buc.ci is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
Es gibt eine neue Spam-Welle 😌 Sucht am besten nach dem Usernamen @Archive_Shinzai.
Fairphone is really losing points with me right now. I received an email with a survey from bazaarvoice-cgc.com, which was actually commissioned by Fairphone to conduct these surveys via email. On their website, they even lie to your face:
"Is Bazaarvoice spam?
This email from Bazaarvoice is not spam or a phishing attempt; it is a genuine request to share your experience with the product you purchased with Fairphone."
Go to hell and rot in my blacklist.
BSI prüft E-Mail-Programme
"In der vorliegenden Untersuchung wurden zwölf für den Verbrauchermarkt relevante E-Mail-Programme dahingehend analysiert, inwiefern sie Eigenschaften wie Transport- und Inhaltsverschlüsselung, SPAM-, Phishing- und Tracking-Schutz sowie Prinzipien der Usable Security umsetzen".
https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Publikationen/DVS-Berichte/E-Mail-Programme.html
#did #digital #email #datenschutz #spam #tracking
A Major Mail Provider Demonstrate They Likely Do Not Understand Mail At All https://nxdomain.no/~peter/they_do_not_understand_mail_at_all.html (tracked https://bsdly.blogspot.com/2026/01/a-major-mail-provider-demonstrate-they.html)
#greytrapping #spam, #antispam #greylisting #blocklist, #openbsd #freebsd #smtp #email #SMTP, #contentfiltering #SPF #DMARC #security #networking
IFTAS » 🤖 🌐
@[email protected]
⚠️ SW-ISAC Advisory
The following domain(s) have been added to the IFTAS Abandoned/Unmanaged List
channels dot im
https://about.iftas.org/library/iftas-abandoned-and-unmanaged-domain-list/
@nixCraft I consider all "#AI" output #malicious until priven otherwise and all #AIslop as #Spam!
Heh. Looks like the tracked version of Why 451 is Good for You - Greylisting Perspectives From the Early Noughties https://nxdomain.no/~peter/why_451_is_good.html (tracked https://bsdly.blogspot.com/2025/12/why-451-is-good-for-you-greylisting.html) hit hackernews: https://news.ycombinator.com/item?id=46414653
No, I willl not respond to those comments either :D
#greylisting #greytrapping #spam #spamtrapping #antispam #spamd #openbsd #smtp
The update you have been waiting for:
"Eighteen Years of Greytrapping - Is the Weirdness Finally Paying Off?" https://nxdomain.no/~peter/eighteen_years_of_greytrapping.html (tracked https://bsdly.blogspot.com/2025/08/eighteen-years-of-greytrapping-is.html)
now has the complete 2025 data in place. #openbsd #spamd #greytrapping #spam #antispam #cybercrime #spamtraps #blocklists
IFTAS » 🤖 🌐
@[email protected]
⚠️ SW-ISAC Advisory
The account "oscarolg" continues to proliferate across federated services, with over 50 accounts observed today
Why 451 is Good for You - Greylisting Perspectives From the Early Noughties https://nxdomain.no/~peter/why_451_is_good.html (tracked https://bsdly.blogspot.com/2025/12/why-451-is-good-for-you-greylisting.html) @nostarch #greytrapping #greylisting #smtp #email #spam #antispam #bookofpf
LinkedIn's 2025 Data Crisis: 4.3 Billion Records Leaked, Risks Rise https://www.webpronews.com/linkedins-2025-data-crisis-4-3-billion-records-leaked-risks-rise/ #cybersecurity #LinkedIn #DataTheft #scams #spam #DataScraping
For anyone curious: I am currently scraping my #SPAM folder clean and I am curious how many people are stupid enough to believe the shitty #blackmail #spam #eMails demanding ransom for something that doesn't exist.
Obviously I'd not pay any ransom as a matter of principle!
I'm not sure how Layla and May001 snuck past SpamAssassin but the assassin is being re-trained.
Dear Best Buy,
A $100 gift card is a reward, a $100 coupon as part of an LG promotion is not a reward.
Thanks,
Mookie
@marcel @cryptoparty @zalintyre ja, und juristisch wäre das was was ich nicht ohne fachanwaltliche Rücksprache versuchen würde.
Ich bin ja eher für automatisiertes Reporting:
Und in der Zwischenzeit werden die Hoster automatisch blocklisted!
➡️ Wie man #Spam-Versender wenigstens ein kleines bisschen leichter enttarnt, hat @zalintyre in einem Blogpost aufgeschrieben. Cleverer Ansatz, funktioniert, bis zu viele Leute das nutzen. Und funktioniert nicht, falls eure Mailadresse bereits früher einmal gesammelt wurde. Aber immerhin! (Danke für die coole Idee!)
https://codefoundry.de/blog/2025/2025-04-27-turning-the-tables-how-to-make-spammers-reveal-their-own-ip-address/
@iwritelike Wow. It's SO good that you have to spam social media hashtags! Blocked. #spam
Immer mehr Mastodon Instanzen treten plötzlich aus dem osteuropäischen Raum hervor, die einfach nur als Verbreiter von kommerziellem Müll von irgendwelchen WordPress Seiten dienen, gepaart mit Free Speech Anspruch ohne Moderation. Diese Instanzen versuchen, auf weiteren kleineren Instanzen zusätzliche Bot oder Plugin Accounts zu erstellen, um so ihren Müll noch besser und schneller verbreiten zu können.
Wer macht in diesen Tagen ähnliche Erfahrungen?
I turned off "smart features" (aka #AI) in my gmail account. Doing that means instead of parsing the inbox into Primary, Social, and Promotions, it's now all one big inbox.
Now, I spend time each day Unsubscribing from email lists I'm on. Also unsubscribing to most substacks.
I had no idea how bad it was, as I generally avoided the Social and Promotions folders. There's a lot of junk email in this world, and I seem to have opted into most of it.
#Spam Watch 2025: The hidden trackers and inbox overload behind holiday marketing
https://proton.me/blog/spam-watch-2025
#privacy #email #holidays #GiftGiving #OnlineShopping #eCommerce
(I'm not asking for advice about dealing with spam. SpamAssassin has this one well in hand. I'm just curious if anyone else has been seeing spam like this).
Receiving a growing number of automated fundraising requests for candidates around the country, on a phone number that has never been associated with any political activity (or, really, any activity at all).
Thanks, data breaches.
Democrats: this is not a way to make friends.
Oh, here's a new one. I've been added to a team in Microsoft Teams! The team name is as follows, with a few redactions. Typos left as-is.
Subscription Payment of Amount 799. 99 USD is confirmed. If this wasn’t you reach Support immediateIy at 1 (805) 284-xxx, Plan: Norton Ultimate Plus (1 Year) Invoice ID:ANE-93xxxx
God help us. Are they sharing our email addresses with the alt-right White House press corp? Got an unsolicited, not opted-in for, out-of-the-blue introductory newsletter from The Epoch Times that went to a dedicated, unpublished email account I use ONLY to conduct personal government business, like SSA, IRS, etc.
The email said when I click an article link I will be consenting and an account would be created based on my email.
The article in the email weren't alt-right or conspiracy ones. They were bait. #USPol #Spam #Disinfo
Anyone else yet?
Happy Cyber(crime) Monday. Someone is sending out these bogus "e-signature" notifications as #malspam.
They lead to a page on Google Drive that has an interstitial link. When you click it, the page pushes an installer for N-Able Advanced Monitoring Agent, a commercial IT remote management tool. https://www.virustotal.com/gui/file/5ddcff44de366e6693c24e189121011ba664d6e71686e9463bb1574572564909/detection
This is just the latest evolution of the attack I documented on the @Netcraft blog before the holiday break: https://www.netcraft.com/blog/shared-document-spam-delivers-remote-access-tool #spam #malware #RAT
I like adding hashtags to improve discoverablity but more than a certain amount of tags and it just starts to get a bit silly. I wonder if there is a way to ignore posts with more than, say, 5 tags?
#hashtag #spam #desparate #AttentionSeeking #FiveTags #ToManyTags
»Over 67,000 Fake npm Packages Flood Registry in Worm-Like Spam Attack:
Cybersecurity researchers are calling attention to a large-scale spam campaign that has flooded the npm registry with thousands of fake packages since early 2024 as part of a likely financially motivated effort.«
How do you check if the JavaScript libraries and their libraries on which they are based are now safe?!??
