Slashdot Mirror


Do Unsubscribe Links Stop Spam?

Kaiten writes "Brian McWilliams of Spam Kings fame has just published a fascinating spammer exposé over at Salon. Using a pseudonym, he was hired to send junk email on behalf of a spam operation that has been burying people (me included) with spam for fake Rolex watches. The article details how the spammers handle the 200,000-plus unsubscribe requests they get each month. Seems that LOTS of geeks actually cross their fingers and click those remove links. And, surprise, surprise, the spammers usually ignore the unsubscribe requests."

4 of 521 comments (clear)

  1. just DO IT! (was: Re:That's easy...) by beh · · Score: 4, Interesting


    I'm actually (at the cost of some traffic) using this to help me fight spam...

    It's not just that spammers are ignoring these requests, they will actually just merge their lists with the responses (on the off chance that you might try to also unsubscribe some of your other email addresses / or a friend's email address).

    In fact, if you enter just a random address in there, you can be pretty sure that this address will get spammed in the future, too.

    If you use bayesian filter software, like bogofilter or spamprobe, you can turn this into an advantage. I've actually "unregistered" some previously non-existent email address on my internet domain that I'm not going use anywhere else. Now I know that any email coming in for that address is definitely spam - and can hence use it to automatically improve bogofilter/spamprobe by passing that email from procmail into them with the spam "learn" flags set.

    1. Re:just DO IT! (was: Re:That's easy...) by Ozwald · · Score: 5, Interesting

      I'm wondering, you can kill a goldfish by giving it too much food. It just keeps eating and eating until it runs out of food or dies.

      Running Spammers out of money just isn't happening, not sure why. But what if we did the opposite? We run the "unsubscribe" link with a script that creates millions of invalid email addresses (on an non existant domain please, not mine). Their system will automatically add it to their database. If enough people do this, what if anything will break? I'm thinking that the signal to noise ratio on their distribution CD's will give them a nightmare of a maintenance issue or make it take to long to transmit overwhelming their SMTP service, but I dunno.

      Oz

  2. Company ID by Tablizer · · Score: 5, Interesting

    One thing really missing is a national or perhaps even a global unique "company ID". Law makers are so eager to tag and trace individuals, but ignore company tracking. It is time for a national company-ID number.

    Any company that wants to do business in the US would be required to have such a number and include it in any email they send across our borders, perhaps as a new email header attribute. Ideally it would be globally enforced and the US could pressure problem countries such as China to crack down on businesses that abuse email and/or the company number.

    There are too many fly-by-night companies running around.

  3. Re:That's easy... by Alphi1 · · Score: 4, Interesting
    I'm not so sure. As an experiment early this year, march I guess, I went through my entire junk mail folder in an attempt to get as much spam as I could. What the hell, hey, I'm getting several hundred messages a day and more can't hurt, and even if it trebled it'll help train my spam filter, right? I entered my email address in all the unsubscribe links I could find. I forgot about it for a while, and it wasn't until 2 months later I noticed an EXTREME drop in the number of spam emails. My last entire week of spam totals 51 emails. Curiously, not one of them contains an unsubscribe link. It's not down to "stopping spam" but it's a couple of orders of magnitude less. I never kept detailed stats on exactly when the drop off occurred, so I can't for sure say the unsubscribe links stopped it, but they certainly didn't add to it. This story has inspired me to test entering a brand new unguessable email address into unsubscribe forms online, to see what happens coming from the other direction. That's going to take effort to dig up email archives though. I just don't have any spam available WITH unsubscribe links any more.

    I did something similar a little while ago... I've had my home e-mail address for many years (going back to when I was more naive than now, with my e-mail posted on web pages, newsgroups, and the like).

    Because of all of that, I used to get a bunch of spam e-mails (I don't remember off the top of my head, but I thought it was around 90-120 a day.


    I was very close to just closing the account and opening a new one (to get a fresh start), when I decided to try something.


    I figured I'd try clicking all the unsubscribe links I could, all the while tracking (weekly) how many spam e-mails I was getting.


    To make a good experiment, I kept statistics for a few weeks before I even started, and got my averages then.


    Then I clicked the "unsubscribe" links every time I could find one in the spams coming to me.


    I did that for about a month.


    After that month, I *DID* notice a significant drop in spams (down about 50% on average), which was a pleasant surprise.


    The bad thing, is that it was only temporary. After a few months passed, I was right back up to the original level.


    So long story short - it seemed to help in the short-term, but long-term it didn't help. On the other hand, long-term didn't exactly hurt either (I'm still not getting MORE spam e-mails on that account than before I started my experiment).