Stop obfuscating your email address - a geek mistake
mindscape.co.nz
mindscape.co.nz
I get around 2400 spam a day. I've tried three different spam filters recommended to me by people I trust and who generally know about these things, and they get about 97% to 98% accuracy. Worse, they produce false positives. With 50 spam per day, plus having to trawl through the spam bin to look for the false positives, I decided to write my own.
My spam filter is highly tuned to my traffic and I get about 10 spam through per day. More, there are about 2 false positives per month, although that's very hard to quantify.
The problem with putting up a form is that people want a reply, and yet they can't type their own email address properly. About half the emails I get through my various forms have subtle and not-so-subtle misspellings of the return address, and it can cost me hours to track them down.
No, obfuscated email addresses is still my best tool in this situation.
reCaptcha Mailhide (http://mailhide.recaptcha.net/) is a good solution to this.
It hides your e-mail behind a CAPTCHA, but once it's solved it's an actual, well-formed address, that can be copied or clicked. Also, it's very clear if you've solved the CAPTCHA - it's no always clear if solved the "riddle" of an obfuscation correctly.
> ... visitors that can't spell their own email address
> ... likely to screw your obfuscated address up as well
> ... it's no always clear if solved the "riddle" of an
> obfuscation correctly.
They are likely to screw it up, but at least they get the feedback of a bounced email. There is a recovery mode, and it's their problem.With an incorrectly spelled return address on a form there is no recovery mode at all, and they get no feedback that it hasn't worked.
Isn't that the point of the article? That you are offloading work onto the peopel you ostensibly want to get in touch with you?
(I'm not saying it's wrong for you to do so, just that your statement seems to line up perfectly with the author's premise that obfuscating your email address is taking your problem and making it their problem).
To me, that's conclusive proof that the form is worse than the obfuscated address.
Further, there's a balance to be achieved. I've analysed the types of people I want to contact me, and of those who can't work out my address there are two types. One type is those that I really don't care about - nuisance, spam, content-free, or time-wasters. The others that I do care about usually have a different route to me, one that's specifically tailored to them and made as easy as possible. That one has a specially designed anti-spam measure built into it.
Plaintext links have high usability. The mail is organized within the user's mail program where it can be retrieved, collated by subject, and so forth. It can be copied and pasted. It's the abslute best thing for them :-)
First, that depends. They may hit an existing domain with a catch-all mailbox configured, or they may hit a legitimate mailbox at your provider, where the receiver may or may not think to reply that they got the wrong address.
Second, what percentage of users (especially in the segment that might misspell their own email address) will know what to do with a bounce mail?
My filtering now achieves around 99.6% filtering, and about 1 detected false positive per month. It would be interesting to see how gmail copes with my 2400 spam per day, and what accuracy it achieves, but it's a non-starter because of how I use email.
The only downside is that you have to manually verify your custom domain's 'sent from' addresses in Gmail, so you can't easily reply from arbitrary addresses.
1. Create a catch-all address for the domain you're going to use that isn't the normal postmaster one.
2. Pick a three- or four-letter combination of letters that rarely appears in normal conversation (like dcj, for example).
3. Set a mail filter on the catch-all account to forward all mail that has your three-letter combination as a part of its recipient list to your real address.
This means that for every service you sign up for, you can create a new address (I always use domainname.code@mydomain) that is trackable and gets to you. For example, I just signed up with Via Rail's online system - using the address viarail.dcj@mydomain. It will get forwarded to my real address (since it's got the dcj in there), if I start getting spam on it I'll know where they got the email address from, and if it gets really bad I can just change my filters to block all email to viarail.dcj@mydomain.
You could do something with Gmail's plus-addressing, but I find that many services don't accept those email addresses.
A free alternative is SneakEmail (http://www.sneakemail.com) which allows you to set up disposable addresses that forward to your primary account, and allows you to set up pre-forwarding filters. They also create a unique address for the sender of each email, and you can set up your SneakEmail filters to insert this as the reply-to address of each email you receive.
For 95% of the things I sign up for, however, I'm not that paranoid - the slight decrease in security is offset by the added convenience of not having to log into a third-party service (like SneakEmail) to get what I'm doing done.
Gmail lets you insert periods between the letters of your username. So if my email address is someusername@gmail.com, the following are valid variants of my email address:
some.username@gmail.com
some.user.name@gmail.com
s.omeusername@gmail.com
And so on. So you can use variants for different services you sign up for. Also note that you can substitute @googlemail.com for @gmail.com.
I've used it for years with good results. People will even email me thinking that I've exposed my email address to spammers encouraging me to use the blah [at] blah dot com style.
For instance, I always sign up with [servicename].account@mydomain.com and only ever give out my personal e-mail to people i meet in person.
The great thing is that if a [servicename].account address starts getting spam, i know which service sold my address and i can just blackhole that address.
