Posted on

Financial incentives that keep marginally effective spam profitable

Spam does not need to work well.

It only needs to work often enough to pay for itself.

That difference explains a lot of ugly internet behavior.

In 2008, researchers infiltrated the Storm botnet and measured real spam conversion rather than relying on surveys. Their Spamalytics experiment observed 28 pharmacy purchases from a massive campaign, equivalent to roughly one purchase for every 12.5 million pharmacy spam messages they tracked. See Spamalytics: An Empirical Analysis of Spam Marketing Conversion.

That conversion rate is microscopic.

The researchers explicitly warned against generalizing the exact number to every campaign.

The important result is the economics: microscopic can still be nonzero.

Cheap distribution changes what counts as success

A physical advertiser pays for printing, postage, delivery, airtime, staff, or inventory for every additional contact.

Digital bulk messaging can push the marginal cost of another million attempts much lower.

If the cost of adding another recipient is tiny, the campaign can tolerate extraordinary failure.

An OECD background paper on spam made the same point years earlier: low distribution costs allow bulk email to remain profitable even at very low response rates, especially because much of the receiving and filtering cost is borne by ISPs, businesses, and users. See the OECD’s Background Paper for the Workshop on Spam.

That creates a strange incentive.

The sender does not need to persuade most people.

The sender needs access to enough people.

Externalized cost is part of the business model

Imagine a campaign that sends ten million messages.

Almost everyone deletes them.

Mailbox providers filter them. Recipients waste a few seconds. Abuse desks handle complaints. Shared platforms protect their reputations. Blocklists and machine-learning systems process the traffic.

The sender does not reimburse any of those parties.

If a tiny number of recipients buy a product, enter credentials, install malware, or generate affiliate commissions, the campaign may still produce revenue.

That is why annoyance is not an effective market signal by itself.

The people bearing the annoyance are usually not the people deciding whether the next campaign is profitable.

Failure at human scale can be success at machine scale

This is one of the central economic features of Spam Empires.

A campaign can be despised by 9,999,999 people and still be judged internally by the one conversion that paid the server bill.

Automation makes that possible because the sender does not experience rejection one person at a time.

No human salesperson hears twelve million people say no.

The system records clicks, purchases, infections, or leads.

Everything else becomes statistical exhaust.

Spam is not persistent because it persuades everybody.

It is persistent because the internet made it possible to lose almost every interaction and keep playing.

Posted on

Abuse-reporting systems that make individual complaints hard to pursue

Reporting abuse can feel like being asked to investigate the abuse first.

A recipient sees an unwanted or malicious message.

The service provider may need the full headers, sending IP, URL, timestamp, account identifier, screenshots, logs, or a description precise enough to route the complaint to the correct internal team.

Those details are useful.

They are also exactly the sort of details an ordinary user may not know how to find.

Google Cloud’s current abuse form, for example, asks reporters to provide abusive IP addresses or URLs and says that full HTTP request headers and additional logs can make an investigation more useful. It also notes that Google may only follow up if more information is needed. See Google Cloud’s abuse reporting form.

That is reasonable from an investigator’s perspective.

From the reporter’s perspective, it can feel like dropping evidence into a slot in the wall.

Actionable reports need context

Service operators cannot act safely on vague accusations.

“This guy is spamming me” does not establish who actually sent the mail. The visible From address can be forged. A URL may redirect. A message may have passed through several providers. A hosting company may only control one component of the chain.

Technical evidence narrows the problem.

Amazon SES complaint notifications illustrate the kind of structured evidence providers can work with: complaint type, recipient, arrival time, feedback ID, and sometimes the original message headers. See Amazon SES complaint notification examples.

Machines love that structure.

People usually arrive with a screenshot and irritation.

Feedback is often intentionally limited

Abuse teams also face privacy and security constraints.

A provider may suspend an account without telling the reporter exactly what happened. It may aggregate a complaint with thousands of others. It may be unable to disclose an investigation into another customer.

Google’s public reporting guidance says it may respond only when additional information is required or when there is more to share. See Google’s abuse-reporting guidance.

That can make a valid report look ignored even when it contributed to enforcement.

