How to Hit a Spamtrap and Do It Right

H-E-B, a regional grocery chain in south-central Texas and northeastern Mexico, is sending bulk email confirmation requests to a pure spamtrap with an associated name that never belonged to that spamtrap. The requests appear to be confirmed opt-in (COI) requests. If they are, then the spamtrap will not be added to H-E-B’s list despite either a typo during the subscription process or a subscription forgery. (Spamtraps don’t respond to confirmation requests any more than they subscribe for bulk email.) The sending ESP is PulsePoint.

H-E-B, if this was a proper COI confirmation, please congratulate yourselves and specifically any managers who implemented the policy to confirm subscriptions. (PulsePoint, if this was your idea, H-E-B owes you their thanks and, in my never-humble-enough-opinion, a bonus.) If it was instead a welcome message to an email address that was added to the list without confirmation, be warned that somebody added a pure spamtrap to your list today. You might want to remove those email addresses, and then consider how to avoid that in the future.

Sending IP: 96.46.132.78

Spam Sample:

Actual Headers:

Received: from mail6.welcome.confirmrequest.com (mail6.welcome.confirmrequest.com [96.46.132.78])
        by <xxx> (Postfix) with ESMTP id <xxx>
        for <xxx>; Mon, 16 Jan 2012 09:xx:xx -0600 (CST)
DKIM-Signature: <xxx>
DomainKey-Signature: <xxx>
Received: by mail6.welcome.confirmrequest.com id <xxx> 
        for <xxx>; Mon, 16 Jan 2012 09:xx:xx -0600 
        (envelope-from <out-<xxx>@welcome.confirmrequest.com>)
From: H-E-B <H-E-B@welcome.confirmrequest.com>
Reply-To: Confirm Request <<xxx>@welcome.confirmrequest.com>
To: <xxx>
Message-ID: <<xxx>.JavaMail.root@welcome.confirmrequest.com>
Subject: Welcome to H-E-B Online!
MIME-Version: 1.0
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable
X-PDTA: <xxx>
list-unsubscribe: <mailto:unsub-<xxx>@welcome.confirmrequest.com>
X-PVIQ: <xxx>
Date: Mon, 16 Jan 2012 09:xx:xx -0600

Readable Email:

From: H-E-B <H-E-B@welcome.confirmrequest.com>
To: <spamtrap>
Subject: Welcome to H-E-B Online!
Reply-To: Confirm Request <<xxx>@welcome.confirmrequest.com>

This is a one time mailing. This message was not sent to you unsolicited. You are receiving this email because you requested to receive more information from the advertiser below on one of our promotional sites at 2012-01-16 09:xx:xx from the IP address xxx.xxx.xxx.xxx.

Thanks for subscribing to H-E-B emails!

<removed>

HEB.com, 646 S Main Ave.
San Antonio, TX 78204

9 Responses to How to Hit a Spamtrap and Do It Right

  1. I beg your pardon, but I’m not seeing the part that the spamtrap needs to do in order to complete the COI procedure. Did you leave it out altogether or was there none?

  2. Oops, failed to include the link. I’ll go dig the spam up and post it in a bit.

  3. So this was a bit confusing to me at first since H-E-B is not one of our clients. After some digging, we figured out the source of the email. This email was sent by a lead acquisition partner of H-E-B who is one of our clients. This firm has been a long time client and does not buy any data, so your trap address had to have been manually keyed into one of their co-reg paths by someone else for you to have received this note.

    The confirmation note that you received is passive is nature, so your address will likely be passed on to H-E-B as a lead if you do not take action on the confirmation message to unsubscribe. If you do not unsub, my guess is that you will see email hit this address from H-E-B in the future, but it will not be from PulsePoint, it will be from whoever H-E-B’s ESP is. I hope this helps.

    Damian
    VP Professional Services, PulsePoint

    • Damien, this email confirmation wasn’t sent to a real email address: it was sent to a spamtrap. I have no idea who your “lead acquisition” partner is, but the owner of this email address didn’t ask to be placed on a bulk email list of any kind. So the process broke down somewhere. I’m glad that they’re discarding the data for that day. I would also suggest that they might want to take a look at how this information is sourced.

      • I’ll definitely pass this on. Is the trap address named in a way where it is possible that someone else just choose it as a fake email address when they were filling out a form? I know that happens all the time with some simply named addresses that I have at gmail where I get welcome notes from big brands where it is very clear that someone else just happened to type in my address

    • Just my €.02 – I find that method of “verifying” addresses (opting in by default unless action is taken to opt out) vile and unacceptable. If one bothers to confirm, the least that they can do is make it proper COI.

  4. Update: Just spoke with our client and since there was a trap address manually input into one of their forms, they are going to discard all the leads from that day instead of passing onto H-E-B, so you should not be seeing anything else.

    Thanks

    Damian

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Go back to top