#spamd

Peter N. M. Hansteenpitrh
2026-01-18

The latest "Lazy reading" by Dragonfly Digest @dragonflydigest dragonflydigest.com/ has "Eighteen years of Greytrapping" nxdomain.no/~peter/eighteen_ye featured. Later this year it will be nineteen years :) (and updates will come)

Peter N. M. Hansteenpitrh
2026-01-03

Heh. Looks like the tracked version of Why 451 is Good for You - Greylisting Perspectives From the Early Noughties nxdomain.no/~peter/why_451_is_ (tracked bsdly.blogspot.com/2025/12/why) hit hackernews: news.ycombinator.com/item?id=4

No, I willl not respond to those comments either :D

Peter N. M. Hansteenpitrh
2026-01-01

The update you have been waiting for:

"Eighteen Years of Greytrapping - Is the Weirdness Finally Paying Off?" nxdomain.no/~peter/eighteen_ye (tracked bsdly.blogspot.com/2025/08/eig)

now has the complete 2025 data in place.

Peter N. M. Hansteenpitrh
2025-12-24

Possibly not blogworthy, but: One puzzling side effect of running greytrapping (as chronicled in nxdomain.no/~peter/eighteen_ye) is seeing the uptick in password guessing using even the obviously generated gibberish local parts, and the sheer volume of tries (see nxdomain.no/~peter/should_i_st and links therein).

Peter N. M. Hansteenpitrh
2025-09-30

Hm. log entries like

Sep 30 00:54:41 skapet spamd[83364]: (GREY) 171.4.7.241: <maillist@mailserver.com> -> <somethingreallystupid@bsdly.net>
Sep 30 00:54:41 skapet spamd[83004]: new entry 171.4.7.241 from <maillist@mailserver.com> to <somethingreallystupid@bsdly.net>, helo ns3000605.ip-37-59-46.eu

have me suspect they are actually reading my stuff such as nxdomain.no/~peter/eighteen_ye

Peter N. M. Hansteenpitrh
2025-09-24

And yes of course, that became a fresh spamtrap, number 8205067 or thereabouts. see the old favorite nxdomain.no/~peter/eighteen_ye

Peter N. M. Hansteenpitrh
2025-09-15

glancing at the log I see attempts like

Sep 15 14:53:06 skapet spamd[85002]: (GREY) 103.120.44.85: <cotompryor@bsdly.net> -> <cotompryor@bsdly.net>
Sep 15 14:53:06 skapet spamd[70382]: Trapping 103.120.44.85 for tuple 103.120.44.85 [103.120.44.85] <cotompryor@bsdly.net> <cotompryor@bsdly.net>

I suspect another campaign but won't know for sure until something actually inboxes (unlikely) or enough shows up in the log itself. In the meantime, nxdomain.no/~peter/despicable_

Peter N. M. Hansteenpitrh
2025-09-10
Peter N. M. Hansteenpitrh
2025-09-06

Have you been wondering why the list of imaginary friends at nxdomain.no/~peter/traplist.sh has been expanding quicker than usual this week?

It's because I found another batch of old logs that are now getting the more thorough treatment (also see nxdomain.no/~peter/eighteen_ye or tracked bsdly.blogspot.com/2025/08/eig)

Peter N. M. Hansteenpitrh
2025-08-22
Peter N. M. Hansteenpitrh
2025-08-21

Hm. It looks like my publishing the "Eighteen years of greytrapping ..." retrospective nxdomain.no/~peter/eighteen_ye (bsdly.blogspot.com/2025/08/eig) has generated an uptick in digital archaeology. People are fetching the archived lists at a surprising rate.

Peter N. M. Hansteenpitrh
2025-08-17

Aug 17 09:38:58 skapet spamd[36107]: (GREY) 141.98.10.53: <test@bsdly.net> -> <glinksbiz2025@hotmail.com>
Aug 17 09:38:58 skapet spamd[30363]: Trapping 141.98.10.53 for tuple 141.98.10.53 host-141-98-10-.domain <test@bsdly.net> <glinksbiz2025@hotmail.com>
Aug 17 09:38:58 skapet spamd[30363]: new greytrap entry 141.98.10.53 from <test@bsdly.net> to <glinksbiz2025@hotmail.com>, helo host-141-98-10-.domain

Yes, nxdomain.no/~peter/eighteen_ye

Peter N. M. Hansteenpitrh
2025-08-12
Peter N. M. Hansteenpitrh
2025-08-02

In 2013 I wrote up "Maintaining A Publicly Available Blacklist - Mechanisms And Principles" (also bsdly.blogspot.com/2013/04/mai) . TL;DR: blocklisting is a kind of public shaming, be sure your process is verifiable and transparent.

Minor edits today, links to resources and inside.

Peter N. M. Hansteenpitrh
2025-07-25

Following up on previous, the LinkedIn discussion revealed that there are people who have not heard about greylisting.

So here is my 2012 piece with updates, "In The Name Of Sane Email: Setting Up OpenBSD's spamd(8) With Secondary MXes In Play - A Full Recipe" nxdomain.no/~peter/in_the_name

.conf

Peter N. M. Hansteenpitrh
2025-07-25

"Oh yes, you signed up for this. You did. Honest." nxdomain.no/~peter/oh_yes_you_ A linkedin post (linked within) reminded me of this post (from 2009), now added here, almost pristine

Peter N. M. Hansteenpitrh
2025-06-24

September 7, 2022 the 300,000th spamtrap was added to our list of imaginary friends, see "The Things Spammers Believe - A Tale of 300,000 Imaginary Friends" nxdomain.no/~peter/spammers_be.

Today, the number at at nxdomain.no/~peter/traplist.sh rolled past 5,000,000 (yes, five million).

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst