#antispam — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #antispam, aggregated by home.social.
-
@jeffmcneill The email situation's interesting.
On the one hand, it's TCP/IP networking which routes mail, though it might be possible to apply the peering notion to mail servers rather than network peers.
(Technically, of course, VOIP also operates over TCP/IP, though that's only a subset of total phone traffic, and ... I'm not entirely clear on how that might operate.)
The next question is whether or not it would make sense for individual email servers to be bonded. That probably splits sensibly into a few categories:
Large email service providers: Gmail, iCloud (Apple), Outlook (Microsoft), Yahoo, Proton, etc.
Individuals operating their own servers (families, small groups, generally not business-oriented).
Businesses and organisations self-serving email for their own employees.
Other online services with an email notification component: FB, Fediverse servers, Reddit, Pagerduty, etc. These serve third party email, rather than just personal or own staff, often notifications though potentially user-generated messages as well.
Mailing lists. This is a common sticking point for other anti-spam proposals. (See classically: https://craphound.com/spamsolutions.txt, and yes this is a somewhat market-based solution.)
Mail-campaign services. Generally: sales/marketing emails, such as Mailchimp, ActiveCampaign, etc. Third-party mail, generated by the third parties and generally sent in mass to large numbers of fourth parties.
Black-hat "bulletproof" email providers. Spamhauser.
Proxy servers. Individual systems hijacked by third parties to send spam.
Questions:
- Does it make sense to bond each of these classes?
- How much should that bond be / how should a bond be computed?
- What is excessive (say, for individuals), what is insufficient (say, for major email service providers), to permit legit mail, but discourage spam?
- What forms of abuse might be triggered through such a system? Spurious claims, joe-jobs, and the like, say? How should those be mitigated or addressed?
- Who can file claims, who gets paid?
I'm not going to answer those, it's for discussion. I think there might be some viability to this. It's not a per message postage concept ("microtransactions"), but instead an aggregated and risk-based skin-in-the-game notion.
I do think that bulletproof hosters and proxies would be pretty well addressed, while large services and marketing providers would be strongly incentivised to clean up their acts. Smaller servers should be reasonably OK under this schema, and might aggregate to a large pooled bond (small servers already often have to direct outbound through a larger provider already).
-
Interesting #antispam thing: in 2022 I reached a cash settlement with a company that unlawfully used my personal data for marketing. You'd think they would have deleted my data, but no - their assets have been bought by another company, who has started using my personal data unlawfully.
There is absolutely no way in law, in which you can acquire personal data of individuals from another company and use it for lawful marketing - this sort of shit should simply never happen!
-
Auf dem #Fedicamp habe ich heute zusammen mit @wuffel einen Erfahrungsaustausch angestiftet, bei dem wir beraten haben, wie wir mit der Flut dubioser Mastodon-Account-Anträge umgehen können. Hier sind Notizen dazu:
Was tun gegen Mastodon-Account-Registrierungen durch Bots & Klickworker?
Anlass
FakeNews-Kampagne #PortalKombat und ähnliche: https://about.iftas.org/library/suspected-portal-kombat-accounts/
Vorsorgemaßnahmen
- Schaltet Registrierungen von offen auf halboffen um, falls ihr das nicht schon getan habt. Und verlangt eine Begründung! Ihr findet das unter Einstellungen > Administration > Serverregeln > Registrierungen
- Schreibt auf eure About-Seite, was in einer guten Begründung drinstehen sollte.
- Sollte euch doch mal ein Spammer/Sleeper durchrutschen, dann wäre es fatal, wenn er Einladungen erzeugen dürfte. Leider ist das der Default. Ändert das bitte in Einstellungen > Administration > Rollen > Standard. Die allermeisten User nutzen diese Funktion eh nicht. Mods und Admins können dann weiterhin Einladungslinks generieren.
Abwehrstrategie E-Mail-Domain
Mastodon lässt es zu, Account-Registrierungen von bestimmten E-Mail-Domains automatisch zu verwerfen. Ein Massenimport der unten verlinkten Listen ist mit Hilfe des mitgelieferten Server-Tools
tootctlmöglich.- Suche in ca. 70.000 Wegwerf-Domains: https://disposable.github.io/disposable-email-domains/lookup
- Repo dazu: https://github.com/disposable/disposable
- Bei so einer langen Liste steigt die Gefahr des Overblockings.
