Category: spam

  • Spam is getting more selective – Annual Design Awards

    Spam emails are certainly getting more selective.

    The email harvesting robots which trawl the web are now (on a strangely positive side) aligning harvested email addresses and targeting them at specific groups (ie email addresses that have not been opted in, but just collected in plain text from different websites it finds).

    I’m sure my email address has now just been ‘sold’ (for a very small price no doubt), to lists claiming I’ve been opted in.

    One of the hidden email addresses on the Parlour Design website (one that a typical human browser would have no reason to find), has just been invited to the ‘Annual Design Awards’, whereby for a fee, we can enter into a competition and submit our best design.

    Using their special promotional code sent via email, we can also get a discount!

    So if we were genuinely being invited by a human, they would have used one of the publicised email addresses on the main website.

    Similarly, my belief is that if this was a genuine industry award, we wouldn’t pay to enter, but that the cost of looking through my entry would be covered by their advertising and sponsorship of the event.

    I will of course be keeping clear of it.

    That particular email address has now been blocked from further spam indefinitely, and the area it was used for, has now been updated to a new email address again.

    I wonder how long it’ll be before this new email gets spammed again!

  • Sending business emails to Yahoo

    One of my clients manages a reasonably large mailing list of around 500 opt-in users, they used to be able to send their newsletter via ‘Outlook Express’ using the Bcc: field, their ISP has now blocked this practise for fear of spamming.

    A few weeks ago we were able to get around this by sending emails to just 100 people at a time (rather than all 500 at once).

    Now, more recently, they can’t even send emails to 50 users at a time from their real opt-in list, via Outlook Express, or Outlook 2007, or similar!

    We then discovered that now emails sent in html (rather than plain text emails) were going through to yahoo users with blank content for the message body, and just the subject line showing, rather than of course the carefully composed message.

    Through various tests, we’ve found the best option to send emails, in plain text only, using our free ‘newsletter’ website add-in for existing and new clients.

    This so far seems to get the emails straight through, to each user one at a time, and is certainly the best way to do it at the moment. Hopefully this will remain as successful, however, more research on the subject brings up the following message board:
    http://www.ahfx.net/weblog.php?article=107

    So, the consensus seems to be very much: Switch your emails from yahoo, to gmail, hotmail, or ideally your own domain name (for just a few pound a year, with free online web-mail), and tell all your clients to do this too, otherwise, it’s highly likely key messages from your bank, travel agent, favourite web forums, etc. are all being deleted automatically without your knowledge!

  • How to Reduce Spam – as a web designer (or working with a web designer)

    Never put an email address in it’s plain text form anywhere on a web page, anywhere! This includes within the front end text, and within the html source code (including online forms, and ‘mailto’ tags).

    There is now a huge bunch of web based ‘robots’ who very quickly scan the text and source codes of websites around the world, finding anything that resembles an email address. Most commonly, they look out for the @ symbol, and then will pull of the few words either side of it, store this in a massive database, and sell it on to anyone who’s willing to pay a pittance for it. From experience, the various Nigerian email scams were one of the first to start pulling off email address in this way around 10 years ago. Of course now it’s hugely popular by many many more (particularly those trying to sell various pharmaceutical drugs, or ‘share option’ warnings / recommendations.

    I once had an email address I’d given to a popular business group, appear (without my initial permission) on their database of members’ directory. It was only up for about 2 weeks before I’d realised, and had it taken down. Unfortunately, due to the nature of that particular email address I couldn’t block it entirely, close it down, or reject all email sent to it.. However, I never replied to any email address sent to it, nor even read them after the first couple of weeks of it appearing.

    The number of spam emails started small enough at about 1-2 per day, within a week this was up to 5-6 per day (which was when I completely stopped using it). However, around a year on, I decided to have a quick look at how many spam emails were waiting for me, so cleared my inbox for the onslaught. Amazingly, despite never having replied to any email, nor even read them.. over the course of the year, there were over 10,000 emails waiting, and I was receiving on average (from the email history), around 300 spam emails every single day as that particular email address propagated itself through various spam list databases

    I’ve personally be using this particular technique of email encryption on websites for around the past 10 years. Only once has any email address used in this way, ever been picked up by some sending spam emails (this was when someone manually went through a website I manage, and manually pulled off all the email addresses listed. Who then used it to send unsolicited emails from two UK companies to the individuals listed. The companies were immediately reported to the information commissioners and further action was taken against them! Those email addresses have never been spammed again!.

    Never put an email address in it’s plain text form anywhere on a web page, anywhere!

    There are a huge bunch of web based ‘robots’ who very quickly scan the text and source codes of websites around the world, finding anything that resembles an email address. Most commonly, they look out for the @ symbol, and then will pull of the few words either side of it, store this in a massive database, and sell it on to anyone who’s willing to pay a pittance for it.

    Be very carefully where any digital versions of your client’s brochures or posters may appear on the web, as pdf documents for example, which show the full email address as plain text, within the readable document (so do edit any pdf documents to hide the email address, before you upload it to any website).

    If for whatever reason, you don’t want to use the method above for encrypting the email address in ASCII code, the easiest way around the common problem of the at symbol, is for any publicity with which you want to digitalise and put on the web, always swap the @ symbol for the word at, ‘at’, (at) or similar. For example emails(at)ourcompanydomain.co.uk. Most human users will quickly recognise what to swap around for themselves, although as the (at) technique seems the most common, I don’t expect it will be long until a robot is designed to pick this up too.

    Adding extra characters in a different colour, just before your domain name, with instructions beneath the email address, is a pretty effective way. For example emails@SPAMourcompanydomainname.co.uk with instructions for humans to remove the SPAM, is also pretty effective.

    If you’re managing the emails of a largely publicised company receiving a lot of unsolicited enquiries to various key staff members, and you have a list of staff (with their first name and surname listed somewhere on your website), try not use the classic firstname.surname@ourcompanydomain.com as these will often be tried by unsolicited callers trying to get in contact.

  • How to Reduce Spam – as a business

    Never send bulk emails to your clients using the To: or Cc: field. This then displays everyone’s email address to everyone else in the list. Firstly that’s like sending a photocopy of your entire client list to everyone else in it, every time you do it.

    Secondly, once an email address is listed in this way on someone else’s computer, when their computer get infected by a particular type of virus, it will scan the entire computer for anything that resembles anything like an email address (whether there’s been direct communication between the two people or not), and then store all these email addresses on a big database, to be sold on for fractions of a pence each, many times in the future. Whenever you send bulk emails, use the Bcc: field instead (Blind Carbon Copy), as this will only show to that recipient, the address of the sender, those in the Cc: field, but no-one else in the Bcc: field (it actually gets sent in such a way, the big list of email addresses for your bulk mailout usually don’t even appear in the source code of the email.

    All email programs have the Bcc field, although sometimes it’s hidden by default. A quick search on the web will tell you how to show it again.

    Train your staff on how they can personally help to minimise spam (directing them to the page above if you like, or you can access a host of books and educational matter on the subject on the web, or at your local bookshop).

    When first getting your new business domain, never use the email addresses info@ mail@ sales@ webmaster@
    As soon as your domain name is listed in various search engines and domain name lists (which are of course good for your search engine rankings), spam groups will automatically send junk emails to those email addresses.
    Try to be slightly more creative and use things like ‘enquiries’ ‘information’ etc.

    Never put an email address in it’s plain text form anywhere on a web page, anywhere!

    There is now a huge bunch of web based ‘robots’ who very quickly scan the text and source codes of websites around the world, finding anything that resembles an email address.

    Most commonly, they look out for the @ symbol, and then will pull of the few words either side of it, store this in a massive database, and sell it on to anyone who’s willing to pay a pittance for it.

    Similarly be very carefully where any digital versions of your brochures or posters may appear, as pdf documents for example, which show your full email address. The easiest way around this, is for any publicity with which you want to digitalise and put on the web, always swap the @ symbol for the word at, ‘at’, (at), *at* or similar. For example emails(at)ourcompanydomain.co.uk.

    Most human users will quickly recognise what to swap around for themselves, although as the (at) technique seems the most common, I don’t expect it will be long until a robot is designed to pick this up too.

    Adding extra characters in a different colour, just before your domain name, with instructions beneath the email address, is a pretty effective way. For example emails@SPAMourcompanydomainname.co.uk with instructions for humans to remove the SPAM, is also pretty effective.

    If you’re a largely publicised company receiving a lot of unsolicited enquiries to various key staff members, and you have a list of staff (with their first name and surname listed somewhere on your website), try not use the classic firstname.surname@ourcompanydomain.com as these will often be tried by unsolicited callers trying to get in contact.

  • How to Reduce Spam – Introduction

    How to Reduce Spam

    What is Spam?

    ‘Spam’ is unsolicited bulk email. To be spam it needs to be both unsolicited (ie you haven’t directly requested it), and sent as part of a bulk email (although some spamming organisations are trying to get around this, by using a type of mailmerge to get around this particular point, despite it still being completely unsolicited.

    In the UK, any UK business, targeting a UK individual with spam can be prosecuted and fined. Unfortunately business to business unsolicited email can’t be stopped very easily. Neither can spam generated and sent from outside the UK. If you have a complaint, you can make an official report through the Information Commissioner’s Website.