Jangomail’s Reverse Spam
April 16th, 2008So I signed up for Eyespot the other day, just to try it out. Eyespot is an online video editor, and it’s really spiffy (although I like Jumpcut a bit more). But, online video editing is not what this post is about; rather, this is about how a legitimate email newsletter from Eyespot, in an ironic twist, managed to disguise itself as spam so well that it took a bit of detective work indeed to discover that it wasn’t so.
Pretty much the entire message body is available at http://shootmixshare.blogspot.com/2008/04/build-your-own-site-w-eyespot.html, which is a decent warning sign in itself. There were a few noteworthy differences, however.
Bizarro Spam
In a world where hot black snow falls up, spam would look like the email I recieved from eyespot; completely legitimate info with what seems like deliberate touches to make it look like spam, to me and to gmail alike. First off, all the links were rewritten. Here’s an example:
http://x.jngo1.net/y.z?l=http%3A%2F%2Feyespot.com%2Fmixables%2FThieveryCorporation&e=1055&j=103500431
The domain of that link, x.jngo1.net, is a huge red flag. At this point, I was fairly convinced it was some sort of phishing attempt, and I was gearing up to write an angry email to eyespot for handing over my email address. However, since I am young and foolhardy and also using a Linux machine, I went ahead and clicked it anyway - and it brought me to the Eyespot site.
I looked all around for evidence of foul play, but nothing came up. So I did a whois in jngo1.net, and a company called Silicomm.com came up. Curious, I went to their site, and was presented with a link to Jangomail.com. Jangomail? That sequence of consonants and an ‘o’ sounds familiar. And sure enough, jangomail.com is a newsletter app that is apparently used by Eyespot to send highly ignored newsletters. Evidently the url rewriting is nothing more nefarious than some tracking code.
So what did we learn?
We learned that GMail registers weird urls as spam, or is possibly blocking this jangomail domain for non-Eyespot-related spams, or is blocking all mail with recieved-from jangomail.com headers (mine was magellen@jangomail.com). It’s hard to blame jangomail.com for this. They seem to be a legitimate company, and having worked for a company that does email newsletters I can tell you that it’s not easy to keep your domains off the blacklist, or to keep your users legitimate. x.jngo1.net is probably just something they though was obscure enough that google wouldn’t block it.
What could Eyespot learn from this? Maybe tracking your clicks isn’t worth your emails getting dumped in the bin. As for Jangomail, I have no real advice; better, more profit-motivated minds than mine have wrestled with this problem before. However, maybe they could take a trick or two from Freshview’s Campaign Monitor, they seem to be doing ok. In fact, I know one Matthew Patterson from Freshview has stumbled across this blog before in his technorati-fuelled meanderings, so maybe he has some insight on this. To comment on. Because I’m actually really curious now.
Fuel another post