Don't verify email addresses by sending spam to them

garaetjjte1 pts0 comments

Don't verify email addresses by sending spam to them

Don’t verify email addresses by sending spam to them

23.06.2026

Much have been said about futility of trying to validate email addresses.<br>Generally accepted advice is that you should just send verification link<br>and don’t care about trying to validate it before hand.

But what if you were<br>really hell-bent on having validation step, and at the same time follow the advice?<br>Apparently some people decided they could to it by… sending spam.

Take this Pangram sign-up form. Filling email field here will perform this request:

curl --request POST --data '{"email": "example@example.com"}' https://www.pangram.com/api/validate-email

And soon enough, without doing anything else, you will get an mysterious email. Whaaa…?

Date: Tue, 23 Jun 2026 15:29:10 +0000<br>From: "Winwin Insights"<br>To:<br>Reply-To:<br>Subject: Fact of the day: Magnetic<br>Message-ID:<br>Precedence: Bulk<br>MIME-Version: 1.0<br>Content-Type: text/html; charset=UTF-8<br>Content-Transfer-Encoding: base64

PCFET0NUWVBFIGh0bWw+IDxodG1sPiA8aGVhZD4gPG1ldGEgY2hhcnNldD0iVVRGLTgiPiA8L2hl<br>YWQ+IDxib2R5IHN0eWxlPSJmb250LWZhbWlseTogQXJpYWwsIHNhbnMtc2VyaWY7IGZvbnQtc2l6<br>ZTogMTZweDsgY29sb3I6ICMzMzM7Ij4gPGRpdiBzdHlsZT0icG9zaXRpb246IGFic29sdXRlOyBs<br>ZWZ0OiAtOTk5OXB4OyB0b3A6LTk5OTlweDtkaXNwbGF5OiBub25lOyI+SGkgdGhlcmUsPGJyPiBB<br>IG1hZ25ldGljIGRvbWFpbiBpcyBhIHJlZ2lvbiB3aXRoaW4gYSBtYWduZXRpYyBtYXRlcmlhbCBp<br>biB3aGljaCB0aGUgbWFnbmV0aXphdGlvbiBpcyBpbiBhIHVuaWZvcm0gZGlyZWN0aW9uLiBUaGlz<br>IG1lYW5zIHRoYXQgdGhlIGluZGl2aWR1YWwgbWFnbmV0aWMgbW9tZW50cyBvZiB0aGUgYXRvbXMg<br>YXJlIGFsaWduZWQgd2l0aCBvbmUgYW5vdGhlciBhbmQgdGhleSBwb2ludCBpbiB0aGUgc2FtZSBk<br>aXJlY3Rpb24uIFdoZW4gY29vbGVkIGJlbG93IGEgdGVtcGVyYXR1cmUgY2FsbGVkIHRoZSBDdXJp<br>ZSB0ZW1wZXJhdHVyZSwgdGhlIG1hZ25ldGl6YXRpb24gb2YgYSBwaWVjZSBvZiBmZXJyb21hZ25l<br>dGljIG1hdGVyaWFsIHNwb250YW5lb3VzbHkgZGl2aWRlcyBpbnRvIG1hbnkgc21hbGwgcmVnaW9u<br>cyBjYWxsZWQgbWFnbmV0aWMgZG9tYWlucy4gVGhlIG1hZ25ldGl6YXRpb24gd2l0aGluIGVhY2gg<br>ZG9tYWluIHBvaW50cyBpbiBhIHVuaWZvcm0gZGlyZWN0aW9uLCBidXQgdGhlIG1hZ25ldGl6YXRp<br>b24gb2YgZGlmZmVyZW50IGRvbWFpbnMgbWF5IHBvaW50IGluIGRpZmZlcmVudCBkaXJlY3Rpb25z<br>LiBNYWduZXRpYyBkb21haW4gc3RydWN0dXJlIGlzIHJlc3BvbnNpYmxlIGZvciB0aGUgbWFnbmV0<br>aWMgYmVoYXZpb3Igb2YgZmVycm9tYWduZXRpYyBtYXRlcmlhbHMgbGlrZSBpcm9uLCBuaWNrZWws<br>IGNvYmFsdCBhbmQgdGhlaXIgYWxsb3lzLCBhbmQgZmVycmltYWduZXRpYyBtYXRlcmlhbHMgbGlr<br>ZSBmZXJyaXRlLiBUaGlzIGluY2x1ZGVzIHRoZSBmb3JtYXRpb24gb2YgcGVybWFuZW50IG1hZ25l<br>dHMgYW5kIHRoZSBhdHRyYWN0aW9uIG9mIGZlcnJvbWFnbmV0aWMgbWF0ZXJpYWxzIHRvIGEgbWFn<br>bmV0aWMgZmllbGQuIFRoZSByZWdpb25zIHNlcGFyYXRpbmcgbWFnbmV0aWMgZG9tYWlucyBhcmUg<br>Y2FsbGVkIGRvbWFpbiB3YWxscywgd2hlcmUgdGhlIG1hZ25ldGl6YXRpb24gcm90YXRlcyBjb2hl<br>cmVudGx5IGZyb20gdGhlIGRpcmVjdGlvbiBpbiBvbmUgZG9tYWluIHRvIHRoYXQgaW4gdGhlIG5l<br>eHQgZG9tYWluLiBUaGUgc3R1ZHkgb2YgbWFnbmV0aWMgZG9tYWlucyBpcyBjYWxsZWQgbWljcm9t<br>YWduZXRpY3MuIE1hZ25ldGljIGRvbWFpbnMgZm9ybSBpbiBtYXRlcmlhbHMgd2hpY2ggaGF2ZSBt<br>YWduZXRpYyBvcmRlcmluZzsgdGhhdCBpcywgdGhlaXIgZGlwb2xlcyBzcG9udGFuZW91c2x5IGFs<br>aWduIGR1ZSB0byB0aGUgZXhjaGFuZ2UgaW50ZXJhY3Rpb24uIFRoZXNlIGFyZSB0aGUgZmVycm9t<br>YWduZXRpYywgZmVycmltYWduZXRpYyBhbmQgYW50aWZlcnJvbWFnbmV0aWMgbWF0ZXJpYWxzLiBQ<br>YXJhbWFnbmV0aWMgYW5kIGRpYW1hZ25ldGljIG1hdGVyaWFscywgaW4gd2hpY2ggdGhlIGRpcG9s<br>ZXMgYWxpZ24gaW4gcmVzcG9uc2UgdG8gYW4gZXh0ZXJuYWwgZmllbGQgYnV0IGRvIG5vdCBzcG9u<br>dGFuZW91c2x5IGFsaWduLCBkbyBub3QgaGF2ZSBtYWduZXRpYyBkb21haW5zLjxicj4gQmVzdCw8<br>L2Rpdj4gPGRpdiBzdHlsZT0iZm9udC1zaXplOiAwOyBsaW5lLWhlaWdodDogMDsiPiAmIzgyMDM7<br>IDwvZGl2PiA8L2JvZHk+IDwvaHRtbD4=

