They want to know if you're doing any domain validation for requests sent to your URL, otherwise someone could quite easily eat up their quota by sending POST requests to the URL in the form.
They want to know if you're doing any domain validation for requests sent to your URL, otherwise someone could quite easily eat up their quota by sending POST requests to the URL in the form.
Would there be a reason to do this other than to eat a competitor's quota or just cause someone trouble?
The malicious actor would not benefit in any other way, correct? They would not actually get the submitted data…
It’s taken me a couple days to put it into words, but the important thing for me was a product lesson.
The lesson was that it’s possible to lower friction to this point, build or buy an anti/bot/spam system and still have margin.
If there was a malicious user abusing the service and they manage to bypass our spam protection then I'll definitely make sure they're taken are of as spam doesn't count towards your quota.
Because you can control the whole http request using say curl and use proxies.
Conversely I wouldn’t be surprised if some privacy extensions hide the referrer.
You could do some basic bot detection though. Even a css hidden non-hidden field might catch the bots.