3 ms·
I don't think this would work in practice. My employer sends daily deal emails without using a third-party service like SendGrid or SES and what we do is pay a
by semanticist 3y ago
I don't think this would work in practice. My employer sends daily deal emails without using a third-party service like SendGrid or SES and what we do is pay a company like Validity who interface with the big email providers for us. They have honeypot emails that get and validate our emails, they get feedback from the providers on how much they like/dislike us, and we get reports on this.
So an attack like this would be very obvious very quickly, even leaving aside that we'd notice a huge spike in email sign-ups and probably kill their accounts (especially since they're not going to be buying anything from those sock puppet accounts!).
- altdataseller 3y agoYou’re assuming most small companies are as vigilant as your company
- tootie 3y agoIf email is business critical, you do it. I work for a pretty small company and we do stuff like this. We have a sender tool that gives us a static sender IP, reports deliverability, click rates and at least estimates open rates. We also have a tool to estimate the quality of a newsletter sign up email address and not collect any disposable emails.
- semanticist 3y agoA small company will use a service like SendGrid, or even MailChimp at the higher level. Those services will do a lot of checking for you and investigating this kind of weirdness/attack is exactly why you pay them money! If they're sending directly, then they'll definitely be as vigilant as us, or they'd never get emails into people's inboxes!
- lippihom 3y agoIf they're not using a third-party service what are they using? Daily deal sounds like it's very high volume...
- semanticist 3y agoWe run our own mail servers. I would not recommend it for most people!