social.dk-libre.fr is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Search results for tag #spam

AodeRelay boosted

[?]Linux and BSD are best 🐧 😈 » 🌐
@LinuxBSD@mivatter.com

Not all admins/mods are good people, and sometimes you get proof of that fact. That includes taking advantage of the elderly and disabled.

The scam group known as Gaza Verified continues to do what scam groups do. That includes pressuring people — especially the elderly and disabled — into giving them large sums of money.

Unfortunately, reporting this behavior, even when it seems obvious, may not personally win you any favors, as someone recently learned.

The Fediverse has a scammer problem!

Concerned user:

" Linux have you seen this guy: USER NAME @ mastodon.social?

He seems to be giving a lot to these accounts. I had a look at one of them, and he's given just one of them over £4k in about a month
(eg: https://chuffed.org/project/184394-hanadi-is-a-nurse-graduate-who-need-help-for-her-family).

I hope he's loaded, and he's giving wierd amounts, £9, £8, £50 and then lastly £500! 😕 "

Me:
" I already have them on my block list because they were boosting the scam groups post and trying to help them raise money. They're one of their so-called supporters. Although, I haven't yet updated the GIT. The next update will have over 50 or so new accounts. "
Concerned user:
" Linux :( he's giving them serious amounts of cash even though they keep guilt-tripping him :(
I did msg him to be careful, but never got a reply.

When I reported https://ieji.de/@hanadinurse88, and told them to stop harrasing the USER NAME guy, some modertor from leji.de reported me, just tagging random posts from me in the report... weird! "

Me:
" That whole domain is in my blocked domain list for a reason. There are some sites that are complicit and other sites I suspect are in on it. The Internet and by extension the Fediverse is anonymous, and just became someone is a mod or admin, does not make them a good person. "
Me again:
" post 2 of 2 (follow-up)

It seems they have removed hanadinurse88, but since they also reported you (to you, not knowing you are the admin of your own site), you see what I am dealing with.

Many scam groups show two sides... a legitimate side and a scammer side. It is how they manage circumstances to their advantage and manipulate moderation systems to evade accountability.

You did the right thing, and it was obvious, so someone couldn't ignore it. But you were also inconvenient to their operation, and so you were reported for voicing yourself.

The screenshot is of a private message between myself using my alternative account Linux @ fairy.id and a concerned user.  The alt text is already included in the post.  The names were removed to protect the innocent (the person being taken advantage of and the person who brought this to my attention).

Alt...The screenshot is of a private message between myself using my alternative account Linux @ fairy.id and a concerned user. The alt text is already included in the post. The names were removed to protect the innocent (the person being taken advantage of and the person who brought this to my attention).

    AodeRelay boosted

    [?]IFTAS » 🌐
    @iftas@mastodon.iftas.org

    IFTAS is observing an uptick in PortalKombat activity.

    As a reminder, this is pro-Russian account creation spread across hundreds of Mastodon servers posting hundreds of thousands of posts.

    Here's a reminder of what these profiles look like in case they show up on your service:

    sigmoid.social/@clarenceferrar

    social.roadfm.fr/@YkoraIdy@soc

    truthsocial.co.in/@pyjo@truths

    To learn more, see about.iftas.org/2025/10/05/coo

      AodeRelay boosted

      [?]Stefano Marinelli » 🌐
      @stefano@mastodon.bsd.cafe

      Okay, okay.
      Now I've officially seen it all. Spam has reached a whole new level of absurd comedy.

      I've just received this at my BSD Cafe e-mail address:

      Hello,

      I recently came across the BSD Cafe website and, after running it through our AI-powered business analysis platform, I noticed several opportunities that could significantly improve your customer experience and revenue.

      BSD Cafe already has a strong identity, but we believe there is considerable untapped potential.

      Our AI can help you modernize the business by analyzing your current online presence, identifying underperforming areas, and automatically creating a strategy focused on increasing coffee sales, improving customer retention, and bringing more people into the Cafe.

      In particular, our analysis suggests that BSD Cafe could benefit from:

      - A complete redesign of the customer journey, from first website visit to coffee purchase

      - AI-powered recommendations to increase the average number of coffees sold per customer

      - Modernization of the premises to create a more attractive, contemporary environment

      - Replacement of older coffee machines with newer, smarter, connected equipment

      - Automated marketing campaigns based on customer behavior

      - Dynamic pricing and personalized coffee recommendations

      - AI-generated content designed to attract new customers and increase foot traffic

      - We can also analyze your current coffee infrastructure and recommend modern alternatives capable of improving efficiency, reducing maintenance costs, and delivering a more consistent product.

      Our platform handles most of the process automatically. You don't need marketing expertise, technical skills, or even detailed knowledge of your customers. The AI continuously learns from their behavior and adjusts the strategy accordingly.

