 UTC: several listwashing requests.

Dear Monster.com (NYSE:MWW),

You are spamming me. Stop it. Please.

You're sending marketing email to an address that has never given informed consent to receive it.

Not only that, but you're even breaking the spirit, if not the letter, of the U.S. CAN-SPAM Act. While your unwelcome missive does include the proscribed physical address and unsubscribe link, they are displayed in white text on a white background.

Yes, really. (I dare say they'd be more visible if my email client displayed HTML images by default, but like many clients, it doesn't.)

Naturally, it's also in violation of the law in which your UK subsidiary operates. There was no "prior consent" given, within the meaning of the Privacy and Electronic Communications (EC Directive) Regulations 2003. Offenders are liable to a fine of up to £5,000 in a magistrate's court, or an unlimited fine if the trial is before a jury.

Update May 1 3.30 UTC:
I've received a couple of email messages and a Twitter DM from Monster, expressing apologies for the situation. Sadly, these expressions of regret don't extend to actually fixing the spam problem; they appear to be an attempt to listwash.

Sorry, Monster; listwashing is bad practice. My standard operating procedure is to never unsubscribe from a list that I did not subscribe to.

If Monster wishes to solve this problem, it would stop sending email to addresses of people who did not subscribe. I'm open to a public dialogue on this subject: feel free to tweet or comment here, rather than privately emailing or DM'ing.

Today's Tweets

  • 07:32 The swines! Flu panic blamed on Twitter and blogs ping.fm/D7j7T #itblogwatch #swineflu Voices of reason drowned by twits #
  • 08:00 @djtechnocrat Yes, but it was always thus. Twitter makes the whole thing grow faster, whipping ignorance into a huge frenzy. #swineflu #
  • 08:56 I'll be at Infosec on Thursday afternoon only. Currently available for briefings 1.45pm-4pm. #
  • 11:48 @hprice Loudmouth workers leaking data through social networking sites tinyurl.com/d4p7uc #
  • 11:50 Planning to keynote at Inbox/Outbox in mid-June. inbox-outbox.com #
  • 12:11 @hprice LOL #
Thanks: LoudTwitter

Tuesday, 28 April 2009

Today's Tweets

Thanks: LoudTwitter