The reverse also happens: a report genuinely goes nowhere because it lacked usable evidence, reached the wrong provider, described behavior outside the provider’s rules, or was lost among enormous abuse volume.

Reporting friction is part of the spam economy

This matters because every additional step raises the cost of complaining.

Most recipients will not inspect headers, identify infrastructure providers, submit multiple forms, and preserve evidence for a $49 miracle supplement email.

They delete it.

At industrial scale, that means abuse can generate far more annoyance than formal complaints.

A good reporting system therefore needs two things that pull in opposite directions:

low friction for ordinary users and enough technical detail for operators to act accurately.

Spam Empires thrive in the gap between those requirements.

The message takes one second to send.

The complaint can require homework.

Posted on

The cost of spam shifted onto recipients, moderators, and service operators

Spam is cheap because somebody else pays the bill.

Not necessarily in money.

Sometimes the payment is five seconds of attention.

Sometimes it is a moderator reviewing a queue, an abuse team tracing headers, a mail provider operating filtering infrastructure, or a business employee digging a real customer inquiry out from under fifty fake SEO pitches.

The economics have been understood for a long time. An OECD paper on spam described what it called a transfer of cost: sending bulk email is extremely cheap, while receiving, storing, downloading, filtering, and handling it imposes costs on ISPs, businesses, and individuals. See Spam Issues in Developing Countries.

The technology has changed since 2005.

The cost-shifting logic has not.

The sender buys scale; everybody else buys defense

Consider one unwanted message.

The sender pays almost nothing for the additional delivery.

The recipient has to identify it, ignore it, delete it, unsubscribe, report it, or wonder whether it is legitimate.

The mailbox provider had to accept or reject the connection, run reputation checks, inspect the message, store it if accepted, classify it, expose reporting controls, aggregate complaints, and maintain the systems that make all of that work.

The website owner receiving contact-form spam pays with moderation time.

The forum administrator pays with anti-abuse plugins and account review.

The legitimate bulk sender pays because other customers poisoned the reputation of shared infrastructure.

Each interruption is tiny.

Industrial scale turns tiny into infrastructure.

Defensive systems are themselves a cost of spam

Blocklists, machine-learning filters, feedback loops, authentication standards, abuse desks, rate limits, reputation dashboards, and moderation tools are useful technologies.

They also exist because open communication channels attract abuse.

Spamhaus says its blocklists reduce email infrastructure costs and human-resource requirements by helping administrators reject abusive traffic earlier. See the Spamhaus Blocklist documentation.

That is a benefit of filtering.

It is also evidence of the burden being filtered.

Attention is the least visible invoice

Recipient cost is particularly difficult to measure.

Five seconds deleting one junk message is negligible.

Five seconds multiplied across millions of people is not.

The same is true of false positives. Stronger filtering saves time until it blocks a wanted invoice, password reset, or customer inquiry and somebody has to investigate.

Spam Empires survive because the sender does not have to compensate everyone who handles the unwanted traffic downstream.

The campaign can fail for 99.999% of recipients and still impose work on nearly all of them.

That is the economic trick.

The sender pays to send.

The internet pays to make sending tolerable.

Posted on

Recycled addresses and unreliable claims of an opted-in audience

An email address can stay the same after its meaning changes.

That is bad news for anyone treating a ten-year-old mailing list as a permanent record of human consent.

Mailboxes disappear. Employees leave companies. Role addresses move to new staff. Old consumer accounts go dormant. Some abandoned addresses are eventually repurposed by anti-spam systems as recycled spam traps.

Mailchimp describes recycled traps as addresses that were once real accounts but became inactive and were later used to identify senders who continue mailing stale contacts. See Mailchimp’s explanation of spam traps.

Spamhaus describes a similar process for what it calls dead-address traps: an address can reject mail for a long period and later be reactivated as a trap. See Spamhaus on spamtraps.

The important lesson is larger than spam traps.

A mailing-list record describes a relationship at a moment in time.

Permission belongs to a person and context, not merely an address

Suppose alex@example.com subscribed to a newsletter in 2017.

The sender may have a perfect record showing that Alex clicked a confirmation link.

Years later, the address has been abandoned, reassigned, converted to a role account, or transformed into a trap. The database still says confirmed subscriber.

The database is historically correct and presently wrong.

That is why list maintenance matters.

A sender needs more than evidence that permission existed once. It also needs evidence that the address remains deliverable and that the relationship has not obviously gone stale.

Mailchimp recommends archiving inactive contacts partly because stale addresses can become traps. Spamhaus likewise recommends re-permissioning old lists in some situations rather than assuming an ancient consent record remains meaningful. See Spamhaus guidance for old mailing lists.

Old data can become false without anyone lying

This is a useful Spam Empires problem because it does not require a villain.

A company can honestly say, “this address opted in.”

The current recipient can honestly say, “I never did.”

Both statements can be true if the mailbox changed.

That is what makes provenance and maintenance different tasks.

Provenance answers: how did this address enter the list?

Maintenance answers: does that old event still describe the person receiving the message today?

Industrial marketing systems are very good at preserving records.

Human relationships are less cooperative.

A database can remember consent long after the consenting human has left the building.

Posted on

Blocklists and the collateral damage of shared sending infrastructure

A blocklist can identify an abusive source without knowing every person using the same pipe.

That is where the trouble begins.

Modern email is full of shared infrastructure. Thousands of organizations can send through the same email service provider. Many websites can share a hosting network. A marketing platform may place unrelated customers behind the same pool of outbound IP addresses.

That makes reputation efficient.

It also makes reputation contagious.

Spamhaus explains that its Spamhaus Blocklist can contain individual IP addresses or entire IP ranges associated with spam and other abusive activity. Receiving mail administrators decide whether to reject, flag, or further filter mail based on those listings. See the Spamhaus Blocklist documentation and its explanation of how blocklists are used.

The enforcement unit can therefore be larger than one individual sender.

Shared infrastructure creates shared risk

Suppose one customer on a shared outbound mail platform sends a terrible purchased list.

Complaints rise. Spam traps are hit. The shared sending IP acquires a bad reputation.

Other customers using that same IP may be sending ordinary newsletters to people who asked for them.

Mailchimp openly describes this problem in its documentation on spam traps: if a sending IP is denied or blocklisted, that can affect delivery for other Mailchimp users sharing the infrastructure. See Mailchimp’s explanation of spam traps.

This is not evidence that blocklists are careless.

It is evidence that attribution becomes difficult when many independent actors share technical resources.

Broad blocking and precise attribution pull in opposite directions

Receiving systems operate under pressure.

They may need to reject enormous volumes of abusive mail in real time. Investigating every message back to the exact contractual customer behind an IP is often impossible during the SMTP transaction.

A broad reputation signal is fast.

A precise human attribution is slow.

That tradeoff creates false-positive risk.

Spamhaus itself warns that different blocklists are designed for different purposes and that using one in the wrong place can create problems. Its Policy Blocklist, for example, identifies IP ranges that should not send mail directly to destination servers; Spamhaus has specifically warned providers not to misuse that list against authenticated outbound users. See its discussion of PBL misuse.

The lesson is not that blocklists are bad.

Without reputation systems, recipients and mail operators would absorb even more abuse.

The lesson is that technical reputation belongs to infrastructure, while responsibility belongs to actors.

Those two layers do not always line up neatly.

Spam Empires exploit shared systems because scale loves aggregation.

The defensive side aggregates too.

Sometimes innocent mail gets caught between them.

Posted on

Spam complaint thresholds and the unequal consequences of audience scale

One thousand spam complaints sounds catastrophic.

It might be.

It might also represent one-tenth of one percent of a million delivered messages.

Scale makes raw complaint counts surprisingly easy to misuse.

Gmail currently tells senders to keep user-reported spam rates below 0.1% and to prevent them from reaching 0.3% or higher. For bulk senders, rates at or above 0.3% can make them ineligible for delivery mitigation until the rate remains below that level for seven consecutive days. See Gmail’s sender guidelines FAQ.

Yahoo likewise tells senders to keep complaint rates below 0.3%. See Yahoo Sender Hub best practices.

These systems use rates for a reason.

Counts punish size; rates can hide volume

Imagine two senders.

Sender A delivers 1,000 messages. One recipient reports spam.

Complaint rate: 0.1%.

