(Resolved): Revolutionary Lifestyle Shopping for… Spamtraps
This issue has been resolved. The blog remains posted because blogs shouldn’t disappear, to make sure that Google and other search engines and archives get the update, and in hopes that other people can learn something from it and the comments. 🙂
Elephanti, a web portal for shoppers geared towards those who use mobile apps, today for the first time sent advertising emails to two spamtraps. Neither spamtrap had ever heard from Elephanti before, and both were closed in 2008. The ESP is Sendgrid.
The Elephanti web site is apparently still in beta, which suggests that this is a startup. That would account for the ignorance Elephanti shows about the proper way to send bulk email. First, that a company “built a unique business” is not a reason to send them bulk email. The ONLY legitimate reason to send bulk email to anybody is because they asked you to send it to them. Second, sending bulk email from <noreply@elephanti.com> was also a bad move. It’s rude to send email to people whom you do not want to hear from via email.
Sendgrid, I suspect that somebody at Elephanti or a marketing company that they hired purchased a list. You know how to educate customers about bulk email; please do so with these customers. They obviously can use the help. 🙂
Sending IP: 208.115.235.233
Spam Sample:
Actual Headers:
Received: from o1.mailer.sendible.com (o1.mailer.sendible.com [208.115.235.233])
by <xxx> (Postfix) with SMTP id <xxx>
for <xxx>; Fri, 1 Jun 2012 12:xx:xx -0000 (UT)
DKIM-Signature: <xxx>
Received: by 10.12.xx.xx with SMTP id <xxx>
Fri, 01 Jun 2012 12:xx:xx -0000
Received: from sendible.com (unknown [10.9.xx.xx])
by mi16 (SG) with ESMTP id <xxx>
for <xxx>; Fri, 01 Jun 2012 07:xx:xx -0500 (CST)
Received: from mail pickup service by sendible.com with Microsoft SMTPSVC;
Fri, 1 Jun 2012 12:xx:xx +0000
From: Elephanti <noreply@elephanti.com>
MIME-Version: 1.0
To: <xxx>
Reply-To: Elephanti <noreply@elephanti.com>
Date: 1 Jun 2012 12:xx:xx +0000
Subject: =?utf-8?B?UmVhY2ggeW91ciBjdXN0b21lcnMgbGlrZSBuZXZlciBiZWZvcmU=?=
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: base64
Message-ID: <Sendible-<xxx>@sendible.com>
X-OriginalArrivalTime: <xxx>
X-Sendgrid-EID: <xxx>
X-Sendgrid-ID: <xxx>
Readable Email:
From: Elephanti <noreply@elephanti.com>
To: <spamtrap>
Subject: Reach your customers like never before
Reply-To: Elephanti <noreply@elephanti.com>
You’re reading this because you’ve built a unique business, and we have a game-changing way to help customers find it, whether they’re across town or across the street.
We are Elephanti, a growing online and mobile network that’s revolutionizing how you connect with shoppers. When you create a merchant profile with Elephanti, you can:
- Enjoy a virtual storefront targeted at shoppers interested in your products
- Offer loyalty rewards and special offers to your best customers
- Socially engage with your customers and keep them informed of latest updates.
<removed>
___
This message was intended for <xxx>. If you do not wish to receive this type of email in the future, please unsubscribe from this list.
http://tracker.sendible.com/messages/<xxx>
Hello,
Ryan Harris with SendGrid here. I will be reaching out to the client. They sender is: http://sendible.com/. They appear to be sending on behalf of several of their own clients.
I will make sure this sender is is properly vetting their clients. Thank you for the article and sorry for the inconvenience.
Ryan Harris
Lead Abuse Engineer
I didn’t realize that you had ESP or marketer clients. 🙂 I hope that your customer understands the rules, and can educate their customer. (I know Sendgrid; I don’t know Sendible.) Thanks for the update!
Today Elephanti hit the same spamtraps with more purely advertising emails. :/ There is no indication that Sendible has done anything to rein in their customer. Sendgrid, please lean on your customer about this: if Elephanti is hitting two of my spamtraps, they are probably hitting more at other places. :/
I have stopped traffic from this account as they have yet to respond to my warning I sent to them.
