6 ms·
Don't verify email addresses by sending spam to them
- hopeless 3mo agoMy first thought would be that they've been hacked (or something else, like a CRM attached to their systems, has).
- bstsb 3mo agothe actual base64 email itself is an HTML document, with a bunch of filler text about metal magnets! > Hi there, A magnetic domain is a region within a magnetic material in which the magnetization is in a uniform direction. This means that the individual magnetic moments of the atoms are aligned with one another and they point in the same direction [...] they sign off the email with a zero-width space set to "font-size: 0" for some reason
- tom1337 3mo agoAlso, the magnet text is not visible: style="position: absolute; left: -9999px; top:-9999px;display: none" maybe they try to warm up those emails to use them for other "campaigns" later on...
- mike-cardwell 3mo agoThe text is added to get around bayesian filters. The spammer doesn't want the text to be displayed to the end user though typically.
- autoexec 3mo agoA smart bayesian filter would catch email with invisible text. Legitimate email shouldn't have any, but I have seen it more than once in spam
- gus_massa 3mo agoThe text is from https://en.wikipedia.org/wiki/Magnetic_domain https://en.wikipedia.org/wiki/Magnetic_domain that uses a CC BY-SA 4.0. I hope they remembered to add the atribution as requested :)
- xp84 3mo agoStrange to see this in an apparent real product. And also I don't see how this does much to 'validate' it... It could be a valid email that belongs to a random stranger, like, tcook@apple.com for instance. Part of me wonders if someone has added something nefarious into their backend which just collects and exfiltrates new emails as people sign up.
- vova_hn2 3mo agoThe idea that they really send spam to validate an email address sounds to insane to be believable. Is it possible that they are somehow leaking the address to actual spammers? For example, they (or the hypothetical email validation SaaS) use an infected email validation library that ex-fills every email supplied to it, or something like this.
- p2edwards 3mo agoYeah. The abundance of comments that take the article at face value makes me pause. I assumed it was satire.
- kirmerzlikin 3mo agoCan it be that Pangram doesn't send any spam itself but instead (intentionally or not) leaks your email address to some spammer who then does the sending?
- autoexec 3mo agoSpamming, leaking, or selling. Either way, I now know that I want nothing to do with Pangram.
- aarjaneiro 3mo agoMagnetic domain
- legitster 3mo agoI just did a signup on a brand new email address and was not able to recreate. No random spam emails reported. Just a normal verification email. It's likely that the email the author received is pure coincidence. Especially if they are using a client that downloads emails in batches. FWIW it looks like their validation email is sent by Customer.IO via Mailgun. Both have squeaky clean service agreements so it's unlikely they are shooting off the data to spammers. Edit: No way! I did end up getting a random empty email. From a "Adventure-Meter Department" at bugbusterbrigade.com. The topic of the email was "Scents and Memory". This is a really weird email. It's not a spam email, it's some sort of attempt at inbox testing. Perhaps it's an attempt to sniff out AI agents signing up for their service?
- garaetjjte 3mo agoMaybe they don't do that for larger destination providers. But definitely no coincidences here. (in the post I replaced address with example.com because I'm curious if I will ever get other spam onto it, but here's another one unmodified) curl --request POST --data '{"email": "pangramdemo@milek7.pl"}' https://www.pangram.com/api/validate-email https://milek7.pl/mailverifyspam/another.txt https://milek7.pl/mailverifyspam/another.txt
- EvanAnderson 3mo agoI just tried with a new email at my domain. I'm excited to see what I get.
- deleted 3mo ago[deleted]
- JdeBP 3mo agoMailgun's validation API, presumably the underpinnings of Pangram's, returns more than a simple yes/no validity. My educated guess is that this is part of figuring out all of those extra fields. * https://mailgun.com/products/validate/ https://mailgun.com/products/validate/ * https://documentation.mailgun.com/docs/validate/oas/openapi-validate-final/validations/get-v4-address-validate https://documentation.mailgun.com/docs/validate/oas/openapi-...
- jiveturkey 3mo agolooks like a response to https://news.ycombinator.com/item?id=48445834 https://news.ycombinator.com/item?id=48445834
- efazati 3mo agoin this context now the whole conversation made more sense
- saltcured 3mo agoI would make even stronger advice. If you want to verify an email, send me a one-time code with several hours expiry that I have to resubmit through my logged in web identity at your site. It drives me batty that a financial provider (retirement vendor from previous employer) won't seem to let my "paperless" setting remain active. Only because I don't ping their abusive email tracking pixels etc. To me, paperless means I can log in and download my quarterly PDF statements and related documents, and they won't be left in a mailbox on the street. It doesn't mean I have to subject myself to reading your silly emails with a promiscuous client.
- teeray 3mo agoI really wish you could provide a PGP public key to your bank and have them just email the damn pdf every month.
