PrintCountry: Still Spamming Purchased Lists :/

A few weeks ago I blogged about a spamtrap hit by PrintCountry, an online printer ink and printing supplies seller. PrintCountry is still sending bulk email to the same long-closed email address, and is now hitting an additional email address that as far as I know has never existed at all. The email states that both email addresses was added to the system a short time ago. This is not possible; neither email address has been live since 2006, so there was nobody who could have subscribed that email address to any list in the past few weeks.

It strains the limits of my credulity to believe that PrintCountry could have gotten two such spamtraps on its list because of unverified subscriptions and typos, the usual sometimes-true excuse for single spamtrap hits. At this point, I am convinced that PrintCountry purchased a list. The ESP is BlueHornet, a division of Digital River.

BlueHornet, if you’re reading this, you need to do something about your customer’s spamming. The customer might not realize what they are doing. They might have purchased a list believing it to be opt-in; many list sellers claim that their lists are opt-in. Some of these lists were opt-in for a specific product or company, but (of course) people do not opt-in to lists whose only criteria for use is that somebody had the money to purchase the list! In other words, in the real world there is no such thing as a list for sale that is opt-in for a purchaser who sends bulk email to it. That bulk email is opt-out by definition, and thus by definition is spam.

Sending IP: 216.54.194.20

Spam Sample:

Actual Headers:

Received: from smtp.yerevan.bluehornet.com (smtp.yerevan.bluehornet.com [216.54.194.20])
        by <xxx> (Postfix) with ESMTP id <xxx>
        for <xxx>; Fri,  4 Nov 2011 08:xx:xx -0500 (CDT)
X-MSFBL: <xxx>
DKIM-Signature: <xxx>
Received: from [10.64.xx.xx] ([10.64.xx.xx:xx] helo=<xxx>)
        by <xxx> (envelope-from <xxx>)
        (ecelerity 3.0.28.38595 r(<xxx>)) with ESMTP
        id <xxx>; Fri, 04 Nov 2011 06:xx:xx -0700
Message-ID: <xxx>
Date: Fri, 04 Nov 2011 06:xx:xx -0700
From: "Christy B - PrintCountry.com" <christyb@printcountry.com>
Reply-To: christyb@printcountry.com
To: <xxx>
X-Outgoing: echo
Subject: Get Free Shipping on Your Order!
List-Unsubscribe: <mailto:unsub-<xxx>@listunsub.bluehornet.com>
Mime-Version: 1.0
Content-Type: multipart/alternative;
    boundary="--<xxx>"

Readable Email:

From: <xxx> – PrintCountry.com <<xxx>@printcountry.com>
To: <spamtrap>
Subject: Get Free Shipping on Your Order!
Reply-To: <xxx>@printcountry.com

===========================================
Get Free Shipping on Orders over $50
===========================================

Start Shopping Now:

http://echo3.bluehornet.com/ct/<xxx>

*Free shipping applies on the U.S. orders over $50. For orders including toners and/or weighing more than 3 pounds with a long distance ZIP code, free shipping does not apply.

Need help with this promotion? Call PrintCountry on 1-866-775-2697.

Copyright © 2011 PrintCountry
www.printcountry.com

This message was intended for: <xxx>
You were added to the system October 5, 2011. For more information
please follow the URL below:
http://echo3.bluehornet.com/subscribe/source.htm?<xxx>

Follow the URL below to update your preferences or opt-out:
http://echo3.bluehornet.com/phase2/survey1/survey.htm?<xxx>

15 Responses to PrintCountry: Still Spamming Purchased Lists :/

  1. Two spamtrap hits is the minimum required for an SBL listing. Usually we wait to see considerably more, of course.

  2. Hi Spamtrap,

    This is Can from Printcountry.com.

    I saw your other posts and based on the Subject lines that email must belong to a customer. If you could provide me the email address I would be more than happy to tell you when and where exactly we got that email address.

    We have never purchased a mailing list. In fact all emails must be double opt-in in order to send out a mass email from Bluehornet.

    I’ll be waiting for you reply.

  3. SpamBouncer,

    As I wrote in my previous message, I work for PrintCountry.com. We are not ESP as you can simply figure out by visiting our website. I don’t understand what you mean by own behalf.

    If you could provide me the email address, I will be happy to figure out this issue.

    Just accusing us with spamming does not help to anybody!

    Best Regards,
    Can

    • I did look. Your previous comment, however, seemed to contradict what the web site showed when I checked it; you appeared to be asking for information to help a customer. It appears that I misunderstood, and that you were asking for the spamtrap address.

      Antispammers and other people who keep spamtraps don’t normally provide spamtrap email addresses to anybody. There are multiple reasons, which I’ve discussed at various points on this blog. The two big ones are:

      • Malicious subscriptions. If the identity of a spamtrap becomes known, then business competitors and other malicious individuals (including what I call rabid nutcase antispammers) can deliberately subscribe these spamtraps to your lists. If you (like too many businesses) don’t confirm subscriptions, then you’ll add the spamtraps to your list. Like most serious antispammers, I don’t want my spamtraps used by malicious individuals to cause trouble, so I’m careful not to expose them.

      • Listwashing. Just having you remove the spamtrap from your list doesn’t fix the problem. The problem isn’t the spamtrap itself — it’s that you sent unsolicited bulk email to any email address. Until the underlying problem that got a spamtrap and (presumably) other non-opted-in email addresses on your list is fixed, you will continue to send spam.

      The spamtraps in question does not belong to your customers. Neither of them has belonged to a real person since 2006. During the interim, both were completely disabled and rejected all email at SMTP time with a 500-level SMTP rejection for periods of from eighteen months to three years in the case of these two email addresses. If you recently reactivated a list that was over five years old and have not contacted for at least that length of time, then maybe they belonged to customers all those years ago, but they do not now.

      Otherwise, you obtained these email addresses either through forged subscriptions, which is odd given that there are two of them, or because somebody, somewhere, purchased a list and added it to your existing email addresses. Needless to say, you might not have known about it. I’d suggest that you do some more research because, if PrintCountry.com is hitting my spamtraps, they’re inevitably hitting other email addresses that also do not belong to customers and also did not ask for that email.

      • Hello,

        I work with cancelik, and I am the one manages the store’s customer database.
        Another co-worker manages the mailing lists on BlueHornet, but I do know that she gets the list from me.

        I assure you that we do not buy email lists. Its pros and cons have been discussed in the past whenever we see such activities done by our competitors, but we chose not to do the same. As a person who deals with spam on a daily basis I not only find it annoying and unethical, but also not feasible (the conversion rate for such lists tend to be very low according to statistics).

        We could have affiliates who might be spamming to increase their revenues, but by looking at the email headers you posted this is very unlikely. However we do retain customers’ account for a long time even before 2006. Sometimes, we do send promotional emails to win the customers back who haven’t been active for a long time. Some of those messages are delivered and opened but some of them bounce back. When enough bounce back occurs, Blue Hornet automatically removes the address in question from the list.

        With all the information available here I can only guess that, for very old email addresses, not enough bounce backs occur because of the low frequency of promotional emails to these addresses. However, if you receive the email OK, and do not take any action (e.g. clicking on unsubscribe link you) you may keep receiving emails naturally.

        The reason why cancelik asked for the specific email address is so that we can track the source. If you can email me just one email address personally I can check and see if it was one of our customers, or service subscribers. If it’s not in our customer database, but in BlueHornet list somehow, then you are right, we do have a problem that we need to investigate. Thank you for your help.

        • I’m sorry, but I can’t divulge spamtraps. The only time I would do so intentionally (not in error) is in response to a subpoena, and then that spamtrap would need to be shut down. This isn’t personal; it’s policy.

          Just how infrequently do you send promotional emails? Also, just how many bounces does it take with a brand new email address before it is removed, because one of these spamtraps is a pure spamtrap. It never belonged to a real person at all.

          • We do have weekly, monthly, and seasonal emails. The one sent on October 5th seems to be the weekly regular email to our customers.

          • We will double-check this with BH, and make sure the addresses get removed after 2 (at most) bounce backs.

          • Even seasonal emails should have bounced sufficiently after three years to be removed from your list. And even seasonal emails should have bounced immediately and repeatedly with the pure spamtrap. I’d take a hard look at your bounce processing.

  4. Oops, it’s worse than I thought. One of those spamtrap email addresses wasn’t in time out; it didn’t exist. At all. Ever. :/ The domains for these email addresses are different, and neither of them appears a likely candidate for a typo in a web form.

    • To clarify, are you saying you have received emails from us at spam trap addresses such as

      somename1@somedomain.com
      somename2@anotherdomain.com

      where ‘somedomain’ and ‘anotherdomain’ are nowhere close to a legitimate domain names?

      The only reason I can think of is that someone must have entered those (twice) deliberately during a purchase when creating an account.

      • No. I’m saying that I have received emails from PrintCountry.com to spamtrap addresses that are legitimate domains, but different from one another and not easily or commonly typoed domains. There has been some controversy over use of “typo” domains, domains with names that are common typos of widely-used legitimate domains, in the antispam world, so I made the point that these spamtrap email addresses were not at domains of that type. There is nothing about either email address that should have looked strange or abnormal.

        • I must have wrongly worded, my apologies. That’s exactly what I meant.

          It still doesn’t change the fact that these emails must have been entered by some visitor on our web site any time since 2004. It’s against PrintCountry’s policy to buy email lists.

          BlueHornet, if you’re reading this, you need to do something about your customer’s spamming.

          When Blue Hornet receives a complaint, they tell us with a proof provided by the recipient (copy of the email message, including the target email address). We then find the source and the explanation (100% of the time, it’s a customer or a subscriber, or a friend referred by a customer) with the exact date/time of the transaction. And this happens very rarely.

          This part was so far about defending my company against false accusations listed on this page. As for the technical part…

          Since there exists black lists that rely on spam traps, which now I believe not 100% accurate, we will consider policy changes on BlueHornet which reduce the retry time for hard-bounced emails. If you are telling the truth, this will not only decrease the number of unnecessary emails sent, it will also increase the deliverability.

          Thank you for your help, and explanations. I just want to be clear that we are with you, not against you.

          • I figured you were trying to get as much information as you could, and I’m happy to give you what I can divulge. Something to keep in mind: we antispammers report spam. We don’t read minds. What I know is that these emails have been sent to my spamtraps. What I don’t know, and can’t know, is what led that to happen. I can guess, and I can look at probabilities, that’s all. There are a lot more companies that send spam out there because of mistakes (small and big) than because of an intent to spam.

            The problem from my point of view is that recognizing this doesn’t stop the spam. Teh good part from my point of view is that recognizing this also points to a solution — the ESPs (mostly) and the companies (largely) don’t want to spam and can use this information to stop it. That’s what I’m trying to do on this blog. 🙂

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Go back to top