Slashdot is powered by your submissions, so send in your scoop

 



Forgot your password?
typodupeerror
×

Do Unsubscribe Links Stop Spam? 521

Kaiten writes "Brian McWilliams of Spam Kings fame has just published a fascinating spammer exposé over at Salon. Using a pseudonym, he was hired to send junk email on behalf of a spam operation that has been burying people (me included) with spam for fake Rolex watches. The article details how the spammers handle the 200,000-plus unsubscribe requests they get each month. Seems that LOTS of geeks actually cross their fingers and click those remove links. And, surprise, surprise, the spammers usually ignore the unsubscribe requests."
This discussion has been archived. No new comments can be posted.

Do Unsubscribe Links Stop Spam?

Comments Filter:
  • Don't do it! (Score:5, Informative)

    by sjrstory ( 839289 ) * on Wednesday December 15, 2004 @12:20PM (#11093030) Homepage
    A reply confirms there is a live person behind the email address. And for those with a HTML-enabled email client, a cleverly placed (and sized, ie 1 pixel) embedded image to an external site with a unquie string keyed to your email address is yet another trick spammers have for confirming your address.
  • MIT Spam Conference (Score:5, Informative)

    by JohnGrahamCumming ( 684871 ) * <slashdot@jgc.oERDOSrg minus math_god> on Wednesday December 15, 2004 @12:21PM (#11093045) Homepage Journal
    And if you like what you read you can come and hear the author speak at the MIT Spam Conference [spamconference.org] on January 21.

    John.
  • by erikkemperman ( 252014 ) on Wednesday December 15, 2004 @12:21PM (#11093055)
    ..But the big corps too. Coincidentally, I tried to remove myself from the iTunes list (which I had accidentally enlisted for when downloading QT) only the find that the unsubscribe-URL "contained no data". Hmm. Double hmm.
  • Re:Don't do it! (Score:5, Informative)

    by NardofDoom ( 821951 ) on Wednesday December 15, 2004 @12:25PM (#11093104)
    Apple's Mail.app has a good feature that doesn't load messages in suspected spam unless you click a button. Quite handy. Not sure if it's in Thunderbird, though.
  • by Anonymous Coward on Wednesday December 15, 2004 @12:26PM (#11093121)
    Dec. 14, 2004 | Casper Jones is the head of BlackMarketMoney.com, a spam operation that's been pelting the Internet with junk e-mail for fake Rolex watches. I'm almost positive his name is a pseudonym. But does he know that Chris Smith is not my real name?

    That's how I introduced myself last month, when I sent Casper an e-mail asking to join his spamming crew. I fibbed to him that I was a full-time bulk e-mailer looking for a new sponsor. I said that one of my business associates had recommended his program. (For authenticity, I lightly sprinkled typos and grammatical errors throughout the message.)

    I wanted to be one of Casper's sales affiliates. In today's world of spam, a sales affiliate sends out junk mail on behalf of a spam-site operator or "sponsor," who assigns the affiliate a special tracking code to include in his e-mail ads. For every sale the affiliate's spams generate, he is paid a commission by the site operator. Sponsors also provide "remove" lists, spamming software, and other support to help their affiliates successfully market the site.

    Since September, Casper and his associates had been clogging my various e-mail accounts with ads for a watch shop called Royal-Replicas.com (formerly onlinereplicastore.com). I filed several complaints with the Chinese Internet service provider hosting the site, to no avail.

    I suppose I could have just clicked the "unsubscribe" links in the dozen or so spams they sent me every day. But I didn't trust these people one bit. I was sure that if I could get inside Casper's operation, I would find hard evidence confirming what savvy Internet users instinctively know: Trying to unsubscribe from spam is a fool's game.

    Just look at the place. Royal-Replicas.com provides no physical mailing address in its junk e-mails or at the site. The domain's registration record lists someone in Spain as the owner. The site is hosted on a server in China, but the order page cites prices in Indian rupees as well as U.S. dollars. The headers of the spams reveal that many have been sent via "zombied" home computers. Even the headers of Casper's private e-mails are a fraud. (He routed all his messages to me through proxy computers in South Korea.)

