Fake privacy policies

I sign up at a lot of websites and liberally spray email addresses across the net. These signups are on behalf of one customer or another and each webform gets its own tagged and tracked email address. I always have a specific goal with each signup: getting a copy of a customer’s email, checking their signup process, auditing an affiliate on behalf of a customer or identifying where there might be a problem in a process. Because I have specific goals, I am pretty careful with these signups and usually uncheck every “share my email address” box I can find on the forms.
In every case the privacy policies of my clients and the things they tell me are explicit in that addresses will not be shared. It’s all opt-in, and email addresses are not shared without permission. Even in the cases where I am auditing affiliates, my clients assure me that if I follow this exact process my address will not be shared. Or so the affiliates have assured them.
Despite my care and the privacy policies on the websites, these addresses occasionally leak or are sold. This is actually very rare, and most of the websites I test never do anything with my address that I don’t expect. But in a couple cases these email addresses have ended up in the hands of some hard core spammers (hundreds of emails a day) and there was no useful tracking I could do. In other cases the volume has been lower, and I’ve watched the progression of my email addresses being bought and sold with morbid fascination.
Today an address I signed up at a website about a year ago got hit with multiple spams in a short time frame. All came from different IPs in the same /24. All had different domains with no websites. Whois showed all the domains were registered behind a privacy protection service. Interestingly, two of the domains used the same CAN SPAM address. The third had no CAN SPAM address at all. None of these addresses match the data I have on file related to the email signup.
It never ceases to amaze me how dishonest some address collection outfits. Their websites state clearly that addresses will not be bought an sold, and yet the addresses get lots of spam unrelated to the original signup. For those dishonest enough to do this they’ll never get caught unless recipients tags and tracks all their signups. Even worse, unless their partners test their signups or their mailing practices, the partners may end up unwittingly sending spam.

Related Posts

The unexpected email

In almost every discussion of “how to stop spam” someone will come up with the idea that if a recipient only allowed known people to send them email then the spam problem would be solved. There are lots of problems with this type of solution, but one of the biggest is that it ignores that sometimes the unexpected email is wanted. Typically, these unexpected but wanted emails is from an old friend or contact. But sometimes, the unexpected email can actually look like unsolicited bulk email and yet be wanted.
I actually received one of those emails today. The folks at http://schmap.com found my flickr stream and sent me email asking me for permission to use a couple of my photos in their London city guide. Completely unexpected, but very welcome email.
Sometimes, in the struggle to keep email useful and to keep spam out of the inbox, we forget how useful and wanted that unexpected email can be.

Read More

Question from the comments

On yesterday’s post there is a question in the comments that I think needs a bit more discussion.

Read More

Brand name spam

I’ve been getting a lot more spam advertising name brand companies. Places like FTD Flowers, Seattle Coffee Direct, Wal-Mart, Jet Blue, Gevalia and VistaPrint seem to all be working with spammers. In some cases, I am getting the same email to different email addresses from different domains and different IP addresses.
I am sure, if asked, all the advertised companies would say they have no knowledge of spamming by their vendors. I’m sure they would say that their vendors tell them I opted in to the email and must have just forgotten. I am sure that this isn’t really spam.
Except it really is spam. Real companies with real brands do use the services of spammers. When caught they loudly protest their innocence and talk about rogue affiliates. In the best cases they will “fire” the affiliate and then look the other way when the affiliate signs back up.
Spam is sending mail to people who never requested it. Hiring someone to do it for you doesn’t mean you aren’t a spammer. With the economy tanking and companies trying to maximize their bottom line, more and more name brands seem to be jumping on the spam bandwagon. It is not an unexpected development, but it will mean more aggressive spam filtering and more difficult email delivery for everyone.

Read More