Free Newsletters
InfoWorld Daily

InfoWorld
Log-in | Register
E-BUSINESS SECRETS  

Spam-proof the contact addresses you put on your site

Tips for keeping your info out of the hands of harvesters

By Brian Livingston
February 28, 2003
 

UCE (unsolicited commercial e-mail), which grew to comprise 40 percent of all e-mail last December, according to filtering service Brightmail.com, is on track to become the majority of all e-mail messages sent worldwide this year.

Free IT resource

Hear how top CIOs turn change into a competitive advantage.

Sponsored by HP

Free IT resource

Try Sun servers, workstations and storage products free for 60-days.

Sponsored by Sun Microsystems

Thousands of words have been written on this subject, and I won't repeat them here. Instead, my object today is to help you protect the customer-service e-mail addresses you post on your site from being "harvested" by UCE professionals or "spammers."

How do spam pros get addresses from your site?

1. Inexpensive "harvesting" programs search the Web looking for anything that contains an "at" sign, as all e-mail addresses do.

2. Spammers use "dictionary attacks" to find valid addresses in large companies. On average, 30 percent of corporations' e-mail server capacity -- totaling about half of all attempted e-mail connections -- is currently being consumed by robots probing for addresses, according to spam-fighter Postini.com.

Despite this exposure, it's pretty hard for an e-business to exclude e-mail addresses from its pages:

1. E-mail is usually a far cheaper means of customer support than using toll-free numbers (although many e-commerce sites use both).

2. Input forms and "contact pages" provide some defense against harvesters, but you still need to make some addresses visible for customers who might wish to contact you at a later time.

I faced these problems myself when I was developing a "contact page" for my new Web site, BriansBuzz.com. The solution I adopted allows visitors to (a) write down an address for later use, (b) click a link to create a new message on the spot, or (c) use an input form. See: http://www.BriansBuzz.com/w/contact

1. My contact address is visible in the text, but with its punctuation spelled out: person "AT" BriansBuzz "DOT" com. While most humans can easily understand this pattern, it confuses most (but not all) of today's harvesting programs. What makes this technique foolproof is that visitors are told to add "help" or "tip" to the subject line of their message. This is an instruction no robot could ever comprehend.

2. Clicking the address starts a new message in whatever e-mail program the visitor may have. My address and the required keyword automatically appear in the To and Subject lines. To keep harvesters from simply reading my address from the page's HTML, the link is driven by a script that assembles the address without it appearing in the code. Some harvesters can read scripts, but they would never devote the time to parsing such code -- it's far faster just to move on to sites where addresses are in plain view.

3. Finally, an input form takes comments from visitors who don't wish to use their own e-mail client. They may be using an Internet cafe or a friend's PC that doesn't have their preferred program. Forms such as this are relatively safe from harvesters, because robots can't decipher the code behind the form.

I'm not completely satisfied with the security of this system, but it's far better than nothing. Since my public e-mail address has been available through InfoWorld for years, I've seen how much spam comes to addresses that are visible in plain text.

Send me the techniques you've found the most reliable to "cloak" your addresses from harvesters. I'll share the best tips in a future issue, and send a gift certificate to the readers whose comments I print. Send e-mail to mailto:Brian@BriansBuzz.com, with "tip" in the subject.

- - - - - - - - - - - - - - - - - - - - - - - - - - -

LIVINGSTON'S TOP 10 NEWS PICKS O' THE WEEK

1. E-businesses indicted for selling roach clips and paraphernalia: http://www.internetnews.com@5a0.tc/449

2. Companies experience 30 Internet attacks a week on average: http://www.datamonitor.com@3n.be/831

3. New directories help you find Internet cafes as you travel: http://www.searchenginewatch.com@1c.to/c19

4. Salon.com and its 53,000 subscribers aren't going away without a fight: http://www.salon.com@e.la/1001

5. Diplomat allegedly slain by victim of the Nigerian e-mail scam: http://www.wired.com@31.dk/13e9

6. Low-cost content management systems for Web sites reviewed: http://www.imagingmagazine.com@836.as/17d1

7. XML authoring tools to handle your content are compared: http://www.imagingmagazine.com@a6r.ms/1bb9

8. The pros and cons of building your data exchange on SOAP vs. .Net: http://www.builder.com@th.gs/1fa1

9. Wow! Some HTML tricks your mother never taught you: http://www.webdevelopersjournal.com@54.vg/2389

10. Can't find kitty? Push this button and your cat beeps: http://curtiselectro.homestead.com@a2.tc/2771

- - - - - - - - - - - - - - - - - - - - - - - - - - -

WACKY WEB WEEK: SIGNS OF PREPAREDNESS

I hope you've been paying careful attention to those in charge of America 's homeland security, who've done their best to inform everyone how duct tape can protect you from a biological-weapon attack.

Now the Internet has been employed in this educational effort, with an entire Ready.gov site full of informative, Euro-style signage to help you remember important safety tips. I especially like the official placard that means, "If you're driving when you see a nuclear explosion, pull over to the side of the road." Additional and enhanced information is contributed by Yayhooray.com, which has developed fresh commentary to go with each sign. I laughed until I cried. See: http://www.yayhooray.com@n6.be/c3b1

- - - - - - - - - - - - - - - - - - - - - - - - - - -

ABOUT THE AUTHOR: Brian Livingston is publisher of http://www.BriansBuzz.com. Research Director is Vickie Stevens. Brian has published 10 books, including:

Windows Me Secrets: http://www.amazon.com@isbn.at/0764534939

Windows 2000 Secrets: http://www.amazon.com@isbn.at/0764534130

You'll receive a gift certificate good for a book, CD, or DVD of your choice if you're the first to send Brian a Top Story or Wacky Web Week he prints. Send tips to mailto:Brian@BriansBuzz.com with "tip" in the subject line.





 


 
Brian Livingston is publisher of BriansBuzz.com. Send tips to him at brian@briansbuzz.com.

  More Brian Livingston columns

 

TOP NEWS:


»  Four quick tips for choosing an IM security product
71 percent of businesses will invest in real-time messaging this year. If you're one of them, be sure to protect your enterprise

»  Forrester analysts ID hot IT jobs
Research group finds 16 IT roles with a promising future

»  Nvidia claims 10 hours of HD video on Tegra chip
The Tegra 600 and 650 can be used with hard disk drives and are designed partly for mobile Internet devices

»  Database vendors add Google's MapReduce
Greenplum and Aster Data Systems will support Google's programming technique, developed for parallel processing of large data sets across commodity hardware

»  Network management: Tips for managing costs
New technologies, changing requirements, and ongoing equipment maintenance and upgrades cost money, but there are ways to manage expenses

»  EMC targets SMBs, branch offices with new low-end storage
Celerra NX4 highlights include thin provisioning, snapshot technology for data recovery and backups, and Web-based console for management of storage volumes




MIGRATING TO VISTA
Join Windows Vista Expert, Richard Whitehead as he presents the benefits and challenges of migrating to Windows Vista. Sponsored by Novell

»  Click here to view this Webcast
  The Path to Enterprise Security
This is your comprehensive guide to Enterprise Security. In it you'll find solutions to the most pressing security threats facing you and your company. Learn the latest on insider threats and how to effectively minimize risk within your organization. Sponsored by Nokia

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 

FIND PRODUCTS AND COMPANIES
» COMPLETE PRODUCT GUIDE



TECHNOLOGY INDEX
• Applications
• Application Development
• Security
• Networking
• Wireless
• Platforms
• Hardware
• Data Management
• Storage
• Web Services
• Business
• Telecom
• Professional Services
• Standards

TECH WATCH 


What's the 411 on GOOG-411?
Just as Google has become synonymous with "performing a Web search," 411 is understood to mean "information" -- as in "what's the 411?" I was thus surprised to discover, from a billboard, no less, that the king of search is taking on the ...

Apple HTML source reveals 'iPhone Extreme'
"This one's a stretch..." reports AppleInsider. Um, yeah. Reporting on HTML code sightings of product names could be called a stretch, but iPhone Extreme has a ring to it. Now, that sounds like the product Apple should have released first, rather ...

COLUMNISTS

Unified under law
Ephraim Schwartz's Column and Blog (InfoWorld) - In the litigious world we live in, deploying a unified communications platform in your enterprise could...
» MORE COLUMNISTS

MORE INFOWORLD BLOGS


Open Sources 
Product Management
When I joined MySQL four years ago, there was quite a lot of debate about product management. We didn't actually have ...

Zero Day 
Botnet herders tending smaller flocks
New research backs up the theory that botnet operators are keeping their networks smaller in a continued effort to keep ...



• Advice Line
• Database Underground
• The Deep End
• Enterprise Mac
• Geeks in Paradise
• Grid Meter
• The Gripe Line
• InfoWorld Daily
• Inside IT
• IT Troubleshooter
• ITXtreme
• Open Sources
• ProdBlog
• Real World SOA
• Reality Check
• Security Adviser
• SMB IT
• The Storage Network
• Tech Watch
• Virtualization Report
• Zero Day

ADVERTISEMENT


RESOURCE CENTERadvertisement 

GOVERNMENT IT & POLICY
'If you don't go after the network, you're never going to stop these guys. Never.'
From the State Department, All the News for Inquiring Minds
TechPresident, the Internet Citizenry's New Consensus Taker



Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist