We Beat Spam — and Now Your Own Mail Server Can’t Send Anything

From one man typing 320 addresses by hand in 1978 to botnets running 90% of all email in 2008

分享
cover-medium-16x9
creator generate

IT HISTORY

We Beat Spam — And Now Your Own Mail Server Can’t Send Anything

If you have ever set up email for a domain you own, your DNS probably holds three TXT records:

  • one starting with v=spf1,
  • one stuffed with a long public key for DKIM,
  • and one on _dmarc.

Setting them up is a nuisance, and getting a single one wrong means your domain either can’t send at all or lands straight in the recipient’s spam folder.

It all goes back to an email sent 50 years ago.

Date:  1 May 1978 1233-EDT 
From: THUERK at DEC-MARLBORO 
Subject: ADRIAN@SRI-KL

One Man, One Directory, 320 Addresses

In May 1978, Gary Thuerk, a marketing manager at DEC, wanted to hold two open houses in California to promote the new DECSYSTEM-20. He had few contacts on the West Coast, so he had an engineer named Carl Gartley work through the printed ARPANET directory and type the West Coast addresses, one at a time, for a mass mailing.

There is a nice detail here. The mail program they used, SNDMSG, accepted only about 320 addresses in its header fields, so the overflow ran from To into CC and finally into the message body. The actual advertisement started several hundred addresses down the page.

ARPANET logical map, March 1977
ARPANET logical map, March 1977, fourteen months before that email. The whole network fit in a printed directory. Image: ARPANET, public domain, via Wikimedia Commons
DECSYSTEM-2020
A DECSYSTEM-2020, one of the models that email was selling. Photo: Jason Scott, CC BY 2.0, via Wikimedia Commons

This is probably the earliest verifiable spam email, and sending it cost two people a few days at a keyboard with a paper directory open in front of them.

It eventually drew official attention. Major Raymond Czahor, chief of the ARPANET Management Branch at the Defense Communications Agency, sent out a notice in all caps:

THIS WAS A FLAGRANT VIOLATION OF THE USE OF ARPANET AS THE NETWORK IS TO BE USED FOR OFFICIAL U.S. GOVERNMENT BUSINESS ONLY.

The warning worked. Nothing happened, as it had for more than a decade.

But this was only the beginning, because the method worked too well.

Thuerk still doesn’t think he did anything wrong. He told Computerworld in 2007 the mailing sold “$13 million or $14 million worth” of machines, and added, “you don’t blame the Wright Brothers for every flying problem.”

Complaining Stopped Working

Sixteen years later, two lawyers turned it into a business. On April 12, 1994, Phoenix immigration attorneys Laurence Canter and Martha Siegel posted an ad titled “Green Card Lottery-Final One?” to at least 5,500 Usenet newsgroups. They didn’t crosspost one copy; they posted a separate message in every group, so a reader subscribed to ten groups saw it ten times.

Their ISP was buried in complaints, its mail servers crashed for two days, and the account was cut off. But in an interview that December, the two said the ad brought in 1,000 new clients and $100,000, at a cost of a few cents. That June, they did it again, to a thousand groups.

Thuerk stopped after one attempt because he cared what the ARPANET community thought of him. Canter and Siegel did not care. They went on to publish a book, How to Make a Fortune on the Information Superhighway, teaching other people to do the same. Once sending costs a few cents, a reputation is not worth much.

In 1997 the Tennessee Supreme Court disbarred Canter, partly over that mailing. By then the ad was three years old and spam no longer depended on any one person.

Over those two or three years it had become an industry. Sanford Wallace founded Cyber Promotions in 1995 to do bulk email full time, and at its 1996 peak the operation was sending an estimated 30 million messages a day.

He could send that volume because SMTP was never designed to keep anyone out. Postel had assumed a set of mutually trusting servers, so every mail server was an open relay by default — anyone could hand it a message and have it forwarded on their behalf. By the mid-1990s, more than 90% of servers were still in that state. A bulk sender handed one message plus a long recipient list to somebody else’s machine, and that machine did the fan-out, the bandwidth, and the delivery. His own box never had to carry the load.

Service providers could only sue them one at a time. CompuServe won a temporary restraining order in October 1996 and a judgment in the Southern District of Ohio the following year; AOL sued twice, EarthLink sued as well, and Cyber Promotions ended up with an injunction and a $65,000 fine. But a lawsuit stops one person. Open relays were on by default across the whole network, and a sender could simply move to another server and keep going.

Paul Vixie
Paul Vixie in 2014. In 1997 he and Dave Rand built the first DNSBL. Photo: ImaginingtheInternet, CC BY 3.0, via Wikimedia Commons

That same year Paul Vixie and Dave Rand built the RBL, the Real-time Blackhole List, and the first DNSBL. The logic was blunt: if complaining doesn’t work, block the IP. The arms race between bulk mailers and anti-spam started here.

