Posted on

Bulk email vendors and responsibility for abusive customers

A bulk email provider can truthfully say:

We did not write that message.

That does not mean the provider has no role in what happens next.

Email delivery services supply the machinery customers need to send at scale: SMTP or API access, domain authentication, sending IPs, reputation monitoring, bounce processing, complaint handling, analytics, and enough throughput to reach enormous lists quickly.

That infrastructure is useful to legitimate businesses.

It is also useful to abusive senders.

Amazon SES makes the tension visible in its current enforcement documentation. AWS tracks bounce and complaint rates, places accounts under review when complaint rates become too high, and can pause sending if problems continue. Its documentation says high complaint rates are commonly associated with mail recipients did not expect or did not want. See Amazon SES sending review process FAQs.

AWS currently recommends keeping complaint rates below 0.1%; accounts at or above that level can be reviewed, and substantially higher rates can lead to sending being paused.

The exact threshold is less important than the principle:

The infrastructure provider is watching what its customers do because customer abuse damages the infrastructure itself.

Reputation is shared farther than the customer thinks

A bad sender does not only hurt recipients.

It can damage IP reputation, domain reputation, feedback relationships, abuse desks, and the deliverability of other customers using nearby infrastructure.

That gives bulk vendors a practical reason to enforce acceptable-use rules.

The vendor may require opt-in practices, investigate complaints, suspend credentials, rate-limit suspicious activity, or demand remediation before restoring service.

These controls are not proof that every complaint means spam. People sometimes report legitimate mail. Lists age. Addresses are mistyped. Transactional messages can annoy recipients too.

Patterns matter.

Large customers create awkward incentives

The uncomfortable part is economic.

A high-volume customer can also be a high-revenue customer.

Removing one may protect infrastructure while costing the provider money. Keeping one may preserve revenue while increasing complaints and reputational risk.

The provider therefore sits in the middle of the Spam Empire supply chain: not necessarily the author, not necessarily the beneficiary of the advertised product, but the party operating the pipes.

Industrial email abuse survives when everybody in that chain can point downstream and say the bad behavior belonged to somebody else.

The pipes still carried it.

Posted on

Lead brokers that sell one inquiry to multiple advertisers

A person can ask one company for a quote and accidentally start a small parade.

That is the strange arithmetic of lead generation.

A lead generator collects a person’s interest in a product or service—insurance, lending, education, solar installation, home repair, or something similar—and passes that information to businesses willing to pay for access to the potential customer.

The Federal Trade Commission describes the basic model plainly: lead generators cultivate consumer interest and sell the resulting lead information to third parties. The data can pass through multiple online marketing entities before reaching the business that finally contacts the consumer. See the FTC’s workshop on online lead generation.

That model is not inherently deceptive.

The problem begins when the consumer’s understanding of the transaction is much smaller than the actual distribution of their data.

One click can create many sales conversations

The user may believe they are asking for one mortgage quote, one insurance comparison, or one service estimate.

Behind the form, the lead can be sold to several buyers, resold again, or routed through a marketplace of marketers.

In a 2024 settlement involving Response Tree, the FTC alleged that websites collected consumer information under misleading pretexts and sold leads that were then used for millions of illegal telemarketing calls. The FTC said some of the company’s operations offered thousands of leads for sale per day. See the FTC’s Response Tree settlement announcement.

That case involved alleged unlawful conduct and should not be treated as representative of every lead-generation business.

It does illustrate the amplification mechanism.

One submitted form can create contact from many parties.

Disclosure has to explain multiplication

A meaningful disclosure should make the scope understandable before the person submits their information.

Who receives the lead? One provider or many? What categories of companies? By email, phone, or text? Is the information sold again? Is the list of potential partners finite and identifiable, or effectively open-ended?

A tiny sentence saying “marketing partners may contact you” can be technically visible while failing to communicate the practical result.

That practical result is what matters to the recipient.

Spam Empires are not built only by people blasting random addresses.

