Slashdot Mirror


Proving You Are Not a Spammer?

tfinniga asks: "A spammer has recently started using my domain name as 'From:' addresses when sending out spam. I'm worried about my domain being blacklisted, and I'm annoyed by the bounces — I'm getting about 1000 bounce messages a day. Unfortunately, I give out a different email address to each site I visit: slashdot@example.com, paypal@example.com, amazon@example.com, etc., and the spammer is using a different address for each mail, so simple address filtering doesn't work. What is the best way of avoiding being put on a blacklist, and dealing with the flood of bounces?"

3 of 127 comments (clear)

  1. Use whitelisting by chatgris · · Score: 5, Interesting

    I run my email the exact same way that you do, and I have had the same problems. Fortunately, I've never been rejected as a spammer based on my domain name alone, and if you are hopefully someone else here can help you solve that problem.

    As far as stopping the bounces... The only way I've found that works is to use a whitelist system... filter all of the addresses that you know are good (paypal@example.com, etc) into folders, and everything else goes into a generic catchall folder that you give a quick scan to before moving it to a long term keep folder.

    Just a note... I highly recommend the keep folder over just trashing the message. When's it's morning and you are groggily mass deleting messages, sometimes good messages get axed accidentally... If you have your own domain, it's likely that you have POP so long term storage shouldn't be a problem.

    Josh

    --
    Open Your Mind. Open Your Source.
  2. Re:me too by Amiga+Lover · · Score: 5, Interesting

    This isn't entirely on topic, but it's related to my experience of having spammers use my domain in the From: field.

    Dealing with the hundreds or thousands of bounces was inconvenient, but I noticed one string of bounces was coming from a regular user who had a script set up to bounce about a hundred spammy messages of their own in response to each spam they detected.

    I mailed them telling them what a useless idea that was, and all I got back was the same bounce - a hundred messages all with the line "PISS OFF WITH YOUR SPAM AND TAKE IT ELSEWHERE", and my original message quoted.

    Figuring it was email from my domain (now blacklisted on their server/client somehow), I emailed from another email account, telling them the same thing, and got the same bounces. Third time I tried, I emailed them without describing my domain anywhere in the email, letting them know their spam bounces weren't going to real spammers, rather to the email addresses of those that the spammer had spoofed.

    The string of abuse I got back was essentially two pages of ranting, telling me a spammer couldn't fake a From: address, my domain must have been hacked, calling me an idiot who should be banned from the net. The usual teenager response.

    The simple fix? Sending email to their account with my domain listed in the body so it triggered their hundred-message spam bounce, but with the From: field set to the idiot's own email address.

    I only had to send one. My next message to them reminding them their From: address could indeed be faked bounced back with a mailbox full message from their ISP. Seems his spam-bounce script had seen my email to him with my domain listed in the body, sent back 100 rude messages all to the From: field address (which was himself), each of which also carried my domain in the text. those hundred emails to himself also each must have triggered his spam bounce script, making 10,000 emails to himself from himself... and so on.

    Gave me some amusement to make up for having spammers using my domain :)

  3. Next time, prefix them by Wordplay · · Score: 4, Interesting

    It's a little late now, but the real problem is how you picked your email aliases. Start them all with the same prefix. Like, if I'm wordplay@foozle.com (I'm not, btw, so don't mail me), I might use wp-paypal@foozle.com, wp-ebay@foozle.com, etc. Then I can filter anything that's not addressed to wordplay or wp-*.