Roedy said:
I have noticed that most of the spam comes not from the email address
I have plastered all over my website, but from and address I use for
filling in web forms on the net when you give you email address to
download a piece of software or to activate it.
SOMEBODY is selling lists to spammers.
Sometimes this may be due to desktop email-borne worms that use local
harvested email addresses not only for delivery but for obfuscating the
sender. By this process, private correspondent email addresses can be
leaked onto the Internet.
More likely are the companies that sell their list of customers to
"affiliates" for advertising who either turn out to be spammers or the
ones that sell them to spammers.
This is one of the reasons to hand out tagged email addresses. For
instance with sendmail-based mail servers and others (including Gmail,
apparently), you can use an address like this:
(e-mail address removed)
that will deliver to
(e-mail address removed)
and allow you to see where the address came from. For instance, if you
end up getting spam from (e-mail address removed), and you only
gave that address to amazon.com, you know where the leak occurred.
Similar things can be done with sneakemail or mailinator with unique,
obuscated local addresses that are easy to track back to the source and
difficult to convert into an untagged address.