# What is up with strings of random letters in spam mail?

**URL:** <https://boards.straightdope.com/t/what-is-up-with-strings-of-random-letters-in-spam-mail/201908>\
**Category:** Factual Questions\
**Created:** [September 16, 2003, 6:42am UTC](https://boards.straightdope.com/t/what-is-up-with-strings-of-random-letters-in-spam-mail/201908 "2003-09-16T06:42:15Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![Seven](https://avatars.discourse-cdn.com/v4/letter/s/3d9bf3/32.png) [@Seven](https://boards.straightdope.com/u/Seven)\
**Post date:** [September 16, 2003, 6:42am UTC](https://boards.straightdope.com/t/what-is-up-with-strings-of-random-letters-in-spam-mail/201908/1 "2003-09-16T06:42:15Z")

</div>

> [@](#):
>
> SUPER i i FAST i i ACTING i! i! i! i AND i i QUICK i i PENIS i i ENLARGEMENTS i! i
> 
> **aqortcdjnpzd qksxcqt w vctx f cvmef r teqz**

I seem to be getting more and more spam with strings of garbage. Anyone know what’s up with that?

---

<div class="post-metadata">

**Author:** ![hajario](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/hajario/32/171_2.png) [@hajario](https://boards.straightdope.com/u/hajario)\
**Post date:** [September 16, 2003, 6:56am UTC](https://boards.straightdope.com/t/what-is-up-with-strings-of-random-letters-in-spam-mail/201908/2 "2003-09-16T06:56:46Z")

</div>

It is supposed to foil spam blocking software.

Haj

---

<div class="post-metadata">

**Author:** ![Thaumaturge](https://avatars.discourse-cdn.com/v4/letter/t/858c86/32.png) [@Thaumaturge](https://boards.straightdope.com/u/Thaumaturge)\
**Post date:** [September 16, 2003, 8:16am UTC](https://boards.straightdope.com/t/what-is-up-with-strings-of-random-letters-in-spam-mail/201908/3 "2003-09-16T08:16:33Z")

</div>

Of course, it also makes it even easier to see that it is spam and should be deleted. Not that I expect spammers to make any sense.

---

<div class="post-metadata">

**Author:** ![ccwaterback](https://avatars.discourse-cdn.com/v4/letter/c/df705f/32.png) [@ccwaterback](https://boards.straightdope.com/u/ccwaterback)\
**Post date:** [September 16, 2003, 12:21pm UTC](https://boards.straightdope.com/t/what-is-up-with-strings-of-random-letters-in-spam-mail/201908/4 "2003-09-16T12:21:59Z")

</div>

Since the OP got answered lickety-split, I hope you don’t mind the hijack.

Any body out there know how spam detectors work?

(I know, they look for MY name in the “from” field, but other than that.)

---

<div class="post-metadata">

**Author:** ![RealityChuck](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/realitychuck/32/195_2.png) [@RealityChuck](https://boards.straightdope.com/u/RealityChuck)\
**Post date:** [September 16, 2003, 12:29pm UTC](https://boards.straightdope.com/t/what-is-up-with-strings-of-random-letters-in-spam-mail/201908/5 "2003-09-16T12:29:56Z")

</div>

> [@](#):
>
> \*Originally posted by Thaumaturge \*  
> \*\*Of course, it also makes it even easier to see that it is spam and should be deleted. Not that I expect spammers to make any sense. \*\*

Not really. It’s hard to program a computer to recognize random characters as something to be blocked.

Many spam blockers block on words in the messages. If a certain percentage of words in the message are indicators of spam, then the message is blocked. However, random characters aren’t in the database.

For instance, suppose your spam blocker considers the word “fnord” to be an indicator of spam. Thus the message “fnord” gets a 100% spam count. Now add the random characters: “fnord nkdnfe khnn nnbubu bkfbjkda” The trigger word is only 20% of the message. This may be enough to sneak by.

---

<div class="post-metadata">

**Author:** ![bradwalt](https://avatars.discourse-cdn.com/v4/letter/b/858c86/32.png) [@bradwalt](https://boards.straightdope.com/u/bradwalt)\
**Post date:** [September 16, 2003, 1:28pm UTC](https://boards.straightdope.com/t/what-is-up-with-strings-of-random-letters-in-spam-mail/201908/6 "2003-09-16T13:28:13Z")

</div>

Spam senders can generate thousands of copies , with each recipient getting a different string of random characters. The sender’s ISP won’t recognize this as a “mass e-mail” since each recipient is getting a unique copy.