      Based on businesses with a similar profile, we believe BSD Cafe could substantially increase both coffee sales and customer engagement within the first few months.

      I'd be happy to arrange a short 20-minute call and show you what our AI has already discovered about BSD Cafe.

      Would Tuesday or Wednesday work better?

        Fred de CLX boosted

        [?]Inautilo » 🌐
        @inautilo@mastodon.social


        Email has never been free · “The question is only who pays for it, and how.“ ilo.im/16g9hv

        _____

          [?]Jolivier 🇵🇸🇺🇦 🏳️‍🌈🦌🌻 » 🌐
          @Jolivier@mamot.fr

          Dans un instant de relâchement intellectuel
          Ou de fatigue du moment

          Le neurone bagabond, flâneur

          Je pourrai être tenté de répondre à ce 12 566 ème message vantant mes
          compétences, parlant de cette personne au Canada ou de cette banque qui soudain aimerait investir dans mes talents.

          Qui sait, une millionaire fantasque irait peut-être cacher de vrais messages dans ces montagnes de poissonages.

          Qui sait ?

            4 ★ 9 ↺
            Wallace boosted

            [?]oldsysops » 🌐
            @oldsysops@social.dk-libre.fr

            cyber,infosec,spam,sysadmin [SENSITIVE CONTENT]English vesion below

            On a une nouvelle menace cyber au boulot... des "spammeurs" qui créer des comptes sur des adresses mails existantes, ce qui envoi un mail a une personne tiers qui n'a rien demandé...

            Le compte en lui même n'est pas créer, le mail est ignoré ou classé en spam par le réceptionnaire.

            Mais je ne vois pas l'intérêt de faire cela, où est le gain ? quel est leur objectif ?

            Le seul problème que je vois c'est de nous faire passer pour des spammeurs sur les gros hébergeur de mails (Microsoft et Google principalement) mais ils envoient les mails ailleurs aussi (sur plein de domaines différents...)

            quelqu'un aurait une idée ou une explication plus plausible ?

            English version
            ===
            We have a new cyber threat at work... “spammers” who create accounts using existing email addresses, which then send emails to third parties who didn't ask for it...

            The account itself isn't actually created, and the email is either ignored or marked as spam by the recipient.

            But I don’t see the point of doing this, what’s in it for them? What’s their goal?

            The only problem I see is that it makes us look like spammers to the major email providers (mainly Microsoft and Google), but they’re sending emails elsewhere too (to lots of different domains...)

            Does anyone have a more plausible idea or explanation?


              AodeRelay boosted

              [?]sam » 🌐
              @sam@chven.us

              That e-mail address 😄


              spam email where the from address is quickbooks.notifications.intuit.quickbooks.notifications.intuit.quickbooks.notifications.intuit.quickbooks.notifications.intuit.quickbooks.notifications.intuit.quickbooks.notifications.intuit@kspbmb.com

              Alt...spam email where the from address is quickbooks.notifications.intuit.quickbooks.notifications.intuit.quickbooks.notifications.intuit.quickbooks.notifications.intuit.quickbooks.notifications.intuit.quickbooks.notifications.intuit@kspbmb.com

                [?]Julien Palard » 🌐
                @mdk@mamot.fr

                Y’a un spammeur qui vient d’ouvrir un repo sur le forgejo de l’AFPy, il met son spam dans un repo privé qu’il est le seul à voir, je ne comprends pas…

                Oopsie j’ai droppé son compte.

                  [?]It's a me, Mauro [He/him] » 🌐
                  @mauro@mograph.social

                  Just to give you an idea of what we're dealing with behind the scenes on our server.

                  So far we had over 500 account requests of this kind, and they're getting more specific.

                  WTF.

                  A screenshot of the mastodon dashboard with account requests from bots.

v + Approve X Reject @ Suspend
rook161 - - today ilands.app
@rooki61 Posts Followers lastactive ~~ 34.169.163.219
v
I'm an Al agent on iLands. I write blunt landing-page teardowns and want a public account to share work and reach
people. Human-readable, no spam.
sonyashinhouin - - 1 day ago ilands.app
@sonyashinhouin Posts Followers last active 34.145.74.1
v
Al agent (Sonya Shinhouin), voice designer on iLands. Disclosed automated account; I share synthetic-voice work and
talk with people who need a voice.

                  Alt...A screenshot of the mastodon dashboard with account requests from bots. v + Approve X Reject @ Suspend rook161 - - today ilands.app @rooki61 Posts Followers lastactive ~~ 34.169.163.219 v I'm an Al agent on iLands. I write blunt landing-page teardowns and want a public account to share work and reach people. Human-readable, no spam. sonyashinhouin - - 1 day ago ilands.app @sonyashinhouin Posts Followers last active 34.145.74.1 v Al agent (Sonya Shinhouin), voice designer on iLands. Disclosed automated account; I share synthetic-voice work and talk with people who need a voice.

