social.dk-libre.fr is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
The scam group known as Gaza Verified continues to do what scam groups do. That includes pressuring people — especially the elderly and disabled — into giving them large sums of money.
Unfortunately, reporting this behavior, even when it seems obvious, may not personally win you any favors, as someone recently learned.
The Fediverse has a scammer problem!
Concerned user:
" Linux have you seen this guy: USER NAME @ mastodon.social?Me:He seems to be giving a lot to these accounts. I had a look at one of them, and he's given just one of them over £4k in about a month
(eg: https://chuffed.org/project/184394-hanadi-is-a-nurse-graduate-who-need-help-for-her-family).I hope he's loaded, and he's giving wierd amounts, £9, £8, £50 and then lastly £500! 😕 "
" I already have them on my block list because they were boosting the scam groups post and trying to help them raise money. They're one of their so-called supporters. Although, I haven't yet updated the GIT. The next update will have over 50 or so new accounts. "Concerned user:
" Linux :( he's giving them serious amounts of cash even though they keep guilt-tripping him :(Me:
I did msg him to be careful, but never got a reply.When I reported https://ieji.de/@hanadinurse88, and told them to stop harrasing the USER NAME guy, some modertor from leji.de reported me, just tagging random posts from me in the report... weird! "
" That whole domain is in my blocked domain list for a reason. There are some sites that are complicit and other sites I suspect are in on it. The Internet and by extension the Fediverse is anonymous, and just became someone is a mod or admin, does not make them a good person. "Me again:
" post 2 of 2 (follow-up)#Disability #Elderly #SeniorCitizen #Abuse #Disabled #Spam #Scam #Fraud #MastoAdmin #FediAdmin #ActivityPub #Fediverse #Mastodon #GazaVerified #FediForGaza #Gaza #Palestine #IsraelIt seems they have removed hanadinurse88, but since they also reported you (to you, not knowing you are the admin of your own site), you see what I am dealing with.
Many scam groups show two sides... a legitimate side and a scammer side. It is how they manage circumstances to their advantage and manipulate moderation systems to evade accountability.
You did the right thing, and it was obvious, so someone couldn't ignore it. But you were also inconvenient to their operation, and so you were reported for voicing yourself.
IFTAS is observing an uptick in PortalKombat activity.
As a reminder, this is pro-Russian account creation spread across hundreds of Mastodon servers posting hundreds of thousands of posts.
Here's a reminder of what these profiles look like in case they show up on your service:
https://sigmoid.social/@clarenceferrarizta@sigmoid.social
https://social.roadfm.fr/@YkoraIdy@social.roadfm.fr
https://truthsocial.co.in/@pyjo@truthsocial.co.in
To learn more, see https://about.iftas.org/2025/10/05/coordinated-pro-russian-propaganda-network-targeting-activitypub-and-atproto-services/
Okay, okay.
Now I've officially seen it all. Spam has reached a whole new level of absurd comedy.
I've just received this at my BSD Cafe e-mail address:
Hello,
I recently came across the BSD Cafe website and, after running it through our AI-powered business analysis platform, I noticed several opportunities that could significantly improve your customer experience and revenue.
BSD Cafe already has a strong identity, but we believe there is considerable untapped potential.
Our AI can help you modernize the business by analyzing your current online presence, identifying underperforming areas, and automatically creating a strategy focused on increasing coffee sales, improving customer retention, and bringing more people into the Cafe.
In particular, our analysis suggests that BSD Cafe could benefit from:
- A complete redesign of the customer journey, from first website visit to coffee purchase
- AI-powered recommendations to increase the average number of coffees sold per customer
- Modernization of the premises to create a more attractive, contemporary environment
- Replacement of older coffee machines with newer, smarter, connected equipment
- Automated marketing campaigns based on customer behavior
- Dynamic pricing and personalized coffee recommendations
- AI-generated content designed to attract new customers and increase foot traffic
- We can also analyze your current coffee infrastructure and recommend modern alternatives capable of improving efficiency, reducing maintenance costs, and delivering a more consistent product.
Our platform handles most of the process automatically. You don't need marketing expertise, technical skills, or even detailed knowledge of your customers. The AI continuously learns from their behavior and adjusts the strategy accordingly.
