Viewable With ANY Browser

Note: My Web pages are best viewed with style sheets enabled.

Unrated

Spam: The Junking of Junk E-Mail

Copyright © 1999-2001, 2003-2007 by David E. Ross

The first time some terms are used on this page, they are links to a glossary. The glossary appears as a separate page.

In a scene from a biographical, made-for-TV movie about Alexander Graham Bell, the inventor of the telephone is sitting in his home. The phone rings, and he answers it. He starts cursing and hangs up. It was a telemarketer, using Bell's own invention to annoy him.

A phone call from a telemarketer might waste my time, annoy me, and even prevent me from receiving a phone call that I want. But I do not pay for the call. Junk mail — the U. S. Postal Service now calls it "standard mail" instead of "bulk mail" — also wastes my time, annoys me, and clogs the landfills. But I do not pay to receive junk mail; the advertiser pays the postage.

The sender of spam (junk E-mail) does not pay for my Internet connection; I do. In some nations, connections to the Internet are metered; the user pays for the connection by the minute. This is very much like receiving junk facsimiles; the recipient pays for the paper and toner to receive unwanted advertisements.


What To Do About Spam?

There are various actions individuals can take to handle spam. No-Spam graphic


ISP Filtering

Many ISPs filter spam at their E-mail servers. This trend responds to two issues. First of all, their subscribers have been complaining about the time it takes for them to search through junk messages to find the message they want. Then there is the large amount of space spam occupies on a server until a subscriber downloads those messages.

ISWest's Filter

ISWest used an internally developed spam filter. It was initially quite effective, stopping well over 80% of the spam reaching its mail server. However, the spammers eventually became too clever at by-passing this filter. Thus, ISWest installed a commercial filter, Mail Guardian (a version of CanIt!) by Roaring Penguin Software.

Like the old filter, Mail Guardian is heuristic. That is, it "learns" the characteristics of spam from inputs sent by ISWest's subscribers. To protect subscribers against losing an incoming message that has been falsely identified as spam, spam messages are not deleted. Instead, they are saved and made available through a Mail Guardian Web interface. If I find a legitimate message has been filtered, I can use the Web interface to have Mail Guardian deliver the message to me.

This use of Mail Guardian is free to ISWest customers. For a fee, I could also mark spam that bypasses the filter and non-spam that is caught by the filter so that Mail Guardian can tune its filter. Since Mail Guardian seems to stop a major portion of spam, however, I choose to use only the free capabilities.

All ISPs should use filters that have the characteristics of ISWest's filter:

ISWest's filter seems effective, contrary to the declaration of the California Legislature. The same filter concept is used by Mozilla-based E-mail clients Thunderbird and SeaMonkey. The difference is that ISWest applies its filter at the mail server before I see my E-mail while the Mozilla clients (not running a mail server for the public) apply their filters in the mail client as messages are downloaded.

Broken Filters

Accurately identifying spam via software is highly problematical. It can be worse when an ISP deploys a filter developed by an outside vendor or uses an outside service to identify the sources of spam. The Internet remains a highly technical system, and good filters are also very technical. Many ISPs, however, fail to employ professionals who really understand what is happening.

Most of these problems occur when an ISP relies on a simplistic approach to filtering, generally on a filter that uses a list of "bad" IP addresses or mail server domains. This does not work! This approach to filtering relies too much on the past, on what spammers did yesterday. At best, this approach to filtering fails to stop spam when spammers quickly abandon old E-mail accounts and start new ones with different IP addresses or domain names. More often, this approach results in legitimate messages being rejected because of a blanket interdiction against an entire mail server or even an entire ISP. It should be unacceptable for a major ISP to use a simplistic third-party spam blocker that relies on a list of IP addresses rather than on analyzing messages to determine if they are really spam.

Note, however, that an ISP can carry filtering to any length it chooses, even rejecting all E-mail messages from a competitor for the sole reason of competition. There is no law requiring an ISP to relay E-mail messages to its own subscribers from an outside service. However, this has never been tested in court. With AOL blocking PBI and ISWest and then SBC Global and PBI blocking ISWest — all for no good reason — perhaps an ISP blocked because of a false reason can successfully sue the blocking ISP. That might be the only way ISPs can be forced to use technically sound methods of preventing spam.


Legislation

*** Begin Right Sidebar ***

Virginia Arrests Man for Spam Email Under New Law

Thu Dec 11, 3:07 PM ET

DULLES, Va. (Reuters) — Virginia authorities said on Thursday they had arrested and charged a North Carolina man for sending "spam" e-mail in the first use of a new state law that could bring penalties of up to 20 years in prison.

Virginia Attorney General Jerry Kilgore said Jeremy Jaynes had been arrested earlier Thursday in Raleigh, N.C., on four counts of using fraudulent means to transmit spam. Kilgore told a news conference that officials were in negotiations for the surrender of a second man, Richard Rutowski, on the same charges.

Jaynes was charged with violating limits on the number of messages a marketer can send and falsifying routing information, both illegal under the Virginia law that carries penalties of 1-5 years in prison on each count.

Although based in North Carolina, Virginia is asserting jurisdiction over Jaynes because he sent messages through computers located in the state. Roughly 50 percent of the world's Internet traffic passes through Virginia, home to big Internet companies like Time Warner Inc.'s American Online unit and MCI.

Spam has grown from a minor annoyance to a major threat to the stability of the Internet, experts say, and now makes up more than half of all e-mail traffic, according to several surveys. "These criminals are harming businesses in Virginia, and that concerns us," Kilgore told the news conference at AOL headquarters in Dulles, Va.

Copyright © 2003 Reuters Limited

*** Begin Right Sidebar ***

In California (where I live), several anti-spam laws have been enacted.