---

<div class="post-metadata">

**Author:** ![dwc1970](https://avatars.discourse-cdn.com/v4/letter/d/a183cd/32.png) [@dwc1970](https://boards.straightdope.com/u/dwc1970)\
**Post date:** [September 16, 2003, 4:54pm UTC](https://boards.straightdope.com/t/what-is-up-with-strings-of-random-letters-in-spam-mail/201908/7 "2003-09-16T16:54:15Z")

</div>

Could ISP’s run spell-checking with its spam filters? It would have to be a more advanced form of spell-checking since many legitimate people make misspellings in email. It could work so that misspelled words could at least be flagged with alternate suggestions. If too many of the “words” don’t resemble valid words and cannot be flagged with correct spelling suggestions then the email could be targeted as spam. Any thoughts on this idea?

---

<div class="post-metadata">

**Author:** ![NutWrench](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/nutwrench/32/20193_2.png) [@NutWrench](https://boards.straightdope.com/u/NutWrench)\
**Post date:** [September 16, 2003, 5:01pm UTC](https://boards.straightdope.com/t/what-is-up-with-strings-of-random-letters-in-spam-mail/201908/8 "2003-09-16T17:01:56Z")

</div>

The random letters are a way of creating a unique CRC code for each spam so that they can’t be mass-deleted by anti-spam software.

Spammer should die like pigs in hell.

---

<div class="post-metadata">

**Author:** ![Merijeek](https://avatars.discourse-cdn.com/v4/letter/m/f05b48/32.png) [@Merijeek](https://boards.straightdope.com/u/Merijeek)\
**Post date:** [September 16, 2003, 5:04pm UTC](https://boards.straightdope.com/t/what-is-up-with-strings-of-random-letters-in-spam-mail/201908/9 "2003-09-16T17:04:45Z")

</div>

> [@](#):
>
> \*Originally posted by dwc1970 \*  
> \*\*Could ISP’s run spell-checking with its spam filters? It would have to be a more advanced form of spell-checking since many legitimate people make misspellings in email. It could work so that misspelled words could at least be flagged with alternate suggestions. If too many of the “words” don’t resemble valid words and cannot be flagged with correct spelling suggestions then the email could be targeted as spam. Any thoughts on this idea? \*\*

Still won’t help.

Instead of putting strings of random characters, they’ll just strings of random words. Those random words are legit, and so it still makes it through.

Of course, the moment a spam blocker blocks a legitemate e-mail, well, it’s getting uninstalled.

-Joe

---

<div class="post-metadata">

**Author:** ![Moo\_the\_Magic\_Cow](https://avatars.discourse-cdn.com/v4/letter/m/ebca7d/32.png) [@Moo\_the\_Magic\_Cow](https://boards.straightdope.com/u/Moo_the_Magic_Cow)\
**Post date:** [September 16, 2003, 8:51pm UTC](https://boards.straightdope.com/t/what-is-up-with-strings-of-random-letters-in-spam-mail/201908/10 "2003-09-16T20:51:11Z")

</div>

**RealityChuck** , I think what Thaumaturge meant was that it made it easier for a human to recognize the e-mail as spam(as opposed to all the spam I get from “June” about “The meeting”).

---

<div class="post-metadata">

**Author:** ![Seven](https://avatars.discourse-cdn.com/v4/letter/s/3d9bf3/32.png) [@Seven](https://boards.straightdope.com/u/Seven)\
**Post date:** [September 17, 2003, 8:15am UTC](https://boards.straightdope.com/t/what-is-up-with-strings-of-random-letters-in-spam-mail/201908/11 "2003-09-17T08:15:18Z")

</div>

Thwarting spam-blocking was what I was thinking, I just wasn’t sure.

In a way I kind of like having “hjdgfdlgjewo0rgjklfjhsdg” in the subject line because I know it’s spam and I can just delete it.