Sometimes industrialized marketing begins with a real human inquiry and becomes garbage through multiplication.

Posted on

Affiliate programs that outsource unsolicited promotion

Affiliate marketing creates a simple incentive:

Bring me a customer and I will pay you.

That can fund perfectly ordinary promotion—reviews, newsletters, comparison sites, videos, and referrals from audiences that actually asked to hear from the promoter.

It can also create a distance problem.

The brand gets the sale. The affiliate chooses how aggressively to chase it.

If the affiliate uses unsolicited or deceptive email, the recipient may see a message from some disposable sender while the company benefiting from the conversion sits several steps away.

That distance does not necessarily erase responsibility.

The Federal Trade Commission has brought cases where companies allegedly paid affiliates who sent unlawful spam to drive traffic. In a 2005 enforcement action involving adult websites, the FTC said the defendants could be liable for illegal messages sent by affiliates because they paid others to send email on their behalf. See FTC Cracks Down on Illegal X-rated Spam.

The FTC’s current CAN-SPAM compliance guide also warns that a seller who pays or gives someone a benefit for generating traffic or referrals may have compliance obligations depending on the facts. See the FTC CAN-SPAM compliance guide.

Outsourcing can also outsource temptation

A salaried marketing employee has a manager, a company account, and a reputation tied directly to the employer.

An affiliate may only get paid when somebody converts.

That can reward volume and experimentation. Honest affiliates still follow rules and protect their audiences. Bad ones may use misleading sender names, scraped addresses, deceptive subject lines, or other tactics if the commission exceeds the expected cost of getting caught.

The merchant can then be tempted to treat the problem as somebody else’s behavior.

But the economic chain still ends at the promoted product.

Accountability follows the money and control

A serious investigation asks who designed the campaign, who supplied the creative material, who paid commissions, who tracked referrals, what rules affiliates were given, whether complaints were monitored, and whether known abusers were removed.

Not every affiliate violation proves the merchant ordered it.

Not every merchant can plausibly claim ignorance forever either.

That is what makes affiliate spam industrial rather than merely annoying.

The person pressing Send can be replaceable.

The incentive system behind them may be the durable part.

Posted on

Snowshoe spam and the distribution of volume across many senders

Snowshoe spam is named after the trick that makes a snowshoe work.

Spread the weight across a larger surface.

Spamhaus defines snowshoe spamming as distributing spam output across many IP addresses and domains in order to dilute reputation metrics and evade filters. See the Spamhaus glossary.

The important detail is that snowshoe spam is not simply a lot of spam from a lot of places.

It is a sending strategy built around distribution.

One sender can look almost ordinary

Imagine a campaign that needs to send one million messages.

Sending all one million from a single new IP makes the source extremely obvious. Volume spikes. Complaint ratios accumulate quickly. Reputation systems have one clear object to punish.

Spread the same campaign across hundreds of IPs and domains, however, and each individual sender may produce a much smaller amount.

Spamhaus documented this problem years ago: snowshoe sources could send modest volumes that looked superficially like ordinary bulk mail while collectively producing a much larger campaign. See Two month “snowshoe” trek results.

This differs from a botnet in an important way.

Botnets commonly use compromised devices belonging to unsuspecting people. Snowshoe operations typically rely on ranges, servers, domains, and infrastructure deliberately provisioned for sending.

Both distribute traffic.

The ownership model is different.

Detection requires stepping back

Looking at one IP can miss the pattern.

Investigators instead compare timing, message templates, destination URLs, domain registrations, hosting relationships, sender naming, tracking codes, and other shared characteristics across the broader campaign.

The challenge is avoiding the opposite mistake: several customers of the same provider are not automatically one spam operation.

Aggregate evidence has to show coordination, not merely proximity.

That makes snowshoe spam a good example of industrial garbage hiding inside fragmentation.

Each sender can look small.

The empire only appears when you stop staring at one footprint and look at the whole field.

Posted on

Disposable domains and the economics of sender replacement

A domain name can be a reputation.

It can also be a paper cup.

Legitimate organizations usually have reasons to keep the same domain working: customers know it, links point to it, authentication accumulates around it, employees use it, and losing it would be expensive.

An abusive sender can have the opposite incentive.

Once a domain develops a poor reputation, the cheap option may be to abandon it and register another one.

Spamhaus describes this behavior in its documentation on domain blocklisting and snowshoe activity. It notes that abusive operations may use many domains and IP addresses that change frequently, while legitimate bulk senders generally invest in durable identities and long-term reputation. See the Spamhaus Domain Blocklist FAQ.

The point is not that a new domain is suspicious by definition.

The point is that replaceability changes the cost of enforcement.

Reputation only works when somebody cares about keeping it

Sender reputation is useful because bad behavior is supposed to create future consequences.

If a domain sends unwanted mail and recipients complain, filters can learn. If the same identity keeps sending, those consequences accumulate.

But if the operator expects to discard the domain after a short campaign, reputation becomes less of a deterrent.

The sender is not repairing the building.

They are moving to another motel room.

Cheap registration, automated DNS configuration, disposable landing pages, and large domain inventories can make that strategy practical at scale.

The address changes; the operation may not

Investigators therefore look beyond the visible domain.

Repeated templates, tracking parameters, affiliate identifiers, hosting patterns, name servers, registration timing, payment destinations, linked infrastructure, message wording, and campaign schedules can reveal relationships among apparently separate senders.

None of those clues alone proves common ownership. Shared infrastructure and templates can have innocent explanations.

But continuity can exist even when the domain name does not.

This is another industrial feature of Spam Empires: the identity in the From line or hyperlink may be designed to die young.

The operation survives because replacing the label costs less than rehabilitating it.

Posted on

Botnets as infrastructure for large-scale unsolicited email

A botnet solves a spammer’s infrastructure problem by making somebody else own the infrastructure.

Instead of sending millions of messages from one clearly identifiable server, an operator controls a large population of infected computers and distributes work across them.

Microsoft’s 2020 disruption of the Necurs botnet shows the scale this can reach. Microsoft reported that Necurs had infected more than nine million computers worldwide and had been used to distribute spam, malware, scams, and other attacks. The disruption required legal and technical coordination across 35 countries. See Microsoft’s account of the Necurs botnet disruption.

Nine million infected machines are not nine million willing senders.

They are nine million pieces of stolen capacity.

Distribution changes the economics

A single sending server has obvious limits.

It has one provider, a finite amount of bandwidth, a visible IP reputation, and a clear choke point. If it starts producing abusive mail, a provider can suspend it and filters can learn the source.

A botnet spreads that burden across many devices and networks.

The machine owner may pay for the electricity and Internet connection. The ISP handles the traffic. Mail providers process and reject the messages. Security companies track the infrastructure. Recipients spend attention sorting what escaped the filters.

The operator externalizes much of the cost.

That is one reason botnets became such powerful infrastructure for Spam Empires.

Taking down a sender is not the same as taking down the system

If one campaign domain disappears but the underlying botnet survives, the delivery network can be reused.

It may send a different advertisement tomorrow, deliver malware next week, or be rented into another criminal operation. Conversely, disrupting a botnet does not eliminate unsolicited email as a business model; another delivery mechanism can replace it.

This is the industrial distinction that matters.

The visible email is a product.

The botnet is a factory floor made out of stolen computers.

Posted on

Compromised accounts as delivery channels with borrowed reputations

A stolen sending account comes with something more valuable than a password.

It comes with history.

An established mailbox or email-service account may already have a recognizable sender name, legitimate contacts, authenticated infrastructure, normal traffic patterns, and a reputation built over months or years.

An attacker who gains access can borrow all of that temporarily.

Amazon Web Services describes the problem directly in its guidance for Amazon SES. If credentials with permission to send mail are compromised, a malicious actor can use the customer’s SES account to send spam or phishing messages. AWS warns that the resulting bounce and complaint rates can damage sender reputation and can lead to the account’s sending ability being paused. See AWS guidance on securing compromised email-sending credentials.

