5 ms·
How do you prevent someone from spamming you with random usernames? For example: random1@lastname.com random2@lastname.com random3@lastname.com Do you have
by takoid 4y ago
How do you prevent someone from spamming you with random usernames? For example:
random1@lastname.com
random2@lastname.com
random3@lastname.com
Do you have a whitelist as well?
- sigstoat 4y agoin my experience that sort of "send some spam to addresses we have no reason to believe exist" behavior takes the form of sending stuff to $commonfirstname@domain not $service@domain nobody is sending email to alsdkjfadf@domain
- takoid 4y agoYou are right. But I think using a catch all with a separate username for each service/business is becoming an increasingly common practice so I would imagine it’s only a matter of time before spammers catch on and begin exploiting this.
- ylk 4y ago> nobody is sending email to alsdkjfadf@domain That’s actually the kind of spam I used to receive on a very short domain with a catch-all. I guess they loop through short domain names and then try to brute-force the local part.
- mynameisvlad 4y agoInterestingly, I have <3letters>.one but I think because it's an uncommon TLD and a seemingly random 3 letters, I haven't had that issue.
- leipert 4y agoSimply doesn't happen. Spammers seem to rely on "real" email addresses which they get from leaks and such.
- neogodless 4y agoI've seen this. Comes in waves - maybe 100s of emails over a few days. Then years of nothing. They get caught by spam filters pretty easily. I do whitelist a few email addresses, filter others into folders. And every once in a while, I have to empty out my spam folder. Not a big deal to me, and still think it's worth using catch-all email and unique email addresses all over the internet.
- jasonjayr 4y agoUsing random emails like that is a super easy way of getting caught up in a spam trap, which would get you blocked easily. One of our users used a throwaway a@apple.com, which earned us a complaint inside of an hour, just by sending a welcome/confirm message.
- mynameisvlad 4y agoThat's not really an issue for end users getting emails at <somerandomthing>@<theirowndomainname>, which is what the thread is about.
- bhhaskin 4y agoBut it is for spammers. Which is why it doesn't make sense for spammers to do that.
- iliketrains 4y agoI do the same as KMnO4 and I think I have never received an email to a random address that I haven't shared before. Currently the biggest volume of spam is coming to adobe@ and github@ (along with some dating sites). Actually, I did receive one, from my friend who typed the entire message in the name before the @ and left the body and subject empty :D
- TonyTrapp 4y agoI do the same and I did receive a few, to some addresses that looked like UUIDs. It was just a handful of addresses, so they were easy enough to block.
- function_seven 4y ago> Actually, I did receive one, from my friend who typed the entire message in the name before the @ and left the body and subject empty :D So something like this? From: bobby@tables.com To: myplanejustlandedcanyoucomepickmeup.thx@lastname.com Subject: <blank> Body: <blank>
- sam_lowry_ 4y agoLittle Bobby Tables ;-) You've made my evening!
- iliketrains 4y agoExactly! The message was like 3x longer, I wonder what is the limit?
- rOOb85 4y agoReminds me of the classic bob wehadababyitsaboy https:/youtube.com/watch?v=9JxhTnWrKYs
- deleted 4y ago[deleted]
- tablespoon 4y ago> How do you prevent someone from spamming you with random usernames? For example: You don't, but spammers don't care that much to do what you describe. Think like a spammer. Why would a spammer motivated by profit to do that on a small personal domain? It makes sense on large service (e.g. gmail, yahoo, comcast), because they might increase their audience, but on a personal domain they're just going to swamp someone's inbox in a way that makes it even less likely they'd bite.
- kevincox 4y agoIn practice this isn't very common. In most cases if you block the email that they got a hold of they will just give up rather than trying random addresses. However it does happen a little. Because it sounded like fun I actually added a signature to my addresses. So it looks like github.com-abcdef@example. Then the spam filter will check the signature and if it is invalid it will give it a high spam weight. (Other than a few widely-published addresses that are accepted at neutral weight)
- egberts1 4y agoWhitelist.
- teawrecks 4y agoMy understanding of how email works is: for each email sent, there's a sending and receiving server that exchange a message between users on each. * If a server tries to send an email to a user that doesn't exist on another server, the email will "bounce", and the receiver will automatically respond with an error (we've all seen this). * If a server slowly spams another server with emails to invalid users (say once an hour) they'll just get bounced back each time. No harm done. * If a server spams another server with an onslaught of emails, even if they are to a valid user, at some point it becomes a DOS attack and the IP of that server will be blacklisted. So the case you're probably concerned about is the second one where they could essentially brute force a username slowly enough that they don't trigger any red flags. But the time investment, compute power, and bandwidth necessary to do that is not worth how easy it would be to mitigate that. "Great you figured out my email address. Blocked." If they're going to spend time shooting into the dark like that they might as well be guessing random passwords to public facing ssh servers (which bots are doing all the time).
- GeekFortyTwo 4y agoI do similar and never see that occur. What I do get are a lot of misdirected messages for people at a school district(one letter, that sounds the same, off from mine) and a defunct tech school in India. The amount of personal information that companies will send to an unverified email address is terrifying. Devs, please make sure you send a confirmation email before believing an address is good. If I was malicious I could really mess with a lot of travel plans for people, among many other things.