How to handle lots of spam
We've got about 2,000 pending spam comments, mostly as replies to existing threads. First off, congrats for the detection rate. With Tender's recent spam filtering additions, we saw few or no false negatives, and I just skimmed the first few pages of spam and there's no false positives either.
What's the best way to delete these? It would be about 70 pages of Next Page -> Select All -> Delete, and I expect this volume to continue. I'm fine doing that, just wanted to see if there's a better way right now. Thanks.
Discussions are closed to public comments.
If you need help with Tender please
start a new discussion.
Keyboard shortcuts
Generic
| ? | Show this help |
|---|---|
| ESC | Blurs the current field |
Comment Form
| r | Focus the comment reply box |
|---|---|
| ^ + ↩ | Submit the comment |
You can use Command ⌘ instead of Control ^ on Mac

1 Posted by Troy on 15 Oct, 2012 04:23 PM
Wow, my ticket about spam got spam. XRumer and the like just love anonymous comment forms..
2 Posted by Julien on 15 Oct, 2012 07:51 PM
Hi Troy,
We do need an "empty spam" button at some point, but in the meantime, I can manually empty your spam folder for you. This will delete everything.
The workflow I recommend is to clear your spam folder once, inbox-zero like, and then go through your spam folder every day, restoring things that shouldn't be there, and deleting the rest. It is much easier to spot false positives when you only have a few items to look at, as opposed to pages and pages.
So just confirm with me that you want the folder and emptied and I'll do it. And don't hesitate if you have any other question.
Cheers!
3 Posted by Troy on 15 Oct, 2012 08:09 PM
Hi Julien,
Yes, feel free to empty it. Thanks.
As far as inbox/spam folder zero, it was at zero a month or two ago. I'm not sure what the story is with all of these (recent, recategorization, something else), but we normally check it regularly.
BTW, I made this ticket public again. Tiny suggestion: when you make a ticket private, mention it in the reply.
Thanks,
Troy
4 Posted by Julien on 15 Oct, 2012 09:28 PM
Hi Troy,
Your spam folder is empty.
I usually mark most conversations as private out of habit, but point taken. I'll be better next time.
Let me know if you need anything else.
Julien closed this discussion on 15 Oct, 2012 09:28 PM.
Troy re-opened this discussion on 08 Nov, 2012 01:26 PM
5 Posted by Troy on 08 Nov, 2012 01:26 PM
Hey Julien, if it's useful info, we're averaging about 20/day (~475 in ~23 days) with a fairly low-profile site. They're all Web comments.
6 Posted by Christophe on 08 Nov, 2012 05:21 PM
Hello,
We are also experiencing more and more spams... May be 3-4 weeks ago we had a rate of approx 20 spams per days. We are currently at 50 spams per days...
I have the feeling that the spam level where spam are considered to be deleted is to high....
Do you think there can be a solution on your side (eg lowering the spam level... or anything better)? as the spam level is becoming difficult to manage...
thanks
christophe
7 Posted by Julien on 08 Nov, 2012 10:04 PM
Hi Christophe,
We have been discussing spam a lot recently, and there are a couple of minor changes I want to work on to make the experience of reviewing/emptying spam a lot easier.
I'd like to know what exactly you'd want: make it easier to review spam, emptying the spam folder, having spam auto-delete after X time, get less spam to start with?
We already use a number of techniques to limit spam before it even gets to your site, and I feel like we have a pretty good detection level in terms of false positives and missed spam messages, but if spammers try harder and/or your site becomes more popular, you will get more spam, even if it goes directly to the trash.
I'm also not quite sure what you mean by "the spam level where spam are considered to be deleted is too high". Can you expand on that? Ie, what is really your problem: spam not correctly identified, or spam correctly identified but too much of it, or maybe a little of both?
Thanks!
8 Posted by Troy on 09 Nov, 2012 02:53 AM
Does it do any SpamAssassin-style scoring? My ideal workflow would be to sort by score instead of by date, look through the lowest-scoring page or two of comments (until I'm basically looking at a full page of spam), and then use a button to mass-delete everything that's left.
I'd end up reviewing the 10% or 20% that were borderline, and deleting the rest in one fell sweep.
Sort of related: I'd be curious to see the source IP of comments and a country-level geocoding of it (in the admin view). I can't act on it, it's just interesting to see where the sender (or their botnet hosts) live.
Troy
9 Posted by Christophe on 09 Nov, 2012 08:59 AM
@julien;
10 Posted by Troy on 09 Nov, 2012 02:14 PM
I agree that the spam filter is very good. We have about the same false positive rate as @christophe.
11 Posted by Julien on 09 Nov, 2012 06:29 PM
Hey Troy, Christophe,
Thanks for the feedback. I'll make some changes in the next few days and I'll get back to you.
