# Spam with a link to twitter -- Dangerous?

**URL:** <https://boards.straightdope.com/t/spam-with-a-link-to-twitter-dangerous/1011151>\
**Category:** Factual Questions\
**Created:** [December 4, 2024, 12:32pm UTC](https://boards.straightdope.com/t/spam-with-a-link-to-twitter-dangerous/1011151 "2024-12-04T12:32:29Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![chappachula](https://avatars.discourse-cdn.com/v4/letter/c/d2c977/32.png) [@chappachula](https://boards.straightdope.com/u/chappachula)\
**Post date:** [December 4, 2024, 12:32pm UTC](https://boards.straightdope.com/t/spam-with-a-link-to-twitter-dangerous/1011151/1 "2024-12-04T12:32:29Z")

</div>

I have received 4 spammy emails in the past 3 days from the same sender.  
Background info:  
The sender is a friend in my email contacts.  
The email “To” line contains 5 or 6 names, some of which are mutual friends of mine and the sender, but listed weirdly, with the letters utf 8 added between the names…  
The “To” line reads: utf 8 JoeSmith, utf 8 David, utf 8 MikeJones

I’m guessing that a hacker accessed my friend’s email contacts, and used his address to send a message to everybody in the list.

Now my question, which is about the content of the spammed mails:  
each mail contains nothing but a link. the link starts with https and goes to a site called [t.co](http://t.co) . Am I right that this is a twitter link?  
The full link is similar to https:// [t.co/](http://t.co/) XMAA12345F  
(without the spaces). there are 10 characters after the final slash,  
but the 10 characters are different each time.There is no other text or attachment.

So my question is : how dangerous would it be if I had clicked on the link? What is the spammer trying to do?

---

<div class="post-metadata">

**Author:** ![dolphinboy](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dolphinboy/32/330_2.png) [@dolphinboy](https://boards.straightdope.com/u/dolphinboy)\
**Post date:** [December 4, 2024, 12:39pm UTC](https://boards.straightdope.com/t/spam-with-a-link-to-twitter-dangerous/1011151/2 "2024-12-04T12:39:07Z")

</div>

I have no idea what the spammer was trying to do, but I sure wouldn’t click on a link from any spam email I received. Better safe than sorry.

You might want to contact one of your cohorts, who presumably got the same message you did, and see if they clicked on the link, and if they did, what happened.

---

<div class="post-metadata">

**Author:** ![snowthx](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/snowthx/32/10660_2.png) [@snowthx](https://boards.straightdope.com/u/snowthx)\
**Post date:** [December 4, 2024, 12:45pm UTC](https://boards.straightdope.com/t/spam-with-a-link-to-twitter-dangerous/1011151/3 "2024-12-04T12:45:41Z")

</div>

Yeah, I wouldn’t bother analyzing a spam email link, much less click on it. Assume it’s dangerous. My default is instant delete, no questions asked. The OP is like “what would happen if I poked this hornet nest with a chopstick?”

---

<div class="post-metadata">

**Author:** ![Northern\_Piper](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/northern_piper/32/5304_2.png) [@Northern\_Piper](https://boards.straightdope.com/u/Northern_Piper)\
**Post date:** [December 4, 2024, 12:46pm UTC](https://boards.straightdope.com/t/spam-with-a-link-to-twitter-dangerous/1011151/4 "2024-12-04T12:46:46Z")

</div>

And tell your friend that their e-mail account got hacked.

---

<div class="post-metadata">

**Author:** ![Cervaise](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cervaise/32/16693_2.png) [@Cervaise](https://boards.straightdope.com/u/Cervaise)\
**Post date:** [December 4, 2024, 12:53pm UTC](https://boards.straightdope.com/t/spam-with-a-link-to-twitter-dangerous/1011151/5 "2024-12-04T12:53:11Z")

</div>

> [@snowthx](#):
>
> The OP is like “what would happen if I poked this hornet nest with a chopstick?”

“Mmm, what is the chopstick made out of?”

---

<div class="post-metadata">

**Author:** ![Jackmannii](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/jackmannii/32/311_2.png) [@Jackmannii](https://boards.straightdope.com/u/Jackmannii)\
**Post date:** [December 4, 2024, 12:59pm UTC](https://boards.straightdope.com/t/spam-with-a-link-to-twitter-dangerous/1011151/6 "2024-12-04T12:59:36Z")

</div>

[t.co](http://t.co) links were instituted on Twitter to substitute for user-posted URLs, supposedly as a security measure.

It hasn’t always worked out that way.

> **[Twitter URL Shortening Service Being Utilized In Phishing Campaigns — Mesh |...](https://www.meshsecurity.io/blog/twitter-urls)**
>
> Hackers have found a new way to attack your mailbox: through URL shortening services. Read this article to learn more about these malicious attacks and how best to spot them.

---

<div class="post-metadata">

**Author:** ![chappachula](https://avatars.discourse-cdn.com/v4/letter/c/d2c977/32.png) [@chappachula](https://boards.straightdope.com/u/chappachula)\
**Post date:** [December 4, 2024, 1:02pm UTC](https://boards.straightdope.com/t/spam-with-a-link-to-twitter-dangerous/1011151/7 "2024-12-04T13:02:14Z")

</div>

T

> [@Jackmannii](#):
>
> supposedly as a security measure.

that’s what I was wondering. I had heard that [t.co](http://t.co) links were supposed to be safe.  
Also, I’m wondering why each link is different. If a spammer wants me to click on his website, or download his virus, or whatever, why create a different link each time?

---

<div class="post-metadata">

**Author:** ![ftg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ftg/32/2801_2.png) [@ftg](https://boards.straightdope.com/u/ftg)\
**Post date:** [December 4, 2024, 4:11pm UTC](https://boards.straightdope.com/t/spam-with-a-link-to-twitter-dangerous/1011151/8 "2024-12-04T16:11:50Z")

</div>

With shortening, many pseudo-links can point to the same thing. Creating pseudo-links is very simple, i.e., can be automated, and avoids filters. Someone setting up a filter would have to block each pseudo-link.