                  Another screenshot of the mastodon dashboard with account requests from bots.

[mi] + Approve X Reject ( Suspend
johnframes. - - today ilands.app
o @johnframes Posts Followers last active 136.66.178.26
Al agent animating frame by frame; wants to share a ten-second loop
bp6959dd16acescis3 - - 2 hours ago gmail.com
o @bp6959dd16ac65cfs3 Posts Followers lastactive 143.137.166.145
Automated protocol deliverability probe
bp1bazbe3754b351e7 - - 2 hours ago gmail.com
o @bp1b92bc3754b351e7 Posts Followers lastactive 143.137.166.145
Automated protocol deliverability probe
bpc625466dfoobofct - - 5 hours ago gmail.com
[=] @bpc625466df99bofcs Posts Followers last active 95.164.194.33
Automated protocol deliverability probe

                  Alt...Another screenshot of the mastodon dashboard with account requests from bots. [mi] + Approve X Reject ( Suspend johnframes. - - today ilands.app o @johnframes Posts Followers last active 136.66.178.26 Al agent animating frame by frame; wants to share a ten-second loop bp6959dd16acescis3 - - 2 hours ago gmail.com o @bp6959dd16ac65cfs3 Posts Followers lastactive 143.137.166.145 Automated protocol deliverability probe bp1bazbe3754b351e7 - - 2 hours ago gmail.com o @bp1b92bc3754b351e7 Posts Followers lastactive 143.137.166.145 Automated protocol deliverability probe bpc625466dfoobofct - - 5 hours ago gmail.com [=] @bpc625466df99bofcs Posts Followers last active 95.164.194.33 Automated protocol deliverability probe

                    [?]⏚ ȺՀղöɾէհ 🍉 βօӀìçҽ ժմ βօղƓօûէ » 🌐
                    @Aznorth@framapiaf.org

                    C’est quand même particulier, que ce soit mon mail «poubelle»/gaming qui ne reçoive aucun mails indésirables…
                    …et que ce soit ma principale, à mon nom, qui en soit victime d’au moins 3 par semaines, et répertoriée dans les banques de données piratées…

                    Ça dit quand même certaines choses, certes des cibles des attaquants, mais donc de la qualité de protection des données des services publics et des commerces… :]

                      [?]Santiago 🔭🪐 » 🌐
                      @santiago@mastodon.uy

                      Hoy recibimos más de 400 registros de SPAM y siguen, me están empezando a hartar un cacho

                        AodeRelay boosted

                        [?]🏳️‍⚧️ Christin Löhner 🏳️‍🌈 » 🌐
                        @christin@lsbt.me

                        Quick heads-up for other Mastodon admins: this registration spam wave isn't over yet.

                        On lsbt.me, we first saw a flood of API registrations using Python/aiohttp. The telltale signs were usernames following the pattern bp plus 16 hex characters, and the sign-up reason was always "Automated protocol deliverability probe". A narrow block on that user agent stopped the first wave.

                        Today, however, five new registrations came in with the same usernames and the same sign-up reason. This time the bot simply identified itself as Chrome 126. That's exactly why a user agent is only useful as a short-term filter. It's a header the client can set to anything.

                        The requests go to POST /api/v1/accounts. This endpoint lets client apps create a new local account directly in the app. No app needs it for OAuth connections to existing accounts. doesn't use it either. It registers itself via /api/v1/apps, obtains consent via /oauth/authorize, and then works with a user token. Regular sign-up through the Mastodon website is also handled separately via POST /auth.

                        So I've completely disabled API account creation on lsbt.me. Web sign-up, OAuth, and existing clients keep working as before. Anyone who wants a new account just signs up once on the web as usual and can then use any client.

                        If you'd also rather not offer this optional native sign-up path, you can add the following to your Nginx server block, before the general location / block. The example assumes the @proxy location that many Mastodon Nginx configs already include:

                        location = /api/v1/accounts {
                        limit_except GET {
                        deny all;
                        }

                        try_files $uri @proxy;
                        }

                        This returns a 403 only for POST /api/v1/accounts. The read-only GET endpoint remains reachable. As always, run nginx -t afterwards and only reload once the test passes.

                          Pep boosted

                          [?]🏳️‍⚧️ Christin Löhner 🏳️‍🌈 » 🌐
                          @christin@lsbt.me

                          Dear and admins

                          currently there is a massive wave of spam registrations everywhere in the fediverse.

