Home / Blogs

Analyzing The Inbox of a Spammer's Domain

Consider this scenario: you need a domain name for your site so you go to your favorite domain registrar's website and upon a quick search find that your third choice is actually available! You quickly pull your credit card and register the name. Everything is good and you can't wait to have your new domain start pointing to your site and represent your official email address. But not so fast — some of the recent events are revealing that, these days, when you are registering a domain name there is one more critical thing you need to do: check under the hood!

As more and more domains expire and exchange hands, registering a domain is becoming no different than buying a used car. First you need to determine whether the domain you are about to register is fresh out of the factory or previously owned. Then, you need to find out where it's been.

The Case of a Mistaken Identity

Last month Simon Grainger, of Merseyside, northern England, failed to check under the hood when he registered a domain name for his daughter and, as a result, ended up among the 15 lawsuits Microsoft filed shortly after accusing defendants of collectively flooding its systems and customers with more than 2 billion deceptive unsolicited e-mail messages!

According to Grainger, he "received a writ on June 17, 2003 from the U.S.-based corporation, alleging that he was a spammer and had been harvesting e-mail addresses from its MSN site". Wrong domain at the wrong time!

The 43-year-old telecommunications engineer has said the three websites he owns are used for his teenage daughter's home page and for a local flying club, not for spamming. He believes he was targeted because a domain name he bought last year may have been used in spam attacks by a previous owner.

Opening a Can of Worms

On July 3 2003, 'cyberangels.nl' was intentionally re-registered by Spamvrij.nl, a Dutch foundation fighting spam. 'cyberangels.nl' is a domain that was previously owned by Cyberangels, a company know to have been heavily involved in spamming. Reportedly, spammers eventually felt forced to drop the domain when the ground under their feet got too hot.

Since MX-records for cyberangels.nl now point to spamvrij.nl too, the new owners were able to get all their emails and apparently it has not been a pretty site: bounces, spam complaints, and what have you!

So what kind of emails does a major spammer receive in the course of three days? According to this report 6305 emails! Here is the breakdown of those emails reported by the new registrants:

1. 6305 emails in (basically) three days
2. We received 5880 bounces and forwards
3. We received 12 spams for @cyberangels
4. We received 40 attempts to annoy Cyberangels
5. We received 371 complaints about Cyberangels
6. We received 2 business mails

The full analysis of this domain is being logged by Spamvrij.nl as it unfolds.

By CircleID Reporter

Related topics: DNS, Domain Names, Email, Spam

WEEKLY WRAP — Get CircleID's Weekly Summary Report by Email:

Comments

Re: Analyzing The Inbox of a Spammer's Domain Denise  –  Aug 27, 2003 9:37 PM PDT

This is fantastic! What are your reprint policies? I would like to quote the first few sentences of this article and link back to this page from my e-zine, The Dreamspace News. My last issue was devoted to "Hackers, scammers, slammers and spammers". This would be a perfect follow-up.

Re: Analyzing The Inbox of a Spammer's Domain Ali Farshchian  –  Aug 28, 2003 8:30 AM PDT

Glad you found this article valuable and thanks for your comment.

"I would like to quote the first few sentences of this article and link back to this page from my e-zine" — this would be fine.

Re: Analyzing The Inbox of a Spammer's Domain Denise  –  Aug 28, 2003 8:55 AM PDT

Thank you. It should be out by Sept 12

Re: Analyzing The Inbox of a Spammer's Domain joyce levin  –  Mar 05, 2007 12:15 AM PDT

Can anyone help?  How can I find out who the previous owners of a domain name are?  Any advice would be much appreciated.

To post comments, please login or create an account.

Related Blogs

Related News

Topics

Industry Updates – Sponsored Posts

Nominum Launches 1st Comprehensive Mobile Security Solution That Protects Both Network and End User

Neustar Names Becky Burr as its Chief Privacy Officer

Frontline and Nominum Deliver Integrated DNS-Based Platform to Enhance Enterprise Security

Nominum Launches Comprehensive Suite of DNS-Based Security Solutions for Russian Service Providers

Call for Nominations to the Public Interest Registry .ORG Advisory Council

Nominum Sets New Record for Network Speed and Efficiency

Recursive DNS Talk: Round Trip Times, Delegations and Performance

Oman Relaunches .om with the Support of ARI Registry Services

Implementing a Cyber-Security Code of Conduct: Real-Life Lessons From Australia (Webinar)

Domains Ending With .JP.NET Now Available to the General Public at Bargain Prices

Minds+Machines Wins Back-End Registry Services Contract For .BASKETBALL

DDoS Attacks: Top 10 Trends and Truths (Video)

.US Celebrates American Small Business, Surprises Unsuspecting Small Business Owner

Architelos Introduces 'Velocity' to Help TLDs Market in Evolving Domain Name Industry

Nominum Chairman and Chief Scientist, Dr. Paul Mockapetris Inducted into the Internet Hall of Fame

Nominum and Nixu Software to Deliver Centralized DNS and DHCP Management Solution

Minds + Machines Will Host New dot Rugby gTLD

DNS on Defense, DNS on Offense

Managing Outbound Spam: A New DNS-based Approach For Stopping Abuse (Webinar)

PIR Launches First-Ever .ORG Television Commercial In India

Hot Topics

dotMobi

Mobile

Sponsored by
dotMobi
Nominum

IPv6

Sponsored by
Nominum
Neustar UltraDNS

DNS

Sponsored by
Neustar UltraDNS
Minds + Machines

Top-Level Domains

Sponsored by
Minds + Machines
Verisign

Security

Sponsored by
Verisign
Afilias

DNS Security

Sponsored by
Afilias