# Is there any way to stop spam being sent FROM my domain?

**URL:** <https://boards.straightdope.com/t/is-there-any-way-to-stop-spam-being-sent-from-my-domain/427334>\
**Category:** Factual Questions\
**Created:** [November 21, 2007, 4:54pm UTC](https://boards.straightdope.com/t/is-there-any-way-to-stop-spam-being-sent-from-my-domain/427334 "2007-11-21T16:54:20Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![NajaNivea](https://avatars.discourse-cdn.com/v4/letter/n/22d042/32.png) [@NajaNivea](https://boards.straightdope.com/u/NajaNivea)\
**Post date:** [November 21, 2007, 4:54pm UTC](https://boards.straightdope.com/t/is-there-any-way-to-stop-spam-being-sent-from-my-domain/427334/1 "2007-11-21T16:54:20Z")

</div>

It’s not actually being sent from my account, but I know there’s spam out in the world being masked and showing up in people’s inboxes as being from **spamityspam** @[mydomain].com. Very occasionally I’m unable to send someone a message as their servers have blocked my domain because of this. Occasionally I get spam “returned” to my inbox as being unable to send, like so:

> [@returnedspam](#):
>
> Hi. This is the qmail-send program at [keytrail.com](http://keytrail.com).  
> I’m afraid I wasn’t able to deliver your message to the following addresses.  
> This is a permanent error; I’ve given up. Sorry it didn’t work out.
> 
> \<younginbreedransom@pythonchallenge.com\>:  
> Sorry. Although I’m listed as a best-preference MX or A for that host,  
> it isn’t in my control/locals file, so I don’t treat it as local. (#5.4.6)
> 
> — Below this line is a copy of the message.
> 
> Return-Path: \< **myactualaddress** @ **myactualdomain**.com\>  
> Received: (qmail 1724 invoked from network); 21 Nov 2007 05:02:51 -0000  
> Received: from [agropodderzhka.krsn.ru](http://agropodderzhka.krsn.ru) (HELO [clients.krsn.ru](http://clients.krsn.ru)) (217.117.182.57)  
> by [www.keytrail.com](http://www.keytrail.com) with SMTP; 21 Nov 2007 05:02:51 -0000  
> Received: from Robert Norris (10.12.13.17) by [clients.krsn.ru](http://clients.krsn.ru) (PowerMTA™ v3.2r4) id hfp19o45d64j71 for \<younginbreedransom@pythonchallenge.com\>; Wed, 21 Nov 2007 12:07:41 +0700  
> Message-Id: \<20071121190741.15885.qmail@clients.krsn.ru\>  
> To: \<younginbreedransom@pythonchallenge.com\>  
> Subject: November 74% OFF  
> From: Canadian Doctor Louisa Hogue \<younginbreedransom@pythonchallenge.com\>  
> MIME-Version: 1.0  
> Content-Type: text/plain; charset=“iso-8859-1”  
> Content-Transfer-Encoding: 8bit
> 
> Best Price for VIAGRA & CIALIS ONLINE, All Credit Cards Accepted, FREE DELIVERY

Now, I categorically did not send that, and have never, to my knowledge, discussed the selling or purchasing of any erectile dysfunction medications, online or off. I also don’t recognize any of the other information contained in the header.  
Is there anything I can do to stop this kind of thing?

---

<div class="post-metadata">

**Author:** ![Yag\_Rannavach](https://avatars.discourse-cdn.com/v4/letter/y/858c86/32.png) [@Yag\_Rannavach](https://boards.straightdope.com/u/Yag_Rannavach)\
**Post date:** [November 21, 2007, 5:07pm UTC](https://boards.straightdope.com/t/is-there-any-way-to-stop-spam-being-sent-from-my-domain/427334/2 "2007-11-21T17:07:23Z")

</div>

No. You can add an spf record which will cause some servers to reject the mail before it hits their spam filters, but not every server supports it.

Unless you’re running an open relay…Check to make sure your mail server requires a username/pass before it will send.

---

<div class="post-metadata">

**Author:** ![Lightnin](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/lightnin/32/180_2.png) [@Lightnin](https://boards.straightdope.com/u/Lightnin)\
**Post date:** [November 21, 2007, 5:09pm UTC](https://boards.straightdope.com/t/is-there-any-way-to-stop-spam-being-sent-from-my-domain/427334/3 "2007-11-21T17:09:48Z")

</div>

Odds are, the spam isn’t being sent from your domain. The spammer’s just putting your domain name in the “sent from” box. And no, there’s nothing you can do about it.

I get a lot of spam bounces to my domain as well. I just set GMail to forward emails that complain about it into my spam folder. Nothing I can do about it, so why bother reading it?

---

<div class="post-metadata">

**Author:** ![Yag\_Rannavach](https://avatars.discourse-cdn.com/v4/letter/y/858c86/32.png) [@Yag\_Rannavach](https://boards.straightdope.com/u/Yag_Rannavach)\
**Post date:** [November 21, 2007, 5:14pm UTC](https://boards.straightdope.com/t/is-there-any-way-to-stop-spam-being-sent-from-my-domain/427334/4 "2007-11-21T17:14:31Z")

</div>

Missed the edit window.

I realize that what I said may not be crystal clear 😉

The spf record says “These server(s) are authorized to send from my domain”, and then receiving mail servers can (optionally) check the spf record to see if the mail was sent from the right server. It doesn’t stop the mail getting sent or rejected, but it can stop your domain getting flagged as a spammer.