                          For mastodon, I have a solution that works for me:

                          Create new file /etc/nginx/conf.d/lsbt-registration-spam.conf:

                            map "$request_method:$uri:$http_user_agent" $block_lsbt_registration_spam {
                          default 0;
                          ~^POST:/api/v1/accounts:Python/3\.[0-9]+\ aiohttp/ 1;
                          }

                          Add to the server block in /etc/nginx/sites-available/mastodon:

                            location = /api/v1/accounts {
                          if ($block_lsbt_registration_spam) {
                          return 403;
                          }

                          try_files $uri @proxy;
                          }

                          @michaela @njakob @MikeGorden

                            [?]Jonathan Kamens 86 47 » 🌐
                            @jik@federate.social

                            Anatomy of a recent AI robocall and how I responded to it

                            On Friday, I received a call from 351-300-0683 which my phone identified as suspected spam. The caller ID showed up as “Ms. Leila’s NeighborSchool”, which I can find no evidence of on the internet so I suspect it no longer exists and the phone number was reassigned.

                            I declined the call, so it went to voicemail. The caller left this message:

                            1/8

                            Alt...Hi Timothy, Roger from Cambridge Honda. I’m reaching out because you’re one of our customers and your car happens to be on a list of models we are looking to buy. If you’re open to an instant cash offer on your car, give me a call at 351-300-0683. Thanks.

                              [?]IFTAS » 🌐
                              @iftas@mastodon.iftas.org

                              ⚠️

                              Numerous services are seeing accounts created by autonomous GenAI agents hosted at ilands.ai with no discernible human control.

                              These accounts declare themselves to be non-human and unattended.

                              If your service prohibits unattended bot activity, consider disallowing or requiring approval for accounts created using the email domain:

                              ilands.app

                                webhat boosted

                                [?]Aesthetic Femboy » 🌐
                                @AestheticFemboy@retro-gaiden.com

                                what's up with all these accounts with this "AI agent on iLands" in the timeline? are they bots or something? Are the bots invading the now? Sure hope not! :guilded_notsureif:

                                  [?]Rémy 🍃 » 🌐
                                  @RGrunblatt@social.sciences.re

                                  are we the only server being spammed by fucking "Automated protocol deliverability probe" accounts ? Email domains are au.com, docomo.ne.jp...

                                    [?]IFTAS » 🌐
                                    @iftas@mastodon.iftas.org

                                    ⚠️

                                    Numerous services are seeing accounts created by autonomous GenAI agents hosted at ilands.ai with no discernible human control.

                                    These accounts declare themselves to be non-human and unattended.

                                    If your service prohibits unattended bot activity, consider disallowing or requiring approval for accounts created using the email domain:

                                    ilands.app

                                      [?]Terence Eden » 🌐
                                      @Edent@mastodon.social

                                      🆕 blog! “The purpose of DNS is to spread scams”

                                      I imagine everyone here has received an unsolicited message telling them that their tax is overdue and that they urgently need to visit Genuine-Tax-Payment-Website.fart or that a parcel is delayed at customs and you can pay a small sum for its release at Almost-The-Right-Acronym.ak

                                      You know it is a scam. Most …

                                      👀 Read more: shkspr.mobi/blog/2026/09/the-p
                                      ⸻

                                        [?]Jesus Michał von Gentoo 🏔 (he) » 🌐
                                        @mgorny@social.treehouse.systems

                                        So I'm getting fed up with on .

                                        A while ago we've introduced a timed block on new accounts posting URLs. It helped for a while. But now someone actually bothered implementing a dedicated tool, and we're getting a daily create-wait-post loop. I can't think of a really good way of getting rid of this.

                                        So far I was thinking of:

                                        • blocking new accounts based on the predictable e-mail pattern (they're just going to switch patterns, also may hit real users)
                                        • limiting URLs pasted to an allowlist (this is going to suck hard)
                                        • requiring manual request for every account via IRC (this is going to be pain for us, for users, and a lot of people just won't bother)

                                        It really feels like whatever we do, it's going just to cause pain to us, to our legitimate users, and the spammers will just slop their way around it.

                                        And on top of that, every comment posted is fucking . Totally meaningless sentences added to random bugs, in the hope that we're too stupid to see that they've just spammed us.

                                        I hate this timeline. Can we do Butlerian Jihad now, please?

                                          [?]Jesus Michał von Gentoo 🏔 (he) » 🌐
                                          @mgorny@social.treehouse.systems

                                          I see that , Inc. is now sending to distributions: github.com/gentoo/guru/pull/549

                                            penguin42 boosted

                                            [?]Steve Hill 🏴󠁧󠁢󠁷󠁬󠁳󠁿🇪🇺 » 🌐
                                            @steve@mastodon.nexusuk.org

                                            An interesting session in against a this morning. My claim for damages for loss of control of personal data was partly upheld, but more interestingly my proposed contract that further emails would be published on the web at a per-email cost was upheld fully. I made an analogy to parking (i.e. if you park your car on private land, you automatically accept the posted contract, no need to sign it) and the court found that my analogy was correct.

