Ask HN: What to do about random email sign-up attacks?
They input an email address, we send confirmation email, they click on that confirmation to continue the sign-up flow.
The challenge that I have been recently facing is that some bad actor(s) input other people emails. The bad actor cannot do anything with this since they do not have access to the email accounts. However, the problem is that those random people are now blasted with what is effectively spam. This is damaging to my service reputation because it appears like I am sending unsolicited emails.
The IPs, user-agents, etc. are all different. There is an element of sophistication to how this is executed.
It is the first time that I am dealing with this at a meaningful scale and I cannot think of what's a good way to counteract.