---

<div class="post-metadata">

**Author:** ![NajaNivea](https://avatars.discourse-cdn.com/v4/letter/n/22d042/32.png) [@NajaNivea](https://boards.straightdope.com/u/NajaNivea)\
**Post date:** [November 21, 2007, 6:53pm UTC](https://boards.straightdope.com/t/is-there-any-way-to-stop-spam-being-sent-from-my-domain/427334/5 "2007-11-21T18:53:25Z")

</div>

[QUOTE=Lightnin’]  
Odds are, the spam isn’t being sent from your domain. The spammer’s just putting your domain name in the “sent from” box.  
[/quote]

I know–it was just the most concise title I could come up with.

> [@](#):
>
> And no, there’s nothing you can do about it.
> 
> I get a lot of spam bounces to my domain as well. I just set GMail to forward emails that complain about it into my spam folder. Nothing I can do about it, so why bother reading it?

Sigh.  
That’s sort of what I figured.  
**Yag** , I’ll look into it and see if I can make that happen.

Thanks, all!

---

<div class="post-metadata">

**Author:** ![CookingWithGas](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cookingwithgas/32/485_2.png) [@CookingWithGas](https://boards.straightdope.com/u/CookingWithGas)\
**Post date:** [November 21, 2007, 9:16pm UTC](https://boards.straightdope.com/t/is-there-any-way-to-stop-spam-being-sent-from-my-domain/427334/6 "2007-11-21T21:16:22Z")

</div>

This is the equivalent of someone putting your name as the return address on a letter that someone else is sending, and it’s just as impossible to prevent.

---

<div class="post-metadata">

**Author:** ![ianzin](https://avatars.discourse-cdn.com/v4/letter/i/ed655f/32.png) [@ianzin](https://boards.straightdope.com/u/ianzin)\
**Post date:** [November 21, 2007, 10:24pm UTC](https://boards.straightdope.com/t/is-there-any-way-to-stop-spam-being-sent-from-my-domain/427334/7 "2007-11-21T22:24:12Z")

</div>

It’s called back scattering (or backscattering). I’ve been the victim of it as well. There is apparently little or nothing you can do about it - at least not once it’s happened.

When you first register your domain and create your website, you can take some precautions to lessen the risk of it happening. The point is to eliminate any plain text reference to your domain anywhere on your site, because this makes it easy for spiders and bots to harvest your domain name. If you must include a reference to your own domain, include extraneous characters and tell human readers to ignore them e.g. contact [john@mydomainxxx.com](mailto:john@mydomainxxx.com) (but delete the xxx bit). Humans can do this easily, spiders and bots can’t do it. Or only include your domain name embedded in a graphic. This isn’t the perfect solution, but it eliminates one common source of the problem.

---

<div class="post-metadata">

**Author:** ![Tim\_T-Bonham.net](https://avatars.discourse-cdn.com/v4/letter/t/46a35a/32.png) [@Tim\_T-Bonham.net](https://boards.straightdope.com/u/Tim_T-Bonham.net)\
**Post date:** [November 26, 2007, 12:47am UTC](https://boards.straightdope.com/t/is-there-any-way-to-stop-spam-being-sent-from-my-domain/427334/8 "2007-11-26T00:47:45Z")

</div>

[QUOTE=ianzin]  
It’s called back scattering (or backscattering). I’ve been the victim of it as well. There is apparently little or nothing you can do about it - at least not once it’s happened.

[/QUOTE]  
The same thing can happen with regular postal mail, too, you know.

A few years ago, we had a situation where some cowardly bigot would send crude anti-gay letters to any person mentioned in the newspaper as being gay, saying anything positive about a gay person, law enforcement people who arrested or prosecuted any gay bashers, etc. In the return address spot on the mailing envelope, he would put the address of someone else, often a local black or native american organization, or the home address of a community leader in one of those groups.

Besides hiding his own address, he was apparently trying to incite bad feelings between various Twin Cities minority groups.

So using a false return address is not new to Internet spam!

---

<div class="post-metadata">

**Author:** ![TimeWinder](https://avatars.discourse-cdn.com/v4/letter/t/bcef8e/32.png) [@TimeWinder](https://boards.straightdope.com/u/TimeWinder)\
**Post date:** [November 26, 2007, 2:12am UTC](https://boards.straightdope.com/t/is-there-any-way-to-stop-spam-being-sent-from-my-domain/427334/9 "2007-11-26T02:12:20Z")

</div>

[QUOTE=ianzin]  
When you first register your domain and create your website, you can take some precautions to lessen the risk of it happening. The point is to eliminate any plain text reference to your domain anywhere on your site, because this makes it easy for spiders and bots to harvest your domain name. If you must include a reference to your own domain, include extraneous characters and tell human readers to ignore them e.g. contact [john@mydomainxxx.com](mailto:john@mydomainxxx.com) (but delete the xxx bit). Humans can do this easily, spiders and bots can’t do it. Or only include your domain name embedded in a graphic. This isn’t the perfect solution, but it eliminates one common source of the problem.  
[/QUOTE]

On the other hand, users can’t click on such links (if you make them so they can, the robot can harvest the actual address), which makes them a lot less useful for actual businesses. Relying on your customers to \*type \*a URL, or carefully delete characters out of an email address in their “send” line, regardless of how short or simple, is a good way to reduce your customer base. Some won’t be able to figure out how to do it, others won’t be bothered, and some won’t even notice that they have to, and will end up sending their messages nowhere. Plus, it makes you look like a fly-by-night business that can’t afford a real spam filter (or worse, doesn’t know how to use one). So it depends on exactly what the domain name is used for whether this greeking of addresses is a good idea.