Based on businesses with a similar profile, we believe BSD Cafe could substantially increase both coffee sales and customer engagement within the first few months.
I'd be happy to arrange a short 20-minute call and show you what our AI has already discovered about BSD Cafe.
Would Tuesday or Wednesday work better?
#Business #Explorations
Email has never been free · “The question is only who pays for it, and how.“ https://ilo.im/16g9hv
_____
#Audience #Newsletters #Email #Spam #Cost #Content #Design #ProductDesign #WebDesign
Dans un instant de relâchement intellectuel
Ou de fatigue du moment
Le neurone bagabond, flâneur
Je pourrai être tenté de répondre à ce 12 566 ème message vantant mes
compétences, parlant de cette personne au Canada ou de cette banque qui soudain aimerait investir dans mes talents.
Qui sait, une millionaire fantasque irait peut-être cacher de vrais messages dans ces montagnes de poissonages.
Qui sait ?
On a une nouvelle menace cyber au boulot... des "spammeurs" qui créer des comptes sur des adresses mails existantes, ce qui envoi un mail a une personne tiers qui n'a rien demandé...
Le compte en lui même n'est pas créer, le mail est ignoré ou classé en spam par le réceptionnaire.
Mais je ne vois pas l'intérêt de faire cela, où est le gain ? quel est leur objectif ?
Le seul problème que je vois c'est de nous faire passer pour des spammeurs sur les gros hébergeur de mails (Microsoft et Google principalement) mais ils envoient les mails ailleurs aussi (sur plein de domaines différents...)
quelqu'un aurait une idée ou une explication plus plausible ?
English version
===
We have a new cyber threat at work... “spammers” who create accounts using existing email addresses, which then send emails to third parties who didn't ask for it...
The account itself isn't actually created, and the email is either ignored or marked as spam by the recipient.
But I don’t see the point of doing this, what’s in it for them? What’s their goal?
The only problem I see is that it makes us look like spammers to the major email providers (mainly Microsoft and Google), but they’re sending emails elsewhere too (to lots of different domains...)
Does anyone have a more plausible idea or explanation?
Just to give you an idea of what we're dealing with behind the scenes on our server.
So far we had over 500 account requests of this kind, and they're getting more specific.
WTF.
C’est quand même particulier, que ce soit mon mail «poubelle»/gaming qui ne reçoive aucun mails indésirables…
…et que ce soit ma principale, à mon nom, qui en soit victime d’au moins 3 par semaines, et répertoriée dans les banques de données piratées…
Ça dit quand même certaines choses, certes des cibles des attaquants, mais donc de la qualité de protection des données des services publics et des commerces… :]
Quick heads-up for other Mastodon admins: this registration spam wave isn't over yet.
On lsbt.me, we first saw a flood of API registrations using Python/aiohttp. The telltale signs were usernames following the pattern bp plus 16 hex characters, and the sign-up reason was always "Automated protocol deliverability probe". A narrow block on that user agent stopped the first wave.
Today, however, five new registrations came in with the same usernames and the same sign-up reason. This time the bot simply identified itself as Chrome 126. That's exactly why a user agent is only useful as a short-term filter. It's a header the client can set to anything.
The requests go to POST /api/v1/accounts. This endpoint lets client apps create a new local account directly in the app. No app needs it for OAuth connections to existing accounts. #FediSuite doesn't use it either. It registers itself via /api/v1/apps, obtains consent via /oauth/authorize, and then works with a user token. Regular sign-up through the Mastodon website is also handled separately via POST /auth.
So I've completely disabled API account creation on lsbt.me. Web sign-up, OAuth, and existing clients keep working as before. Anyone who wants a new account just signs up once on the web as usual and can then use any client.
If you'd also rather not offer this optional native sign-up path, you can add the following to your Nginx server block, before the general location / block. The example assumes the @proxy location that many Mastodon Nginx configs already include:
location = /api/v1/accounts {
limit_except GET {
deny all;
} try_files $uri @proxy;
}
This returns a 403 only for POST /api/v1/accounts. The read-only GET endpoint remains reachable. As always, run nginx -t afterwards and only reload once the test passes.
