I have a pet peeve, it's people thinking that my situation is the same as theirs, and giving me advice that is wrong for me.
I get around 2400 spam a day. I've tried three different spam filters recommended to me by people I trust and who generally know about these things, and they get about 97% to 98% accuracy. Worse, they produce false positives. With 50 spam per day, plus having to trawl through the spam bin to look for the false positives, I decided to write my own.
My spam filter is highly tuned to my traffic and I get about 10 spam through per day. More, there are about 2 false positives per month, although that's very hard to quantify.
The problem with putting up a form is that people want a reply, and yet they can't type their own email address properly. About half the emails I get through my various forms have subtle and not-so-subtle misspellings of the return address, and it can cost me hours to track them down.
No, obfuscated email addresses is still my best tool in this situation.
Your visitors that can't spell their own email address is likely to screw your obfuscated address up as well. I've seen email in my outbound queue to whatever@domain.dot.tld and variations. I wouldn't be surprised if someone never realizes that AT is @ (in non-English speaking locales, @=at is not at all obvious. In the Nordic languages it's known as (elephant's) trunk-A. ) and gives up before the mail leaving the client.
It hides your e-mail behind a CAPTCHA, but once it's solved it's an actual, well-formed address, that can be copied or clicked. Also, it's very clear if you've solved the CAPTCHA - it's no always clear if solved the "riddle" of an obfuscation correctly.
> ... visitors that can't spell their own email address
> ... likely to screw your obfuscated address up as well
> ... it's no always clear if solved the "riddle" of an
> obfuscation correctly.
They are likely to screw it up, but at least they get the feedback of a bounced email. There is a recovery mode, and it's their problem.
With an incorrectly spelled return address on a form there is no recovery mode at all, and they get no feedback that it hasn't worked.
Isn't that the point of the article? That you are offloading work onto the peopel you ostensibly want to get in touch with you?
(I'm not saying it's wrong for you to do so, just that your statement seems to line up perfectly with the author's premise that obfuscating your email address is taking your problem and making it their problem).
The author suggests that using a form makes the problem go away. My experience says that people who can't de-obfuscate an email address frequently can't type their return address correctly. The obfuscated address gives them feedback in the form of a bounced email, and thereby gives a recovery mode. The incorrect return address in the form gives no recovery mode at all.
To me, that's conclusive proof that the form is worse than the obfuscated address.
Further, there's a balance to be achieved. I've analysed the types of people I want to contact me, and of those who can't work out my address there are two types. One type is those that I really don't care about - nuisance, spam, content-free, or time-wasters. The others that I do care about usually have a different route to me, one that's specifically tailored to them and made as easy as possible. That one has a specially designed anti-spam measure built into it.
I have to agree with your disdain for forms. I hope that when given the choic ebetween obfuscating an email address and providing a form, our response will be to improve our spam filtering and offer a plaintext mailto: link.
Plaintext links have high usability. The mail is organized within the user's mail program where it can be retrieved, collated by subject, and so forth. It can be copied and pasted. It's the abslute best thing for them :-)
> but at least they get the feedback of a bounced email.
First, that depends. They may hit an existing domain with a catch-all mailbox configured, or they may hit a legitimate mailbox at your provider, where the receiver may or may not think to reply that they got the wrong address.
Second, what percentage of users (especially in the segment that might misspell their own email address) will know what to do with a bounce mail?
I'm using Gmail for my domain and received zero spams in well over a year. My email address is all over the web. What are you using for your spam filter?
I am less worried about receiving spam and more worried about not receiving good mails. Are you sure that Gmail's spam filter has zero false positives as well? If you are sure, how do you know? I can not check my spam folder manually because it contains thousands of mails.
At one point I was checking it religiously but I've come to trust it after never finding a legitimate mail in my spam folder after a long period of time. I still check it from time to time, and again, I don't find legitimate mail tagged as spam.
Most confirmation mails (and the like) end up in my Gmail junk folder. E-Mails from normal people never. And for me it has just become a automatic process to look in the junk folder for those.
I don't bother obfuscating either. I do get spam occasionally, but the gmail algorithm learns so once I mark a particular type of spam as spam it never comes up again.
I can't use gmail because I have the requirement to create email addresses on-the-fly. I have my own domain and can do that. The result is I need good spam filtering.
My filtering now achieves around 99.6% filtering, and about 1 detected false positive per month. It would be interesting to see how gmail copes with my 2400 spam per day, and what accuracy it achieves, but it's a non-starter because of how I use email.
I do this all the time with Google Apps to track who sells my email address, creating a new one for each place I signup.
1. Create a catch-all address for the domain you're going to use that isn't the normal postmaster one.
2. Pick a three- or four-letter combination of letters that rarely appears in normal conversation (like dcj, for example).
3. Set a mail filter on the catch-all account to forward all mail that has your three-letter combination as a part of its recipient list to your real address.
This means that for every service you sign up for, you can create a new address (I always use domainname.code@mydomain) that is trackable and gets to you. For example, I just signed up with Via Rail's online system - using the address viarail.dcj@mydomain. It will get forwarded to my real address (since it's got the dcj in there), if I start getting spam on it I'll know where they got the email address from, and if it gets really bad I can just change my filters to block all email to viarail.dcj@mydomain.
You could do something with Gmail's plus-addressing, but I find that many services don't accept those email addresses.
Yahoo Mail offers a service called AddressGuard that does exactly this, but it's only available to paid accounts. You can also easily use these as your from address, so even in direct correspondence, you still shield your primary address from the recipient. (This allowed me to verify that eMusic sells their subscriber list to spammers.)
A free alternative is SneakEmail (http://www.sneakemail.com) which allows you to set up disposable addresses that forward to your primary account, and allows you to set up pre-forwarding filters. They also create a unique address for the sender of each email, and you can set up your SneakEmail filters to insert this as the reply-to address of each email you receive.
SneakEmail is great; it's what I use when I'm seriously suspicious of who I'm sending mail to.
For 95% of the things I sign up for, however, I'm not that paranoid - the slight decrease in security is offset by the added convenience of not having to log into a third-party service (like SneakEmail) to get what I'm doing done.
Good idea. For those of us who use an @gmail.com address, here's what you can use in lieu of plus signs, which as JimmyL said often don't work:
Gmail lets you insert periods between the letters of your username. So if my email address is someusername@gmail.com, the following are valid variants of my email address:
some.username@gmail.com
some.user.name@gmail.com
s.omeusername@gmail.com
And so on. So you can use variants for different services you sign up for. Also note that you can substitute @googlemail.com for @gmail.com.
I use a custom domain, but have it set up to forward all addresses to Gmail, mainly to use their spam filter. I'm not sure what your particular use-case for the on-demand addresses is, but you might be able to set up some Gmail label rules to sort it for you on that end too.
The only downside is that you have to manually verify your custom domain's 'sent from' addresses in Gmail, so you can't easily reply from arbitrary addresses.
I get around 2400 spam a day. I've tried three different spam filters recommended to me by people I trust and who generally know about these things, and they get about 97% to 98% accuracy. Worse, they produce false positives. With 50 spam per day, plus having to trawl through the spam bin to look for the false positives, I decided to write my own.
My spam filter is highly tuned to my traffic and I get about 10 spam through per day. More, there are about 2 false positives per month, although that's very hard to quantify.
The problem with putting up a form is that people want a reply, and yet they can't type their own email address properly. About half the emails I get through my various forms have subtle and not-so-subtle misspellings of the return address, and it can cost me hours to track them down.
No, obfuscated email addresses is still my best tool in this situation.