Like every self-respecting spam sender, they rotate through many domains (not exhaustive!):

apiaryapiaries.com<br>avaspaintinggallery.com<br>bonfirebeat.com<br>catnipblissfulhaven.com<br>chloesgardeninghaven.com<br>classmerge.com<br>endurovistawear.com<br>fragjoystick.com<br>gainswiftwave.com<br>ghostlygourd.com<br>hydroponicseeders.com<br>lanternlyric.com<br>mangomysticfusion.com<br>northchronicle.com<br>pasturelandplough.com<br>platformerboss.com<br>pyxisvoyager.com<br>raisetyrvalor.com<br>rockandrender.com<br>ryeirrigator.com<br>sifgoldenshine.com<br>sipandsweater.com<br>storybookstage.com<br>strategycrit.com<br>thruwaymotors.com<br>tillageacre.com<br>venusbases.com

But unlike typical spammer, they really go to the extra mile trying to get their spam delivered, immediately retrying from different servers when rejected (apparently some of their IPs listed on DNSBLs. hmm, I wonder why…):

Jun 23 16:15:36 milek7.pl postfix/smtpd[404910]: connect from mta2.icicleglimmerfrost.com[31.133.27.229]<br>Jun 23 16:15:38 milek7.pl postfix/smtpd[404910]: NOQUEUE: reject: RCPT from mta2.icicleglimmerfrost.com[31.133.27.229]: 554 5.7.1 Service unavailable; Client host [31.133.27.229] blocked using spam.spamrats.com; SPAMRATS IP Addresses See: http://www.spamrats.com/bl?31.133.27.229; from= to= proto=ESMTP helo=<br>Jun 23 16:15:39 milek7.pl postfix/smtpd[404910]: disconnect from mta2.icicleglimmerfrost.com[31.133.27.229] ehlo=2 starttls=1 mail=1 rcpt=0/1 quit=1 commands=5/6<br>Jun 23 16:15:39 milek7.pl postfix/smtpd[404910]: connect from mailc.plowdairy.com[93.120.120.78]<br>Jun 23 16:15:40 milek7.pl postfix/smtpd[404910]: NOQUEUE: reject:...

email spam from addresses milek7 postfix

Related Articles