Ryan
That should stop the spam, in any event. I hope they’ve got the sense to listen when they do get in contact.
Just wanted to post to give some closure on this. Sendible had claimed to stop sending emails on behalf of this client. I haven’t seen any recent postings in regards to Sendible sending to spam traps.
Ryan
I have not seen any additional spam from this spammer so far, so I expect that Sendible has done as they said that they would. I’m not at all confident that Elephanti won’t spam my spamtraps again, but expect that if they do it will at least be from somewhere else. Thanks much!
Hi
Gavin Hammar here, CEO of Sendible. All our customers have to agree to not using bought lists. They are forced to agree to these terms before registering with us.
We have now suspended this user’s account and have reached out to them. We do actively monitor our users’ lists and this one seems to have slipped through.
We’ll keep you updated. Thanks for reporting this.
Welcome to the MainSleaze blog, Gavin. 🙂 And good luck educating your clients. I hope they are educable. <wry grin>
Hi all,
This is Shawn from Elephanti.
Firstly I’d like to apologize for any inconvenience caused.
We were made aware of our 3rd party email campaigns being flagged as spam and immediately halted these campaigns and terminated our working relationship with the database vendor. Since that time, we have taken considerable corrective measures to ensure that e-mails that we send out are only sent to list subscribers and not at random.
As you mentioned earlier, we are a startup and when those e-mailers were sent out, we were in the midst of a test phase and made the mistake of choosing the wrong vendor. I thank you for bringing this adverse choice to light.
At present, we’ve taken the necessary steps to ensure that this mistake is not, and will not, be repeated and as such, I would like to kindly request that you remove this blog entry.
Again, thank you for bringing this to light and for assisting in our making the right moves forward.
Shawn Dass
Manager, Planning & Operations
Elephanti
Good to hear from you, Shawn!
Your description certainly sounds like what I saw. Unlike so many startups and not-so-startups (Sprint), Elephanti appears to have learned from experience. I appreciate the candor of your statement. People and companies make mistakes sometimes. One mistake, even a big one, does not necessarily (or usually) mean a permanent pattern.
For the record (since you know it, but others might not), spam from Elephanti has stopped cold. The spams reported in this blog were sent in early June. It is now late August, two and a half months later, and I have not seen any spams from Elephanti since then, or heard from anybody who has.
We don’t delete blog entries from the MainSleaze blog, even when a spam incident is satisfactorily resolved. Blogs aren’t designed to work that way, and we don’t want to loose the value of seeing how old incidents worked out. What we do when a company that spammed takes responsibility and does what is necessary to fix the problems that led to the spam (as you have) is to mark the blog “resolved”. I will do that with this blog. Anybody who Googles your name and finds the blog will also find that it has been resolved. If they read the blog and comments, they will see your post and this.
I’m confident that anybody with an IQ above room temperature and more patience than a two-year-old child won’t hold an early mistake against you or your company.
SpamBouncer,
As mentioned, we’re a startup. The mistake was made during a testing phase with the unfortunate choosing of the wrong database vendor and, with your help in bringing this to light, we resolved this and set in place some policies to ensure we avoid a similar occurence.
I acknowledge your practice of leaving blog entries in place so people in the same space would be able to read and learn from them. However, we launch our product and service soon. We expect people to be searching for the product on all search engines and even though there would be people who read further into this entry and understand that this matter has been resolved, there may be some people who would take this entry at surface value and move right past looking at who we are, thus penalizing us for a mistake we made during a test phase, resolved and set standards to avoid in future, all before we’ve even launched.
Taking into consideration your policy that people who make similar mistakes may learn from this entry, may I then request that instead of completely removing this post, that you kindly remove or rename our company name? This small change would allow for readers of this blog to continue to benefit from this entry while not penalizing us for an action that we have both resolved and set standards to avoid any similar occurence of in future.
I seek your understanding in this and hope you respond to my request favorably.
Thank you.
Shawn
Actually, you’ll notice that we did in the title of the blog, which is what Google prioritizes in searches. I can also remove the company name in the tags, and will do that. We won’t modify the spam sample, so we can’t remove your company name entirely, but the other measures should take the heat off.
SpamBouncer,
Most appreciated.
Shawn