Sender B delivers 1,000,000 messages. One thousand recipients report spam.

Complaint rate: also 0.1%.

The rate says the same fraction of recipients objected.

The count says Sender B created one thousand times as many individual complaints.

Neither measurement is automatically superior.

If the question is how likely is one recipient to complain?, the rate is useful.

If the question is how much total complaint handling did this campaign generate?, the count matters.

Thresholds are not proof of favoritism

This becomes important when people compare a giant advertiser with a tiny sender and conclude that one is being protected because it can generate more complaints without disappearing.

That conclusion may be true in a particular case.

But the raw numbers cannot prove it.

A fair comparison needs the same denominator, similar message types, similar recipient acquisition, similar complaint definitions, similar time periods, and evidence about what enforcement actually followed.

Large senders may also face requirements that small senders do not. Gmail classifies a sender that reaches roughly 5,000 messages per day to personal Gmail accounts as a bulk sender and permanently applies additional requirements such as both SPF and DKIM, DMARC, and one-click unsubscribe for promotional mail.

That is explicitly different treatment based on scale.

It is not evidence that the treatment is more lenient.

Complaint metrics describe behavior, not consent history

Even a low complaint rate does not prove that every recipient wanted the mail.

Many people delete unwanted messages instead of reporting them. Some never see a message because it was filtered. Others tolerate marketing they did not particularly request.

A complaint rate is therefore one signal about recipient reaction.

It is not a census of unwanted mail.

Spam Empires operate at scales where denominators matter.

Without them, a thousand complaints can look enormous and one-tenth of one percent can look tiny.

They can describe the same campaign.

Posted on

Email authentication as an identity check rather than proof of consent

A perfectly authenticated email can still be unwanted.

That sounds obvious until the green lights start appearing in the headers.

SPF passes. DKIM passes. DMARC passes. The domain aligns correctly. The message came through TLS. Technically, the sender has done a lot right.

What those checks establish is mostly identity and authorization at the domain level.

They do not establish permission from the recipient.

Google’s current Gmail requirements make this distinction visible. Bulk senders must authenticate mail with SPF and DKIM, publish DMARC, and align the visible From domain with authenticated domains. Google separately tells senders to avoid unwanted mail, keep complaint rates low, and provide one-click unsubscribe for promotional messages. See Gmail’s email sender guidelines FAQ.

Those are separate requirements because they answer separate questions.

Authentication asks who is speaking

SPF checks whether the sending server is authorized for a domain.

DKIM verifies a cryptographic signature attached by the sending domain.

DMARC ties authentication to the domain shown to the user and lets domain owners publish handling policies for failures.

These systems are enormously useful against spoofing and impersonation.

If an attacker sends a fake bank message from infrastructure the bank never authorized, authentication can help a receiving system detect the mismatch.

But suppose the real bank sends a promotional message from its real servers using its real domain.

Authentication can correctly say: yes, this really came from the bank.

It cannot say: yes, Leo asked for this offer.

A verified nuisance is still a nuisance

This matters because sender reputation can be mistaken for recipient consent.

A large company can authenticate every message flawlessly and still mail an old address, over-message an inactive customer, misunderstand a signup, or keep sending categories of promotion the recipient no longer wants.

The inverse is also possible. A small legitimate sender can make an authentication mistake while sending mail that subscribers genuinely requested.

Identity and desirability are correlated only indirectly.

To establish permission, investigators need a different evidence trail: where the address was collected, what wording appeared beside the form, whether the person confirmed the subscription, what categories of messages were described, when the permission was recorded, and whether the person later opted out.

The FTC’s CAN-SPAM guidance also makes a useful legal distinction. U.S. federal law generally does not require prior opt-in consent for commercial email, provided the sender follows the law’s requirements and honors opt-outs. See the FTC’s Candid answers to CAN-SPAM questions.

So even lawful, authenticated, and wanted are three different properties.

Spam Empires become easier to study when those properties are not collapsed into one another.

Authentication can tell you a great deal about who sent the message.

It cannot tell you whether the human receiving it ever wanted to hear from them.

Posted on

Deliverability consulting and the business of reaching guarded inboxes

Getting an email accepted by a mail server is not the same thing as getting it welcomed by a human.