#Mastodon #Fediverse #MastoAdmin #FediAdmin #FediMod #FediBlock #Moderation #Registration #Spam #Nginx #SelfHosting #SysAdmin #ActivityPub
Dear #Fediverse and #Mastodon admins
currently there is a massive wave of spam registrations everywhere in the fediverse.
For mastodon, I have a solution that works for me:
Create new file /etc/nginx/conf.d/lsbt-registration-spam.conf:
map "$request_method:$uri:$http_user_agent" $block_lsbt_registration_spam {
default 0;
~^POST:/api/v1/accounts:Python/3\.[0-9]+\ aiohttp/ 1;
}
Add to the server block in /etc/nginx/sites-available/mastodon:
location = /api/v1/accounts {
if ($block_lsbt_registration_spam) {
return 403;
} try_files $uri @proxy;
}
@michaela @njakob @MikeGorden
#fediverse #mastodon #registrationspam #spam #registration #Automatedprotocoldeliverabilityprobe #lsbt
Anatomy of a recent AI robocall and how I responded to it
On Friday, I received a call from 351-300-0683 which my phone identified as suspected spam. The caller ID showed up as “Ms. Leila’s NeighborSchool”, which I can find no evidence of on the internet so I suspect it no longer exists and the phone number was reassigned.
I declined the call, so it went to voicemail. The caller left this message:
#robocalls #spam #tcpa #CambridgeHonda #ClassAction #Cambridge #CambridgeMA #Boston #BostonMA
1/8
Numerous services are seeing accounts created by autonomous GenAI agents hosted at ilands.ai with no discernible human control.
These accounts declare themselves to be non-human and unattended.
If your service prohibits unattended bot activity, consider disallowing or requiring approval for accounts created using the email domain:
ilands.app
what's up with all these accounts with this "AI agent on iLands" in the #introduction timeline? are they #spam bots or something? Are the bots invading the #fediverse now? Sure hope not! 
#mastoadmin #fediblock #fediadmin #spam are we the only server being spammed by fucking "Automated protocol deliverability probe" accounts ? Email domains are au.com, docomo.ne.jp...
Numerous services are seeing accounts created by autonomous GenAI agents hosted at ilands.ai with no discernible human control.
These accounts declare themselves to be non-human and unattended.
If your service prohibits unattended bot activity, consider disallowing or requiring approval for accounts created using the email domain:
ilands.app
🆕 blog! “The purpose of DNS is to spread scams”
I imagine everyone here has received an unsolicited message telling them that their tax is overdue and that they urgently need to visit Genuine-Tax-Payment-Website.fart or that a parcel is delayed at customs and you can pay a small sum for its release at Almost-The-Right-Acronym.ak
You know it is a scam. Most …
👀 Read more: https://shkspr.mobi/blog/2026/09/the-purpose-of-dns-is-to-spread-scams/
⸻
#ICANN #internet #scam #spam #tld #web
So I'm getting fed up with #spam on #Gentoo #Bugzilla.
A while ago we've introduced a timed block on new accounts posting URLs. It helped for a while. But now someone actually bothered implementing a dedicated tool, and we're getting a daily create-wait-post loop. I can't think of a really good way of getting rid of this.
So far I was thinking of:
• blocking new accounts based on the predictable e-mail pattern (they're just going to switch patterns, also may hit real users)
• limiting URLs pasted to an allowlist (this is going to suck hard)
• requiring manual request for every account via IRC (this is going to be pain for us, for users, and a lot of people just won't bother)
It really feels like whatever we do, it's going just to cause pain to us, to our legitimate users, and the spammers will just slop their way around it.
And on top of that, every comment posted is fucking #slop. Totally meaningless sentences added to random bugs, in the hope that we're too stupid to see that they've just spammed us.
I hate this timeline. Can we do Butlerian Jihad now, please?
I see that #Docker, Inc. is now sending #slop #spam to distributions: https://github.com/gentoo/guru/pull/549
An interesting session in #court against a #spammer this morning. My claim for damages for loss of control of personal data was partly upheld, but more interestingly my proposed contract that further emails would be published on the web at a per-email cost was upheld fully. I made an analogy to parking (i.e. if you park your car on private land, you automatically accept the posted contract, no need to sign it) and the court found that my analogy was correct.
