King Ice: Jewelry for the Iced-Out Spamtrap

King Ice, an online retailer of hip-hop jewelry for men, today sent a bulk email advertisement to an email address that has never heard from it before, and that was closed in 2004. The email makes no claim to opt-in, and provides no postal address or contact information for the advertiser that is visible in the text portion of the email. (Most of the email consists of remotely-loaded graphics.) The ESP is Campaigner.

Why is King Ice suddenly emailing an email address that has never heard from it before? The domain kingice.com was first registered in 2006, two years after this spamtrap could last have been a legitimate email address, so this is not bulk email sent to a fallow list. A typoed subscription is (in my opinion) unlikely in this case, but possible. I really think that King Ice probably purchased a list, however, although I can’t prove it.

Sending IP: 216.24.225.26

Spam Sample:

Actual Headers:

Received: from mta26.cp20.com (mta26.cp20.com [216.24.225.26])
        by <xxx> (Postfix) with ESMTP id <xxx>
        for <xxx>; Sat, 19 May 2012 14:xx:xx -0000 (UT)
Received: by mta26.cp20.com id <xxx> for <xxx>; Sat, 19 May 2012 14:xx:xx -0000 
        (envelope-from <KingIce_com_<xxx>@cp20.com>)
Message-ID: <<xxx>@backend.cp20.com>
Date: Sat, 19 May 2012 14:xx:xx -0000
X-Campaign: <xxx>
List-Unsubscribe: <mailto:KingIce_com_<xxx>@cp20.com?subject=unsubscribe>
Bounces-To: KingIce_com_<xxx>@cp20.com
Errors-To: KingIce_com_<xxx>@cp20.com
Reply-To: KingIce_com_<xxx>@cp20.com
To: <xxx>
From: "KingIce.com" <sales@kingice.com>
Subject: Get 15% Off Your Purchase & Browse Our Gold Collection
MIME-Version: 1.0
Content-Type: text/html

Readable Email:

From: KingIce.com <sales@kingice.com>
To: <spamtrap>
Subject: Get 15% Off Your Purchase & Browse Our Gold Collection
Reply-To: KingIce_com_<xxx>@cp20.com

<removed>

Giveaways, contests, exculsive discounts and more.

<removed>

You are subscribed to this mailing list as <xxx>. Please click here to modify your message preferences or to unsubscribe from any future mailings. We will respect all unsubscribe requests.

4 Responses to King Ice: Jewelry for the Iced-Out Spamtrap

  1. This sender has been with us for a while and has never run into a problem until now. We’ve asked about their practices and believe they are trying to do the right thing.

    Is this the first time they’ve hit this trap? If so, the numbers involved don’t suggest a purchased list.

    Thanks,
    Dave

  2. I agree that having a single spamtrap hit proves nothing except that somebody made a mistake. However, this email does not anywhere in its text indicate that the sender even claims that it was opt-in. Having an email address that has not been live since 2004 suddenly start receiving email from a company that has never sent email to it before, combined with no indication of opt-in, suggests to me that something may not be right.

    If the customer is purchasing lists or obtaining email addresses that did not opt-in and mailing those email addresses, it would seem to be in your customer’s best interest to fix the problems now instead of waiting til the customer’s email is blocked somewhere important. That’s why I reported it.

  3. My apologies, I believe we crossed a wire. I’m asking so that I can determine the size of the delta involved. (So that we can deal with the issue now.)

    We’ve spoken with the client and they swear up and down there is permission, albeit single opt-in for some (for the moment) and actual purchases for most.

    This sender has been with us just under 1 year. They have no history of [excessive] complaints, good interaction and an appearance of organic list growth. Unless they are buying lists in 500-address increments, all indicators suggest this sender isn’t acting in bad faith.

    Is it possible these guys are the victim of a bad or malicious signup? Because if not, the outcome will be very different.

    • I can’t absolutely rule out that somebody might have done a malicious subscription, but I strongly doubt it. A typo is in my opinion considerably more likely. The reason is that my spamtraps are for the most part closely held; their identities are secret and I go to some effort to keep it that way. This particular spamtrap has no visible connection to me.

      It also isn’t the sort of spamtrap that a simpleminded malicious subscriber would choose to type into somebody’s web form. It looks like an ordinary email address. It isn’t an obvious typosquat of a popular name or domain, and it doesn’t contain an insulting word or acronym. (No “stop.spamming.me@” or the like.) If a mischiefmaker wanted to make trouble for your customer, one of my real email addresses, or an email address of another antispammer, would meet the need much better.

      A malicious attacker *could*, of course, obtain a known dirty list and “script it’ so that it is fed automatically into your customer’s web form. That sort of attack is usually the work not of a rabid nutcase antispammer, but a commercial rival or angry former customer. If this is the case, I would expect that you will see a spike in spam reports or complaints. If you don’t, I don’t think that deliberate seeding of a non-confirming web form is likely.

      Often I post a spam report when a company hits just one spamtrap, if there are aspects of the spamtrap or situation that look interesting to me. I don’t expect an ESP to simply treat my single spamtrap report as conclusive proof that a customer is doing something terrible. It’s a data point. I want you to make a note, and then see if anything else turns up that might combine with that data point to indicate that there’s a problem.

      If nothing turns up, your customer might just be the victim of a user who typoed an email address. If other spam complaints come in, or you find other reasons to suspect the legitimacy of your customer’s list, then you can act.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Go back to top