- RulerOf 3mo agoThat'd be nice, but I'd even settle for the plain pdf attached to the email.
- saltcured 3mo agoFor things like financial records, I would not want plain PDF in the email. I think it needs encryption for confidentiality. I am geeky enough to use PGP or S/MIME if they had the option, but I can definitely see how vendors would see this as too fringe with retail customers. I would not like the typical "secure email" which is nothing more than a volatile link back into yet another website.
- wwind123 3mo agoHmm, yeah some people feel that plain emails are not secure for sensitive information. As a result, some banks provide a "secure email" box that's usually PITA to use. It'd be great if there's a unified API for all financial institutes to provide sensitive info (statements, tax forms etc.) and you just need to run a software tool to download them once in a while or when you need it.
- zephen 3mo agoInteresting business model. Sell verification services to one set of clients, and use the harvested email addresses to sell spam delivery to another set of clients. It's like having a space in a big building downtown with storefronts on two opposite streets. Babysitting/childcare services here; rent a child to go the park with and help you pick up chicks there. The similar playing-both-sides against the middle that I'm struggling with right now: companies sell (physical) mail addresses to other companies for beaucoup bucks. But if you want to correctly report that your wife has been dead for 9 years because you're tired of getting her USPS spam, they want to charge you to add you to their profitable database.
- rubinlinux 3mo agoThere is a procedure common in mail sending where you ALMOST do this. You connect to their mail server, tell it you have a message for them, and wait to see if it rejects you or accepts the message. Then you disconnect without actually sending the message. I wonder if this is some kind of confusion among the devs behind this, or some benefit to really sending the message that I can't think of. Does it contain a tracking pixel or anything?
- gerdesj 3mo agoThat's recipient testing based on mailbox name. I don't recommend that for spammers - its so trite and early 2000s. I wont allow you to test deliverability to my email domains without you sending an email I can analyze and decide to allow or drop mid stream. I also get to drop it before you consider it sent. I obviously drop connections that just establish from and to and go weird after that.
- lwhi 3mo agoI have a Gmail address in the format of x.surname@gmail.com, which is obviously potentially applicable to tens of thousands of people. The amount of misdirected mail I get is astounding. I literally just got a delivery updaye for hair removal cream, with the option to sign the unknowing recipient up to a paid for tracking subscription service. The problem isn't just making sure the address is valid. You need to ensure you're sending communications to the correct person.
- mcv 3mo agoI still have a gmail address that looks in no way like a name, and that's not stopping me from receiving some really weird misdirected email. Often my random collection of characters with some dots in between (apparently Gmail ignores dots in your name).
- pocksuppet 3mo agoYou seem to be getting unsolicited commercial email, a.k.a. spam, and could possibly initiate legal action against the sender. If you did so, it would cause the entire industry to stop using email verification, and probably switch to phone number until they get sued for the exact same thing with phone numbers.
- andai 3mo agohttps://xkcd.com/1279/ https://xkcd.com/1279/
- Topgamer7 3mo agoCan we talk about the reddit spam too? Like how they allow bots to sign up accounts, with random email addresses. Which then sends spam/verify emails, with no recourse? I want to block new accounts to my email, but I have no options.
- maxspero 3mo agoHey! Founder of Pangram here. We use Zerobounce and CustomerIO for email validation. I had no idea this was happening. Not entirely sure which one this is coming from, but this is not intentional on our part. Will dig deeper and eliminate the part of the stack that is sending spam — definitely not good that this is happening.
- technion 3mo agoI'm reading the ZeroBounce docs and it seems very relevant. Look at this step: "We recheck all unknown emails using IPs from different geographical locations". This matches exactly what this article describes as getting these emails from a range of locations. The step before that is just "Proprietary Technology", which sounds like a good cover for what's going on here. How else are you testing an email address after between "real time SMTP server check"?
- deleted 3mo ago[deleted]
- maxspero 3mo agoFollow-up: our vendors have told us that they do not send any emails as part of the validation process. Either somebody is lying, or there's something even weirder going on. We still have more tests to run to isolate which software package it could be.
- maxspero 3mo agoUpdate: this is actually ZeroBounce’s Verify+ feature which we figured out after some escalation. It’s now disabled!
- scosman 3mo ago"ghostlygourd.com" is a S+ tier domain. Would click
- andai 3mo agoI'm more of a venusbases.com kinda guy
- aitchnyu 3mo agoDid any site implement incoming emails to signup@domain.com which then sends you a timebound signup form? No spam filtering drama.
- Akronymus 3mo agoKiwifarms did something like that, where you have to send an email to confirm your signup.
- casey2 3mo agoa botnet is not spam, garbage text is not spam, spam is defined primary by being unsolicited AND unwanted. This is solicited. Don't confuse the map for the territory. What we see here is a so called "expert" in anti-spam technology completely losing site of the goal and complaining that world should conform to their system. This is learned helplessness masquerading as expertise.