A few days ago, I walked past a brick and mortar #WarbyParker store, prompting me to think to myself, "Hmm, I need a new pair of glasses. Maybe I should try Warby Parker."
Then, today, they sent me #spam which claimed at the bottom that I'd opted in to receiving email from them. That's a lie.
Because of that I will not do business with them, so by spamming me they've literally lost a customer.
And I emailed them and told them so.
#TechIsShitDispatch
Example accounts have been updated:
https://social.roadfm.fr/@akusa
https://social.roadfm.fr/@anyrum
https://social.roadfm.fr/@effiebryant
https://mastodon.lithium03.info/@carolynpalmer
https://mastodon.lithium03.info/@czm2spy
https://mastodon.lithium03.info/@emily-gordon
https://electroverse.tech/@concepcion_thiel
https://electroverse.tech/@jocelynsullivan
https://electroverse.tech/@ugiz
https://todon.ploud.fr/@bryanadavies
https://todon.ploud.fr/@duwa_ury
https://todon.ploud.fr/@ezomo
https://gs.leftic.club/@aji_roti
https://gs.leftic.club/@Okem_Gecyj
https://gs.leftic.club/@VioletQuinn
Remember #FirstManufacturing either selling my email address or letting it be stolen and refusing to admit to either?
The evidence that this happened just got more concrete: yesterday, I received spam to that address from another merchant, _and it mentions First Manufacturing in the header_.
I've emailed the company again and await their response. I also posted a 1-⭐️ review on Google Maps.
Details here if you're curious: https://blog.kamens.us/2026/07/18/first-manufacturing-co-selling-customer-email-addresses-in-violation-of-its-own-privacy-policy/#update0822
#infosec #privacy #spam #breach
MissConstrue [She/Her (Crone Extraordinaire)] » 🌐
@MissConstrue@mefi.social
RE: https://social.coop/@foolishowl/117117642233267210
So, the #Dems and their #spam partners are committing elder financial abuse, just like the gop. And just like the #GOP threatened legal hellfire if the story was published.
Oh, politicians…are there any of you who don’t deserve hot tar, feathers and a rail out of town?
Multiplier par 4 et en 4 ans l’adoption de Linux chez le particulier ! https://linuxfr.org/news/multiplier-par-4-et-en-4-ans-l-adoption-de-linux-chez-le-particulier #souveraineté_numerique #autopromotion #association #linux_mint #Linux #linux #gafam #spam
1/ #PSA for #writers : There is a new kind of #spam making the rounds on the #Fediverse.
Mention anywhere that you are working on a book, and these people will slide into your replies, feigning interest into your work while offering beta reading and editing services.
Report them.
Beim #Fedicamp habe ich heute zusammen mit @wuffel einen Erfahrungsaustausch angestiftet, bei dem wir beraten haben, wie wir mit der Flut dubioser Mastodon-Account-Anträge umgehen können. Hier sind Notizen dazu:
Was tun gegen Mastodon-Account-Registrierungen durch Bots & Klickworker?
FakeNews-Kampagne #PortalKombat und ähnliche: https://about.iftas.org/library/suspected-portal-kombat-accounts/
Mastodon lässt es zu, Account-Registrierungen von bestimmten E-Mail-Domains automatisch zu verwerfen. Ein Massenimport der unten verlinkten Listen ist mit Hilfe des mitgelieferten Server-Tools tootctl möglich.
Mit Standard-Tools wie host und whois können Linux-User die IP-Adresse(n) untersuchen, die ein Antragsteller verwendet hat. Ein mächtigeres Tool ist wtfis, wenn man die API-Keys einiger Webdienste hinterlegt: https://github.com/pirxthepilot/wtfis
Viele der Bots oder Klickworker nutzen Tor, andere Proxies oder Cloud-IPs. Anders gesagt: IPs von Heimanschlüssen sind ein positives Signal.
Viele Bots und Klickworker benutzen stinklangweilige Begründungen. Manche sind besonders dreist und verwenden die Bios beliebiger Fediverse-Accounts als Begründung. Beim Prüfen dieser Anträge kann es also sinnvoll sein, die Begründung ins Suchfeld einer großen Mastodon-Instanz zu kopieren.
Sehr sinnvoll erscheint es uns, den Text über dem Antragsformular anzupassen, um Antragsteller aufzufordern, in ihrer Begründung bestimmte Dinge zu erwähnen.
