Fake Mailchimp Subscribers – A Solution?

In a followup to the recent post about fake email subscribers, Update to Fake Email Subscriber Post,  after working with Mailchimp’s support, I believe we have found the culprit, and potentially a solution.

Mailchimp confirmed that my API key was being used to add these fake subscribers, but it was unclear if the key had been discovered or if they were, in fact, coming from my signup form. So I changed to a new API key and disabled everything but my form for signup, with the new key. The fake subscribers still came in. But we could see they were not being added from Mailchimp, they were definitely hitting the API from my other site.

So I started digging into what was happening on the site. Again, there were no matching visits to the page, so it seemed odd to me that the signups were legit, and it turns out, they weren’t. Digging through some logs, I could see that the same bots submitting spam comments using a POST method without ever viewing the page, were using a POST method to submit subscribe requests. My addition of a captcha to the form had no effect on those submissions, the spammers had obviously found a way around that. To prove that, I enabled the same cptcha on comments to see if the spam comments were still being posted. Askimet was marking them as spam, but with the captcha they shouldn’t post at all, right? Wrong.

That particular captcha WordPress plugin was no match for the spammers. So off to Google we go. I found a recommendation for a plugin named Goodbye Captcha, that uses a captcha-style analysis to block spam attempts without the user actually seeing a captcha. I turned that on for comments, and the Mailchimp form.

In two days, it has blocked 11 subscribe attempts. (Yes, it has reporting, this is awesome!) I have had no fake subscribers added to my list.

Fingers crossed…..

 

Similar Posts

  • Comments spam

    I guess the new addition of the TableEditor turned out to be a double-edged sword last night. Yes, someone did leave a comment that was nothing more than “come visit my blog” with a link, and yes I did delete it. Unfortunately, I also left a comment by Anita that referred to said spam comment,…

  • Patience Wearing Thin with Google Plus?

    I saw a post on Google Plus today by Niki Black, that resonated with me. You’d better roll out some new things ASAP Google+ or you’re going to tank. Allow 3d party developers access to your API so I can post to Google+ from my feed readers. Or I’m going to stop cross-posting because it…

  • |

    Social Networks as "The Neighborhood"

    Image by mikemac29 via Flickr One of the more interesting conversations I had in New York with the family was, oddly enough, about social networking. Mostly due to the fact that I had “connected” with some of the family I was seeing that day on Facebook, and was sharing my plans to be part of…

  • Bullet-ins

    A post with a bullet, or three. * Firefox’s update went pretty smoothly on my laptop, it had one little hiccup on my work desktop. After restarting Firefox, the Clippings extension threw up a script error. Disabling Clippings and reinstalling it fixed the problem. BTW, Clippings is a very handy tool when your helpdesk software…

  • Linked – How to repair a trust problem

    She mentions a round of layoffs as an example of breaking trust, and I’m glad she included that. All too often, when a round of layoffs occurs, senior management will return to talking about the culture or set of core values they expect all employees to follow without ever acknowledging that it’s different now. You can’t just return to talking about the importance of teamwork and diversity when you just canned 10% of the team as if nothing happened.

  • | |

    Tumblr

    Recently, a friend contacted my wife and I asking about good places to start a blog. The request reminded me that while I had seen many articles talking about the success of Tumblr as a blogging platform and a community, I really hadn’t spent any time trying to figure out what the appeal is. So,…

2 Comments

  1. GoodBye Captcha solved my problem as well.
    It is totally amazing! 34 fake subscriptions blocked in less than a day!
    Thanks for letting us know

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

To respond on your own website, enter the URL of your response which should contain a link to this post's permalink URL. Your response will then appear (possibly after moderation) on this page. Want to update or remove your response? Update or delete your post and re-enter your post's URL again. (Find out more about Webmentions.)