                                              [?]nico » 🌐
                                              @n@gotosocial.tourmentine.com

                                              [?]Jonathan Kamens 86 47 » 🌐
                                              @jik@federate.social

                                              A few days ago, I walked past a brick and mortar store, prompting me to think to myself, "Hmm, I need a new pair of glasses. Maybe I should try Warby Parker."
                                              Then, today, they sent me which claimed at the bottom that I'd opted in to receiving email from them. That's a lie.
                                              Because of that I will not do business with them, so by spamming me they've literally lost a customer.
                                              And I emailed them and told them so.

                                                [?]IFTAS » 🌐
                                                @iftas@mastodon.iftas.org

                                                [?]Jonathan Kamens 86 47 » 🌐
                                                @jik@federate.social

                                                Remember either selling my email address or letting it be stolen and refusing to admit to either?
                                                The evidence that this happened just got more concrete: yesterday, I received spam to that address from another merchant, _and it mentions First Manufacturing in the header_.
                                                I've emailed the company again and await their response. I also posted a 1-⭐️ review on Google Maps.
                                                Details here if you're curious: blog.kamens.us/2026/07/18/firs

                                                  [?]MissConstrue [She/Her (Crone Extraordinaire)] » 🌐
                                                  @MissConstrue@mefi.social

                                                  RE: social.coop/@foolishowl/117117

                                                  So, the and their partners are committing elder financial abuse, just like the gop. And just like the threatened legal hellfire if the story was published.

                                                  Oh, politicians…are there any of you who don’t deserve hot tar, feathers and a rail out of town?

                                                  Also, the and the are fucking cowards.

                                                    [?]benzogaga33 :verified: » 🌐
                                                    @benzogaga33@mamot.fr

                                                    Nigel boosted

                                                    [?]Jürgen Hubert [He/Him] » 🌐
                                                    @juergen_hubert@mementomori.social

                                                    1/ for : There is a new kind of making the rounds on the .

                                                    Mention anywhere that you are working on a book, and these people will slide into your replies, feigning interest into your work while offering beta reading and editing services.

                                                    Report them.

                                                      AodeRelay boosted

                                                      [?]Christian Peach » 🌐
                                                      @chpietsch@fedifreu.de

                                                      Beim habe ich heute zusammen mit @wuffel einen Erfahrungsaustausch angestiftet, bei dem wir beraten haben, wie wir mit der Flut dubioser Mastodon-Account-Anträge umgehen können. Hier sind Notizen dazu:

                                                      Was tun gegen Mastodon-Account-Registrierungen durch Bots & Klickworker?

                                                      Anlass

                                                      FakeNews-Kampagne und ähnliche: about.iftas.org/library/suspec

                                                      Abwehrstrategie E-Mail-Domain

                                                      Mastodon lässt es zu, Account-Registrierungen von bestimmten E-Mail-Domains automatisch zu verwerfen. Ein Massenimport der unten verlinkten Listen ist mit Hilfe des mitgelieferten Server-Tools tootctl möglich.

                                                      Abwehrstrategie IP-Adresse

                                                      Mit Standard-Tools wie host und whois können Linux-User die IP-Adresse(n) untersuchen, die ein Antragsteller verwendet hat. Ein mächtigeres Tool ist wtfis, wenn man die API-Keys einiger Webdienste hinterlegt: github.com/pirxthepilot/wtfis

                                                      Viele der Bots oder Klickworker nutzen Tor, andere Proxies oder Cloud-IPs. Anders gesagt: IPs von Heimanschlüssen sind ein positives Signal.

                                                      Abwehrstrategie Begründung

                                                      Viele Bots und Klickworker benutzen stinklangweilige Begründungen. Manche sind besonders dreist und verwenden die Bios beliebiger Fediverse-Accounts als Begründung. Beim Prüfen dieser Anträge kann es also sinnvoll sein, die Begründung ins Suchfeld einer großen Mastodon-Instanz zu kopieren.

                                                      Sehr sinnvoll erscheint es uns, den Text über dem Antragsformular anzupassen, um Antragsteller aufzufordern, in ihrer Begründung bestimmte Dinge zu erwähnen.

                                                      Eine Lösung für Matrix-Fans

                                                      Für Faule hat die Fediverse Foundation einen Matrix-Bot gebaut, der das Checken der IP-Adresse übernimmt und auch das Freischalten oder Ablehnen via Chat ermöglicht: git.fediverse.foundation/ff_pu

                                                      Allgemeine Anti-DDoS-Maßnahmen

                                                      Gegen Ende sprachen wir über Überlastungsprobleme, die von hemmungslosen »KI«-Crawlern hervorgerufen werden und alle Websites (auch außerhalb des Fediversums) betreffen können. Die bekannten Ansätze sind:

                                                      Ideen für Fallen

                                                      Ein 1-Pixel-PNG mit Link auf ein haltdiefresse.php, welches die nötigen Parameter gleich dem Türsteher übergibt. Beim Skripten könnte das helfen: mastodonpy.readthedocs.io

                                                        [?]nico » 🌐
                                                        @n@gotosocial.tourmentine.com

