# Email Spam - How Is This Happening

**URL:** <https://boards.straightdope.com/t/email-spam-how-is-this-happening/635002>\
**Category:** Factual Questions\
**Created:** [September 17, 2012, 8:23pm UTC](https://boards.straightdope.com/t/email-spam-how-is-this-happening/635002 "2012-09-17T20:23:12Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![MindsEye\_Watering](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mindseye_watering/32/3619_2.png) [@MindsEye\_Watering](https://boards.straightdope.com/u/MindsEye_Watering)\
**Post date:** [September 17, 2012, 8:23pm UTC](https://boards.straightdope.com/t/email-spam-how-is-this-happening/635002/1 "2012-09-17T20:23:12Z")

</div>

Over the last few weeks, I’ve been getting spam from a company. What seems mystifying to me is that the spam is coming from _ **my** _ email address.

I’ve complained to the ISP about this and forwarded the messages to their “Abuse” department, but I’ve heard nothing back from them yet.

How is this possible?

Also, if they have access to my email address to send spam, can they read my email too?

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![Inner\_Stickler](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/inner_stickler/32/318_2.png) [@Inner\_Stickler](https://boards.straightdope.com/u/Inner_Stickler)\
**Post date:** [September 17, 2012, 8:27pm UTC](https://boards.straightdope.com/t/email-spam-how-is-this-happening/635002/2 "2012-09-17T20:27:31Z")

</div>

The From line on an email is like the Return Address on a snail mail letter. Much as there’s nothing stopping me from mailing a letter with your return address on it\*, there’s nothing stopping spammers from sending emails with your address in the from line. There really isn’t anything your ISP can do. If you think you ran afoul of a phishing email or that your password has been compromised, you should certainly change it, but it’s unlikely that they can read your actual email.

\*I’ve always wondered what would happen if I mailed a letter with some nonsense address on the front, the true destination as the return address and no postage. I mean besides being arrested for defrauding the mail or whatever.

---

<div class="post-metadata">

**Author:** ![Lips\_Obsession](https://avatars.discourse-cdn.com/v4/letter/l/bbce88/32.png) [@Lips\_Obsession](https://boards.straightdope.com/u/Lips_Obsession)\
**Post date:** [September 17, 2012, 8:28pm UTC](https://boards.straightdope.com/t/email-spam-how-is-this-happening/635002/3 "2012-09-17T20:28:05Z")

</div>

Most likely they’re just spoofing your address in the email they’re sending to you. It’s one method spammers use to bypass people’s spam filters. I would think it would be highly unlikely they have access to your actual email account. If they did and were using it to send spam, you’d be getting a lot of bounced spam messages back as spammers usually have a lot of “bad” addresses in the lists they use so a lot of the email gets bounced back to whatever address they are sending from.

---

<div class="post-metadata">

**Author:** ![MindsEye\_Watering](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mindseye_watering/32/3619_2.png) [@MindsEye\_Watering](https://boards.straightdope.com/u/MindsEye_Watering)\
**Post date:** [September 17, 2012, 11:31pm UTC](https://boards.straightdope.com/t/email-spam-how-is-this-happening/635002/4 "2012-09-17T23:31:10Z")

</div>

> [@Lips\_Obsession](#):
>
> Most likely they’re just spoofing your address in the email they’re sending to you. It’s one method spammers use to bypass people’s spam filters. I would think it would be highly unlikely they have access to your actual email account. If they did and were using it to send spam, you’d be getting a lot of bounced spam messages back as spammers usually have a lot of “bad” addresses in the lists they use so a lot of the email gets bounced back to whatever address they are sending from.

Thanks. That makes me feel a little better.

**Inner Stickler** , I understand what you’re saying, but shouldn’t the actual “From” mail address used to send the spam appear somewhere in the header of the message? How can there be no real “From” (or origination) on the message?

---

<div class="post-metadata">

**Author:** ![tellyworth](https://avatars.discourse-cdn.com/v4/letter/t/977dab/32.png) [@tellyworth](https://boards.straightdope.com/u/tellyworth)\
**Post date:** [September 17, 2012, 11:57pm UTC](https://boards.straightdope.com/t/email-spam-how-is-this-happening/635002/5 "2012-09-17T23:57:01Z")

</div>

> [@MindsEye\_Watering](#):
>
> **Inner Stickler** , I understand what you’re saying, but shouldn’t the actual “From” mail address used to send the spam appear somewhere in the header of the message? How can there be no real “From” (or origination) on the message?

The originating servers will appear in the headers, but there is no such thing as a “real From address”. As IS said, it’s exactly like the return address on an envelope; anyone can put any address they like.

---

<div class="post-metadata">

**Author:** ![Reverend\_Meade](https://avatars.discourse-cdn.com/v4/letter/r/6a8cbe/32.png) [@Reverend\_Meade](https://boards.straightdope.com/u/Reverend_Meade)\
**Post date:** [September 18, 2012, 12:21am UTC](https://boards.straightdope.com/t/email-spam-how-is-this-happening/635002/6 "2012-09-18T00:21:56Z")

</div>

> [@Lips\_Obsession](#):
>
> Most likely they’re just spoofing your address in the email they’re sending to you. It’s one method spammers use to bypass people’s spam filters. I would think it would be highly unlikely they have access to your actual email account. If they did and were using it to send spam, you’d be getting a lot of bounced spam messages back as spammers usually have a lot of “bad” addresses in the lists they use so a lot of the email gets bounced back to whatever address they are sending from.

