Don't verify email addresses by sending spam to them
Don’t verify email addresses by sending spam to them
23.06.2026
Much have been said about futility of trying to validate email addresses.<br>Generally accepted advice is that you should just send verification link<br>and don’t care about trying to validate it before hand.
But what if you were<br>really hell-bent on having validation step, and at the same time follow the advice?<br>Apparently some people decided they could to it by… sending spam.
Take this Pangram sign-up form. Filling email field here will perform this request:
curl --request POST --data '{"email": "example@example.com"}' https://www.pangram.com/api/validate-email
And soon enough, without doing anything else, you will get an mysterious email. Whaaa…?
Date: Tue, 23 Jun 2026 15:29:10 +0000<br>From: "Winwin Insights"<br>To:<br>Reply-To:<br>Subject: Fact of the day: Magnetic<br>Message-ID:<br>Precedence: Bulk<br>MIME-Version: 1.0<br>Content-Type: text/html; charset=UTF-8<br>Content-Transfer-Encoding: base64
PCFET0NUWVBFIGh0bWw+IDxodG1sPiA8aGVhZD4gPG1ldGEgY2hhcnNldD0iVVRGLTgiPiA8L2hl<br>YWQ+IDxib2R5IHN0eWxlPSJmb250LWZhbWlseTogQXJpYWwsIHNhbnMtc2VyaWY7IGZvbnQtc2l6<br>ZTogMTZweDsgY29sb3I6ICMzMzM7Ij4gPGRpdiBzdHlsZT0icG9zaXRpb246IGFic29sdXRlOyBs<br>ZWZ0OiAtOTk5OXB4OyB0b3A6LTk5OTlweDtkaXNwbGF5OiBub25lOyI+SGkgdGhlcmUsPGJyPiBB<br>IG1hZ25ldGljIGRvbWFpbiBpcyBhIHJlZ2lvbiB3aXRoaW4gYSBtYWduZXRpYyBtYXRlcmlhbCBp<br>biB3aGljaCB0aGUgbWFnbmV0aXphdGlvbiBpcyBpbiBhIHVuaWZvcm0gZGlyZWN0aW9uLiBUaGlz<br>IG1lYW5zIHRoYXQgdGhlIGluZGl2aWR1YWwgbWFnbmV0aWMgbW9tZW50cyBvZiB0aGUgYXRvbXMg<br>YXJlIGFsaWduZWQgd2l0aCBvbmUgYW5vdGhlciBhbmQgdGhleSBwb2ludCBpbiB0aGUgc2FtZSBk<br>aXJlY3Rpb24uIFdoZW4gY29vbGVkIGJlbG93IGEgdGVtcGVyYXR1cmUgY2FsbGVkIHRoZSBDdXJp<br>ZSB0ZW1wZXJhdHVyZSwgdGhlIG1hZ25ldGl6YXRpb24gb2YgYSBwaWVjZSBvZiBmZXJyb21hZ25l<br>dGljIG1hdGVyaWFsIHNwb250YW5lb3VzbHkgZGl2aWRlcyBpbnRvIG1hbnkgc21hbGwgcmVnaW9u<br>cyBjYWxsZWQgbWFnbmV0aWMgZG9tYWlucy4gVGhlIG1hZ25ldGl6YXRpb24gd2l0aGluIGVhY2gg<br>ZG9tYWluIHBvaW50cyBpbiBhIHVuaWZvcm0gZGlyZWN0aW9uLCBidXQgdGhlIG1hZ25ldGl6YXRp<br>b24gb2YgZGlmZmVyZW50IGRvbWFpbnMgbWF5IHBvaW50IGluIGRpZmZlcmVudCBkaXJlY3Rpb25z<br>LiBNYWduZXRpYyBkb21haW4gc3RydWN0dXJlIGlzIHJlc3BvbnNpYmxlIGZvciB0aGUgbWFnbmV0<br>aWMgYmVoYXZpb3Igb2YgZmVycm9tYWduZXRpYyBtYXRlcmlhbHMgbGlrZSBpcm9uLCBuaWNrZWws<br>IGNvYmFsdCBhbmQgdGhlaXIgYWxsb3lzLCBhbmQgZmVycmltYWduZXRpYyBtYXRlcmlhbHMgbGlr<br>ZSBmZXJyaXRlLiBUaGlzIGluY2x1ZGVzIHRoZSBmb3JtYXRpb24gb2YgcGVybWFuZW50IG1hZ25l<br>dHMgYW5kIHRoZSBhdHRyYWN0aW9uIG9mIGZlcnJvbWFnbmV0aWMgbWF0ZXJpYWxzIHRvIGEgbWFn<br>bmV0aWMgZmllbGQuIFRoZSByZWdpb25zIHNlcGFyYXRpbmcgbWFnbmV0aWMgZG9tYWlucyBhcmUg<br>Y2FsbGVkIGRvbWFpbiB3YWxscywgd2hlcmUgdGhlIG1hZ25ldGl6YXRpb24gcm90YXRlcyBjb2hl<br>cmVudGx5IGZyb20gdGhlIGRpcmVjdGlvbiBpbiBvbmUgZG9tYWluIHRvIHRoYXQgaW4gdGhlIG5l<br>eHQgZG9tYWluLiBUaGUgc3R1ZHkgb2YgbWFnbmV0aWMgZG9tYWlucyBpcyBjYWxsZWQgbWljcm9t<br>YWduZXRpY3MuIE1hZ25ldGljIGRvbWFpbnMgZm9ybSBpbiBtYXRlcmlhbHMgd2hpY2ggaGF2ZSBt<br>YWduZXRpYyBvcmRlcmluZzsgdGhhdCBpcywgdGhlaXIgZGlwb2xlcyBzcG9udGFuZW91c2x5IGFs<br>aWduIGR1ZSB0byB0aGUgZXhjaGFuZ2UgaW50ZXJhY3Rpb24uIFRoZXNlIGFyZSB0aGUgZmVycm9t<br>YWduZXRpYywgZmVycmltYWduZXRpYyBhbmQgYW50aWZlcnJvbWFnbmV0aWMgbWF0ZXJpYWxzLiBQ<br>YXJhbWFnbmV0aWMgYW5kIGRpYW1hZ25ldGljIG1hdGVyaWFscywgaW4gd2hpY2ggdGhlIGRpcG9s<br>ZXMgYWxpZ24gaW4gcmVzcG9uc2UgdG8gYW4gZXh0ZXJuYWwgZmllbGQgYnV0IGRvIG5vdCBzcG9u<br>dGFuZW91c2x5IGFsaWduLCBkbyBub3QgaGF2ZSBtYWduZXRpYyBkb21haW5zLjxicj4gQmVzdCw8<br>L2Rpdj4gPGRpdiBzdHlsZT0iZm9udC1zaXplOiAwOyBsaW5lLWhlaWdodDogMDsiPiAmIzgyMDM7<br>IDwvZGl2PiA8L2JvZHk+IDwvaHRtbD4=
Like every self-respecting spam sender, they rotate through many domains (not exhaustive!):
apiaryapiaries.com<br>avaspaintinggallery.com<br>bonfirebeat.com<br>catnipblissfulhaven.com<br>chloesgardeninghaven.com<br>classmerge.com<br>endurovistawear.com<br>fragjoystick.com<br>gainswiftwave.com<br>ghostlygourd.com<br>hydroponicseeders.com<br>lanternlyric.com<br>mangomysticfusion.com<br>northchronicle.com<br>pasturelandplough.com<br>platformerboss.com<br>pyxisvoyager.com<br>raisetyrvalor.com<br>rockandrender.com<br>ryeirrigator.com<br>sifgoldenshine.com<br>sipandsweater.com<br>storybookstage.com<br>strategycrit.com<br>thruwaymotors.com<br>tillageacre.com<br>venusbases.com
But unlike typical spammer, they really go to the extra mile trying to get their spam delivered, immediately retrying from different servers when rejected (apparently some of their IPs listed on DNSBLs. hmm, I wonder why…):
Jun 23 16:15:36 milek7.pl postfix/smtpd[404910]: connect from mta2.icicleglimmerfrost.com[31.133.27.229]<br>Jun 23 16:15:38 milek7.pl postfix/smtpd[404910]: NOQUEUE: reject: RCPT from mta2.icicleglimmerfrost.com[31.133.27.229]: 554 5.7.1 Service unavailable; Client host [31.133.27.229] blocked using spam.spamrats.com; SPAMRATS IP Addresses See: http://www.spamrats.com/bl?31.133.27.229; from= to= proto=ESMTP helo=<br>Jun 23 16:15:39 milek7.pl postfix/smtpd[404910]: disconnect from mta2.icicleglimmerfrost.com[31.133.27.229] ehlo=2 starttls=1 mail=1 rcpt=0/1 quit=1 commands=5/6<br>Jun 23 16:15:39 milek7.pl postfix/smtpd[404910]: connect from mailc.plowdairy.com[93.120.120.78]<br>Jun 23 16:15:40 milek7.pl postfix/smtpd[404910]: NOQUEUE: reject:...