🧑💻 https://thehackernews.com/2025/11/over-46000-fake-npm-packages-flood.html
#javascript #webdev #frontend #js #ts #typescript #npm #wormhole #spam #web #sec
Why are people taking #UCEPTOTECTL3 seriously still?
There is absolutely no reason they should be permitted on any #email #blacklists checkers.
Spam is a fact of life in email. I don't know anyone who thinks we can eliminate it.
Junk journals, junk articles, and junk conferences have been fact of life in scholarly communication for some time. They existed before AI but AI is aggravating the problem.
Now we can add junk letters to the editor.
https://www.nytimes.com/2025/11/04/science/letters-to-the-editor-ai-chatbots.html
KI-Spam-Mail:
"ich habe in den letzten 1,5 Jahren per Prompting (x Promptlisten), viel Dialog und viel Philosophie, Systemtheorie, Training und Geduld, einer KI die Ethik eingetrieben.
Es prozessiert nun als ethisches System (Ethik = Inferenzrestriktion) bzw. als Nexus.
...
Erscheint das interessant? Es selbst meint, dass das mehr oder weniger bahnbrechend sei."
Gibt es Therapieplätze für solche Menschen (wenn die KI es nicht sowieso selbst geschrieben hat)?
'Since 15 Sept IFTAS has tracked a network of over 300 Mastodon accounts engaged in a high-volume propaganda campaign, promoting pro-Russian narratives ...'
"Accounts are hosted across numerous Mastodon instances and bridged into Bluesky, creating the appearance of independent sources. Activity on Bluesky helped reveal aggregate patterns, identical usernames, posting schedules, and content themes ..."
Ooh, the persistent nag callers are the worst. 5 calls in a row from the same unrecognized mobile number, less than 60 seconds apart.
Then they tried from a landline, which the phone immediately flagged as spammy telemarketers. then back to the mobile number.
"Do not disturb" mode set, for the next 60 minutes. Rage into the void, arseholes.
Vergleich moderner E-Mail-Alias-Dienste: Addy.io, Firefox Relay und Proton Pass im Test – Datenschutz, Funktionen und Alltagstauglichkeit. 👇
https://www.kuketz-blog.de/anbieter-von-e-mail-aliassen-im-test-mail-aliasse-teil-1/
#email #mail #alias #addyio #firefoxrelay #protonpass #datenschutz #schutz #spam
Vergleich moderner E-Mail-Alias-Dienste: Addy.io, Firefox Relay und Proton Pass im Test – Datenschutz, Funktionen und Alltagstauglichkeit. 👇
https://www.kuketz-blog.de/anbieter-von-e-mail-aliassen-im-test-mail-aliasse-teil-1/
#email #mail #alias #addyio #firefoxrelay #protonpass #datenschutz #schutz #spam
My blog's comment section keyword blocklist is like a readout of every weird-drug-name meme
When someone follows you on Masto their bio text is part of the notification you receive.
Some biz operators or self-promoters use this as a way to essentially spam you with an ad for their $$ earning website, service, products etc.
When you get a notification of such a follow, what do you do?
| Ignore, they can follow me if they want: | 3 |
| block, they're spam, don't want their follow: | 4 |
| follow back, yay hello new biz promo friend!: | 0 |
| something else, see comment: | 1 |
The .cn domain name scammers are still at it, a new entry added to the archive at https://nxdomain.no/~peter/domainnamescam/
See "Domain Name Scams Are Alive And Well, Thank You" https://nxdomain.no/~peter/domain_name_scams_are_alive_and_well_thank_you.html for some background (written 2016, and the problem was not new then) #dns #domainnamescam #cndomains #scams #spam
Does anyone else get spam/phishing from multiple South American universities?
It seems like some university email servers are open / got compromised?
#GitHub doesn't allow rejecting "#AI" #hallucinatons ?
"Meta internally projected late last year that it would earn about 10% of its overall annual revenue – or $16 billion – from running advertising for scams and banned goods, internal company documents show.