While I do not know any details, I do know that anti-spam laws have been enacted in other states. Any legislation should consider the following:

Most important, Congressional action on this issue should not block state laws (contrary to Congress's action on pollution and privacy legislation). Legislation being considered by Congress in 2003 would not only undo state laws and legalize some spam banned by states but would also favor business over consumers by allowing only ISPs to sue spammers. Recipients whose E-mail is clogged with spam would not be allowed to file lawsuits.

Oops! Too bad! Congress passed its legislation that indeed invalidated stronger state laws. And yes, the new federal law only allows ISPs to sue spammers; and it only provides for "opt-out" controls, not "opt-in" as provided in some of the state laws it repealed. But then, spam — very much like personal information — is business. As intended by Republican leaders of Congress, the new federal law has proven totally ineffective in reducing the flood of spam. Advertising über alles!


A New Source of Spam

[Written in February 2000]

According to the webzine Salon.com, a new "service" threatens to change the character of spam. Epidemic Marketing, Inc. is soliciting the public to become free subscribers to its service. Subscribers are given advertisements to insert into E-mail messages they send. The advertisements contain Web links. If the recipients select the links, the senders receive a small payment.

Get real! This is still spam, and I intend to handle it as I describe elsewhere on this page. I do not care if the message is from a friend or relative; spam is still unwanted in my E-mail queue. Unfortunately, the senders of these messages will be the ones whose ISP accounts get cancelled. Epidemic Marketing will remain untouched … at least until a subscriber whose account is cancelled sues Epidemic Marketing for causing the cancellation.


A Vicious Spam

Much spam originates in the nations along the Pacific coast of Asia. Not only are these messages unwanted, but also many are unreadable. They are not written in the Roman characters used in European languages.

A typical subject displays as:

¶W±j°ª¼é¤fªA²G§Y¤é°_¤T§é¯S»ù¾P°â¡A¥u­n9¬ü¤¸´N±a¦^®a¡A½æ§¹¬°¤î¡I
Even longer subjects are often seen. Subjects such as these crash my E-mail client, sometimes so severely that I must reboot my PC. When I delete these message via my ISP's Web-mail interface and then restart my E-mail client, I usually find that the table of contents for my In folder is corrupted.

I just cannot understand why a business in China, Korea, Taiwan, or other Asian nation would send me messages I cannot understand. Fortunately, ISWest's filter is very adept at removing these messages before they reach my mail client.


Really Dumb Spam

Some spam is truly dumb. Actually, some spammers are totally ignorant.

They send messages that no one can read. For example, I sometimes see both the Subject and body of a message that look like the example I gave of vicious spam. Or it might look like:

=A5=B4=C2Z=B1z=A4F=A1I=A5=D1=A9=F3=A5=BB=A4H=A6=B3=A4@=A8=C7=A7x=C3

Some messages have subjects that are too obviously spam (especially spam promoting pornography).

Draw for a holiday in Florida
you should watch me do my thing
herbal pill will actually ENLARGE you
INVESTORS: Blue-Chip, Stock-Trading System---77% Return---Automated
Good sites to see, you asked to be on our list [no, I did not]
Re: john, size matters to me!
perform to pleasure her today.

Some messages have subjects with strange spacing or spelling, apparently an attempt to confuse filters. This may work with E-mail sent to Hotmail. It does not work with ISWest's filter.

Rx - Valium, Xanaxx, Via.gra...ashby [a misplaced . in the word Viagra]
Stop that SPA M emails forever [an extra space in the word SPAM]
Hérbal Viagrä Altérnativé [es with acute accents, a with an umlaut]
ñever pay for what you can get free [n with a tilde]

Some messages are in a foreign language that I don't understand.

Más de 20.000 solteras y solteros
Mise a jour de votre convention collective au 10 novembre 2003

Some messages have nonsense subjects.

guacamole concierge
gyrocompass loot pervasive
bagatelle friday quintillion
That epochal by managerial
you jacobian he euphoric
Be barnacle whichever inconsistent
calvary menial anticipatory
A it surprising
Back thank the external Galactic Spirit?

I made up none of these. Instead, I extracted them from actual spam. The point is that the spam nature of these messages is so obvious that no one (except possibly an Internet masochist) would do anything other than trash them. These spammers have dropped their junk into a black hole with no chance of accomplishing anything. These messages are NOT being read. Some day, one of these spammers might gain the intelligence of a rock and realize that he or she is expending time and effort on a useless task. In the meantime, ISWest's filters are blocking about 18 spam messages for every one that sneaks through.


A Growing Problem

In 2006, I recorded 1,443 spam messages in one month; ISWest's Mail Guardian caught about 1,080 of them. During one month in 2007, I recorded 4,589 spam messages, a growth of 275%. While Mail Guardian caught 2,735 of them, that was a smaller percentage of the total spam (75% in 2006 versus 60% in 2007). Mail Guardian also caught 10 messages that were not spam (0.4% false positives).

Looking at the problem differently, I received 4,759 total E-mail messages in that one month of 2007. Only 170 (or 4%) were "real" messages; 96% were spam. That's 5 legitimate messages against 148 spam messages per day.

At one time, I would start my E-mail client as soon as I sat down and started my computer. I would then leave it running until I shut down my computer. Now, in a defensive maneuver, I first check the messages waiting on the mail server, using my ISP's Web-mail capability to delete the spam that bypassed Mail Guardian. Then, I run my E-mail client only long enough to download the legitimate messages and reply to them, immediately terminating the E-mail client as soon as I am done.

Congress's "business first" anti-spam legislation is obviously a failure. The problem is getting worse, not better.


More Information

The following links may be useful in dealing with spam:

And then, of course, there is the Spam page, owned by Hormel Foods Corp (manufacturers of Spam processed meat).

Last updated 1 August 2007


Valid HTML 4.01