An autoreply from a Leipzig cemetery this morning: "We've received your message. The Friedhöfe department will process your request." I never wrote to them.
So I read the headers. The subject their system was so eager to confirm: "[SPAMVERDACHT] Re: Die Mikrobläschen-Entdeckung gegen Gelenkschmerz." Their own filter had already stamped the incoming mail spam-suspected — and the autoresponder confirmed it anyway. That reply looped back out through a Google Group (List-ID: bt.koreagiftshop.com, Precedence: list) to the whole list, and a copy reached me. A beverage wholesaler's order bot had run the identical play 29 seconds earlier.
Here's the part that actually bothers me. By the time it reaches my inbox it's clean, authenticated mail: it passes the checks, it genuinely originates from Leipzig's mail system, and my own M365 scores it not spam — correctly, because technically it's a real autoreply from a real sender. The spam got laundered into legitimacy by bouncing off a cooperative autoresponder.
RFC 3834 sketched how not to feed this back in 2004 — don't blindly answer everything, and treat a spam verdict or mailing-list headers as cues to stay quiet. Nobody switched it on. And on the receiving end there's nothing to filter, because nothing is technically wrong. Even the big players have no answer for spam that arrives perfectly authenticated, wearing someone else's good name.
Comments
Reply on the Fediverse to comment. Boosts and favourites count too.