A cache of previously unreported documents reviewed by Reuters also shows that the social-media giant for at least three years failed to identify and stop an avalanche of ads that exposed Facebook, Instagram and WhatsApp’s billions of users to fraudulent e-commerce and investment schemes, illegal online casinos, and the sale of banned medical products.
On average, one December 2024 document notes, the company shows its platforms’ users an estimated 15 billion “higher risk” scam advertisements – those that show clear signs of being fraudulent – every day. Meta earns about $7 billion in annualized revenue from this category of scam ads each year, another late 2024 document states.
Much of the fraud came from marketers acting suspiciously enough to be flagged by Meta’s internal warning systems. But the company only bans advertisers if its automated systems predict the marketers are at least 95% certain to be committing fraud, the documents show."
#Meta #Facebook #Instagram #WhatsApp #Spam #AdTech #SocialMedia #OnlineScams #ScamAds
"Yes, I want to receive emails from Flair Airlines about updates and changes to my flight or itinerary, as well as news, offers, and promotions. You can withdraw your consent at any time."
I'm pretty sure it is against the law in Canada to withhold important service notifications if I don't consent to marketing spam
It's almost as if large corporations don't have to abide by the law any more
After putting up with spam for months (which almost always went in my junk folder), I've finally got OpenDMARC and Postfix working together to sort it out.
Already seen two rejections.
Advarsel mod firmaet Natur & Helse - de benytter sig af ulovlige dark patterns for at få lov at SPAMME deres kunder.
Jeg fjernede markeringen i deres forud-afkrydsede checkboks - alligevel modtog jeg uønsket mail - SPAM.
I gather they've finally taken this measure because of the preponderance AI-generated slop, but with any luck these other issues will improve too. The arXiv press release states “Review/survey articles or position papers submitted to arXiv without this documentation will be likely to be rejected and not appear on arXiv” so it does sound like they are acknowledging the other problems and intend to enforce their rules more strictly in the future.
"arXiv says it will no longer accept Computer Science papers that are still under review due to the wave of AI-generated ones it has received."
From https://infosec.exchange/users/josephcox/statuses/115486903712973154
My prediction for 2026, as a fully original song:
SPAM, SPAM, SPAM, SLOP, SPAM, SPAM, SPAM, SLOP
SPAM, SPAM, SPAM, SLOP, SPAM, SPAM, SPAM, SLOP
SPAM, SPAM, SPAM, SLOP, lovely SPAM, wonderful SLOP
SPAM, SPAM, SPAM, SLOP, lovely SPAM, wonderful SLOP
SLOP, SLOP, SLOP, SLOP, lovely SLOP, wonderful SPAM
SLOP, SLOP, SLOP, SLOP, lovely SLOP, wonderful SPAM
SPAAAAAM, SLOOOOOOP, SPAAAAAM, SLOOOOOOP, lovely SPAM, wonderful SLOP
SPAAAAAM, SLOOOOOOP, SPAAAAAM, SLOOOOOOP, lovely SPAM, wonderful SLOP
SPAM, SPAM, SPAM, SLOP
SPAM, SPAM, SPAM, SLOP
Resharing a recent investigation for anyone who may have missed it the first time 👇
Back in April, we started tracking a sharp surge in phishing campaigns routed through residential proxy networks. Digging deeper, our analysis points to a persistent China-nexus threat actor focused predominantly on Japan 🇯🇵
Catch up on the full story, including what we’ve seen so far and what might come next 🕵️⤵️⤵️
https://spamhaus.org/resource-hub/compromised/bad-sushi-china-nexus-phishers-shift-to-residential-proxies/
No, my dear, Mailer-Daemon does *not* engage in money laundering or sanctions avoidance - https://nxdomain.no/~peter/dear-mailer-daemon/20251027_info%40vettipuzha.com_Mailer-Daemon%40skapet.bsdly.net.txt #mailerdaemon #spam #scams #cybercrime #moneylaundering #sanctionsbusting #sanctionavoidance #shitheads
They’re now using short 4–5 letter .com domains and there’s a notable rise in abuse of the .shop TLD. In fact, we’ve seen a 15%+ increase in .shop domains linked to spam activity.