I had that happen to me. They spammed my contact list. Yahoo auto adds any address to my contacts so i kept getting error emails when they tried to spam expired address from six month old Craigslist ads. I changed my password and it stopped.

> [@Inner\_Stickler](#):
>
> \*I’ve always wondered what would happen if I mailed a letter with some nonsense address on the front, the true destination as the return address and no postage. I mean besides being arrested for defrauding the mail or whatever.

I belive Cecil wrote about this. If I remember correctly he said you’d probably get away with it. However, He also felt that it was pretty pathetic to bother.

---

<div class="post-metadata">

**Author:** ![Reply](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/reply/32/15952_2.png) [@Reply](https://boards.straightdope.com/u/Reply)\
**Post date:** [September 18, 2012, 12:46am UTC](https://boards.straightdope.com/t/email-spam-how-is-this-happening/635002/7 "2012-09-18T00:46:46Z")

</div>

> [@Inner\_Stickler](#):
>
> \*I’ve always wondered what would happen if I mailed a letter with some nonsense address on the front, the true destination as the return address and no postage. I mean besides being arrested for defrauding the mail or whatever.

The mailman knocks on your door, gets upset at you, and tells you to tell whoever did that to not do it again.

I know this because my college professor mailed me my final paper after school was over. She didn’t want to pay that much postage (it was a longish paper), so she put my name and address in both the TO: and the FROM: areas, exactly as she said she’d do.

Mailman was annoyed but didn’t make a big deal out of it.

---

<div class="post-metadata">

**Author:** ![CookingWithGas](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cookingwithgas/32/485_2.png) [@CookingWithGas](https://boards.straightdope.com/u/CookingWithGas)\
**Post date:** [September 18, 2012, 1:13am UTC](https://boards.straightdope.com/t/email-spam-how-is-this-happening/635002/8 "2012-09-18T01:13:04Z")

</div>

> [@MindsEye\_Watering](#):
>
> **Inner Stickler** , I understand what you’re saying, but shouldn’t the actual “From” mail address used to send the spam appear somewhere in the header of the message? How can there be no real “From” (or origination) on the message?

You can do this spoof very easily in your own email client by setting up a bogus From address. Somebody got your email address from somewhere and decided it would be handy to send spam to you and use you as the sender. Most people’s email clients do not identify mail from themselves as a blocked sender.

The SMTP protocol was designed by and for honest people in more innocent times. Your email client contacts your SMTP server, and the email message gives a “From” address. The SMTP server has no other way to know who you are except what you tell it (unless your server requires authentication, which many ISPs now require for this reason). The header will accumulate the servers touched in the hops but not the “true” email address sending the mail.

---

<div class="post-metadata">

**Author:** ![MindsEye\_Watering](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mindseye_watering/32/3619_2.png) [@MindsEye\_Watering](https://boards.straightdope.com/u/MindsEye_Watering)\
**Post date:** [September 18, 2012, 1:17am UTC](https://boards.straightdope.com/t/email-spam-how-is-this-happening/635002/9 "2012-09-18T01:17:08Z")

</div>

> [@CookingWithGas](#):
>
> You can do this spoof very easily in your own email client by setting up a bogus From address. Somebody got your email address from somewhere and decided it would be handy to send spam to you and use you as the sender. Most people’s email clients do not identify mail from themselves as a blocked sender.
> 
> The SMTP protocol was designed by and for honest people in more innocent times. Your email client contacts your SMTP server, and the email message gives a “From” address. The SMTP server has no other way to know who you are except what you tell it (unless your server requires authentication, which many ISPs now require for this reason). The header will accumulate the servers touched in the hops but not the “true” email address sending the mail.

Okay, I’m starting to understand now.

Thanks to everyone for your patient explanations.

---

<div class="post-metadata">

**Author:** ![jacobsta811](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/jacobsta811/32/2893_2.png) [@jacobsta811](https://boards.straightdope.com/u/jacobsta811)\
**Post date:** [September 18, 2012, 2:33am UTC](https://boards.straightdope.com/t/email-spam-how-is-this-happening/635002/10 "2012-09-18T02:33:34Z")

</div>

It also means your ISP doesn’t have a very aggressive spam policy - most better spam fighting setups validate from addresses and reject those that are from domains that they control - so if your isp is “[aol.com](http://aol.com)” they would reject [youremail@aol.com](mailto:youremail@aol.com), and [bob@aol.com](mailto:bob@aol.com), [mary@aol.com](mailto:mary@aol.com), unless it was actually sent by the AOL server.

---

<div class="post-metadata">

**Author:** ![MindsEye\_Watering](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mindseye_watering/32/3619_2.png) [@MindsEye\_Watering](https://boards.straightdope.com/u/MindsEye_Watering)\
**Post date:** [September 18, 2012, 4:48am UTC](https://boards.straightdope.com/t/email-spam-how-is-this-happening/635002/11 "2012-09-18T04:48:32Z")

</div>

> [@jacobsta811](#):
>
> It also means your ISP doesn’t have a very aggressive spam policy - most better spam fighting setups validate from addresses and reject those that are from domains that they control - so if your isp is “[aol.com](http://aol.com)” they would reject [youremail@aol.com](mailto:youremail@aol.com), and [bob@aol.com](mailto:bob@aol.com), [mary@aol.com](mailto:mary@aol.com), unless it was actually sent by the AOL server.

It looks as if the spams were sent from my ISP as there is usually another recipient or two in the CC field that are also in my ISP’s domain.

I’ve sent the 5 messages (so far) to the Abuse department of my ISP. Kinda curious what they’ll say or do.

---

<div class="post-metadata">

**Author:** ![Senegoid](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/senegoid/32/6606_2.png) [@Senegoid](https://boards.straightdope.com/u/Senegoid)\
**Post date:** [September 18, 2012, 6:25am UTC](https://boards.straightdope.com/t/email-spam-how-is-this-happening/635002/12 "2012-09-18T06:25:49Z")

</div>

> [@Lips\_Obsession](#):
>
> Most likely they’re just spoofing your address in the email they’re sending to you. It’s one method spammers use to bypass people’s spam filters. I would think it would be highly unlikely they have access to your actual email account. If they did and were using it to send spam, **you’d be getting a lot of bounced spam messages back as spammers usually have a lot of “bad” addresses in the lists they use so a lot of the email gets bounced back to whatever address they are sending from.**

This can happen anyway. Spams often have some bogus “From” address, and/or a bogus “Reply To” address. Thus, they can blast a zillion spams, and a bunch of those will bounce to the alleged (and probably innocent) “From” or “Reply” address. A friend of mine had this happen to him – he got so much bounced spam wrongly bounced to him that his inbox got full to the max and stayed full so he couldn’t get his real mail. He had to abandon that address and get a new one.

May all spammers rot in hell. But this was also a seriously grotesque absence of foresight on the part of the early Internet protocol designers, who saw no need back in the day (late 1960’s or so) to design security and authentication into the whole systems at the lowest levels.

---

<div class="post-metadata">

**Author:** ![Canadjun](https://avatars.discourse-cdn.com/v4/letter/c/76d3ee/32.png) [@Canadjun](https://boards.straightdope.com/u/Canadjun)\
**Post date:** [September 18, 2012, 2:59pm UTC](https://boards.straightdope.com/t/email-spam-how-is-this-happening/635002/13 "2012-09-18T14:59:01Z")

</div>

> [@Senegoid](#):
>
> May all spammers rot in hell. But this was also a seriously grotesque absence of foresight on the part of the early Internet protocol designers, who saw no need back in the day (late 1960’s or so) to design security and authentication into the whole systems at the lowest levels.

When the SMTP and other protocols were developed, the Internet and its predecessors were basically a research tool for the universities and other research organizations. There was no real need at the time for fancy authentication; screwing around would make your sysadmin cranky, which was a pretty good disincentive at the time. It’s doubtful that the early designers had any idea what their invention of the Internet would morph into.

---

<div class="post-metadata">

**Author:** ![gnoitall](https://avatars.discourse-cdn.com/v4/letter/g/bb73d2/32.png) [@gnoitall](https://boards.straightdope.com/u/gnoitall)\
**Post date:** [September 18, 2012, 5:54pm UTC](https://boards.straightdope.com/t/email-spam-how-is-this-happening/635002/14 "2012-09-18T17:54:01Z")

</div>

> [@Canadjun](#):
>
> When the SMTP and other protocols were developed, the Internet and its predecessors were basically a research tool for the universities and other research organizations. There was no real need at the time for fancy authentication; screwing around would make your sysadmin cranky, which was a pretty good disincentive at the time. It’s doubtful that the early designers had any idea what their invention of the Internet would morph into.

And those of use who were using the Internet before the unwashed mob joined us have rued and regretted it almost every day since.

See also [Eternal September](http://en.wikipedia.org/wiki/Eternal_September).

---

<div class="post-metadata">

**Author:** ![Senegoid](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/senegoid/32/6606_2.png) [@Senegoid](https://boards.straightdope.com/u/Senegoid)\
**Post date:** [September 18, 2012, 6:32pm UTC](https://boards.straightdope.com/t/email-spam-how-is-this-happening/635002/15 "2012-09-18T18:32:25Z")

</div>

> [@Canadjun](#):
>
> When the SMTP and other protocols were developed, the Internet and its predecessors were basically a research tool for the universities and other research organizations. There was no real need at the time for fancy authentication; screwing around would make your sysadmin cranky, which was a pretty good disincentive at the time. It’s doubtful that the early designers had any idea what their invention of the Internet would morph into.

Understood. . . .

> [@gnoitall](#):
>
> And those of use who were using the Internet before the unwashed mob joined us have rued and regretted it almost every day since.

. . . and agreed. (Speaking as one who used Usenet in the mid-1980’s, when it was still limited to a more washed sort of mob.)