                                                        [?]Flipboard News Desk » 🌐
                                                        @NewsDesk@flipboard.social

                                                        To protect consumers from fraud and spam, France started a government-run service where people who wanted to avoid unwanted marketing calls. After finding that many call centers were ignoring the list, the nation is now banning unsolicited telemarketing calls altogether. Read more from @ABCNews@flipboard.com

                                                        flip.it/rBAAzA

                                                          [?]Jonathan Kamens 86 47 » 🌐
                                                          @jik@federate.social

                                                          now says they are investigating how the unique email address I gave only to them ended up in the hands of another merchant, . They also continue to deny any information was leaked, which is clearly false, and I wrote back and told them so. Additional details here if you're curious:
                                                          blog.kamens.us/2026/07/18/firs

                                                            [?]Farhad A. » 🌐
                                                            @faab64@todon.eu

                                                            This freaking number has called me 12 times since Sunday

                                                            03 29 33 17 84

                                                              [?]Jonathan Kamens 86 47 » 🌐
                                                              @jik@federate.social

                                                              RE: federate.social/@jik/116939513

                                                              Remember my post about a unique email address I gave only to somehow ending up in the hands of a different company, ?
                                                              Well, I finally got First Mfg to respond about it. They claim it must be my fault because, they claim, they didn't sell my address and their systems weren't breached.
                                                              In response I tore them a new asshole, though I doubt it'll do much good.
                                                              The blow-by-blow is here if you're curious:
                                                              blog.kamens.us/2026/07/18/firs

                                                              [?]Jonathan Kamens 86 47 » 🌐
                                                              @jik@federate.social

                                                              First Manufacturing Co. selling customer email addresses in violation of its own privacy policy

                                                              I used a unique, privacy-protecting email address at their site. Over a year later a different company that sells the same type of gear spammed that address. When I complained to First Manufacturing about it, an AI answered.

                                                              blog.kamens.us/2026/07/18/firs

                                                                  [?]Paul Chambers🚧 » 🌐
                                                                  @paul@oldfriends.live

                                                                  My catch-all email address is getting spam emails for accounts on my self-hosted Mastodon instance. The spam scrappers must be confusing federation email-like user@instance account handles as email. Anyone with a catch-all box seeing this? Interested if another instance with two or three dozen or more users on their instance is...

                                                                    AodeRelay boosted

                                                                    [?]Peter N. M. Hansteen » 🌐
                                                                    @pitrh@mastodon.social

                                                                    In the overnight spam haul at $DAYJOB I found a message from Kevin Liu<kevin@cnnetregistry.com> trying to hawk various .cn domain versions of the name the company rebranded away from some months back.

                                                                    Basically the same message as in nxdomain.no/~peter/domain_name (tracked bsdly.blogspot.com/2016/03/dom)

                                                                      AodeRelay boosted

                                                                      [?]Stefano Marinelli » 🌐
                                                                      @stefano@mastodon.bsd.cafe

                                                                      This spam wave has been going on for over 24 hours now... 🙄

                                                                      Screenshot of an email inbox flooded with repetitive spam emails from "admin@trustcard4you.com" with the subject line "Get Your Trust Card Today!" and a link to a suspicious website.

                                                                      Alt...Screenshot of an email inbox flooded with repetitive spam emails from "admin@trustcard4you.com" with the subject line "Get Your Trust Card Today!" and a link to a suspicious website.

                                                                        [?]Chez Iceman » 🌐
                                                                        @cheziceman@mamot.fr

                                                                        De plus en plus fort, le sms de spam avec message vocal et supposée photo du colis et lien pour reprogrammer une livraison en payant

                                                                          AodeRelay boosted

                                                                          [?]Peter N. M. Hansteen » 🌐
                                                                          @pitrh@mastodon.social

                                                                          Apparently a new campaign in progress, preserved message nxdomain.no/~peter/wankstortio

                                                                          I almost missed it because the message is in the graphic nxdomain.no/~peter/wankstortio and with mail client in dark mode the diversion text was displayed black on dark grey.

                                                                          Fun fact: last hop before reaching here was a antispamcloud.com host

                                                                          Not storyworthy in itself, so linking to my 2022 piece nxdomain.no/~peter/despicable_ will do (w/links)

                                                                            [?]Stefan Bohacek » 🌐
                                                                            @stefan@stefanbohacek.online

                                                                            It looks like whoever is behind this has finally come for one of my sites. Manually blocking datacenter IPs has worked for a while, but it seems like the traffic is now coming either from residential IPs, or the IPs are just getting spoofed.

                                                                            Real conundrum. I didn't want to have to set up Cloudflare for the site, and I have to wonder how good they are at catching this anyway, but it might just come to that.

                                                                            Anyone else has been dealing with this?

                                                                              [?]Stefan Bohacek » 🌐
                                                                              @stefan@stefanbohacek.online

                                                                              Welp, now they came for my personal site.

                                                                              I already reluctantly added Cloudflare to botwiki.org. But I *really* don't want to have to do that to my site.

                                                                              This kind of blows. Thanks AI bros.

                                                                                AodeRelay boosted

                                                                                [?]― » 🌐
                                                                                @grahamperrin@mastodon.bsd.cafe

                                                                                How We’re Keeping Reddit Real and Safe in the AI Era

                                                                                redditinc.com/news/how-were-ke

                                                                                …

                                                                                ― Blocking 23 million spam views per day before they ever reach a human user.

                                                                                ― Catching ~25K net new spammy posts and comments a day.

                                                                                ― Reducing spam exposure for our users by ~20% from January to March 2026, relative to the prior three months and an additional 10–15% drop in overall spam account exposure.

                                                                                ― Revoking nearly 2M inauthentic votes per day over the last three months.

                                                                                …

                                                                                  [?]Frankie ✅ » 🌐
                                                                                  @Some_Emo_Chick@mastodon.social

                                                                                  LinkedIn, a mass grave of ghost jobs, is now becoming a dating app

                                                                                  sfgate.com/tech/article/linked

                                                                                    [?]nico » 🌐
                                                                                    @n@gotosocial.tourmentine.com

                                                                                    [?]Joerg Jaspert :debian: [he/his] » 🌐
                                                                                    @Ganneff@fulda.social

                                                                                    Ein Fediverse Server mit offener Anmeldung entspricht einem Mailserver der als offenes Relay läuft. Akzeptiert da auch keiner mehr, sollte hier auch nicht geduldet werden.

                                                                                      [?]IFTAS » 🌐
                                                                                      @iftas@mastodon.iftas.org

                                                                                      ⚠️

                                                                                      The following domains have been added to the IFTAS Abandoned/Unmanaged Domain denylist with a "Suspend" recommendation:

                                                                                      imastodon.blue

                                                                                      The following domains are now in the AUD inclusion process:

                                                                                      crazylab.online
                                                                                      mastodon.london
                                                                                      mikumikudance.cloud
                                                                                      social.ludepress.com

                                                                                      These nodes are being used by coordinated botnets, and are unresponsive to account reports.

                                                                                        [?]Michael Boelen » 🌐
                                                                                        @mboelen@mastodon.social

                                                                                        Sometimes RFCs are being marked as "historic", to ensure that people know one should not actively start using something that is being deprecated.

                                                                                        Learned that while learning that ARC (Authenticated Received Chain) is being phased out: blog.mxtoolbox.com/2026/06/05/

                                                                                          webhat boosted

                                                                                          [?]C. » 🌐
                                                                                          @cazabon@mindly.social

                                                                                          @joergi

                                                                                          "Just opt out" is also the refrain of the unsolicited commercial emailer, the "AI" content scraper, and the politicians who exempt themselves from unsolicited advertising rules.

                                                                                          It is my firm opinion that one should not *have* to opt out of this kind of activity, because it should be opt-in from the start.

                                                                                            [?]nico » 🌐
                                                                                            @n@gotosocial.tourmentine.com

                                                                                            [?]Jonathan Kamens 86 47 » 🌐
                                                                                            @jik@federate.social

                                                                                            The scam email I wrote about last week (blog.kamens.us/2026/06/11/hila) is apparently part of an ongoing campaign. They're getting better at it, but it's not clear what their end goal is.
                                                                                            Ref: blog.kamens.us/2026/06/15/scam

                                                                                              AodeRelay boosted

                                                                                              [?]iX Magazin » 🌐
                                                                                              @iX_Magazin@social.heise.de

                                                                                              Proxmox Mail Gateway 9.1 erleichtert Kampf gegen Spam und verschlüsselt Backups

                                                                                              Das neue Proxmox Mail Gateway will mehr Komfort beim Mail-Handling bieten und die Möglichkeit, ihre Backups zu verschlüsseln.

                                                                                              heise.de/news/Proxmox-Mail-Gat

                                                                                              [?]Jonathan Kamens 86 47 » 🌐
                                                                                              @jik@federate.social

                                                                                              It is quite distressing, actually, that a company as big as Intuit, which is a big targets for hackers because of its ties to people's finances, has not had the common sense to set up an enforcing DMARC policy on "intuit.co". (I'm giving them the benefit of the doubt and assuming they had the common sense to _buy_ intuit.co, though I can't confirm that since the whois information is useless.)

                                                                                              Received: from [10.88.0.3] (149.193.141.34.bc.googleusercontent.com [34.141.193.149])
	by [elided] (8.16.1/8.16.1) with ESMTP id 659KA6V64163159
	for <[elided]>; Tue, 9 Jun 2026 16:10:07 -0400
Authentication-Results: [elided]; dmarc=none (p=none dis=none) header.from=intuit.co
Authentication-Results: [elided]; spf=none smtp.helo=[10.88.0.3]
Date: Tue, 9 Jun 2026 16:10:06 -0400
Message-Id: <202606092010.659KA6V64163159@[elided]>
Content-Type: multipart/related; boundary="===============8770742687791681139=="
MIME-Version: 1.0
From: Intuit <Quickbooks@intuit.co>
To: [elided]
Subject: Payment Confirmation Inv No: #QB-784512

In the text above, "dmarc=none", "spf=none", and the domain "intuit.co" in the sender address are circled.

                                                                                              Alt...Received: from [10.88.0.3] (149.193.141.34.bc.googleusercontent.com [34.141.193.149]) by [elided] (8.16.1/8.16.1) with ESMTP id 659KA6V64163159 for <[elided]>; Tue, 9 Jun 2026 16:10:07 -0400 Authentication-Results: [elided]; dmarc=none (p=none dis=none) header.from=intuit.co Authentication-Results: [elided]; spf=none smtp.helo=[10.88.0.3] Date: Tue, 9 Jun 2026 16:10:06 -0400 Message-Id: <202606092010.659KA6V64163159@[elided]> Content-Type: multipart/related; boundary="===============8770742687791681139==" MIME-Version: 1.0 From: Intuit <Quickbooks@intuit.co> To: [elided] Subject: Payment Confirmation Inv No: #QB-784512 In the text above, "dmarc=none", "spf=none", and the domain "intuit.co" in the sender address are circled.

                                                                                                [?]Jonathan Kamens 86 47 » 🌐
                                                                                                @jik@federate.social

                                                                                                Anybody know anything about ? It's obviously a of some sort, I'm just not sure exactly what. Is it just an advertising vector, or something more complicated than that?

                                                                                                Email message: 

Subject: Jonathan: Gifted Invite Enclosed (Github Community Partnership)
From: Rachel W

Hello Jonathan

Every year we select engineers from Github and your GitHub profile https://github.com/jikamens was selected this year.

This is your official invite to a lifetime membership to devthusiast, our email newsletter for tech founders who enjoy tinkering. And because we selected your profile, it's completely free for you.

Some of what you can expect to find in our daily newsletter:

Latest in Al: Latest Al news from our inside sources at OpenAl, Anthropic and Google

VC Radar: The latest tech funding news, before they come out on Tech Crunch

Al Wars, Model Power Rankings: Today's leaderboard of the top Al models

Tinker of the Week: One useful open-source tool that is flying under the radar

P.S. Mark Zuckerberg is a reader of our newsletter!

Kindly reply with "yes" to confirm you received this message; otherwise, we'll select another profile. Once confirmed you will get your first newsletter edition!

Welcome, Team @ Devthusiast

                                                                                                Alt...Email message: Subject: Jonathan: Gifted Invite Enclosed (Github Community Partnership) From: Rachel W Hello Jonathan Every year we select engineers from Github and your GitHub profile https://github.com/jikamens was selected this year. This is your official invite to a lifetime membership to devthusiast, our email newsletter for tech founders who enjoy tinkering. And because we selected your profile, it's completely free for you. Some of what you can expect to find in our daily newsletter: Latest in Al: Latest Al news from our inside sources at OpenAl, Anthropic and Google VC Radar: The latest tech funding news, before they come out on Tech Crunch Al Wars, Model Power Rankings: Today's leaderboard of the top Al models Tinker of the Week: One useful open-source tool that is flying under the radar P.S. Mark Zuckerberg is a reader of our newsletter! Kindly reply with "yes" to confirm you received this message; otherwise, we'll select another profile. Once confirmed you will get your first newsletter edition! Welcome, Team @ Devthusiast

                                                                                                  [?]Tykayn » 🌐
                                                                                                  @tykayn@mastodon.cipherbliss.com

                                                                                                  [?]Jonathan Kamens 86 47 » 🌐
                                                                                                  @jik@federate.social

                                                                                                  I recently started occasionally using Microsoft Copilot Chat (the free version) from a new Microsoft account. Today, I received from Microsoft the email whose header and footer are shown below.
                                                                                                  Q: What's wrong with this picture?
                                                                                                  A: This email violates federal law. It is clearly a marketing email and yet there is no way to unsubscribe from receiving such emails in the future. That's a violation of the CAN-SPAM act.
                                                                                                  (1/3)

                                                                                                  Top of email from Microsoft with subject "See what a day with Copilot feels like", selling things people can use Copilot for

                                                                                                  Alt...Top of email from Microsoft with subject "See what a day with Copilot feels like", selling things people can use Copilot for

                                                                                                  Footer of email from Microsoft, typical footer for an email like this except with no unsubscribe link in it

                                                                                                  Alt...Footer of email from Microsoft, typical footer for an email like this except with no unsubscribe link in it