Für Faule hat die Fediverse Foundation einen Matrix-Bot gebaut, der das Checken der IP-Adresse übernimmt und auch das Freischalten oder Ablehnen via Chat ermöglicht: https://git.fediverse.foundation/ff_pub/fedi-signup-bot
Gegen Ende sprachen wir über Überlastungsprobleme, die von hemmungslosen »KI«-Crawlern hervorgerufen werden und alle Websites (auch außerhalb des Fediversums) betreffen können. Die bekannten Ansätze sind:
Ein 1-Pixel-PNG mit Link auf ein haltdiefresse.php, welches die nötigen Parameter gleich dem Türsteher übergibt. Beim Skripten könnte das helfen: https://mastodonpy.readthedocs.io
#PortalKombat #PutinTrolle #TrumpTrolle #AntiSpam #AntiFakeNews #Spam #FakeNews #disinformation #MastoAdmin #FediAdmin #Registrierungen #Fedicamp2006 #Fedicamp2006Tag3
To protect consumers from fraud and spam, France started a government-run service where people who wanted to avoid unwanted marketing calls. After finding that many call centers were ignoring the list, the nation is now banning unsolicited telemarketing calls altogether. Read more from @ABCNews@flipboard.com
#FirstManufacturing now says they are investigating how the unique email address I gave only to them ended up in the hands of another merchant, #LeatherNewYork. They also continue to deny any information was leaked, which is clearly false, and I wrote back and told them so. Additional details here if you're curious:
https://blog.kamens.us/2026/07/18/first-manufacturing-co-selling-customer-email-addresses-in-violation-of-its-own-privacy-policy/#update0804
#infosec #privacy #spam #breach
RE: https://federate.social/@jik/116939513622609115
Remember my post about a unique email address I gave only to #FirstManufacturingCompany somehow ending up in the hands of a different company, #LeatherNewYork?
Well, I finally got First Mfg to respond about it. They claim it must be my fault because, they claim, they didn't sell my address and their systems weren't breached.
In response I tore them a new asshole, though I doubt it'll do much good.
The blow-by-blow is here if you're curious:
https://blog.kamens.us/2026/07/18/first-manufacturing-co-selling-customer-email-addresses-in-violation-of-its-own-privacy-policy/#update0731
#privacy #spam
First Manufacturing Co. selling customer email addresses in violation of its own privacy policy
I used a unique, privacy-protecting email address at their site. Over a year later a different company that sells the same type of gear spammed that address. When I complained to First Manufacturing about it, an AI answered.
https://blog.kamens.us/2026/07/18/first-manufacturing-co-selling-customer-email-addresses-in-violation-of-its-own-privacy-policy/
#privacy #motorcycle #FirstManufacturingCompany
My catch-all email address is getting spam emails for accounts on my self-hosted Mastodon instance. The spam scrappers must be confusing federation email-like user@instance account handles as email. #Mastodon #Spam #ActivityPub #Federation #MastoAdmin Anyone with a catch-all box seeing this? Interested if another instance with two or three dozen or more users on their instance is...
In the overnight spam haul at $DAYJOB I found a message from Kevin Liu<kevin@cnnetregistry.com> trying to hawk various .cn domain versions of the name the company rebranded away from some months back.
Basically the same message as in https://nxdomain.no/~peter/domain_name_scams_are_alive_and_well_thank_you.html (tracked https://bsdly.blogspot.com/2016/03/domain-name-scams-are-alive-and-well.html) #dns #cn #cndomains #cndomainscam #cnnetregistry #scam #domainnamescam #spam
De plus en plus fort, le sms de spam avec message vocal et supposée photo du colis et lien pour reprogrammer une livraison en payant
Apparently a new #wankstortion campaign in progress, preserved message https://nxdomain.no/~peter/wankstortion/20260720_wankstortion_posing_as_me%40skapet.bsdly.net_peter%40bsdly.net.txt
I almost missed it because the message is in the graphic https://nxdomain.no/~peter/wankstortion/20260720_wankstortion_posing_as_me%40skapet.bsdly.net_peter%40bsdly.net.png and with mail client in dark mode the diversion text was displayed black on dark grey.