12 Posted by Julien on 12 Nov, 2012 08:12 PM
Hey Troy, Christophe,
Just a quick update: we fixed the "delete spam" behavior so that when you delete spam, they actually disappear from your spam folder, and you don't get the same page reloaded with the same messages you just deleted (that was quite a drag). We also increased the pagination from 30 to 50, so it should make it faster to skim through a lot of content.
We have a few other ideas, so I'll keep you posted when we make more changes.
13 Posted by Troy on 12 Nov, 2012 08:25 PM
Nice! The bigger pages are great. As far as I'm concerned, if that value
was 100, you'd be able to punt on this indefinitely (for our spam volume).
Skimming ~4 pages of spam every month and mass deleting each page is
totally tolerable, especially since that manual once-over means zero false
positives.
Troy
14 Posted by Troy on 12 Dec, 2012 04:19 PM
Making this ticket public again. Somehow it got marked private.
15 Posted by Troy on 12 Dec, 2012 04:20 PM
If anyone comes across this, the status quo with the changes above is pretty darn good. It takes less than 5 minutes/month now.
Troy
16 Posted by Richard Parslow on 09 Jan, 2013 04:00 PM
Hi
First of all I echo the comments about the efficiency and accuracy of your spam system: we see hardly any false positives and hardly any spam messages get through to the forum.
Like others here, we have seen massive quantities of spam from time to time. Changing our settings from Brain Busters to reCAPTCHA (on your recommendation on a separate discussion) definitely helped. Now however we are seeing increased numbers of spam messages – back up to c100 per day (we are deleting them several times a day).
Since the clever spammers appear to have found a way to break reCAPTCHA, is there anything else we can do?
I would like to permanently exclude ALL originating emails that have appeared in the spam folder and been selected for permanent deletion (using the 'Delete Forever' button). In other words, once I have identified a spam originator, your system should not even forward messages from that address to our spam filter – it should just delete them straight away.
Lots of these are from gmail and other similar 'open' email URLs (yahoo et al). Although I realise that it is very easy to create a new email address to use for spamming, can we not identify the originators by IP address – or have some way to report them to their ISP automatically when we Delete forever?
Cheers
Richard
17 Posted by Troy on 09 Jan, 2013 04:57 PM
One more for being able to see the source IP of comments posted from the Web. I don't want it for reporting to ISPs, I'm just curious where they're coming from.
18 Posted by Julien on 10 Jan, 2013 01:23 AM
Hi Richard, Troy,
Glad to hear it :)
We just deployed a new setting that may help, depending on your situation. Basically, you can now restrict replies on public discussions to staff and the people already involved in the discussion. That allows you to keep discussions public for transparency and as a knowledge base of sorts, but should totally stop spam on existing discussions.
Not all sites will be able to use this, but for those that can, it should help.
Unfortunately, that is not always a good idea. People sometimes clear their spam folder without reviewing it, and that could lead to some legitimate users being marked as "straight delete", which is bad.
That being said, we can examine spam comments in different ways and use multiple criterias to delete a number of them directly. We'll explore that road in the future.
We can't really do that. However, we already use https://www.projecthoneypot.org/ to identify spammers. This means that when some IPs are identified as spammers across other sites, we get that information as well.
I am against exposing the IP of commenters, as there are a number of privacy implications to that.
That's it for today. Keep the conversation going, and I'll post updates when appropriate as well.
Cheers!
19 Posted by Troy on 10 Jan, 2013 04:28 AM
On the privacy implications, that's my problem more than (and quite possibly to the exclusion of) Tender's. Or thought of another way: I can't point fingers at Tender if a problem comes up; I'm accountable. In the same vein, it's my choice what amount of information is appropriate to retain as long as it's not deceptive and within the range of what visitors expect.
As it happens, the entire Internet logs IP addresses. That's not a surprise to visitors, and I think most would be surprised to find out that site administrators can't easily see their IP.
I'd be completely fine with Tender stating that IPs may be retained in its own privacy policy. I expect that they're being kept already anyway.
20 Posted by Troy on 10 Jan, 2013 04:30 AM
Another way to think about this: a vendor is telling me that it doesn't trust me with what is basically my own information.
21 Posted by Richard Parslow on 10 Jan, 2013 01:44 PM
While that is indeed a potential issue, it is still one that is under the user's control. If I make a mistake and wrongly identify a legitimate user as a spammer, that is down to me. I would certainly prefer never again to hear from anyone I have identified as a spammer; and I'll take the risk that someone here might make a mistake!
Nice idea; it is of limited value though. Nearly all our spam messages are ones that have created their own NEW discussions.
I also support Troy's position:
Since IP addresses are open and easily available to the recipient of the email, collecting them and using them to identify spammers is definitely not a privacy issue as such. Of course if the spammers use some technology to mask their IP addresses it will not be effective; I understand however that most of them do not take this precaution.
Cheers
Richard
PS We had 46 (forty-six) spam messages this morning, 2 false positives (from the same person) and 44 that created their own new discussions. How are these breaking reCAPTCHA?
