• Hi there, my hosting provider emailed me that your plugin is directly responsible for an unhealthy use of resources. I checked and indeed, a lot of spammy email adresses (checked on https://cleantalk.org/blacklists/) are being added to the subscribers list. Today a total of 161 confirmation mails (!) have been sent on this account. Even when your plugin removes the registered email adresses after 4 weeks when theyre not activated, they still allow for too much resource use on the server.

    For now, unfortunately, I chose to disable the plugin because it has not been in use on this specific site. But I find it a waste to stop using this plugin on all of my sites. Therefor I am urging you to make a reCAPTCHA solution possible.

    Please share your view (and possible future solutions) on this matter.

    Thank you.

    • This topic was modified 7 years, 1 month ago by Ramzii.
    • This topic was modified 7 years, 1 month ago by Ramzii.
Viewing 12 replies - 1 through 12 (of 12 total)
  • @ramzii

    Personally speaking I have to say that I hate CAPTCHA and I actively avoid forms that use it where I can. That’s just me though!

    I use Bad Behaviour and that stops a huge amount of bad bot traffic to your site.

    If that’s not enough, there is a lockout filter in the code (in seconds) that checks if the end user IP address has submitted an email address recently and blocks them for submitting more until the lockout period has passed. This feature is off by default but it sounds like it might help you.

    I have the same problem, I also received a message from the provider and even turned off the site. If you do not want to use a recaptcha, enter any code that you need to respond to, such as a simple calculation like 5 +3, and so on. I have some domains blocked, but it’s very restrictive …

    @rehakk

    There are simple antispam measures already in place on the form and adding CAPTHCA is entirely possible.

    In the meantime I’m suggesting things I’ve done that have protected my sites from these issues and also pointing out features that already exist in Subscribe2 that may be useful.

    If the reCaptcha module could be added, it would be great! So far, I have secured the site with the recommended “Bad Behavior” plugin …

    Thread Starter Ramzii

    (@ramzii)

    Thank you for your swift reply.

    I am also favoring a reCAPTCHA. Perhaps the invisible solution Google offers?

    https://developers.google.com/recaptcha/docs/invisible

    Please keep us updated. Thank you.

    sffandom

    (@sffandom)

    I will stop using and promoting this plugin if you add reCAPTCHAs without making them optional. That’s a TERRIBLE solution. Spammers have been able to contract with services in Bangladesh and India for years that get past the puzzles.

    Thread Starter Ramzii

    (@ramzii)

    Thats quite a bold statement. Got any sources Michael?

    Ryan Zook

    (@zookcomputer)

    I agree that spam subscription requests are a huge issue. I use SparkPost for email delivery and the many requests (100s in several days) to confirm spam subscriptions has hurt my sender reputation. I’m also using Bad Behavior and it’s not stopping the spam subscriptions.

    Yesterday I set up Anti-spam by CleanTalk, an anti-spam service that is blocking 100% of spam submissions so far. It’s not free but cost is minimal (currently $8/year/site).

    An optional reCAPTCHA integration would be appreciated.

    Travis

    (@lowburn88)

    Any other free services to stop the spam registrations? The “BadBehavior” is not working as previously suggested. I’m getting close to 40 bogus subscriptions per day.

    I appreciate the Anti-spam by CleanTalk recommendation. I just want to exhaust any other free options that may be available first.

    Thread Starter Ramzii

    (@ramzii)

    Im still wondering if the plugin author is building a optional recaptcha. Spam isn’t going away judging by our experiences.

    Is there an update on this problem? WE have hundreds of new subscribers, mostly Russian IPs and BlueHost has stopped sending any blog post updates. Subscribe2–>Send Email still works so we’re thinking BH has shut off the posts due to confirming emails.

    I would block the Russian services by IP address (CIDR blocks).

Viewing 12 replies - 1 through 12 (of 12 total)
  • The topic ‘Heads up; spam is a serious issue’ is closed to new replies.