- Bewährte Teilmenge der obigen Liste mit ca. 7.000 Wegwerf-Domains: https://github.com/disposable-email-domains/disposable-email-domains
- Update: Von @gunchleoc bekam ich ein kurzes Shellscript, das diese Blocklist in eine Mastodon-Instanz importiert: https://codeberg.org/datenfreude/emailblock – am besten jede Nacht per Cronjob.
Abwehrstrategie IP-Adresse
Mit Standard-Tools wie
hostundwhoiskönnen Linux-Nutzende die IP-Adresse(n) untersuchen, die ein Antragsteller verwendet hat. Ein mächtigeres Tool istwtfis, wenn man die API-Keys einiger Webdienste hinterlegt: https://github.com/pirxthepilot/wtfisViele der Bots oder Klickarbeiter:innen nutzen Tor, andere Proxies oder Cloud-IPs. Anders gesagt: IPs von Heimanschlüssen sind ein positives Signal.
Abwehrstrategie Begründung
Viele Bots und Klickworker benutzen stinklangweilige Begründungen. Manche sind besonders dreist und verwenden die Bios beliebiger Fediverse-Accounts als Begründung. Beim Prüfen dieser Anträge kann es also sinnvoll sein, die Begründung ins Suchfeld einer großen Mastodon-Instanz zu kopieren.
Sehr sinnvoll erscheint es uns, die Über-Seite oder den Text über dem Antragsformular anzupassen, um Antragstellende aufzufordern, in ihrer Begründung bestimmte Dinge zu erwähnen.
Eine Lösung für Matrix-Fans
Für Matrix-Nutzende hat die @FediverseFoundation einen Matrix-Bot gebaut, der das Checken der IP-Adresse übernimmt und auch das Freischalten oder Ablehnen via Chat ermöglicht: https://git.fediverse.foundation/ff_pub/fedi-signup-bot
Allgemeine Anti-DDoS-Maßnahmen
Gegen Ende sprachen wir über Überlastungsprobleme, die von hemmungslosen »KI«-Crawlern hervorgerufen werden und alle Websites (auch außerhalb des Fediversums) betreffen können. Die bekannten Ansätze sind:
- Proof of Work, z.B. Anubis
- IP-Sperrlisten, z.B. https://github.com/mitchellkrogza/nginx-ultimate-bad-bot-blocker
- UserAgent-Sperrlisten
- Tarpitting/Teergrubing/Fallen
Ideen für Fallen
Ein 1-Pixel-PNG mit Link auf ein haltdiefresse.php, welches die nötigen Parameter gleich dem Türsteher übergibt. Beim Skripten könnte das helfen: https://mastodonpy.readthedocs.io
#PortalKombat #PutinTrolle #TrumpTrolle #AntiSpam #AntiFakeNews #Spam #FakeNews #disinformation #MastoAdmin #FediAdmin #Registrierungen #Fedicamp2006 #Fedicamp2006Tag3
-
"ho'omalu is an account assessment service for Mastodon. It evaluates new registrations using multiple independent signals, calculates a weighted risk score, and produces a moderator-friendly traffic light verdict"
-
Returning readers will remember my "Eighteen years of greytrapping" piece (https://nxdomain.no/~peter/eighteen_years_of_greytrapping.html or tracked https://bsdly.blogspot.com/2025/08/eighteen-years-of-greytrapping-is.html, and may also remember that it has numbers and graphs.
It's now been more like 19 years of the activity, and the numbers and graphs are refreshed as of end of July.