22 Posted by Christophe on 10 Jan, 2013 02:01 PM
Hello,
FYI: we used to have lot of spam too. We turn our support site in private mode only (we wanted our customers to use their credential associated to our product, for marketing reasons).
So now we just have no more spam at all.
christophe
23 Posted by Richard Parslow on 10 Jan, 2013 02:41 PM
Hi Christophe
Yes, I can see that such a policy would definitely exclude spam!
However we want to have a completely open customer forum, which people can access and browse before they buy. Apart from the marketing benefits (people can see how quickly we respond to support issues!), should people have any issues with the free trials, it is very helpful if they can see any existing public discussions, which may provide the answers they need without needing to contact us.
We (and post originators) can always make any confidential discussions Private; and incoming emails (to [email blocked]) create new Private discussions by default.
So we really need a way to nail the spammers permanently and prevent originators from posting again from the same email address (and preferably from that IP Address!).
Richard
24 Posted by Richard Parslow on 10 Jan, 2013 02:47 PM
PS I noticed that some spam messages were attempts to post to existing discussions that had already been identified as spam(!). So I have changed the settings to "restrict replies on public discussions to staff and the people already involved in the discussion" as recommended – we'll see if that makes any difference...
25 Posted by Julien on 10 Jan, 2013 06:30 PM
Hi all,
Thanks for all the thoughtful comments.
Christophe: private indeed cuts spam entirely :) but Richard is right, it is not practical for everyone.
Troy, Richard: I'm open to exploring the idea of exposing IPs, though we'll need to review our privacy policy and I'll need to discuss it with the team. How do you imagine you would use that information? It seems of limited use in the UI. We do not offer API access to the spam or trash folder so that would be of limited use as well. Can you tell me how you'd ideally like to use it?
Finally Richard, can you expand on "post to existing discussions that had already been identified as spam(!)". That looks like a bug to me,and I'd like to know more.
Cheers!
26 Posted by Troy on 10 Jan, 2013 06:45 PM
I'm not totally sure how I'd use it until I see it :-) I do know that I'd reverse resolve the first half dozen spam source IPs to see country of origin and casually skim for patterns. I'd also have an idea how many distinct senders we have, since i see loose patterns now (many flagged comments from what looks like the same XRumer instance).
I've had a couple cases where I had to ask Tender staff for SMTP headers to an email ticket, but I don't know whether that translates to Web comments. I have no plans to email ISPs; it's a lost cause and waste of time.
I think it's more that my starting point is that source IP is important enough that it's just something to include as general practice (even if it's buried), not to solve a specific use. Some uses for it might emerge or it might end up ignored.
27 Posted by Richard Parslow on 10 Jan, 2013 06:50 PM
Hi Julien
Thanks for the response.
>How do you imagine you would use that information [IP addresses]?)
I probably wouldn't use it at all – since you would be collecting it I was anticipating you would pass it to the relevant ISP/email provider and ask them to delete the email account and bar any others at that IP address from creating new ones on their URL (eg @gmail.com) – although I note from Troy's subsequent comment that this is probably useless :-(.
>can you expand on "post to existing discussions that had already been identified as spam(!)"
Dang, I just deleted load more. I'll send details when more appear (shouldn't be too long – we are receiving tens per hour...). It may be that these were in fact NEW discussions, just using the same Subject as previous spam discussions.
NB barring posts to existing discussions has made no difference at all.
Richard
28 Posted by Troy on 10 Jan, 2013 06:58 PM
@Richard what you describe about ISP reporting isn't feasible. Aside from the difficulty of finding the right ISP contact (which isn't always
abuse@), rate-limiting reports to a given provider (forwarding 50 emails helps no one), if it was possible for ISPs to keep spammers from creating those accounts, they already would. They don't want spammers any more than we or Tender do.For savvy ISPs, forwarding the email to them is not valuable. For clueless ISPs, forwarding the email to them is pointless.
29 Posted by Julien on 10 Jan, 2013 07:12 PM
Hi Richard,
The "prevent newcomers on discussion" prevents spam on existing discussions but specifically prevents one thing: when one spam comments gets through on an existing discussion, which happens rarely, but sometimes, customers get a notification, which sucks. On sites that can use this setting, it prevents this.
As you noticed though, most spam comes as new discussions, so it's of limited use for the rest.
Let me know when/if you find an example of a comment coming in to an existing spammed discussion.
30 Posted by Richard Parslow on 12 Jan, 2013 04:58 PM
@Troy
Thanks for the follow-up
@Julien
>Let me know when/if you find an example of a comment coming in to an existing spammed discussion.
OK, it appears that these are in fact just similarly-named discussions with lots of common elements.
We are still getting too many messages (in spam folder): now HUNDREDS per day. Why has reCAPTCHA suddenly become ineffective in the last couple of weeks? Brain Busters is no better. Is there another "human check" you could use?