    The "About Us" page at Royal-Replicas.com doesn't help much, either. It contains little more than a bizarre rationale for buying its $300 knockoffs rather than the real thing: "Many people purchase watches that cost thousands of dollars and render the wearer liable to get their hand chopped off while walking home from a posh cocktail party."

    Bulk e-mailers are required to honor list-removal requests under the U.S. CAN-SPAM law. But still it's common knowledge that clicking an unsubscribe link or handing over your e-mail address on a junk e-mailer's remove page is insane. The U.S. Computer Emergency Readiness Team (US-CERT) warns that unsubscribe links are "often just a method for collecting valid addresses that are then sent other spam." The FTC has sent warning letters to at least 77 marketers for their failure to honor unsubscribe requests.

    Sure, a few spammers might take your name off to avoid trouble. But to most, you're merely confirming that they've found a live one. Next thing you know, they'll have sold your e-mail address to other spammers as "validated" -- or, in other words, ready for spamming.

    At least, that's what I thought until Casper brought me onboard. My undercover mission into the heart of fake-Rolex spam didn't turn out exactly as I had expected.

    I tried flattering Casper in my e-mails, gushing that he had astutely tapped into a timely and lucrative spamming niche. (You could probably find similar watches on the streets of Chinatown for $25, but hey, some people prefer the convenience of holiday shopping from home.) But Casper doesn't let just anyone join BlackMarketMoney.com. After I sent my introductory e-mail as "Chris Smith" from a free webmail account I had created, he asked to know the name of the person who had referred m

  • Re:Don't do it! (Score:5, Informative)

    by Misch ( 158807 ) on Wednesday December 15, 2004 @12:30PM (#11093169) Homepage
    Thunderbird has a similar feature. It's nice not having images load in e-mails unless I ask for them.
  • Hmm (Score:5, Informative)

    by SnAzBaZ ( 572456 ) on Wednesday December 15, 2004 @12:36PM (#11093246) Homepage
    "Seems that LOTS of geeks actually cross their fingers and click those remove links"

    I really don't agree. Any respectable geek shouldn't be getting spam in the first place, let alone be stupid enough to click the unsubscribe links.

    Personally I haven't had more than 30-50 spams in the last 3 years or so.

    I have my main address, which only 'real people' know, friends and family. It never gets any spam because it's totally secret.

    Then for everything else I assign a throw away address on one of my domains, the mail on these gets checked only when I'm expecting something (like a signup confirmation/verification etc).

    I also have a semi-secret address to give slightly less trustworthy people and to date that hasn't had any spam either.

    Obviously I make sure none of my addresses get posted in plain text on the internet either.

    It is simply a matter of keeping your address clean. The only way spammers can send me mail right now is if they brute force my email address, and that doesn't happen very often.

  • by Junior J. Junior III ( 192702 ) on Wednesday December 15, 2004 @12:36PM (#11093251) Homepage
    Unsubscribe generally does work for legitimate mass mailings, ie the ones you had to sign up for in the first place. It doesn't work for true SPAM, and indeed as others have pointed out, tends to actually make the problem worse.

    It's amazing that this is considered "news", but I guess you have to repeat experiments every so often to prove that the theories they provide support for still hold water.
  • by dmuth ( 14143 ) <doug@muth+slashdot.gmail@com> on Wednesday December 15, 2004 @12:39PM (#11093276) Homepage Journal
    This has been going on since before the days of the (long since defunct) IEMMC with their bogus remove list, which was back in 1997 or so.

    Here's one article that was written about the IEMMC [familychronicle.com].

  • NOOOOOOO (Score:2, Informative)

    by SQLz ( 564901 ) on Wednesday December 15, 2004 @12:40PM (#11093288) Homepage Journal
    Of course they don't. If anything,unsubsribing will triple the spam you do get.

    Besides filtering spam I started creating a seperate email alias for every website I need an email address on. When that alias starts to get spam I delete it, and I know where its coming from.

    The most surprising place I ever get spam from is sears. I think they have someone on the inside selling their customer list because I will start getting spam about 2 weeks after ordering something.
  • by jcoxatonce ( 228245 ) on Wednesday December 15, 2004 @12:42PM (#11093320)
    And it was an interesting experience. @Once has big-name clients who don't want to be thought of as spammers, so the company puts amazing resources into reply handling and unsubscribe systems that actually work. I know, I worked my ass off keeping them running. It was a stark contrast to what a real "spammer" is, at least in my imagination.

    Still, I was never proud to tell people where I worked because people think of bulk email as spam unless they're educated about the difference. In my interviews since I left the firm, I've always had to be very careful to describe the white hat nature of what I used to do.
  • Re:That's easy... (Score:5, Informative)

    by baryon351 ( 626717 ) on Wednesday December 15, 2004 @12:43PM (#11093327)
    I'm not so sure. As an experiment early this year, march I guess, I went through my entire junk mail folder in an attempt to get as much spam as I could. What the hell, hey, I'm getting several hundred messages a day and more can't hurt, and even if it trebled it'll help train my spam filter, right? I entered my email address in all the unsubscribe links I could find.

    I forgot about it for a while, and it wasn't until 2 months later I noticed an EXTREME drop in the number of spam emails. My last entire week of spam totals 51 emails. Curiously, not one of them contains an unsubscribe link. It's not down to "stopping spam" but it's a couple of orders of magnitude less. I never kept detailed stats on exactly when the drop off occurred, so I can't for sure say the unsubscribe links stopped it, but they certainly didn't add to it.

    This story has inspired me to test entering a brand new unguessable email address into unsubscribe forms online, to see what happens coming from the other direction. That's going to take effort to dig up email archives though. I just don't have any spam available WITH unsubscribe links any more.
  • Re:That's easy... (Score:5, Informative)

    by BMcWilliams ( 621149 ) on Wednesday December 15, 2004 @12:43PM (#11093333) Homepage
    Fwiw, if you make it to the end of the article, you'll see that the Rolex spammers actually DID remove me from their lists. (Don't try this at home.)
  • Re:Don't do it! (Score:4, Informative)

    by famebait ( 450028 ) on Wednesday December 15, 2004 @12:47PM (#11093372)
    A reply confirms there is a live person behind the email address.

    Yes, but a live address that isn't likely to respond well to spam. I find it remarkable that so many people love to try to look smart by repeating that old abiout unsubscribe just getting you more spam lists, while obviously noone has actually checked if it is the case.

    Well, I have. At one point my spam bucket just became too big to check in any case (~200/day), so I thought "what the heck; let's see what happens".

    I unsubscribed everything that worked for two days straight. Spam went down 50% over the next few days. Then started to slowly rise again, and after a couple of months was back on the curve that previous history would have predicted.

    Interestingly, it seemed least effective for viagra and penis enlargement spam (which was also the class that often didn't even have a link), and almost 200% effective against porn spam (for the next two months, only one easily recognisable source kept bugging me).

    So the idea that you will necessarily only increase your spam load by using the links does seem to be just a myth, and even the percetion that no spammers heed them.

    Now, that doesn't mean I'm claiming the famous opt-out exploitation has never happened, that the majority of spammers will effect your unsubscribtion, that the effort is worth it, that unsubscribing is any sort of good alternative to a proper filter, or that spammers don't deserve to die in screaming agony in any case. Just reminding people that hearsay is hearsay, even if it sounds like the "expert" opinion.
  • Re:Hmm (Score:2, Informative)