#spam #antispam #spamd #openbsd #greylisting #greytrapping #security #cybercrime #cybersecurity #smtp #email
-
Search Engine Journal: X Live-Tweets Its Fight Against Chatbot Spam In Real-Time. “Nikita Bier, head of product at X (formerly known as Twitter) posted a series of extraordinary tweets about spam on Twitter, explaining the motivation of some of the spammers, they described types of spam and mentioned that some spammers were using Grok to auto-post spam responses at scale. Nikita Bier spent 24 […]
https://rbfirehose.com/2026/07/28/search-engine-journal-x-live-tweets-its-fight-against-chatbot-spam-in-real-time/ -
If you like what you read on www.diaryofafloppingfish.com leave a comment! I would love to interact with you! Of course, not if it is gross or unrelated to the post. Then you just get blocked. Yay, blocking! Boo spam! #Diaryofafloppingfish #mentalhealth #healingtrauma #livingwithCPTSD #survivorcommunity #antispam
-
El lado del mal - Cómo sacar partido a la nueva dirección de e-mail de MyPublicInbox protegida con Tempos https://elladodelmal.com/2026/07/como-sacar-partido-la-nueva-direccion.html #MyPublicInbox #AntiSpam #email #SMTP #Tempos
-
Du möchtest in deinem Unternehmen Realtime-Blocklists von Spamhaus zur Verbesserung der Anti-Spam-Strategie einsetzen? Als langjähriger Spamhaus-Partner bieten wir Spamhaus-Lizenzen in Euro mit deutscher Rechnungsadresse. Gerade für Unternehmen mit hohen Compliance- und Accounting-Anforderungen ist das ein entscheidender Vorteil.
👉 Mehr Infos:
https://www.heinlein-support.de/services/lizenzen/spamhaus -
☕ Pause, mais pas pour les exposants !
Pause café au #Adullact2026, mais nos exposants, eux, ne s’arrêtent pas !
🔍 Démos en cours :
• Stand Maarch : Décrypter le courrier à l’ère de l’IA (LAD, RAD, traitements
intellectuels)
• Stand Probesys : Découverte de AgentJ, l’antispam libre
-
A server I help with has been added to a well-used email blocklist. No diagnostics or example from the blocker, vague reasoning including 'poor reputation'. Email logs going back weeks are clean apart from the block errors. Are some blocklist operators basically extortion rackets now? If they wanted to reduce spam, they'd keep some reasoning for admins willing to fix stuff and ban spammers.
-
We are very close to a new OpenBSD release. "You Have Installed OpenBSD. Now For The Daily Tasks." https://nxdomain.no/~peter/openbsd_installed_now_for_the_daily_tasks.html can help you prepare for the upgrade.
If you are using exim as your MTA (or any other non-base system MTA), "OpenSMTPD Is The Mail Server For The Future" https://nxdomain.no/~peter/time_for_opensmtpd.html contains useful pointers for a better mail future.
#openbsd #newrelease #openbsd79 #opensmtpd #email #smtp #rspamd #antispam #spam #exim
-
Repost for the Sunday crowd:
Migrating mail servers from exim to OpenSMTPD (smtpd) is fun and useful https://www.undeadly.org/cgi?action=article;sid=20260516064650 #openbsd #opensmtpd #smtpd #exim #email #smtp #mail #spam #antispam #greylisting #greytrapping #mailmigration
-
OpenSMTPD Is The Mail Server For The Future https://nxdomain.no/~peter/time_for_opensmtpd.html Migrating to OpenSMTPD from exim on OpenBSD was joyfully painless and smooth. #openbsd #opensmtpd #email #smtpd #rspamd #spam #antispam #greylisting #greytrapping #mailserver
-
Frank geht ran
"Diese Nummer ist alles, was Sie brauchen: 0163 1737743 (Festnetz: 0521 16391643). Franks Nummer können Sie an alle Menschen weitergeben, die nach Ihrer Telefonnummer verlangen, aber mit denen Sie nichts zu tun haben wollen."
-
hm. this thing seems to be popping up again and again https://news.ycombinator.com/item?id=47636937 #greytrapping #email #runyourownmailserver #spam #spamd #greylisting #antispam
-
Want to Guess How Many Spam Comments We’ve Blocked Since 2016? https://lowendbox.com/blog/want-to-guess-how-many-spam-comments-weve-blocked-since-2016/ #Editorial&News #wordpress #antispam #akismet #Spam
-
#InstanceAnnouncement Coordinated Potential Bot Network Suspended
We have detected and suspended 5 coordinated bot accounts today.
