Tell A Friend Spammers
Do you have a Tell A Friend form on your website? If you do, spammers may be taking advantage of you.
Tell a friend systems can be a good part of your website strategy. Tell a friend is much like referrals in the offline world. In the online world, you’re giving your customers an easy way to recommend your services or products to their friends.
Unfortunately, as with any good online strategy, sooner of later spammers will find a way to use something good, and turn it into bad for the rest of us.
I run a URL shortening, hit counting service. Most of my customers are great, and are using the service as it is intended. Then there are the .01% who use it to try to mask their destination URL.
Recently I’ve had a couple of complaints about customers using my service as part of their spam campaigns. That’s how I found out about the spammers also staking advantage of tell a friend systems.
Here’s how they work.
They find a tell a friend form on some website, it doesn’t even have to be a website related to the product they are promoting. One spammer was using a medical site tell a friend form, to send spam promoting their make money from home product.
They submit their emails to be delivered through the tell a friend system to emails they have gathered – emails to people who are obviously not their friends.
They promote their product in the email, using 2 – 3 short url, or url redirection services to try and hide their final destination.
My guess is they are finding tell a friend systems that they can use a bot on, to automatically submit email after email through these tell a friend systems.
So, if you are using a tell a friend system, do you know if it’s being abused?
Here are some ideas I can think of to keep this from happening.
1. Get rid of your tell a friend system. Instead ask your customers to personally send a few close friends an invite to view your services or products.
2. Use a tell a friend system that makes the referring person, confirm their email address by sending them an email with a confirmation link. Do this for each tell a friend request. Yes, this makes things a little more difficult for your referring customer. But, spammers will not be able to confirm if they are using a fake email, and they will not take the time to confirm again and again and again.
This secure tell a friend script is one that may work for you.
3. At the very least, have a tell a friend system that will email you when someone has used your tell a friend system. If you suddenly have several tell a friends notifications, you know you have a problem.
Using tell a friend systems to send spam is nothing new, but I think it has reached a new level with the ability to automatically fill in forms and send hundreds, if not thousands, of spam emails.
Mike
Tagged with: secure tell a friend • tell a friend • tell a friend script • tell a friend spam
Filed under: Main
Like this post? Subscribe to my RSS feed and get loads more!




This blog Is very informative , I am really pleased to post my comment on this blog . It helped me with ocean of knowledge so I really belive you will do much better in the future . Good job web master .
You come to me tenderly. You take my soul places it’s never been before.You give me more of you than I ever knew anyone could give.
Very usefull, Thanks for Sharing
Never heard how to be a blogger
stupid!
you have a great blog here! would you like to make some invite posts on my blog?
28 years later, and counting. Nonetheless at it
I have a question. How does a Bugs Life fit into this theory?