Site icon josh.com

Surprising Spam

Have you ever wondered how a SPAM sender got your email address?

For the past 15 years, I’ve used a different email address every time I filled out a webform . This way, whenever I get a SPAM I can look at the address the SPAM was sent to and know how the sender found out about me.

It is interesting to see where the leaks come up. Here is a short list of some of the people who (willingly or unwillingly) ratted me out to spammers….

23andme.com (11/3/2019)
2BRIGHTSPARKS.COM
AA.COM (added 2/19/2021)
abundancethebook.com (added 4/11/2018)
ascendantny.com (added 5/15/2019)
AUDIOGO.COM (added 5/6/2015)
BARCODE-US.COM
Bitly.com (11/28/2018)
BMWMOA.ORG
boldbook.com (added 4/11/2018)
brooklynbridgeventures.com (from newsletter, added 5/23/2021)
BUYERZONE.COM
cafepress.com (9/6/2023)
canva.com (added 3/24/2020)
CENTREOFTHECELL.ORG
CHECKS.COM
dailymotion.com (added 6/12/2019)*
DERMSTORE.COM (1/18/2013)
DIRECTV.COM
DROPBOX.COM
DYNACNC.COM
E-COUNTERS.COM (1/9/2014)
easyeda.com (6/16/2024)
ecobici.mx (11/26/2025)
ELMSOFT.COM (11/5/2019)
encryptomatic.com (10/19/10)
ENDLESSPOOLS.COM
ESUPPORT.COM (4/2/2019)
FLUKE.COM
FOSCAM.US (added 4/28/2015)
gardeners.com (4/10/2019)
FRIENDSTER.COM (added 6/23/2014)
HELLODIRECT.COM (added 3/4/2019)
HOMEDEPOT.COM
INTELIUS.COM
INFOQ.COM (3/1/2016)
IRR.COM
LearnOutLoud.com (added 11/24/2022)
LAPLINK.COM
LENS.COM (5/10/2019)
LensCrafters.com (12/2/2023)
LEXUSOFENGLEWOOD.COM (added 4/25/2014)
LIVEMODERN.COM
LOGANTURNPIKEMILL.COM (added 2/29/2014)
LOGMEIN.COM
LIFELOCK.COM
LPNY.ORG (added 11/3/2022)
MANDARINHOTEL.COM
MAXIMHQ.COM
MASALAMAC.COM (added 11/7/2022 - restaurant that went out of business long ago)
MORFIK.COM
MYSPACE.COM (3/19/2016)
NYTIMES.COM
NYWATERWAY.COM
PLOTLY.COM (added 4/5/2022 [8 year sleeper!])
RAYANDTERRY.COM (7/30/2015)
REVERSEGENIE.COM
ROKU.COM
SECONDSTAGETHEATER.COM
SEETHROUGHMIRRORS.COM (11/4/2014)
SHAPEWAYS.COM
SHAPESHOT.COM (12/27/2015)
SHEIN.COM (10/5/2019)
SIDEFX.COM
SIMPLE.COM (3/8/2016)
simplyasseenontv.com (added 12/30/2020 [11 year sleeper!])
SMARTBRIDGES.COM
SMITHMICRO.COM (added 4/9/2014)
SOFTWIRED-INC.COM
SOLARWINDS.COM
SPEAKEASY.NET
solidprofessor.com (added 10/14/2020)
SPORTYS.COM
STARBOOTH.COM (added 9/17/2020)
steelseries.com (added 3/25/2022 [7 year sleeper!])
SUPERMAGNETMAN.NET (added 2/2/2015)
TICKETMASTER.COM
tigrlock.com (added 2/24/2026)
TRANSCEND.COM
TruthFinder.com (added 10/5/2023)
TUMBLR.COM (12/31/2018)
VAADIN.COM (2/28/2023)
WALLHOGS.COM
webzinc.com (added 11/7/2010)
WEWORK.COM (added 10/20/2020)
WSJ.COM (added 2/8/2014)
ZENBE.COM
ZEVIA.COM

If you’ve ever given your email address to any of these websites, then it is likely that you can thank them for some of the spams you now get every day. I am talking about hardcore SPAM like offers for Viagra, porn, or African money transfers and not just unwanted emails that might be semi-related to the website that you originally gave your address to.

Some of these sites might intentionally sell or give their email lists to SPAMers, but I suspect that many had their lists hacked or got a virus on a machine that has access to their list. Either way, it makes it hard to trust the company that let it happen.

I typically kill a compromised address as soon as it starts getting spam, but sometimes I want to keep getting the real emails from the original website so I’ll go in and update my account with a brand new, unique email address. Sadly, I often soon start getting spams on the new email address, indicating that the leak was not a one-time event.

BTW, I also use a unique hash for the return address on every email I send out. This lets me know instantly whenever anyone I know gets a virus, uploads their contacts to a website that then sends out splash emails, or falls for a Facebook/GMAIL phishing scam. It happens way too often.

*I signed up for updates on DailyMotion on 6/20/2008(!) and then never clicked the opt-link and so never got a single email on this address for more than a decade before getting a standard “I recorded you watching porn” spam. Talk about sleeper cell address!

Exit mobile version