# Hey Spammers - 2 can play at that game.

**URL:** <https://boards.straightdope.com/t/hey-spammers-2-can-play-at-that-game/336859>\
**Category:** Factual Questions\
**Created:** [December 22, 2005, 9:14pm UTC](https://boards.straightdope.com/t/hey-spammers-2-can-play-at-that-game/336859 "2005-12-22T21:14:15Z")\
**Posts on this page:** 7\
**Page:** 2

<div class="post-metadata">

**Author:** ![Gary\_Robson](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/gary_robson/32/3448_2.png) [@Gary\_Robson](https://boards.straightdope.com/u/Gary_Robson)\
**Post date:** [December 23, 2005, 11:35pm UTC](https://boards.straightdope.com/t/hey-spammers-2-can-play-at-that-game/336859/21 "2005-12-23T23:35:10Z")

</div>

Doggone it! My last post wasn’t referring to you, **wolf\_meister**. I forgot to preview and you snuck in between my reading the thread and responding to it.

I just thought it was great that **Futile Gesture** pointed out why feeding bad email addresses to spambots is a…well…futile gesture.

> [@cazzle](#):
>
> The true goal of [WebPoison.org](http://WebPoison.org) is to make spam spiders pay attention to the “robots” meta tag.

Pardon my cynicism, but spammers haven’t backed off due to filters, mailbombing, threat calls, lawsuits, fines, or jail time. I doubt that WebPoison is suddenly going to turn them into model netizens.

---

<div class="post-metadata">

**Author:** ![Seven](https://avatars.discourse-cdn.com/v4/letter/s/3d9bf3/32.png) [@Seven](https://boards.straightdope.com/u/Seven)\
**Post date:** [December 24, 2005, 2:51am UTC](https://boards.straightdope.com/t/hey-spammers-2-can-play-at-that-game/336859/22 "2005-12-24T02:51:11Z")

</div>

> [@InvisibleWombat](#):
>
> Oh, and for the gutter slime that send out spam with valid return addresses that they’ve stolen from others, it’s even worse. A spammer stuck my return address on a flood of garbage he spewed out, and all the undeliverable messages came back to me! My system’s clean, and I verified that none of this junk came from my server, but since the scuzzball used my return address, I got hundreds and hundreds of bounce messages.

Same thing happened to me.

Bastards.

---

<div class="post-metadata">

**Author:** ![wolf\_meister](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/wolf_meister/32/15202_2.png) [@wolf\_meister](https://boards.straightdope.com/u/wolf_meister)\
**Post date:** [December 24, 2005, 3:34am UTC](https://boards.straightdope.com/t/hey-spammers-2-can-play-at-that-game/336859/23 "2005-12-24T03:34:06Z")

</div>

**Invisible Wombat**  
I was wondering to what you were referring. Anyway, no problem.

**gazpacho**

> [@](#):
>
> I doubt that the lists are tested very well at all. The whole spam business is not populated by reliable ethical people.

I had the same feeling that those lists were poorly tested and I share your opinion about spammers’ subterranean standards of ethics.

* * *

I was _not_ planning to use a real domain for fooling the “bots”. (See the OP and the example address I chose: [jsmith@1h2y3n6g7s8e9ko3j6n7s8q9x0a5f6.com](mailto:jsmith@1h2y3n6g7s8e9ko3j6n7s8q9x0a5f6.com))

Anyway, the idea seems useless and as others have said more harmful than beneficial and I’m not going to use it.  
Okay, so the idea in the OP doesn’t work and it seems as if WebPoison (and other “solutions”) have their doubters. Still, as I asked in my previous posting, couldn’t there be some way to ensure that an E-Mail from a legitimate domain is being sent by that website owner and _not_ some spam impostor?