The attacker gets the delivery channel.

The legitimate owner gets the cleanup bill.

Reputation can be stolen without being transferred

Email systems rely heavily on accumulated trust signals.

A domain that has sent normal correspondence for years looks different from a domain registered this morning. A known coworker’s address looks different to a recipient from an unknown sender. A mature cloud account with authenticated sending may initially look less suspicious than a brand-new operation.

Account compromise exploits that difference.

The recipient sees a familiar identity or reputable infrastructure. The attacker sees camouflage.

That does not mean every message from a compromised account will bypass filters or fool recipients. Sudden volume, strange destinations, unusual content, login anomalies, authentication failures, and complaints can expose the change quickly.

But the abuse starts with borrowed credibility.

The legitimate owner pays twice

First comes the security incident.

Then comes the reputation incident.

The owner may need to rotate credentials, investigate access logs, contact recipients, remove malicious rules, repair domain reputation, handle abuse reports, and convince providers that the account is under control again.

Recipients also pay a trust cost. A real person’s mailbox becomes evidence that even familiar identities need verification when a message suddenly asks for money, credentials, or an unexpected click.

This is why compromised accounts matter to Spam Empires.

Industrial abuse does not always build a sender from scratch.

Sometimes it steals a good one for the afternoon.

Posted on

Address harvesting from public websites and directories

The cruel little trick of a public email address is that the person who needs to remain reachable also becomes easy to collect.

A professor posts an address for students. A small business lists one for customers. A developer puts one in project documentation. A volunteer organization publishes contact details so actual humans can ask questions.

A harvester sees the same page as inventory.

The Federal Trade Commission tested this directly in 2005. Staff created 150 undercover email accounts and posted addresses on public Internet locations including message boards, blogs, chat rooms, and Usenet groups. The FTC reported that spammers continued to harvest addresses from public areas of the Internet. See FTC Study Shows Technology Gaining in the Battle Against Spam.

The practice is old because the economics are obvious.

A crawler can collect addresses faster than a person can decide whether each recipient would reasonably expect the message.

Reachable does not mean subscribed

A public address communicates one thing clearly:

You may contact this person for some purpose.

It does not automatically communicate:

Add this person to an unrelated bulk campaign forever.

Intent matters.

A journalist publishing a tip address is inviting tips. A shop publishing a support address is inviting customer questions. A domain registration contact, conference speaker page, academic directory, or open-source README may expose an address for a specific practical reason.

Mass promotional reuse changes the purpose without asking the owner.

U.S. CAN-SPAM law also treats some address harvesting as especially serious. The FTC’s current compliance guide lists harvesting email addresses among aggravated violations that can trigger additional consequences when the statutory conditions are met. See the FTC CAN-SPAM compliance guide.

The defensive cost falls on the reachable person

Harvesting produces a strange penalty for openness.

People who need public contact details start disguising addresses, routing everything through forms, adding CAPTCHA, using disposable aliases, or hiding behind platform messaging systems.

That makes automated collection harder.

It can also make legitimate contact harder.

The public web loses a little interoperability because somebody decided that every visible mailbox was a lead source.

This is one of the quieter ways Spam Empires change the shape of the internet. Abuse does not merely fill inboxes.

It teaches ordinary people that being easy to reach is a liability.

Posted on

Purchased mailing lists and the trade in uncertain consent

An email address is easy to sell.

The history attached to that address is much harder to package.

A purchased mailing list may arrive as a tidy spreadsheet containing names, companies, job titles, locations, interests, or demographic labels. What it often does not make obvious is the exact chain of events that supposedly authorized the buyer to contact each person.

That distinction matters because possession of an address and permission to use it are different facts.

