[SURBL-Discuss] Software spam with recently registered (fake?) sender domains

Joe Wein joewein at pobox.com
Sun Sep 12 10:11:43 CEST 2004

In recent days I've seen a lot of pirate software advertised in spam that
uses a sender address of the form

"Firstname1 Lastname1" Firstname2Lastname2 at suspectdomain

where suspectdomain is a very recently registered domain (late August-early

Previously software spammers used all kinds of fake sender domains, but non
they had registered themselves and not specifically recently registered
ones. Has anyone else noticed this and has any thoughts about it?

I wonder if spammers are buying lists of recently registered domain names
off registrars in order to poison domain blacklists?