    by gowen ( 141411 ) <gwowen@gmail.com> on Wednesday December 15, 2004 @01:01PM (#11093533) Homepage Journal
    Personally I haven't had more than 30-50 spams in the last 3 years or so. I have my main address, which only 'real people' know, friends and family. It never gets any spam because it's totally secret.
    I have a gmail account. Only my sisters know the address, and it shows no hits on google, web or usenet. It's received 50 spams in the last month, just from spammers using dictionary attacks (and I know thats what they're from, because the subject line gives it away.)
  • Re:Don't do it! (Score:2, Informative)

    by Fishstick ( 150821 ) on Wednesday December 15, 2004 @01:05PM (#11093578) Journal
    Yahoo mail also has the option to block html/images from all mail, but then provides a link to 'show html images' (can't remember the last time I actually wanted to see anything other than text in an email)
  • Re:Don't do it! (Score:2, Informative)

    by tomofdarknesss ( 838172 ) on Wednesday December 15, 2004 @01:06PM (#11093594) Homepage
    i have Apple's mail configured to block all images on incoming mail until I tell it to. it was like 2 clicks.
  • Re:Don't do it! (Score:5, Informative)

    by zerocool^ ( 112121 ) on Wednesday December 15, 2004 @01:10PM (#11093633) Homepage Journal
    Newsflash.

    If you install Service Pack 2, Outlook Express does too.
  • by slicenglide ( 735363 ) on Wednesday December 15, 2004 @01:11PM (#11093639)
    www.salon.com/news/cookie.html

    make it the first page before you visit the main salon.com site and it will bypass them forcing you to watch an ad.

    I use it religiously.
    -Meow.
  • by Megane ( 129182 ) on Wednesday December 15, 2004 @01:39PM (#11094017)
    Of course clicking on the remove links isn't likely to be useful.

    The best way is to run your own mail server and simply prevent the spammers from connecting. One way is to add blackhole lists to your MTA (Sendmail, or whatever). That really did cut my spam quite a bit. But recently I noticed I was still getting quite a bit of spam directly from China and Korea decided to get tough and start blocking net ranges completely. I had tried blocking SMTP from a few /8 address ranges before, but this time I didn't want to unnecessarily block Australia or Japan, so I took the time to look at the /16 level to find sub-ranges to block.

    It's already working, too. Here are the ranges I've added so far. (The second column is the number of connection attempts that were rejected.) At this point, I only plan to add new blocks as I encounter them in actual spam.

    00100 44 2164 deny ip from 63.148.99.224/27 to any
    00100 0 0 deny ip from 65.118.41.192/27 to any
    00110 36 1920 deny tcp from 211.32.0.0/11 to me 25
    00110 2 96 deny tcp from 211.144.0.0/12 to me 25
    00110 6 288 deny tcp from 211.160.0.0/11 to me 25
    00110 6 288 deny tcp from 211.192.0.0/10 to me 25
    00110 0 0 deny tcp from 222.16.0.0/12 to me 25
    00110 6 288 deny tcp from 222.32.0.0/11 to me 25
    00110 13 624 deny tcp from 222.64.0.0/10 to me 25
    00110 0 0 deny tcp from 222.128.0.0/12 to me 25
    00110 0 0 deny tcp from 222.160.0.0/11 to me 25
    00110 4 240 deny tcp from 206.81.80.0/20 to me 25
    00110 0 0 deny tcp from 216.224.0.0/13 to me 25
    00110 0 0 deny tcp from 216.240.0.0/13 to me 25
    00110 0 0 deny tcp from 61.32.0.0/13 to me 25
    00110 0 0 deny tcp from 61.40.0.0/14 to me 25

    Oh, and those first two lines? Google for Cyvelliance and you'll understand why they're there.

  • Re:Don't do it! (Score:2, Informative)

    by jez9999 ( 618189 ) on Wednesday December 15, 2004 @02:44PM (#11094880) Homepage Journal
    I haven't installed SP2, but still use OE. Try Tools | Options | Read | Read all messages in plain text.
  • Re:That's easy... (Score:3, Informative)

    by number11 ( 129686 ) on Wednesday December 15, 2004 @02:49PM (#11094942)
    You can't read the article it's paid subscription... unless someone has a link to more than the first couple of paragraphs.