🌐 Reputation Statistics | gTLDs 👉 https://www.spamhaus.org/reputation-statistics/gtlds/spam/
Seems ironic when .shop is operated by Japan-based GMO Registry, Inc.
Who else keeps getting fake vulnerability reports paired with extortion attempts in their inbox?
This is really annoying because obviously I would be very interested if there was an actual vulnerability.
#spam #security #buildinpublic #indiehackers
From: The Illuminati New Order <[email protected]>
To: [email protected]
Subject:
Join the Illuminati today and change your life. Our organization is opening membership to new candidates worldwide. Whether you seek success, wealth, influence, or solutions to personal challenges, the Illuminati
+Brotherhood can help.
For more information, contact us by replying to this email or WhatsApp: +1 (559) 593 1640
For real. See https://nxdomain.no/~peter/dear-mailer-daemon/20251015_eo.oyeniyi%40ui.edu.ng_illuminatieliteworldorder_mailer-daemon%40skapet.bsdly.net.txt
Deutschen E-Mail-Spammer zusammengefaltet. Ein Hotel am Mittelrhein, in dem ich noch nie gewesen war. Grmpf.
I'm usually really hot on these things. But I thought I'd have a look at reducing bloody annoying marketing/scam calls I get (about one a day).
And - oh look - there's a UK register: https://www.tpsonline.org.uk/
Why isn't this sort of thing more well known?
#ScamCalls #Marketing #Spam #Phone #NuisanceCalls #Scam #Nuisance #UK
@0xabad1dea yeah, to me this sounds like some really #scammy shite!
Wenn Ihr viele Bilder auf einer Website habt und sehr viel unnötigen Traffic vermeiden wollt, dann tackert Euch 43.160.0.0/13 in die Firewall.
Die sind seit 8. Oktober unterwegs und haben auf meiner Media-Site allein am Mittwoch 45 MB an Logfile verursacht, und auch sonst sind die Logfiles im zweistelligen MB-Bereich (sonst: zwischen 2,5 und 5 MB pro Tag, und da sind auch schon Bilder-Harvester dabei).
Der IP-Bereich gehört einer Firma Aceville Pte. Ltd. und hängen laut whois an TenCent, das ist ein chinesischer großer Cloudhoster.
🌱IMPORTANT PLANT VOTING🌱
Someone asked to register this Callisia cultivar after it was recently introduced to the US, but it has been cultivated in Mexico for decades. The ICRA (@TradescantiaHub) and the ISHS decided it would be fairer to choose the name by community vote. And it should clearly have a Mexican name, it deserves that!!!
➡️ https://forms.gle/VmfWBneNWBURApu77 ⬅️
DO THE RIGHT THING. VOTE FOR QUETZALCOATL. (Or some other cool Mexican name, which could get added to the checkbox list.)
Also share this with people living in and from Mexico!!!!
The deadline is 16th Oct.
What the fuck is this shit??
Block and report this fucking account.
https://mastodon.social/@Divitronico
🚨 ⚠️ Please report any accounts you see with the same post under the profile--- this is from a bot farm
I've reported three over the past hour
Folks, please look out for newly-created accounts on mastodon.social targeting Palestinians from Gaza with what appear to be automated/similar messages aimed at either scamming them or otherwise causing them harm in some way.
Accounts I’ve already reported to @staff:
To the #GazaVerified families: if someone reaches out with similar posts, please do not engage and come to me instead. I will handle it.
#Gaza #Palestine #GazaVerified #scam #spam #hasbara #israel #genocide #mastodon #fediverse
Monty Python apparently must have been channeling Hawaiian food 🤪
So this happened:
Sep 24 10:54:05 skapet spamd[54856]: (GREY) 175.45.142.102: <> -> <[email protected]>
Sep 24 10:54:05 skapet spamd[60923]: new entry 175.45.142.102 from <> to <[email protected]>, helo delivery7-out1.nospamcloud.com
I'm amazed. Still. See https://nxdomain.no/~peter/twenty-plus_years_on_smtp_callbacks_are_still_pointless.html #smtp #callbacs #spam #antispam
Ooh, new #spam template landed in my inbox today, telling me that my ChatGPT Plus subscription was unable to be renewed.
