Home / Blogs

Do Spammers Change Their Tactics Based on Recipient Verification? Yes, They Do

Terry Zink

Or, to be more precise, it sure looks like they do.

I wrote on another post on a publicly available spam tool, and I mentioned that I came across a page that allowed people to verify whether or not an email address is actually live. The question naturally arises: do spammers clean up their email contact lists based upon whether or not the address is legitimate?

Spammers would have an incentive to do this - the fewer mails they have to send, the fewer resources they have to consume. Spam blitzes depend on spammers sending out as much as possible in as small a window as possible. The fewer the bots sending mail, the smaller the rate of spam detection.

Do we actually observe spammers changing their sending patterns? I believe that we have evidence that they do. Our customers have the option of doing Directory Services blocks. The way that this works is that customers upload a list of legitimate email addresses to us. When a message hits our network, we look up to see whether or not that email address is available (live). If no such email address exists on the domain, we send back a 554 - Recipient Address Not Available. These are called Directory Service Blocks, or DS blocks for short.

Recently, some customers have started using our DS services more actively. When they do, they have said that the number of total spam blocks in their statistics drop dramatically, sometimes by a factor of 10. Whereas before they were seeing 10 million spam blocks prior to using DS, now they are seeing only 1 million spam blocks. That's a huge drop. What gives? (It's not a problem with our reporting mechanism, btw).

As it turns out, it looks like spammers are changing their behaviour based upon return codes. DS blocks are our first level of spam blocks and then IP blocklists (which send 550s) are our second level. What appears to be happening is the following:

• If a spammer or bot gets 550'ed, they don't give up right away. They move onto a different bot and continue to try to send the same spam. The theory is that the bot is rejected but the email address is still good.

• If a spammer gets 554'ed, they stop sending mail to that email address. The theory is that the email address is not legitimate, so why bother sending mail?

If this is indeed what is going on, it shows a clever resilience amongst the spam and bot community that allow them to learn what is going on in response to their tactics, and then change their tactics appropriately. This doesn't surprise me, I have stated in the past (somewhere) that spammers are like antibiotic-resistant bacteria, evolving to deal with new threats and figuring out ways to survive.

Of course, if this hypothesis is correct, then it means that spammers are using very polluted lists, that is, emails to no where. Looks like whoever sold them those lists didn't give them much quality. That makes me feel a little better, taking the time to engage in a little schadenfreude.

By Terry Zink, Program Manager. Visit the blog maintained by Terry Zink here.

Related topics: Email, Spam

WEEKLY WRAP — Get CircleID's Weekly Summary Report by Email:

Comments

Re: Do Spammers Change Their Tactics Based on Recipient Verification? Yes, They Do Kjetil Torgrim Homme  –  Nov 14, 2007 12:19 PM PDT

This is interesting.  We return 550 for unknown addresses, too — it seems to me we are best served by not changing this.  If someone sends to many unknown recipients, they will be blocked (actually the remainder of the recipients will be temporarily rejected), so if the spammers get better targeted lists, more spam will get through to the valid addresses, too.

To post comments, please login or create an account.

Related Blogs

Related News

Topics

Industry Updates – Sponsored Posts

Nominum Launches Comprehensive Suite of DNS-Based Security Solutions for Russian Service Providers

Nominum Sets New Record for Network Speed and Efficiency

DNS on Defense, DNS on Offense

Managing Outbound Spam: A New DNS-based Approach For Stopping Abuse (Webinar)

MarkMonitor Fraud Intelligence Report, Q4 2011

MarkMonitor Fraud Intelligence Report Released for Q2 2011

Dyn Releases New Powerhouse in Enterprise Class Email Delivery

The Botnet-Counterfeit Drugs Connection

Global Company Leads the Pack as One of the First Microsoft Partners to Offer Exchange 2010

Dyn Inc. Acquires Email Delivery Provider SendLabs

Afilias and .JO Registry Bring Native Language E-mail to Arabic Internet Users

New Monthly Fraud Intelligence Report Now Available

MarkMonitor to Highlight Importance of Cross-Functional Approach to Brand Protection

Preventing Your DNS Account from Being Hacked

Paid Search Ads Can Lead to Fake Goods

Open Phishing Season

.ORG Highlighted for Success in Fighting Phishing

Latest Brandjacking Index Examines How Fraudsters Abuse Financial Brands

New Report Shows .INFO Domain Safest from Phishing Attacks

MarkMonitor AntiFraud Solutions, Combining Proven Antiphishing and Expert Antimalware Capabilities

Hot Topics

Afilias

DNS Security

Sponsored by
Afilias
Nominum

IPv6

Sponsored by
Nominum
Neustar UltraDNS

DNS

Sponsored by
Neustar UltraDNS
Verisign

Security

Sponsored by
Verisign
dotMobi

Mobile

Sponsored by
dotMobi
Minds + Machines

Top-Level Domains

Sponsored by
Minds + Machines