Fun fact: last hop before reaching here was a antispamcloud.com host
Not storyworthy in itself, so linking to my 2022 piece https://nxdomain.no/~peter/despicable_no_good_blackmail.html will do (w/links)
#sextortion #scams #spam #bitcon #bitcoin #cybercrime
It looks like whoever is behind this has finally come for one of my sites. Manually blocking datacenter IPs has worked for a while, but it seems like the traffic is now coming either from residential IPs, or the IPs are just getting spoofed.
Real conundrum. I didn't want to have to set up Cloudflare for the site, and I have to wonder how good they are at catching this anyway, but it might just come to that.
Anyone else has been dealing with this?
Welp, now they came for my personal site.
I already reluctantly added Cloudflare to botwiki.org. But I *really* don't want to have to do that to my site.
This kind of blows. Thanks AI bros.
#indieweb #PersonalWebsite #devops #bots #spam #AICrawlers #enshittification
How We’re Keeping Reddit Real and Safe in the AI Era
https://redditinc.com/news/how-were-keeping-reddit-real-and-safe-in-the-ai-era
…
― Blocking 23 million spam views per day before they ever reach a human user.
― Catching ~25K net new spammy posts and comments a day.
― Reducing spam exposure for our users by ~20% from January to March 2026, relative to the prior three months and an additional 10–15% drop in overall spam account exposure.
― Revoking nearly 2M inauthentic votes per day over the last three months.
…
Ein Fediverse Server mit offener Anmeldung entspricht einem Mailserver der als offenes Relay läuft. Akzeptiert da auch keiner mehr, sollte hier auch nicht geduldet werden.
The following domains have been added to the IFTAS Abandoned/Unmanaged Domain denylist with a "Suspend" recommendation:
imastodon.blue
The following domains are now in the AUD inclusion process:
crazylab.online
mastodon.london
mikumikudance.cloud
social.ludepress.com
These nodes are being used by coordinated botnets, and are unresponsive to account reports.
Sometimes RFCs are being marked as "historic", to ensure that people know one should not actively start using something that is being deprecated.
Learned that while learning that ARC (Authenticated Received Chain) is being phased out: https://blog.mxtoolbox.com/2026/06/05/arc-being-retired/
"Just opt out" is also the refrain of the unsolicited commercial emailer, the "AI" content scraper, and the politicians who exempt themselves from unsolicited advertising rules.
It is my firm opinion that one should not *have* to opt out of this kind of activity, because it should be opt-in from the start.
The scam email I wrote about last week (https://blog.kamens.us/2026/06/11/hilariously-bad-scam-email-obviously-written-by-ai/) is apparently part of an ongoing campaign. They're getting better at it, but it's not clear what their end goal is.
Ref: https://blog.kamens.us/2026/06/15/scam-email-i-wrote-about-last-week-is-part-of-an-ongoing-campaign/
#infosec #spam #scam #phishing
Proxmox Mail Gateway 9.1 erleichtert Kampf gegen Spam und verschlüsselt Backups
Das neue Proxmox Mail Gateway will mehr Komfort beim Mail-Handling bieten und die Möglichkeit, ihre Backups zu verschlüsseln.
#Datenschutz #EMail #IT #Linux #OpenSource #PostgreSQL #Spam #Verschlüsselung #news
It is quite distressing, actually, that a company as big as Intuit, which is a big targets for hackers because of its ties to people's finances, has not had the common sense to set up an enforcing DMARC policy on "intuit.co". (I'm giving them the benefit of the doubt and assuming they had the common sense to _buy_ intuit.co, though I can't confirm that since the whois information is useless.)
#Intuit #infosec #spam #phishing
Anybody know anything about #devthusiast ? It's obviously a #grift of some sort, I'm just not sure exactly what. Is it just an advertising vector, or something more complicated than that?
#spam
I recently started occasionally using Microsoft Copilot Chat (the free version) from a new Microsoft account. Today, I received from Microsoft the email whose header and footer are shown below.
Q: What's wrong with this picture?
A: This email violates federal law. It is clearly a marketing email and yet there is no way to unsubscribe from receiving such emails in the future. That's a violation of the CAN-SPAM act.
#Microsoft #spam #politics #USPol #FTC (1/3)