---

<div class="post-metadata">

**Author:** ![Hari\_Seldon](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/hari_seldon/32/5173_2.png) [@Hari\_Seldon](https://boards.straightdope.com/u/Hari_Seldon)\
**Post date:** [September 17, 2003, 12:40pm UTC](https://boards.straightdope.com/t/what-is-up-with-strings-of-random-letters-in-spam-mail/201908/12 "2003-09-17T12:40:08Z")

</div>

Here is the report I got from SpamAssassin on a piece of spam that I selected at random. Note that 6 points is very marginal and I have seen things with over 20 points, but these are some of the things is looks for:

Content preview: Firmallean Complimentary Supply  
4983yuhrkjhfruiyfr89uy3uioh43ijh NEW SCIENCE BREAKTHR0UGH […]

Content analysis details: (6.00 points, 5 required)  
SUBJ\_REMOVE (0.5 points) BODY: List removal information  
HTML\_FONT\_FACE\_ODD (0.2 points) BODY: HTML font face is not a commonly used  
face  
HTML\_FONT\_COLOR\_RED (0.1 points) BODY: HTML font color is red  
HTML\_WEB\_BUGS (0.1 points) BODY: Image tag with an ID code to identify  
you  
HTML\_MESSAGE (0.1 points) BODY: HTML included in message  
HTML\_IMAGE\_ONLY\_08 (0.9 points) BODY: HTML has images with 600-800 bytes of  
words  
HTML\_IMAGE\_RATIO\_12 (0.3 points) BODY: HTML has a low ratio of text to image  
area  
HTML\_FONT\_BIG (0.1 points) BODY: FONT Size +2 and up or 3 and up  
HTML\_FONT\_COLOR\_UNSAFE (0.1 points) BODY: HTML font color not within safe  
6x6x6 palette  
HTML\_FONT\_BIG\_B (0.5 points) BODY: HTML has a big “font” and “B” tag combo  
HTML\_TAG\_EXISTS\_TBODY (0.1 points) BODY: HTML has “tbody” tag  
HTML\_70\_80 (0.4 points) BODY: Message is 70% to 80% HTML  
MAILTO\_WITH\_SUBJ\_REMOVE (0.5 points) BODY: mailto URI includes removal text  
MAILTO\_WITH\_SUBJ (0.1 points) URI: Includes a link to send a mail with a  
subject  
MAILTO\_TO\_REMOVE (0.4 points) URI: Includes a ‘remove’ email address  
DATE\_IN\_FUTURE\_03\_06 (0.9 points) Date: is 3 to 6 hours after Received: date  
RCVD\_IN\_SBL (0.6 points) RBL: Received via SBLed relay, see  
[http://www.spamhaus.org/sbl/](http://www.spamhaus.org/sbl/)  
[RBL check: found [107.16.6.69.sbl.spamhaus.org](http://107.16.6.69.sbl.spamhaus.org).]  
MIME\_HTML\_ONLY (0.1 points) Message only has text/html MIME parts

The original message did not contain plain text, and may be unsafe to  
open with some email clients; in particular, it may contain a virus,  
or confirm that your address can receive spam. If you wish to view  
it, it may be safer to save it to a file and open it with an editor.

---

<div class="post-metadata">

**Author:** ![RealityChuck](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/realitychuck/32/195_2.png) [@RealityChuck](https://boards.straightdope.com/u/RealityChuck)\
**Post date:** [September 17, 2003, 2:43pm UTC](https://boards.straightdope.com/t/what-is-up-with-strings-of-random-letters-in-spam-mail/201908/13 "2003-09-17T14:43:46Z")

</div>

> [@](#):
>
> \*Originally posted by Moo the Magic Cow \*  
> \*\ ***RealityChuck** , I think what Thaumaturge meant was that it made it easier for a human to recognize the e-mail as spam(as opposed to all the spam I get from “June” about “The meeting”). \*\*

That’s true, but it doesn’t matter to the spammers. They want to get into as many inboxes as possible, even if people delete them without reading. There’s always a percentage that _will_ read them, so a spammer’s goal is to find ways to get past the spam filters, even if it identifies it as spam to the more savvy users.

After all, do you really think spammers are interested in intelligent people? They’re hoping to hook people who are dumb enough to believe their claims. And if you’re dumb enough to do that, you’re dumb enough not to realize the random characters are a marker for spam. 🙂

---

<div class="post-metadata">

**Author:** ![Chronos](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/chronos/32/134_2.png) [@Chronos](https://boards.straightdope.com/u/Chronos)\
**Post date:** [September 17, 2003, 4:17pm UTC](https://boards.straightdope.com/t/what-is-up-with-strings-of-random-letters-in-spam-mail/201908/14 "2003-09-17T16:17:28Z")

</div>

> [@](#):
>
> HTML\_WEB\_BUGS (0.1 points) BODY: Image tag with an ID code to identify you

Why is this only a tenth of a point? Is there any conceivable reason for a legitimate e-mail to include a bugged image tag? Were I setting the filters, I would probably put that above threshhold, right there.
