# What's with the empty bodiless emails?

**URL:** <https://boards.straightdope.com/t/whats-with-the-empty-bodiless-emails/227953>\
**Category:** Factual Questions\
**Created:** [February 7, 2004, 6:17am UTC](https://boards.straightdope.com/t/whats-with-the-empty-bodiless-emails/227953 "2004-02-07T06:17:20Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![AHunter3](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ahunter3/32/368_2.png) [@AHunter3](https://boards.straightdope.com/u/AHunter3)\
**Post date:** [February 7, 2004, 6:17am UTC](https://boards.straightdope.com/t/whats-with-the-empty-bodiless-emails/227953/1 "2004-02-07T06:17:20Z")

</div>

I’ve gotten quite a raft of emails lately that have subjects and other headers but no body.

I don’t just mean no _visible_ body, either. There’s no HTML, no microscopic img src trying to reference some site so as to tell them my email address is valid, just nothing at all.

I do realize they do this kind of thing sometimes just to compose a bounce list to compare with their general spam-mailing list. But why so many lately?

Is it possible that they were virus-laden at one time and that AV software along the route quarantined the attachment while allowing the email itself to pass through?

---

<div class="post-metadata">

**Author:** ![TJdude825](https://avatars.discourse-cdn.com/v4/letter/t/dec6dc/32.png) [@TJdude825](https://boards.straightdope.com/u/TJdude825)\
**Post date:** [February 7, 2004, 8:38am UTC](https://boards.straightdope.com/t/whats-with-the-empty-bodiless-emails/227953/2 "2004-02-07T08:38:03Z")

</div>

I get them too. Mine usually have no subject either. Maybe someone’s just trying to be annoying.

---

<div class="post-metadata">

**Author:** ![Cillasi](https://avatars.discourse-cdn.com/v4/letter/c/71e660/32.png) [@Cillasi](https://boards.straightdope.com/u/Cillasi)\
**Post date:** [February 7, 2004, 11:57am UTC](https://boards.straightdope.com/t/whats-with-the-empty-bodiless-emails/227953/3 "2004-02-07T11:57:24Z")

</div>

Have you tried highlighting the body of the message? I remember getting some of those and when you click and drag your cursor over the body, the message magically appears. It’s usually not worth the effort though.

---

<div class="post-metadata">

**Author:** ![AHunter3](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ahunter3/32/368_2.png) [@AHunter3](https://boards.straightdope.com/u/AHunter3)\
**Post date:** [February 7, 2004, 4:12pm UTC](https://boards.straightdope.com/t/whats-with-the-empty-bodiless-emails/227953/4 "2004-02-07T16:12:46Z")

</div>

Eudora has a “mode” in which email is displayed as plain ASCII. All formatting is displayed as the HTML code and the otherwise-formatted text remains plain black 9 point Monaco. That’s how I know there’s no text and no other body content. No 1-point white text. No \<IMG SRC=“phonyimage\_serialnumber1234556”\> to hit their serve and tag their log file (“aha this one looked”). Nada.

Got four more this morning. The subject is almost always “Hello”, “hey”, or “Hi there”.

---

<div class="post-metadata">

**Author:** ![spingears](https://avatars.discourse-cdn.com/v4/letter/s/ebca7d/32.png) [@spingears](https://boards.straightdope.com/u/spingears)\
**Post date:** [February 7, 2004, 4:37pm UTC](https://boards.straightdope.com/t/whats-with-the-empty-bodiless-emails/227953/5 "2004-02-07T16:37:49Z")

</div>

Are you telling us that you open emails from UNKNOWN parties?

Do you know the risks?

I seldom if ever open any email from any unknown source.

Act “Recklessly.” Delete without remorse or risking a virus!

---

<div class="post-metadata">

**Author:** ![ftg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ftg/32/2801_2.png) [@ftg](https://boards.straightdope.com/u/ftg)\
**Post date:** [February 7, 2004, 4:48pm UTC](https://boards.straightdope.com/t/whats-with-the-empty-bodiless-emails/227953/6 "2004-02-07T16:48:29Z")

</div>

There is _no_ danger in reading an email _as plain text_ assuming you are using an intelligent email program (e.g., Eudora, not Outlook).

I _only_ read email as plain text regardless of source.

I will from time to time look at obvious spam to see what’s new in the world of big jerks. How they’re getting around spam filters, etc.

Note that the subject line itself can have a hidden image tag, but any recently updated email program should dispose of those. There may have only been such a subject line “web bug” and nothing else.

Note that some spam/anti-virus filters automatically remove any “suspect” parts of a message body before you see it.

Last year spammers started getting around filters by having bodies that consisted only of a gif of their message. No text to parse. The latest trend is to use sequences of random words to get around so-called Bayesian filters.

I have no idea why they think that a subject line of:  
building equate flower descend mulberry  
is going to get me to read the body.

---

<div class="post-metadata">

**Author:** ![AHunter3](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ahunter3/32/368_2.png) [@AHunter3](https://boards.straightdope.com/u/AHunter3)\
**Post date:** [February 7, 2004, 8:16pm UTC](https://boards.straightdope.com/t/whats-with-the-empty-bodiless-emails/227953/7 "2004-02-07T20:16:54Z")

</div>

**spingears** :

> [@](#):
>
> Are you telling us that you open emails from UNKNOWN parties?
> 
> Do you know the risks?
> 
> I seldom if ever open any email from any unknown source.

I’m on a Mac.

---

<div class="post-metadata">

**Author:** ![yosemite](https://avatars.discourse-cdn.com/v4/letter/y/3ab097/32.png) [@yosemite](https://boards.straightdope.com/u/yosemite)\
**Post date:** [February 7, 2004, 10:19pm UTC](https://boards.straightdope.com/t/whats-with-the-empty-bodiless-emails/227953/8 "2004-02-07T22:19:19Z")

</div>

Yeah, I’ve noticed this too. Weird. But like you, AHunter, since I’m on a Mac too, I don’t worry about “getting” anything.

---

<div class="post-metadata">

**Author:** ![filmore](https://avatars.discourse-cdn.com/v4/letter/f/7993a0/32.png) [@filmore](https://boards.straightdope.com/u/filmore)\
**Post date:** [February 7, 2004, 10:48pm UTC](https://boards.straightdope.com/t/whats-with-the-empty-bodiless-emails/227953/9 "2004-02-07T22:48:36Z")

</div>

I have received emails with no subject and no content. They are addressed to undisclosed-recepients. Here are the headers from a recent one:

> [@](#):
>
> Received: from [rdu163-104-168.nc.rr.com](http://rdu163-104-168.nc.rr.com) ([rdu163-104-168.nc.rr.com](http://rdu163-104-168.nc.rr.com) [24.163.104.168])  
> by [e3.ny.us.ibm.com](http://e3.ny.us.ibm.com) (8.12.10/8.12.9) with SMTP id i147fIt0712606;  
> Wed, 4 Feb 2004 02:41:21 -0500  
> Date: Wed, 4 Feb 2004 02:41:21 -0500  
> From: [cxioa@excite.com](mailto:cxioa@excite.com)  
> Message-Id: \<[200402040741.i147fIt0712606@e3.ny.us.ibm.com](mailto:200402040741.i147fIt0712606@e3.ny.us.ibm.com)\>  
> To: undisclosed-recipients:;  
> Status: OR

There is no message body.

My guess is this type of email is from spammers attempting to verify email addresses. Perhaps the return address is a vaild address and it will get the bounce messages so they know which emails are not valid.

---

<div class="post-metadata">

**Author:** ![Mangetout](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/mangetout/32/19_2.png) [@Mangetout](https://boards.straightdope.com/u/Mangetout)\
**Post date:** [February 8, 2004, 12:41am UTC](https://boards.straightdope.com/t/whats-with-the-empty-bodiless-emails/227953/10 "2004-02-08T00:41:44Z")

</div>

I’ve had a rash of these lately; it could be one of a number of things:

-A spammer having set up some automated mailer incorrectly

-Your ISP having excised some malicious attachment (I had assumed this the case, however, on reflection, they usually insert a comment to say that they have removed something).

-Someone just trying to be annoying

-Someone hoping that you’ll reply with “WTF?”, thus confirming your account is live and worth spamming.

-Something else.

---

<div class="post-metadata">

**Author:** ![Markxxx](https://avatars.discourse-cdn.com/v4/letter/m/5daacb/32.png) [@Markxxx](https://boards.straightdope.com/u/Markxxx)\
**Post date:** [February 8, 2004, 2:12am UTC](https://boards.straightdope.com/t/whats-with-the-empty-bodiless-emails/227953/11 "2004-02-08T02:12:08Z")

</div>

When I was the systems analyst for a hotel we got rid of all executable programs. If it was one with .exe or others like it, it would simply remove the file. For everyone. All exe (and like) files had to be passed thru myself or the MIS person. This would result in a text message with no file. Of course then everyone just opened a YAHOO account and went around it. So we gave it up.

Perhaps there is a virus or worm and all it does is read someones address book and send out a blank email to everyone on that list. It could be a virus that is more annoyance than harm.

---

<div class="post-metadata">

**Author:** ![Vision4BG](https://avatars.discourse-cdn.com/v4/letter/v/b9bd4f/32.png) [@Vision4BG](https://boards.straightdope.com/u/Vision4BG)\
**Post date:** [February 8, 2004, 7:23am UTC](https://boards.straightdope.com/t/whats-with-the-empty-bodiless-emails/227953/12 "2004-02-08T07:23:13Z")

</div>

I can tell you exactly why these are being sent.

Turns out, the very popular Mailwasher program has a bit of a flaw with it - it stops working when there is a perfectly blank email sitting in your inbox.

Spammers have figured this out and are now sending them out so you think your mail has been cleaned but you still download the spam. Fokkers.

---

<div class="post-metadata">

**Author:** ![bbeaty](https://avatars.discourse-cdn.com/v4/letter/b/c0e974/32.png) [@bbeaty](https://boards.straightdope.com/u/bbeaty)\
**Post date:** [February 8, 2004, 11:14pm UTC](https://boards.straightdope.com/t/whats-with-the-empty-bodiless-emails/227953/13 "2004-02-08T23:14:06Z")

</div>

> [@AHunter3](#):
>
> Got four more this morning. The subject is almost always “Hello”, “hey”, or “Hi there”.

Those are most probably from the novarg/mydoom virus.

> **[Symantec Security Center](https://www.broadcom.com/support/security-center)**
>
> Symantec security research centers around the world provide unparalleled analysis of and protection from IT security threats that include malware, security risks, vulnerabilities, and spam.

[http://enterprisesecurity.symantec.com/article.cfm?articleid=2420](http://enterprisesecurity.symantec.com/article.cfm?articleid=2420)

No doubt the originating ISP is detecting and deleting the infected attachment before sending it on to you. If the only thing in the message was a virus attachment, you’d get a bodiless message.
