Spam

Spam
Spam is unsolicited bulk email, and is originated by advertisers of junk and sent by Spammers.  

Most folks have to waste time looking through their inbox for valid emails from known sources, and some folks open or reply to unsolicited email thats what keeps it going.   I think the folks who reply to spam think "this deal sounds too good to pass up" or "this email sounds too interesting ignore, I'll check it out".

The advertisers want cheap advertising for their junk and hire spammers to actually send their trash to millions of folks.   This is something like cold-calling used to be only, to hundreds of thousands of folks all at once (or at least nightly).   If only 3% or 4% respond the advertiser feels like he is successful and the spammers have known customers and keep spamming them.   Some of these advertisers, who do their own spamming, keep track of responses to their spam so they know they have a "live one" or valid customer.   Oh, and some companies actually broadcast emails about thier product themselves to lists of addresses they have purchased.

SPAMMERS, build lists of user email addresses to prey on.   SPAMMERS get paid by the number of spam emails sent.   These lists are acquired from web sites, intercepted email broadcasts with lists of recipients, social networking sites, etc.   The spammers have scripts that prowl internet sites harvesting email addresses "Spam@UCE.GOV" (where you report spam to the Federal Trade Commission) building their lists.   You actually hear and see advertisements for some spammers on radio and TV, companies like "Constant Contact" and "Exact Target" are both spammers, companies who accumulate (or buy) lists of email addresses then send spam to them for advertisers.   I even see clues that some spammers sell their lists to each other (the same bogus users (from padded lists) show up from a variety of sources).

Here is a sample list of one day's Unknown email, these users have never been on our system
Unk: vdbplyox@ary.com from
Unk: boaesrxp@ary.com from
Unk: NL@ary.com from bbossink@feweb.vu.nl
Unk: wdiungvm@ary.com from
Unk: uzvqxazb@ary.com from
Unk: idggnacd@ary.com from
Unk: phywmgvv@ary.com from
Unk: harper@ary.com from alfred@lowlybill.com
Unk: yhtwgwcz@ary.com from
Unk: vdbplyox@ary.com from
Unk: wqgtlwct@ary.com from
Unk: rugsadei@ary.com from
Unk: uureyqcn@ary.com from
Unk: dafh@ary.com from rodishappy1@yahoo.com
Unk: dafh@ary.com from rodishappy1@yahoo.com
Unk: f.lay1@ary.com from bounce-mc.us2_6444326.1549245 -f.lay1=ary.com@mail124.us2.mcsv.net
Unk: hgwlwkcq@ary.com from
Unk: fhnigpja@ary.com from
Unk: aqmvikdo@ary.com from
Unk: lhhbjyfn@ary.com from
Unk: dafh@ary.com from terra_dakia@yahoo.com
Unk: davephilgreen@ary.com from nnewsome@ptmc.net
Unk: axkmmfky@ary.com from
Unk: rlwxeher@ary.com from
Unk: extfzais@ary.com from send2@mail.j2.com
Unk: pexxylxb@ary.com from
Unk: bijal@ary.com from cesargofge13128@ymail.com
Unk: gyjsxxmx@ary.com from

I have a script that scans each days maillog and makes a list of valid email sent/received, attempts to login, and unknown user names who someone tried to send email to.   The unknown users names are either names that have never been users on my site or total gibberish (like a child playing on a keyboard),   These unknown user emails are rejected (spammer ignores this) so no real user at my domain is bothered by them.   I can understand an occassional unknown user email created by someone's typo, but I get 50 per day.   The unknown users are mostly from IP addresses that also sent SPAM that day, hence I have decided that SPAMMERS, are padding their spam lists.   When a new valid email (user and domain) is harvested, the domain also valid.   This padding is done by adding fake user names at valid domains then, since they get paid by the number of addresses they send to, charging the advertisers for a group of emails about half of which, knowningly go to the trash.    

Ways I Fight Spam
I use a number of methods to fight spam.  
First I configure sendmail to use Internet Black Lists like sorbs.net and spamhaus.org.
  The next thing I do is harvest spamming IP addresses from received SPAM messages and the unknown user list.   I look up the spamming IP on ARIN and then block attempts to access my mailserver from those IP blocks.   I also block all addresses outside the US and some of the larger spam senders from getting valid mail addresses from my nameserver.