Posted on

Financial incentives that keep marginally effective spam profitable

Spam does not need to work well.

It only needs to work often enough to pay for itself.

That difference explains a lot of ugly internet behavior.

In 2008, researchers infiltrated the Storm botnet and measured real spam conversion rather than relying on surveys. Their Spamalytics experiment observed 28 pharmacy purchases from a massive campaign, equivalent to roughly one purchase for every 12.5 million pharmacy spam messages they tracked. See Spamalytics: An Empirical Analysis of Spam Marketing Conversion.

That conversion rate is microscopic.

The researchers explicitly warned against generalizing the exact number to every campaign.

The important result is the economics: microscopic can still be nonzero.

Cheap distribution changes what counts as success

A physical advertiser pays for printing, postage, delivery, airtime, staff, or inventory for every additional contact.

Digital bulk messaging can push the marginal cost of another million attempts much lower.

If the cost of adding another recipient is tiny, the campaign can tolerate extraordinary failure.

An OECD background paper on spam made the same point years earlier: low distribution costs allow bulk email to remain profitable even at very low response rates, especially because much of the receiving and filtering cost is borne by ISPs, businesses, and users. See the OECD’s Background Paper for the Workshop on Spam.

That creates a strange incentive.

The sender does not need to persuade most people.

The sender needs access to enough people.

Externalized cost is part of the business model

Imagine a campaign that sends ten million messages.

Almost everyone deletes them.

Mailbox providers filter them. Recipients waste a few seconds. Abuse desks handle complaints. Shared platforms protect their reputations. Blocklists and machine-learning systems process the traffic.

The sender does not reimburse any of those parties.

If a tiny number of recipients buy a product, enter credentials, install malware, or generate affiliate commissions, the campaign may still produce revenue.

That is why annoyance is not an effective market signal by itself.

The people bearing the annoyance are usually not the people deciding whether the next campaign is profitable.

Failure at human scale can be success at machine scale

This is one of the central economic features of Spam Empires.

A campaign can be despised by 9,999,999 people and still be judged internally by the one conversion that paid the server bill.

Automation makes that possible because the sender does not experience rejection one person at a time.

No human salesperson hears twelve million people say no.

The system records clicks, purchases, infections, or leads.

Everything else becomes statistical exhaust.

Spam is not persistent because it persuades everybody.

It is persistent because the internet made it possible to lose almost every interaction and keep playing.

Posted on

Disposable domains and the economics of sender replacement

A domain name can be a reputation.

It can also be a paper cup.

Legitimate organizations usually have reasons to keep the same domain working: customers know it, links point to it, authentication accumulates around it, employees use it, and losing it would be expensive.

An abusive sender can have the opposite incentive.

Once a domain develops a poor reputation, the cheap option may be to abandon it and register another one.

Spamhaus describes this behavior in its documentation on domain blocklisting and snowshoe activity. It notes that abusive operations may use many domains and IP addresses that change frequently, while legitimate bulk senders generally invest in durable identities and long-term reputation. See the Spamhaus Domain Blocklist FAQ.

The point is not that a new domain is suspicious by definition.

The point is that replaceability changes the cost of enforcement.

Reputation only works when somebody cares about keeping it

Sender reputation is useful because bad behavior is supposed to create future consequences.

If a domain sends unwanted mail and recipients complain, filters can learn. If the same identity keeps sending, those consequences accumulate.

But if the operator expects to discard the domain after a short campaign, reputation becomes less of a deterrent.

The sender is not repairing the building.

They are moving to another motel room.

Cheap registration, automated DNS configuration, disposable landing pages, and large domain inventories can make that strategy practical at scale.

The address changes; the operation may not

Investigators therefore look beyond the visible domain.

Repeated templates, tracking parameters, affiliate identifiers, hosting patterns, name servers, registration timing, payment destinations, linked infrastructure, message wording, and campaign schedules can reveal relationships among apparently separate senders.

None of those clues alone proves common ownership. Shared infrastructure and templates can have innocent explanations.

But continuity can exist even when the domain name does not.

This is another industrial feature of Spam Empires: the identity in the From line or hyperlink may be designed to die young.

The operation survives because replacing the label costs less than rehabilitating it.