A list growing fast is usually good news. A list growing fast at 3am, with hundreds of new subscribers from the same handful of countries, is not.
What is going on
Bots fill in public signup forms all the time. Some are just testing forms. Some are spammers. The nastiest version is called list bombing: an attacker submits a victim's email address to thousands of newsletters at once, flooding their inbox so they miss an important message, like a bank alert.
Your form becomes one of the weapons. And the victim, who never asked for your email, marks it as spam.
Why it hurts you
- Spam complaints. Mailbox providers watch how many people mark your mail as spam. A wave of complaints from people who never signed up can push your whole domain into the junk folder.
- Bounces. Bots also submit made-up addresses. High bounce rates are another red flag for providers.
- Wasted money. Most email platforms charge by list size. You are paying to email people who don't exist or don't want you.
- Bad data. Your open and click rates drop, and every report you build on the list gets a little less true.
Stop it at the form
The cheapest place to stop a fake signup is before it ever reaches your email platform. When the form is submitted, check the IP:
- Datacenter, proxy or Tor? Very few real subscribers sign up from a rented server. Reject it, or require a CAPTCHA.
- VPN? Plenty of real people use one. Let them through, but require double opt-in.
- Clean home or mobile network? Business as usual.
Keep double opt-in
Double opt-in, where the subscriber confirms by clicking a link, is still the single best defence. But remember that scanners click links too. Make the confirmation link open a page with a "Confirm" button rather than confirming on load. Our post on scanners and action links explains why.
Small effort, big difference
An IP check on your signup form is a few lines of code and adds less than a millisecond. The result is a smaller list that opens, clicks and buys. That is the only kind of list worth paying for.