    You just have to click through about five pages of ads.. but there's no animation or sound or anything, so you can click NEXT as soon as the page loads.
  • Re:alternatively (Score:3, Informative)

    by beh ( 4759 ) * on Wednesday December 15, 2004 @02:55PM (#11095018)
    Get your own internet domain (and ideally a provider that allows you free use of subdomains) and that problem is solved permanently, as you can assign new addresses for every single contact and purpose. e.g. my (visiting) card has one specific email address I don't give out anywhere else, and since that address only exists in print, it's fairly safe from spam harvesters... ...similarly, every company I order something from gets an address in the form of companyname.com@biz.mydomain.tld
    That way, I can easily filter out all business related emails (*@biz.) to one mailbox, and in case one of those starts spamming, I will send every future email to that recipient address to bogofilter without even looking at it any more...

    (If you're not allowed sub-domains, it's not too much of a problem either; in that case instead of companyname.com@biz... use something like companyname.com-biz@...
    That still allows you to procmail .*-biz@... to a business mailbox and somespammingidiot-biz@... straight into bogofilter / the trash...

    Benedikt
  • by 5n3ak3rp1mp ( 305814 ) on Wednesday December 15, 2004 @03:06PM (#11095206) Homepage
    1) Use a long email address that is difficult to brute-force
    2) Only give it to real people
    3) Use a mailinator address for online registrations and whatnot where you have to read a reply.
    4) For those sites that force you to reply from a real email address to complete registration, use a spam webmail address.

    This has stopped almost all spam from bugging me.

    Anecdote: My first email address ever was from Cornell in 1990. Cornell has a policy that lets you keep your email address for life by setting up an auto-forward after you graduate. The irony is that Cornell, back in the days before spam, unfortunately picked an address format (initials+number@cornell.edu) that turned out to be easy to brute-force, and that I've since had to turn the auto-forward feature off due to too much spam, defeating the purpose of the "lifetime email address". oh well...
  • by Anonymous Coward on Wednesday December 15, 2004 @03:53PM (#11095858)
    It's funny how one of the two major providers here in France (Wanadoo, to name it), which is supposed to be a serious source, though commercial, won't let you unsuscribe from their news/offers mailing list even though you follow their opt-out prodedure.

    Here and there I've encountered similar issues with various websites that are in no way related to spam. They would just keep sending you their mailing list / special offers even though you clearly asked them not to bug you anymore.

    Based on that experience, opt-out options seem to me to be here for nothing but the kick in a whole lot of cases. Hopefully I learned how to make a good use of hotmail adresses and mailinator.
  • More Spam (Score:1, Informative)

    by EGaming ( 694500 ) on Wednesday December 15, 2004 @03:57PM (#11095897) Homepage
    Clicking the unsubscribe links is actually worse. Not only do they ignore your request to be removed from the list, but they now know you check that account.
  • by 5n3ak3rp1mp ( 305814 ) on Wednesday December 15, 2004 @04:59PM (#11096688) Homepage
    Go to mailinator.com. You'll see what I'm talking about. Scenario:

    You tell Amazon that your address is kencurry@mailinator.com (no need to register at mailinator.com, just do it)

    Amazon sends you email, like a confirmation email.

    You head on down to www.mailinator.com, enter "kencurry" as the email name to check, and voila! there's your email. Check it and forget it. Inbox stays clean. Mailinator holds emails for a few days but eventually deletes them.
  • by Anonymous Coward on Wednesday December 15, 2004 @05:51PM (#11097326)
    Some spammers use "Unsubscribe Link" as a mechanism to verify the validity of the email addresses.

    Also the URLs for images in HTML emails are tailored to confirm that you have actually opened the email and your email-id is valid.

    --
    Anand Babu

Work without a vision is slavery, Vision without work is a pipe dream, But vision with work is the hope of the world.

Working...