Indicators of Compromise:
- Content consists of semantically incoherent English text generated by LLM — no direct harm observed, but likely used for account seasoning and filter evasion
- All 5 accounts registered between 2026-03-18 17:52 and 2026-03-19 23:50
- Profiles contain a single English sentence + emoji, or several meaningless English phrases
- All connection IPs belong to Cloudflare proxy ranges
- Registrant domains include disposable email services and high-risk domains
Actions Taken:
Accounts suspended (all IPs verified as Cloudflare IPs — no user privacy has been compromised):
@iwutyp162.159.XXX.XX
@PhyllisReynolds172.70.XXX.XXX
@ezob104.23.XXX.XX
@uhux_xudym104.23.XXX.XX
@Ethel_Robinson172.68.XXX.XXXEmail domains blocked:
tmail.lt,maxseeding.vn,dqsbf.blema.io.vn,sphinx.launders.money,kimora.spaceNotes:
Registration had previously been set to open in order to simplify the sign-up process. We are now enabling "Require approval" + "Require a reason to join".
If you spot accounts with similar characteristics, or matching email domains/IPs, please report them.
This instance does not welcome malicious or unmoderated bots.#mastodon #fediverse #antispam #spam #instanceadmin #moderation
-
#实例公告 封禁协同潜在的僵尸账户网络
今日检测并封禁了 5 个协同运作的僵尸账户
行为特征:
- 内容为 LLM 生成的无语义英文词句(虽然目前未做出实质性的危害,但是可能是为了养号,规避审查)
- 五个账户全部于
2026年3月18日 17:52—2026年3月19日 23:50注册 - 账户Profile基本为:一段英文+emoji或者几段无意义英文句子
- 所有连接 IP 均属 Cloudflare 代理段
- 注册域名含一次性邮箱服务及高风险域名
已采取的措施:
封禁账户(经核查IP均为Cloudflare IP,未泄露任何用户隐私):
@iwutyp162.159.XXX.XX
@PhyllisReynolds172.70.XXX.XXX
@ezob104.23.XXX.XX
@uhux_xudym104.23.XXX.XX
@Ethel_Robinson172.68.XXX.XXX
封禁邮箱:tmail.lt、maxseeding.vn、dqsbf.blema.io.vn、sphinx.launders.money、kimora.space总结:
由于前段时间为了简化注册流程,关闭了人工审核
将开启“注册时需要批准”+“注册时需要提供理由”
如果大家有发现类似行为特征的新账户,相同邮箱域名/IP请谨慎辨别
本实例不欢迎任何恶意/不受管制的机器人注册 -
@cbouvat
It’s The Shit!
Deso pour le blague, c’est l’appli qui redonne l’espoir face a déluge des aides à installation des panneaux solaires. Et quand il y a une apelle qui passe il y a le plaisir de l’ajouter à la liste commune. C’est ça aussi le fraternité. Pour l’anecdote, les combis compatible à box orange possède une blacklist de 30 places, et il faut retaper le numéro à la main après avoir trouvé l’option dans les menus.
N’oubliez pas à soutenir le projet. #antispam -
You're welcome. 😁
https://codeberg.org/qwebltd/QFlex-Invisible-Landing-Captcha
This is already in place on https://www.qweb.co.uk for testing, and will be rolled out to at least the bigger sites we host imminently.
You can't even tell it's in there, can you? 😏
This was the final jigsaw piece in a whole suite of mechanics I've built to secure our servers from aggressive scrapers. Enormous blog post on it all is incoming. 👍
-
Frank geht ran
"Diese Nummer ist alles, was Sie brauchen: 0163 1737743 (Festnetz: 0521 16391643). Franks Nummer können Sie an alle Menschen weitergeben, die nach Ihrer Telefonnummer verlangen, aber mit denen Sie nichts zu tun haben wollen."
-
I added a few more translations of the phrase "The rest is trash" to the spamtraps at https://nxdomain.no/~peter/traplist.shtml (see https://nxdomain.no/~peter/the_rest_is_trash.html or https://bsdly.blogspot.com/2026/02/the-rest-is-trash.html).
If you want further translations added, please let me know (with translation in your message).
#spamtraps #greytrapping #spamd #openbsd #freebsd #antispam #imaginaryfriends #localization #cybercrime
The list without wrapper text is available as https://www.bsdly.net/~peter/sortlist.txt (BIG! -- 22975800 entries as of right now, will increase)
-
"The Rest Is Trash"
We are now halfway through the nineteenth year of greytrapping, still tracking and collecting from the wealth of imbecility out there
https://nxdomain.no/~peter/the_rest_is_trash.html (tracked https://bsdly.blogspot.com/2026/02/the-rest-is-trash.html) #spamd #greytrapping #greylisting #openbsd #freebsd #spam #antispam #cybercrime