---

<div class="post-metadata">

**Author:** ![Tuckerfan](https://avatars.discourse-cdn.com/v4/letter/t/eada6e/32.png) [@Tuckerfan](https://boards.straightdope.com/u/Tuckerfan)\
**Post date:** [December 24, 2005, 4:00am UTC](https://boards.straightdope.com/t/hey-spammers-2-can-play-at-that-game/336859/24 "2005-12-24T04:00:43Z")

</div>

> [@wolf\_meister](#):
>
> **Invisible Wombat** Still, as I asked in my previous posting, couldn’t there be some way to ensure that an E-Mail from a legitimate domain is being sent by that website owner and _not_ some spam impostor?

Microsoft had proposed something like, and IIRC, AOL had said that they were going to get onboard with it, but I haven’t heard any more about it. Still, I doubt that that would even be truly effective, since it generally takes about a week or so for hackers to figure out how to beat the various copyprotection schemes companies like Sony come up with. Given that there’s plenty of good money to be made via spam, I’m sure that someone will figure out a workaround to it in a fairly short time.

---

<div class="post-metadata">

**Author:** ![wolf\_meister](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/wolf_meister/32/15202_2.png) [@wolf\_meister](https://boards.straightdope.com/u/wolf_meister)\
**Post date:** [December 24, 2005, 4:47am UTC](https://boards.straightdope.com/t/hey-spammers-2-can-play-at-that-game/336859/25 "2005-12-24T04:47:52Z")

</div>

**Tuckerfan**  
Wow that is really frustrating.  
So far, the only effective solution seems to be the one in posting #11.

---

<div class="post-metadata">

**Author:** ![Gary\_Robson](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/gary_robson/32/3448_2.png) [@Gary\_Robson](https://boards.straightdope.com/u/Gary_Robson)\
**Post date:** [December 30, 2005, 8:24pm UTC](https://boards.straightdope.com/t/hey-spammers-2-can-play-at-that-game/336859/26 "2005-12-30T20:24:11Z")

</div>

I don’t have any up-to-date details, but there are (at least) two proposals out for methods of verifying the return address on emails. One of them involves something much like a digital signature using public-key encryption, and the other involves a “ping back” system where the receiving machine does a DNS lookup on the source email address and validates it with the sending domain.

---

<div class="post-metadata">

**Author:** ![lno](https://avatars.discourse-cdn.com/v4/letter/l/a8b319/32.png) [@lno](https://boards.straightdope.com/u/lno)\
**Post date:** [December 30, 2005, 8:46pm UTC](https://boards.straightdope.com/t/hey-spammers-2-can-play-at-that-game/336859/27 "2005-12-30T20:46:01Z")

</div>

> [@Tuckerfan](#):
>
> Microsoft had proposed something like, and IIRC, AOL had said that they were going to get onboard with it, but I haven’t heard any more about it. Still, I doubt that that would even be truly effective, since it generally takes about a week or so for hackers to figure out how to beat the various copyprotection schemes companies like Sony come up with. Given that there’s plenty of good money to be made via spam, I’m sure that someone will figure out a workaround to it in a fairly short time.

You’re thinking of [SPF](http://www.schlitt.net/spf/spf_classic/draft-schlitt-spf-classic-02.html) (originally Sender Permitted From, but now Sender Policy Framework). In a nutshell, it makes it difficult to forge “From” addresses in email.

Broadly speaking, any computer can send email claiming to be from anyone. SPF would allow the administrators of the domain [example.org](http://example.org) to specify which machines are permitted senders from [example.org](http://example.org), and other mailservers would check against that list to determine the trustworthiness of an email. If the administrators of [example.org](http://example.org) restricted their SPF list to “[alice@example.org](mailto:alice@example.org)” and “[bob@example.org](mailto:bob@example.org)”, and if your mailserver received an email from “[carl@example.org](mailto:carl@example.org)”, your mailserver would flag that email as suspect.

To implement this, both the sending and receiving mailservers need to be configured.

Neither Microsoft nor AOL came up with this, and had proposed alternate implementations of it. Both [aol.com](http://aol.com) and MSN/hotmail publish their own SPF records now, and filter incoming mail based on SPF.

[Previous page](https://boards.straightdope.com/t/hey-spammers-2-can-play-at-that-game/336859.md?page=1)
