Incomprehensible spam

Opinion
Jun 6, 20115 mins

Growing Global Economies Falling Prey to Scammers

There are at least four types of spam I receive:

• Phishing: trying to get victims to reveal information that can be used for fraud.

• Fraud: trying to trick victims into giving away money to criminals.

• Stupid: trying to sell real products to people who have no possible interest in the types of products involved.

• Imbecilic: trying to sell anything to people who cannot understand the language of the spam.

Over the last year or so, my spam filters  (for both .gmail.com & .norwich.edu) have been receiving what seems like a steadily growing stream of spam written in languages – and using character sets – that I cannot read. Some of these messages, when translated using Google Translate, appear to be the same old trash – increasing the size of parts of your body, promising untold riches without work, expensive watches at miniscule prices – all the stuff that we are used to. However, there’s an increasing number of messages that seem to be from legitimate companies selling stuff like bearings (“bearing balls”), chemicals, cloth, clothing, concrete pipes, steel coils, and steel tubes. 

In my .edu mailbox in particular, the spam filter is catching repeated invitations to technical conferences in China and elsewhere in Asia; conference topics include advanced measurement and testing, computation theory, computer science and society, “electric and electronics,” and management science and engineering. None of these has an unsubscribe link – but unsubscribe links may actually increase the amount of spam because the recipient has confirmed that an e-mail address on the spammers’ lists is real.

Examination of the filters on my two e-mail accounts showed the following counts of Asian spam (mostly from China, some from Taiwan, Malaysia, Singapore and India):

• Norwich.edu filter from May 9-23: 38/73 spam messages = 52% of the spam

• Google filter from April 14 through May 23: 174 of 664 spam messages = 26% of the spam.

A side note: I’ve seen a worsening flood of both fraudulent and apparently well-meant spam in Spanish from South America as well, including repeated invitations to join the Santiago, Chile paint-ball club – and I live in Vermont.

Anyway, my guess is that the stupid and imbecilic spam messages are actually evidence of a scam perpetrated on the senders. Here’s a letter I wrote to organizers of a security conference in China, including (according to the Website) universities in the U.S. and in Europe:

>Dear Colleagues,

For several months, I and other academics have been receiving unwanted and inappropriate e-mail from conferences in Asia. I regularly receive e-mail from countless conferences using my Norwich University address.

Your organizations – and the unwilling recipients of this flood of e-mail – are the victims of criminals.

The criminals are selling you e-mail advertising that is fraudulent.

They claim to you that your invitations to your conferences will be sent to willing recipients; they are lying.

The e-mail is sent to addresses harvested from the .edu domain with no regard to suitability.

The e-mail managers violate U.S. laws by providing no way to get off their list. I have been trying to remove my address from their lists for months by asking conference organizers to relay my request. There has been no reduction in the unwanted e-mail from these criminals.

It is extremely difficult to block the stream of e-mails because the criminals use numerical domains such as 183.com and keep changing the domain name. It is also possible that they are forging e-mail headers, because some of the domains they use do not exist in the international domain registration system.

Your reputation is being damaged by association with criminals.

Your money is being stolen by having your invitations sent to unwilling and inappropriate recipients.

Please report these criminals to your local police authorities to prosecute them for fraud. You paid for services that you are not receiving.

United States and international organizations whose reputation is being tarnished should terminate their involvement in these conferences until the situation is corrected.

As far as I can see, there’s been no reduction of the spam from the creeps who are lying to their customers.

So what can users do?

• Block all e-mail from top-level domains (TLD) from which you have no reason to expect e-mail. In my case, for example, anyone using, say, a .cn TLD will have to contact me some other way, because all such e-mail goes straight to the spam folders.Web beacons.

• Block all e-mail from specific domains associated with spammers; for example, in the Norwich account spam filter, I cheerfully entered every numerical  domain from 126.com all the way to 200.com; even so, the criminals keep buying new domains or adding qualifiers such as “vip” – I recently added vip.129.com through vip.190.com to the filters.

• Block automatic downloading of HTML content so that less of your bandwidth is consumed by the images included in the spam – and also because you can thus block downloading of

• Set your e-mail client (e.g., Outlook) to reject e-mail with inappropriate character encodings; for example, I block all messages written in Arabic, Baltic, Central European, Chinese Simplified, Chinese Traditional, Cyrillic, Greek, Hebrew, Japanese, Korean, Latin 3, Thai, Turkish and Vietnamese. The only allowed encodings are US-ASCII and Western European.

If you examine your spam filters now and then, you should be able to identify blocked messages that you do want to receive, and you can modify your filters accordingly.

Finally, if you have the time and are feeling particularly friendly, you can let the innocent victims of spam organizations know that they have been defrauded. And be nice about it – we can perhaps generate awareness of the problem among this new cohort of Internet users and get them to fight back against the criminals.