Sprint: MASSIVE Spam Run (Shame on you!)
U.S. telecommunications and network service provider Sprint today sent bulk email to a couple dozen spamtraps of mine and (doubtless) a great many belonging to other antispammers. Most of these email addresses have been closed for periods ranging from five years to over a decade, if they were ever live at all. (I didn’t check them all.) The ESP is Acxiom Digital, which presumably did not expect a customer with Sprint’s reputation and experience to spam a list that could have been sourced from a Millionez CD seller. 🙁
Back in December I blogged about two spam runs through email appender FreshAddress. At the time I did not realize that Fresh Address provided email append services. I assumed that it was simply updating existing email lists, albeit in a highly spammy fashion. I wonder if Sprint might have just deployed the results of that or another email append operation through Acxiom without informing Acxiom of the nature of its list.
Sending IP: 209.11.164.5
Spam Sample:
Actual Headers:
Received: from mh.nextel.m0.net (mh.nextel.m0.net [209.11.164.5])
by <xxx> (Postfix) with ESMTP id <xxx>
for <xxx>; Sat, 18 Aug 2012 12:xx:xx -0000 (UT)
DKIM-Signature: <xxx>
DomainKey-Signature: <xxx>
Received: from [192.168.xx.xx] ([192.168.xx.xx:xx] helo=<xxx>)
by <xxx> (envelope-from <sprint@sprint.delivery.net>)
(ecelerity 3.3.2.44647 r(44647)) with ESMTP
id <xxx>; Sat, 18 Aug 2012 05:xx:xx -0700
Date: Sat, 18 Aug 2012 05:xx:xx -0700 (PDT)
From: Sprint <sprint@sprint.delivery.net>
Reply-to: sprint@sprint.delivery.net
To: <xxx>
Message-ID: <xxx>
Subject: Be sure to watch your inbox for insider exclusives
Errors-to: sprint@sprint.delivery.net
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="<xxx>"
X-eid: <xxx>
X-pid: <xxx>
List-Unsubscribe: <mailto:sprint@sprint.delivery.net?subject=unsubscribe<xxx>>
Readable Email:
From: Sprint <sprint@sprint.delivery.net>
To: <spamtrap>
Subject: Be sure to watch your inbox for insider exclusives
Reply-to: sprint@sprint.delivery.net
>>To view this message with images, use the link below.
http://sprint.r.delivery.net/r/c/r?<xxx>
Here’s the scoop on what being an insider is all about.
http://sprint.r.delivery.net/r/c/r?<xxx>
***********************************************************
The first rule of being a Sprint insider…
Well, there actually aren’t any rules. Just look for great perks like these coming soon to your inbox:
<removed>
If you wish to unsubscribe from Sprint promotional emails, please use the link below.
http://sprint.p.delivery.net/m/u/nex/n.asp?<xxx>
To contact Sprint Nextel, write to:
Office of Privacy – Legal Department, Sprint Nextel
P.O. Box 4600, Reston, VA 20195.
Looks like I’m going to have a “fun” day. My apologies about this. I am on it now. The actual sending IP is .5, not .55 as is posted here. Not that it makes a difference to the issue at hand. Thanks, as always, for this information.
Oops. I’ll fix that. (The spam sample shows the correct IP — I think I typoed while putting it in the header.) Just in case this wasn’t clear from the post, I did NOT think that Acxiom had the slightest clue what Sprint was up to. I wonder if some hotshot young marketing department employee who was foolishly given access to the Sprint account decided to be a hero by uploading a guaranteed opt-in list? <wry grin>
We think we found the offending list, and no, we had no idea about this. It looks like it may have been a selection criteria issue on the client’s end, but I still don’t know more details about that. We are in discussions with them now, so we’ll get to the bottom of this shortly. I’ll update you when I know more.
To close the loop on this, the following is directly from Sprint (this is the only information I am authorized to share on this topic):
Due to a human error during a database update, a non-promotional email was inadvertently sent to 2.9 million email addresses last weekend. Sprint apologizes for any inconvenience this caused. Sprint has identified the trigger that caused the mailing and has added enhanced measures to help ensure it does not happen again.
I appreciate the update, Mark. You did your job, although your client didn’t leave you much latitude. :/
To put it mildly, however, I’m not impressed with Sprint’s handling of this situation. They’re obviously stonewalling, and that leads to the question of what they are trying to hide. My thoughts are that either they let their lawyers dictate to their PR department (a foolish and amateur mistake that I doubt a company this size would make), or they purchased a list/hired an email appender and don’t want to have to admit it in public.