HACKER Q&A
📣 archon810

Has Gmail's spam filter been defeated by this type of spam lately?


Here's an image of what my inbox looks like daily, for months now, even though I report them every time: https://i.imgur.com/obiChVv.png

I asked this question on Twitter earlier today https://twitter.com/ArtemR/status/1597247578000982016 and a lot of people confirmed their inboxes are also inundated by this type of spam messages as of recent.

Is anyone else on HN affected? I'm hoping to get Gmail engineering's eyes on this, and HN is the best bet to make that happen.


  👤 nullc Accepted Answer ✓
Gmail is pretty poor at discarding spam and becoming exceedingly efficient at discarding important messages. Emails from people I just emailed? Spam. PGP encrypted emails? spam. Emails from officers of the court sending important notices? Spam. Email from friend I've been emailing for a decade? Spam. "Watch me embarrass myself xbr82843 (v1@gr@)" ... not spam. "Your McAfee has expired!" ... not spam.

The fact that plenty of junk is getting through hardly matters though because the amount of important messages getting spamcanned means I have to scan the spambox, making the filtering pointless.

The Gmail search stemmer seems have gotten much more useless too, making it much harder to search for things that have been incorrectly spamcanned. For example, PGP and PHP now stem to the same string. PGP encrypted emails have in my experience never been spam and are almost always important, and gmail almost always sends them to spam for me... but now it's hard to even search the spambox since attempting to do so pulls up zillions of message with "php" in URLs.


👤 archon810
Linkified links, since HN doesn't parse links in submissions.

https://i.imgur.com/obiChVv.png

https://twitter.com/ArtemR/status/1597247578000982016


👤 archon810
This Gmail rule seems to do the trick for now: delete anything that has "To finish setting up your Microsoft account, we just need to make sure this email address is yours"

https://mail.google.com/mail/u/0/#search/%22To+finish+settin...

It seems the spam has something to do with inadvertently confirming new Microsoft accounts or something?

Screenshot: https://twitter.com/ArtemR/status/1597351257370374144


👤 ctslaughter
I am seeing an uptick in Gmail spam. My emails are mostly Kohls and Yeti giveaways. SPF pass/fail is a mix. Most messages appear to originate from a Microsoft hostname. I wonder if these are compromised O365 accounts.

👤 shortcake27
Yeah Gmail’s spam filter has been seriously lacking lately.

What I do is find a phrase I’d never expect to see in any legit email, then set up a filter to delete those emails. You can harden it by using quotes in the filter for an exact match (to avoid false positives). You could also just archive if you’re worried about losing stuff. This has worked pretty well for me.


👤 drstewart
Gmail's spam filter has been horrendous lately (~ couple of months)

👤 archon810
Looks like Outlook is somehow involved, and there are also clear SPF fails and Russian domains involved.

I'm really surprised Gmail isn't treating all these signals as prime spam candidates.

https://i.imgur.com/w0Cqu5l.png


👤 roryisok
Which one are we talking about? Because for me its the middle one - mountains of US conservative propaganda masquerading as investment news, neither of which I have any interest in.

👤 samgranieri
Yes. I get this crap. