不要通过发送垃圾邮件来验证电子邮件地址

Hacker News Top 新闻

摘要

文章批评了一个名为Pangram的网站,该网站通过向输入的邮箱地址发送垃圾邮件来验证邮箱,指出这是一种糟糕且具有欺骗性的邮箱验证做法。

暂无内容
查看原文
查看缓存全文

缓存时间: 2026/06/23 22:46

# 不要通过发送垃圾邮件来验证电子邮件地址 来源:https://milek7.pl/mailverifyspam/ #### *2026年6月23日* 关于尝试验证电子邮件地址的徒劳性,已有诸多讨论。普遍接受的建议是:直接发送验证链接即可,无需事先费心验证。但如果你执意要加入验证步骤,同时又想遵循这一建议呢?显然,有些人认为他们可以通过……发送垃圾邮件来实现。 以 Pangram 注册表单(https://www.pangram.com/signup)为例。在此填写邮箱字段后,会发起如下请求: `` curl --request POST --data '{"email": "[email protected]"}' https://www.pangram.com/api/validate-email `` 很快,无需其他操作,你就会收到一封神秘邮件。什么……? `` Date: Tue, 23 Jun 2026 15:29:10 +0000 From: "Winwin Insights" To: Reply-To: Subject: Fact of the day: Magnetic Message-ID: <[email protected]> Precedence: Bulk MIME-Version: 1.0 Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: base64 PCFET0NUWVBFIGh0bWw+IDxodG1sPiA8aGVhZD4gPG1ldGEgY2hhcnNldD0iVVRGLTgiPiA8L2hlYWQ+IDxib2R5IHN0eWxlPSJmb250LWZhbWlseTogQXJpYWwsIHNhbnMtc2VyaWY7IGZvbnQtc2l6ZTogMTZweDsgY29sb3I6ICMzMzM7Ij4gPGRpdiBzdHlsZT0icG9zaXRpb246IGFic29sdXRlOyBsZWZ0OiAtOTk5OXB4OyB0b3A6LTk5OTlweDtkaXNwbGF5OiBub25lOyI+SGkgdGhlcmUsPGJyPiBBIG1hZ25ldGljIGRvbWFpbiBpcyBhIHJlZ2lvbiB3aXRoaW4gYSBtYWduZXRpYyBtYXRlcmlhbCBpbiB3aGljaCB0aGUgbWFnbmV0aXphdGlvbiBpcyBpbiBhIHVuaWZvcm0gZGlyZWN0aW9uLiBUaGlzIG1lYW5zIHRoYXQgdGhlIGluZGl2aWR1YWwgbWFnbmV0aWMgbW9tZW50cyBvZiB0aGUgYXRvbXMgYXJlIGFsaWduZWQgd2l0aCBvbmUgYW5vdGhlciBhbmQgdGhleSBwb2ludCBpbiB0aGUgc2FtZSBkaXJlY3Rpb24uIFdoZW4gY29vbGVkIGJlbG93IGEgdGVtcGVyYXR1cmUgY2FsbGVkIHRoZSBDdXJpZSB0ZW1wZXJhdHVyZSwgdGhlIG1hZ25ldGl6YXRpb24gb2YgYSBwaWVjZSBvZiBmZXJyb21hZ25ldGljIG1hdGVyaWFsIHNwb250YW5lb3VzbHkgZGl2aWRlcyBpbnRvIG1hbnkgc21hbGwgcmVnaW9ucyBjYWxsZWQgbWFnbmV0aWMgZG9tYWlucy4gVGhlIG1hZ25ldGl6YXRpb24gd2l0aGluIGVhY2ggZG9tYWluIHBvaW50cyBpbiBhIHVuaWZvcm0gZGlyZWN0aW9uLCBidXQgdGhlIG1hZ25ldGl6YXRpb24gb2YgZGlmZmVyZW50IGRvbWFpbnMgbWF5IHBvaW50IGluIGRpZmZlcmVudCBkaXJlY3Rpb25zLiBNYWduZXRpYyBkb21haW4gc3RydWN0dXJlIGlzIHJlc3BvbnNpYmxlIGZvciB0aGUgbWFnbmV0aWMgYmVoYXZpb3Igb2YgZmVycm9tYWduZXRpYyBtYXRlcmlhbHMgbGlrZSBpcm9uLCBuaWNrZWwsIGNvYmFsdCBhbmQgdGhlaXIgYWxsb3lzLCBhbmQgZmVycmltYWduZXRpYyBtYXRlcmlhbHMgbGlrZSBmZXJyaXRlLiBUaGlzIGluY2x1ZGVzIHRoZSBmb3JtYXRpb24gb2YgcGVybWFuZW50IG1hZ25ldHMgYW5kIHRoZSBhdHRyYWN0aW9uIG9mIGZlcnJvbWFnbmV0aWMgbWF0ZXJpYWxzIHRvIGEgbWFnbmV0aWMgZmllbGQuIFRoZSByZWdpb25zIHNlcGFyYXRpbmcgbWFnbmV0aWMgZG9tYWlucyBhcmUgY2FsbGVkIGRvbWFpbiB3YWxscywgd2hlcmUgdGhlIG1hZ25ldGl6YXRpb24gcm90YXRlcyBjb2hlcmVudGx5IGZyb20gdGhlIGRpcmVjdGlvbiBpbiBvbmUgZG9tYWluIHRvIHRoYXQgaW4gdGhlIG5leHQgZG9tYWluLiBUaGUgc3R1ZHkgb2YgbWFnbmV0aWMgZG9tYWlucyBpcyBjYWxsZWQgbWljcm9tYWduZXRpY3MuIE1hZ25ldGljIGRvbWFpbnMgZm9ybSBpbiBtYXRlcmlhbHMgd2hpY2ggaGF2ZSBtYWduZXRpYyBvcmRlcmluZzsgdGhhdCBpcywgdGhlaXIgZGlwb2xlcyBzcG9udGFuZW91c2x5IGFsaWduIGR1ZSB0byB0aGUgZXhjaGFuZ2UgaW50ZXJhY3Rpb24uIFRoZXNlIGFyZSB0aGUgZmVycm9tYWduZXRpYywgZmVycmltYWduZXRpYyBhbmQgYW50aWZlcnJvbWFnbmV0aWMgbWF0ZXJpYWxzLiBQYXJhbWFnbmV0aWMgYW5kIGRpYW1hZ25ldGljIG1hdGVyaWFscywgaW4gd2hpY2ggdGhlIGRpcG9sZXMgYWxpZ24gaW4gcmVzcG9uc2UgdG8gYW4gZXh0ZXJuYWwgZmllbGQgYnV0IGRvIG5vdCBzcG9udGFuZW91c2x5IGFsaWduLCBkbyBub3QgaGF2ZSBtYWduZXRpYyBkb21haW5zLjxicj4gQmVzdCw8L2Rpdj4gPGRpdiBzdHlsZT0iZm9udC1zaXplOiAwOyBsaW5lLWhlaWdodDogMDsiPiAmIzgyMDM7IDwvZGl2PiA8L2JvZHk+IDwvaHRtbD4= `` 和所有有尊严的垃圾邮件发送者一样,他们轮换使用多个发件域名(以下列表并非穷尽!): `` apiaryapiaries.com avaspaintinggallery.com bonfirebeat.com catnipblissfulhaven.com chloesgardeninghaven.com classmerge.com endurovistawear.com fragjoystick.com gainswiftwave.com ghostlygourd.com hydroponicseeders.com lanternlyric.com mangomysticfusion.com northchronicle.com pasturelandplough.com platformerboss.com pyxisvoyager.com raisetyrvalor.com rockandrender.com ryeirrigator.com sifgoldenshine.com sipandsweater.com storybookstage.com strategycrit.com thruwaymotors.com tillageacre.com venusbases.com `` 但与典型垃圾邮件发送者不同,他们真是竭尽全力确保垃圾邮件送达:一旦被拒,立即从不同服务器重试(显然他们部分 IP 已列入 DNSBL。嗯,我想知道为什么……): `` Jun 23 16:15:36 milek7.pl postfix/smtpd[404910]: connect from mta2.icicleglimmerfrost.com[31.133.27.229] Jun 23 16:15:38 milek7.pl postfix/smtpd[404910]: NOQUEUE: reject: RCPT from mta2.icicleglimmerfrost.com[31.133.27.229]: 554 5.7.1 Service unavailable; Client host [31.133.27.229] blocked using spam.spamrats.com; SPAMRATS IP Addresses See: http://www.spamrats.com/bl?31.133.27.229; from= to= proto=ESMTP helo= Jun 