gshaw Posted April 24, 2008 Posted April 24, 2008 We have an email address enquiries@... for students etc to send in email questions rather than phone through. I'd expect higher than usual spam due to it being posted on the website and so prob getting harvested by spambots but atm there's 223 mails, all various flavours of Delivery Failures, Mailer-Daemon and so on. I doubt that they're real ones as we'd be on a blacklist by now (happened before) so chances are it's spammers spoofing this enquiries address? Does that sound about right, if so what fixes have people got for securing their public facing email addresses? I don't edit the website but would start by ASCII encoding the link so it works fine for mailto: clicks but useless to spambots, any other suggestions? Ta
Michael Posted April 24, 2008 Posted April 24, 2008 Hide it under a link, don't write it in plain text on your website! Alternatively use a webform like I use on my own website This will greatly reduce the amount of spam you'll receive. Hope this helps
gshaw Posted April 24, 2008 Author Posted April 24, 2008 (edited) Ye well I'd do that anyway but website used to be someone else's job Do you agree that these Undeliverables are due to impersonation of the email address, rather than being due to spam coming out from our side (which I highly doubt seeing as it only happens with this one address?) Hmmmm looking at the website I can't find that address anywhere, there was a web form for contact but it's dead so can't be there... only other place I know of is in the prospectus unless it's on a 3rd party site somewhere... Edited April 24, 2008 by gshaw
Michael Posted April 24, 2008 Posted April 24, 2008 It's not so much Spam but Spoofing, so it appears to come from your address or domain. There's little you can do about it unfortunately.
Ryan Posted April 24, 2008 Posted April 24, 2008 Some staff here (only one or two thankfully) get what can only be described as 'arseloads' of mail like this. Digging through Exchange recently, i discovered she's getting 1 out of 12 emails to her actual inbox (Exchange doing its job filtering), as the rest are all nonsense. She was recently inundated with lots of these spoofed emails "bouncing back". Change of email address sorted it. Not a satisfactory solution by any means, but job done. A solution for you might be a contact form as mentioned (with a change of target address) or do what we did - bin the address, set up an autoresponder and tell them to use an alternate address set up for the same purpose. (We went from admin@ to info@)
Guest kerrymoralee9280 Posted April 24, 2008 Posted April 24, 2008 I got a load of those to my hotmail account not so long back - Looked the real thing but highly doubt there are because they went into the junk folder automatically. Surely if it was a real "we couldn't send this" it wouldn't be classed as junk?
Gerry Posted April 24, 2008 Posted April 24, 2008 Happens to me with my work e-mail. Definately spammers spoofing my address. Sometimes it looks like I'm spamming myself! Just started to happen with my private e-mail too after 5+ years of careful (I thought) use.
gshaw Posted April 24, 2008 Author Posted April 24, 2008 Oh well at least it's confirmed my theory and can be safe in the knowledge it's not the mail server, maybe there's a rule I can set up to dump anything with Mail Daemon, Undeliverable etc for that address? Being a shared mailbox the rule would have to act as mail was arriving rather than happening through Outlook. Don't really wanna fiddle with the Exchange server too much atm as it's on its last legs and rocking the boat isn't a great idea but would be good to know what options I got...
Guest kerrymoralee9280 Posted April 24, 2008 Posted April 24, 2008 You can do that with Exchange - not too hard from what I can remember.
enjay Posted April 24, 2008 Posted April 24, 2008 Our main enquiries address gets swamped too - typically less than 10% of new mails are genuine! My personal (GMail) address is getting hammered at the moment too, around 20 spam emails every day, but the filter is catching every one of them. I used to get hardly any, only 1 or 2 a week, so I'm wondering where I've been careless with publishing my email address... An auto-responder directing people to a new address sounds like the way to go, if it has become too great a problem. Hide that new address behind links, javascript to cloaked the address or put jpeg's of the email address up instead of plain text. I would advise caution setting rules on inbound failure messages, as it will of course catch any real failure notifications too.
FN-GM Posted April 24, 2008 Posted April 24, 2008 On our school website i put the address in a picture, the bots have no chance of detecting it.
srochford Posted April 28, 2008 Posted April 28, 2008 On our school website i put the address in a picture, the bots have no chance of detecting it. Hope you've got an "alt" tag for screenreaders - need to make sure that the page works for visually impaired users. Just saw quite a nice idea today - the address is in text but with the "@" as an image. I'm guessing that most bots will parse the text of a page looking for the "@" symbol so if you take that out then there's nothing for them to find.
elsiegee40 Posted April 28, 2008 Posted April 28, 2008 We had this problem with our enquiries page on the school website. I scrapped the original enquiries email address and created a new one. I then used an alias to that address on the website enquiries form. When the alias starts to get spammed; I simply kill the alias and create a new one and change the address the web form uses. I also feel that avoiding the obvious names for email addresses may help. Enquiries@ is an obvious address for robots to create without scanning your web page.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now