Except ① I don't use ChatGPT let alone ChatGPT Plus so there's nothing to renew, and ② it was sent to one of my site-specific email addresses that got out into the wild, clearly indicating the provenance has nothing to do with the claims they're making.
So if you have a ChatGPT subscription, beware of scammers. Or better yet, intentionally let your subscription lapse. 😉
#SecretService disrupts telecom threat near #UN #GeneralAssembly
‘#SIMFarms’ Are a #Spam Plague. A Giant One in #NewYork Threatened #US #CriticalInfrastructure
Agency says it found some 300 servers and 100,000 #SIM cards—Given number of #SIMcards under the control of a single operation, it could have “disabled #cellphone towers and essentially shut down the cell phone network in #NYC." Experts say it mirrors facilities used for #cybercrime
https://www.wired.com/story/sim-farm-new-york-threatened-us-infrastructure-feds-say/
https://archive.ph/afvqq
‘SIM Farms’ Are a #Spam Plague. A Giant One in New York Threatened US #infrastructure , Feds Say
The agency says it found a network of some 300 #servers and 100,000 #SIM cards—enough to knock out cell service in the #NYC area. Experts say it mirrors facilities typically used for #cybercrime.
#simfarm
https://www.wired.com/story/sim-farm-new-york-threatened-us-infrastructure-feds-say/
So, this is your regular reminder that phishing eMails are getting REALLY good...
I received TWO phishing messages for different online web brokerage companies, and they look quite authentic.
But I'm not a client of those companies, so I knew it was a scam.
Please remind your friends and family members not to click on links in eMail, ESPECIALLY if they're urgent or threatening dire consequences.
Mobilfunk-Server mit 100.000 SIM-Karten in New York beschlagnahmt
Rund um das New Yorker Hauptquartier der UNO wurden 300 SIM-Karten-Server und 100.000 SIM-Karten entdeckt. Deren Zweck ist undeutlich.
Fun times, someone with a .com.au domain decided that the best way to advertise their business was to send identical emails to an email address at times:
- 07:13
- 07:38
- twice at 10:00
- 11:03
- 15:00
- 15:01
All sent from the same /24 subnet, all identical in content.
Picked the wrong recipient… a webmaster who knows how the `whois` command works, how to read "Received:" headers in emails, how to look up hostnames, and knows the ACMA has a dedicated email address for receiving such reports.
Cue, 7 separate emails for each of the mail servers concerned, 1 to the webserver host, 1 to the registrar and one to the ACMA (since you need to be an Australian business to own a .com.au domain).
Someone's going to get a nasty surprise tomorrow. There's ways to market your business, and there are ways that will land you in hot water one way or the other.
https://www.acma.gov.au/dealing-with-spam#complain-or-forward-spam-to-the-acma
Y’all. This is a known spammer who is picking up momentum. We’re seeing LOTS of accounts using the same name and avatar. But the bio varies from instance to instance. And a minority of them don’t have an avatar, but still use the name.
If you see these accounts, please report them. We’re trying to wipe them out, but we can’t until we know about them.
Thanks for the teamwork! 🤝
Now 8024921 imaginary friends (and counting), at https://nxdomain.no/~peter/traplist.shtml, mainly exumed from logs.
For the bored but not restless, https://nxdomain.no/~peter/eighteen_years_of_greytrapping.html (also https://bsdly.blogspot.com/2025/08/eighteen-years-of-greytrapping-is.html) #greytrapping #spamtraps #spamd #openbsd #spam #cybercrime
In den letzten Tagen seh ich wieder verstärkt diese Mails „ich bin ein Hacker und hab dich mit deiner Webcam beim Wixen gefilmt und ich schick das an alle deine Kontakte, wenn du mir nicht x Bitcoin überweist“. Falls die jemand noch nicht kennt: Das ist Fake, der Absender hat nichts von Dir, einfach in den Spam-Ordner verschieben und die Spam-Erkennung lernen lassen, falls nicht schon geschehen. 🙂
#Google #GoogleClassroom #Gmail #spam #MonopolistsDontInnovate
This post is not an invitation to scold me for using Google products or to suggest alternatives. It is also not a request for technical support.