23 16:15:39 milek7.pl postfix/smtpd[404910]: disconnect from mta2.icicleglimmerfrost.com[31.133.27.229] ehlo=2 starttls=1 mail=1 rcpt=0/1 quit=1 commands=5/6 Jun 23 16:15:39 milek7.pl postfix/smtpd[404910]: connect from mailc.plowdairy.com[93.120.120.78] Jun 23 16:15:40 milek7.pl postfix/smtpd[404910]: NOQUEUE: reject: RCPT from mailc.plowdairy.com[93.120.120.78]: 554 5.7.1 Service unavailable; Client host [93.120.120.78] blocked using b.barracudacentral.org; http://www.barracudanetworks.com/reputation/?pr=1&ip=93.120.120.78; from= to= proto=ESMTP helo= Jun 23 16:15:41 milek7.pl postfix/smtpd[404910]: disconnect from mailc.plowdairy.com[93.120.120.78] ehlo=2 starttls=1 mail=1 rcpt=0/1 quit=1 commands=5/6 Jun 23 16:15:41 milek7.pl postfix/smtpd[404915]: connect from servidor.classmerge.com[176.113.182.193] Jun 23 16:15:43 milek7.pl postfix/smtpd[404915]: 53EB982421: client=servidor.classmerge.com[176.113.182.193] Jun 23 16:15:43 milek7.pl postfix/cleanup[404918]: 53EB982421: message-id= Jun 23 16:15:43 milek7.pl postfix/qmgr[404883]: 53EB982421: from=, size=1301, nrcpt=1 (queue active) Jun 23 16:15:43 milek7.pl postfix/lmtp[404919]: 53EB982421: to=, orig_to=, relay=milek7.pl[dovecot/lmtp], delay=1.8, delays=1.7/0.03/0.05/0.03, dsn=2.0.0, status=sent (250 2.0.0 dvDAJS+xOmq4LQYA8NhtAw Saved) Jun 23 16:15:43 milek7.pl postfix/qmgr[404883]: 53EB982421: removed Jun 23 16:15:44 milek7.pl postfix/smtpd[404915]: disconnect from servidor.classmerge.com[176.113.182.193] ehlo=2 starttls=1 mail=1 rcpt=1 data=1 quit=1 commands=7 `` 这一切极其愚蠢,因为要么你通过向地址发送垃圾邮件来“验证”它们,要么目标服务器执行内容过滤,你的垃圾邮件被拒,“验证”失败。我现在非常好奇他们到底是怎么想出这个主意的,因为看起来他们费了相当大的劲。我猜存在某个愚蠢的 SaaS 用来“验证”电子邮件,不过如果最后发现是某个 LLM 智能体失控了,那倒也挺有趣。(Pangram 的实际事务邮件是通过 Mailgun 发送的。)

相似文章

订阅轰炸:电子邮件遭受攻击

Lobsters Hottest

订阅轰炸是一种电子邮件攻击方式,攻击者通过向受害者邮箱发送大量不需要的订阅确认邮件,来掩盖恶意邮件。

有人利用我的开源项目进行网络钓鱼

Hacker News Top

一位开源项目维护者报告称,攻击者滥用了其项目的邀请系统,利用未经验证的注册和已验证的邮箱域名,向超过1.4万人发送了钓鱼邮件。这一事件突显了善意设计如何被恶意利用。

信任却未验证:大型语言模型来源评估中的认知盲区

arXiv cs.LG

这篇论文识别了大型语言模型(LLM)中的一个失败模式:在综合多个来源时,模型不会验证数值统计的有效性,而是依赖分析严谨性的文体标记。作者将此称为“认知对齐”(epistemic alignment),并表明该现象在多个模型和领域中持续存在,且抵制基于提示的缓解措施。