A Filter Is a Black Box You Can Query Forever

Over the next seven years, defenses improved, but still failed to stop it.

SpamAssassin arrived in 2001, and in 2002 Paul Graham published A Plan for Spam, which brought Bayesian statistics into mail filtering. Before that, filters ran on hand-written rules: XXX in the subject means spam, three consecutive all-caps words means spam. Graham’s approach scored the whole message token by token — body, headers, embedded HTML and JavaScript included.

Statistical learning beat hand-written rules by a wide margin, but it came with a problem nobody could design around: a filter is a black box you can query as many times as you like. A spammer only had to install the same filter on his own machine and keep editing until it passed. Edit, test, edit again, at near-zero cost. That is where image spam, deliberate misspellings, and blocks of novel text pasted in as noise came from.

The legal route was tried too, and it went worse. CAN-SPAM, effective January 1, 2004, took the opt-out approach: as long as you include an unsubscribe mechanism and a valid postal address, sending unsolicited commercial email is legal. Worse, it preempted stricter state laws at the same time, including two that would have banned bulk commercial email outright. The day America’s first anti-spam law took effect, the strictest anti-spam laws in the country stopped applying.

Meanwhile, the sending side industrialized. Botnets took over hundreds of thousands of infected home PCs, using other people’s machines and other people’s bandwidth, and the cost stayed at zero. By Symantec MessageLabs’ measure:

Table Image

Nine out of every ten messages, in those years, were spam.

The defense also tried cutting off the source. On November 11, 2008, several upstream ISPs disconnected the hosting provider McColo, which was then estimated to carry roughly three-quarters of the world’s spam traffic, and global spam volume fell by more than 60% overnight. (Estimates differ: Symantec’s probe network measured 65%, other reports put the range between 50% and 80%.)

Volume was back within a month. Sending still cost nothing, so rebuilding was no great burden.

Changing the Question

In thirty years, the defense got exactly one thing right: it changed the question. Instead of asking whether a message looks like spam, ask whether it really came from the domain it claims.

  • SPF: a domain declares in DNS which IPs may send on its behalf
  • DKIM: the sender signs the message with a private key; the receiver verifies with the public key in DNS
  • DMARC: ties both to the From domain the user actually sees, and tells receivers what to do when verification fails

None of the three judges content, which is what breaks the edit-until-it-passes strategy. An attacker can rewrite the wording indefinitely and still never obtain your private key.

Back to those three records in your DNS. Why three, and not one?

Because SPF alone has a hard flaw: forwarding breaks it. Once a message is forwarded, the IP delivering it to the receiving server is no longer on the original domain’s SPF list, so SPF fails outright even for a perfectly legitimate message. DKIM covers that gap because its signature travels with the message and still verifies after several hops, as long as the body and signed headers are untouched. DMARC only requires that one of SPF or DKIM pass in alignment, which is the whole point of configuring both — when forwarding kills SPF, DKIM still carries it.

The cost is glacial deployment. It needs the entire network to cooperate: senders have to configure DNS, receivers have to enforce policy, and neither half means much alone. The specifications were finished in the mid-to-late 2000s, but real effect had to wait for the 2020s. For those intervening years, the technology existed. What was missing was somebody with enough leverage to make the whole network do it.

February 2024

That somebody turned out to be Google and Yahoo. In February 2024, both imposed hard requirements on bulk senders — defined as anyone sending close to 5,000 or more messages to personal Gmail accounts in 24 hours. SPF and DKIM both have to be configured, with at least one aligned to the From domain so DMARC passes; there has to be a DMARC record with a policy of at least p=none; one-click unsubscribe has to work; and the spam complaint rate has to stay under 0.3%, with 0.1% the official recommendation.

Miss any of it and the mail does not reach Gmail.

The effect is obvious. Spam accounted for 44.99% of global email in 2025 by Kaspersky’s measure, roughly half of the 90% in 2010. But spam has not disappeared, only changed shape. The same Kaspersky report counts more than 144 million malicious or unwanted email attachments blocked in 2025, up 15% year over year. Pharmaceutical ads are gone; phishing and business email compromise have taken their place.

The Bill

So this war was won by handing the right to send mail to a handful of companies.

Stand up your own mail server today, configure SPF, DKIM, and DMARC correctly, and your mail will still probably land in spam. Not because your mail is spam, but because you have no reputation history — and reputation history is defined by Gmail, Yahoo, and Outlook, which do not publish their scoring rules and do not owe you an explanation.

Jake Feinler
Jake Feinler in 2006. In 1978 she ran the ARPANET Network Information Center. Photo: Doc Searls, CC BY-SA 2.0, via Wikimedia Commons

On May 7, 1978, Jake Feinler wrote this on the MSGGROUP mailing list. What worried her was that companies with ARPANET access could advertise to a very select market while those without could not:

Consequently if the ones that do have access can advertise their products to a very select market and the others cannot, this is really an unfair advantage.

Sources