The Federal Trade Commission makes an important U.S. legal distinction here. Its CAN-SPAM guidance says the federal law generally does not require prior opt-in consent before sending commercial email, provided the sender follows the law’s requirements and honors opt-outs. But the FTC also warns that purchased lists can be risky because addresses may belong to people who already opted out or may have been collected through unlawful harvesting or dictionary attacks. See the FTC’s Candid answers to CAN-SPAM questions.

So legal ability to send one kind of commercial message is not the same thing as evidence that the recipient asked for it.

The list loses its story as it changes hands

Suppose a person enters an email address to download a report from Company A.

Did the form clearly say Company A would email them? Did it say their address would be sold? Did it identify the eventual buyer? Did it authorize unrelated marketing? Was the permission limited to one topic? Was the box pre-checked? When did this happen?

A CSV containing person@example.com answers none of those questions.

That is why large email platforms often impose standards stricter than the minimum federal rule. Mailchimp, for example, prohibits purchased, rented, and scraped third-party lists under its current audience requirements. See Mailchimp’s audience requirements.

The platform is protecting more than etiquette. Recipients who do not recognize a sender are more likely to ignore, unsubscribe from, or report the message, damaging delivery reputation for everybody sharing the infrastructure.

Consent needs provenance

A meaningful consent claim needs evidence.

Useful records might include the original collection page, the wording shown beside the form, the date and time of signup, what categories of communication were described, whether third-party sharing was disclosed, the identity of the entity collecting the address, and any later opt-out.

Without that provenance, “they were on a marketing list” is circular reasoning.

The Spam Empires problem is not merely that lists became large.

It is that addresses became tradable inventory while the expectations of the humans attached to them were often reduced to a column nobody bothered to include.

Posted on

The transition from individual junk-mail senders to industrial delivery networks

Spam became historically important when it stopped being merely a person with a list and became infrastructure.

Early unsolicited email could be obnoxious without being industrial. One sender acquired addresses, wrote a message, and pushed it outward.

By the 2000s and early 2010s, major spam operations could involve infected computers, command-and-control systems, disposable domains, specialized hosting, affiliate programs, payment processors, fulfillment networks, and people who never personally touched the machine that delivered the email.

The junk message was the visible tip of a supply chain.

The sender became a network

Rustock is one of the clearest documented examples.

Microsoft describes Rustock as a rootkit-enabled spam botnet that covertly used infected computers to distribute unsolicited email. At its peak, Microsoft says it was responsible for more than 30 billion spam messages per day and as much as 30–40% of global spam volume. A single infected machine could send thousands of messages in less than an hour. See Microsoft’s history of the Rustock disruption.

That is no longer the economics of one human pressing Send.

The delivery layer had been distributed across machines belonging to ordinary people who often did not know their computers were participating.

Spam had a value chain too

Researchers later mapped the broader commercial structure behind spam campaigns.

The paper “Click Trajectories: End-to-End Analysis of the Spam Value Chain” examined spam as a business process involving multiple dependencies: domain registrars, DNS, hosting, affiliate programs, payment processing, and fulfillment.

That distinction matters because the organization sending the advertisement was not necessarily the same organization that registered the domain, hosted the storefront, processed the payment, or operated the delivery network.

Specialization made abuse more resilient.

If one domain died, another could replace it. If one delivery source was blocked, traffic could move. If one affiliate stopped, another could continue promoting the same product.

Industrial scale changed everybody else’s job

Once spam became infrastructure, recipients were no longer dealing with individual nuisance senders one at a time.

Mail providers had to build reputation systems, filtering pipelines, abuse desks, authentication standards, blocklists, malware detection, rate limits, and large-scale telemetry just to keep ordinary inboxes usable.

Network operators had to deal with compromised machines. Registrars and hosting companies became part of abuse investigations. Law enforcement and private companies sometimes had to coordinate across multiple jurisdictions to dismantle botnets.

The defensive industry scaled because the offensive industry had already done so.

That is where Spam Empires — The Industrialization of Garbage begins.

The interesting question is no longer simply who sent the junk mail?

It is what machinery made sending billions of pieces of junk economically routine?