That gap supports an entire professional discipline: email deliverability.

Legitimate senders need help with SPF, DKIM, DMARC, domain reputation, IP reputation, bounce handling, complaint rates, list hygiene, feedback loops, sending patterns, and technical mistakes that can cause wanted mail to land in spam.

Those are real engineering problems.

Google’s current Postmaster Tools expose many of them directly, including spam rate, domain and IP reputation, authentication, encryption, and delivery errors. See Gmail’s Postmaster Tools documentation.

A consultant who helps a legitimate newsletter fix broken authentication or identify a damaged sending reputation is not helping a spammer sneak through a side door.

They are helping wanted mail function correctly.

Delivery and desirability are different measurements

The problem begins when inbox placement becomes the only success metric.

A campaign can be technically excellent and socially unwanted.

SPF can pass. DKIM can pass. DMARC can pass. The sending domain can be configured beautifully. The message can still reach somebody who never expected it, no longer wants it, or has repeatedly ignored it.

Google’s own guidance makes this distinction unusually clear. Its Postmaster recommendations do not stop at authentication. Google also tells senders to mail people who want the messages, confirm opt-in, make unsubscribe easy, monitor complaints, and consider removing recipients who no longer engage. See Gmail’s sender requirements and Postmaster FAQ.

That is the line deliverability work cannot engineer around forever.

A guarded inbox is guarding something

Modern inbox filtering exists because open email is constantly abused.

The walls are not arbitrary obstacles placed in front of marketers. They are defenses built for recipients.

A good deliverability practice therefore improves the sender’s behavior as well as its DNS records. It asks why complaint rates rose, whether acquisition sources are trustworthy, whether inactive addresses should be suppressed, whether unsubscribe works, and whether message frequency matches the audience’s expectations.

A bad practice treats every filter as an enemy to defeat.

Spam Empires become sophisticated when they stop asking only how do we send more? and start asking how do we keep getting through?

The responsible answer includes authentication, reputation, and infrastructure.

It also includes a question no technical consultant can remove:

Did the person on the other side actually want this message?

Posted on

The reputational difference between a bulk spammer and a major advertiser

A message from an unknown sender is easy to call spam.

A nearly identical message from a famous company often gets called marketing.

Sometimes that difference is justified.

Sometimes it is mostly reputation wearing a necktie.

The useful question is not whether one sender has a recognizable logo. It is whether the underlying behavior is actually different.

Labels hide the mechanics

A shady bulk sender may scrape addresses, disguise identity, ignore opt-outs, and send indiscriminately.

A major advertiser may have a documented customer relationship, authenticated infrastructure, suppression lists, complaint monitoring, one-click unsubscribe, and teams whose entire job is keeping unwanted mail low.

Those are real differences.

But a recognizable brand can still send messages recipients no longer want. A large company can over-mail inactive customers, bury unsubscribe controls, or stretch a past purchase into years of promotion.

The Federal Trade Commission’s CAN-SPAM guidance does not create a special category for famous senders. Commercial messages are judged by their content and compliance requirements, not by whether the sender bought a Super Bowl ad. See the FTC’s CAN-SPAM compliance guide.

Recipient behavior is useful evidence

Gmail’s current bulk-sender rules provide a more measurable way to compare senders.

Google recommends keeping user-reported spam below 0.1% and preventing it from reaching 0.3% or higher. Its Postmaster Tools also track domain reputation, IP reputation, spam reports, authentication, and delivery errors. See Gmail’s sender-guidelines FAQ and Postmaster Tools documentation.

Those signals do not tell us whether a campaign is ethically perfect.

They do tell us something more useful than brand prestige: how recipients and infrastructure are actually reacting.

Compare behavior before vocabulary

If two senders both contact people who did not expect the message, both send at high frequency, both make stopping difficult, and both generate complaints, calling one a spammer and the other a marketer can obscure more than it explains.

The reverse is also true. A lawful, well-targeted campaign to consenting customers should not be treated as equivalent to harvested-address botnet mail merely because both are bulk email.

Spam Empires need precise language.

Reputation matters.

But reputation is evidence about history, not a hall pass for the next message.