What actually arrives in an open mailbox

« Blog · By

A lot gets written about spam, most of it in general terms. Instead we looked at what actually lands in our mailboxes — and the result is far more clear-cut than we expected.

The numbers

We analysed every message stored in our system:

  • 181 messages in total
  • 180 of them from a single sender domain
  • 180 of them with the same subject line
  • All 180 on one day, spread across five hours
  • Exactly one message per address — 181 addresses, 181 messages

The single exception was a genuine invoice notice from a service provider that had been sent to one of our addresses by mistake.

What that means

The pattern is textbook. No human writes 180 messages in five hours to 180 different recipients with an identical subject. That was a script working through a list.

The telling figure is the ratio of exactly 1.00 messages per address. Someone guessing addresses at random hits the same one repeatedly, or misses entirely. Someone working through a list hits each one exactly once. The sender was not guessing. They had names.

The genuinely unsettling part

We checked when the addresses that were hit had been created:

25 69 59 11 17 2014 2015 2016 2017 2018–2025
Year of creation of the 181 addresses that were hit. The three highlighted bars are 153 addresses together, around 85 percent.

Around 85 per cent of the addresses date from 2014 to 2016. The list being worked through is more than ten years old.

That is the real lesson. An email address that was public once stays on lists. It does not expire; it gets passed along, sold, and used again years later. The people behind those 2014 addresses forgot them long ago. The lists did not.

How does a list like that come about?

We cannot prove where this particular list came from. The most mundane explanation is the likely one: our addresses were discoverable through publicly reachable pages for years — an overview page and links inside the mailbox view that search engines and other programs could follow. We have since closed that off: mailbox addresses no longer appear publicly anywhere and are blocked for search engines.

The general routes by which addresses end up on lists are well known:

  • published on websites, in forums or in legal notices
  • leaked from a provider you were registered with
  • passed on through address trading
  • simply guessed — short names like info or test exist almost everywhere

What the content was

The 180 identical messages were a phishing attempt with a subject line claiming a domain was about to expire and had to be renewed. It is one of the oldest tricks there is: it creates time pressure, targets people who actually own domains, and looks at first glance like administrative routine.

How to spot messages like this is covered in a separate post.

What you can take from it

  1. An address that has been published once is permanently burnt. Not for a year — indefinitely.
  2. Use a separate address for every sign-up. Then you can see which provider passed your data on, and shut down exactly that channel.
  3. Short, obvious names are the worst choice. They are on every guessing list.
  4. Time pressure in an email is a warning sign, not a reason to hurry.

A note on method

The analysis comes from our own database and covers metadata only: timestamp, sender domain, subject and the creation date of the target address. We did not read the content of individual messages for this, and we name no addresses. All the messages have since been deleted — incoming mail here is removed automatically after seven days at the latest.