That way, i never have to obfuscate my address, since i'll always just create a new one for the specific need. It's probably not for everyone though...
EDIT: This experiment shows it to be much less than that (based on volume of spam received) http://techblog.tilllate.com/2008/07/20/ten-methods-to-obfus...
I've blocked a huge volume of comment spam on my sites by blocking certain malformed HTTP headers. The authors couldn't be bothered to check if they were getting it right. I don't think most spam bot authors are A) very well paid or B) very good.
My point is that users smart enough to disguise their emails from spammers are more likely to be wary of their wares.
Kev+myspace@gmail.com, Kev+facebook@gmail.com, Kev+untrustworthysite@gmail.com
If you start getting a bunch of spam to Kev+myspace@gmail.com, filter out all email to that address.
The RFC is extremely permissive, even spaces (yeah, spaces) are allowed in email addresses.
I just use Spamassassin with my domain name and I get about 2 spam messages in my inbox per day, but the spam box gets around 1000 per day. I post my email address on websites because I want to have zero barriers when a customer or lead needs to contact me. It's NOT THEIR PROBLEM that I get spam.
So I agree, just get a good spam filter.
So even trivial obfuscation turns out to help a lot. Here's someone's tests from a year ago:
http://techblog.tilllate.com/2008/07/20/ten-methods-to-obfus...
Every technique reduced spam by 60% or more, and even the dumb-as-rocks replacement of '@' and '.' with 'AT' and 'DOT' reduced the volume by size by over 99%.
1: The analysis runs 1.5 years until July 2008 -- one must assume that crawlers has become more sophisticated. I.e. building the DOM, executing any javascript and then searching all visible text isn't that difficult, and less so now than in 2007.
Also, I would debate that these are high value targets. I'd wager that people who go out of their way to obscure their addresses are much less likely to purchase fake pills or fall for a phishing email than the average user.
Secondly, I don't see how bob is a high value target. Someone who knows what spam is, and knows what a spam bot is, and knows they want to obfuscate it, is probably not someone who would make a purchase if they did receive spam.
I think that's one reason spam bot crawlers don't try that hard to obfuscate addresses: the recipients are of less value than those unobfuscated.
Using the de-obfuscation process as a gating mechanism is arbitrary and perhaps a bit arrogant. There's no reason to assume that familiarity with this convention equates to intelligence or value. Even now, I still run into plenty of people in businesses outside of the tech industry that confuse website and email address formats. That doesn't make them "unworthy" of contacting us; it just means they have a different skillset and knowledge than we do.
Meanwhile, email spammers and scammers are most likely to understand these conventions, since it's their "job" to do so.
1) Use Gmail. Google has written their search engine to know how to detect spam so they know how to stop spam from reaching your email address. I don't think I have ever had even a single spam message even reach my spam folder, and that's thanks to Google. I could put my non-obfuscated email address all over the place and not have to worry.
2) Write a custom contact form. It is not that hard if you know even a little bit of PHP. And if you don't you can always use Zoho forms or some other free online form creator. I never put up contact emails because they are, in my opinion, just as unprofessional as an obfuscated contact email. Contact forms are much more professional.
e d w 5 1 9 AT g m a i l
is not meant to upset anybody.It's a IQ test.
If you can't figure out how to contact me from that data then you'd probably be wasting my time anyway.
Self-solving problem.
The author cannot be bothered to decode such email addresses. If that is the case I probably did not want his email in the first place. Ipso facto, my filter worked.
mailto:chris-hHz389aASKJkjhqweuiSHADKJweiuqzrq@example.com
If Spam increases (or, say, whenever more than 3 emails have been received at one particular address), you shut down the address.
I once implemented the receiving, hmac/signature checking, part for the exim mail-server and a general address-generator class in python and php. But never actually put it to use.
Some note that i learn from Internet to minimize spam emails:
- Never use third party proxy or anonymous network (i.e. Tor). I once work for company that not allowed to use any port except 8080, so for several months i use Tor. Suddenly, after several weeks my spam folder increased with junk emails.
- Make sure you clear all your caches and cookies _before_ and after browsing for pr0n. duh! :)
- Never use any third party application from Facebook/MySpace/any-social-networks, unless you using your non-private mail on your Facebook/MySpace/any-social-networks account.
- Do not read spam email. If you know that email is spam just check it and delete, or let the system delete it automatically, like Gmail do. I do not know anything about SMTP protocol but there is one feature that make your email notified to sender when you read it, by opening your email you just notified the spammer that your email is, at least still, active.
Spammer, in context of the emails gatherer, is not stupid. They know what their doing.
There's a big difference between pushing work on your customers and pushing work on people who don't know you and are trying to contact you the first time.
http://www.google.com/search?q=at+gmail+dot+com
Collect enough patterns and you can harvest tons of email addresses like used to be.
Obviously this might not work if you have a customer support email.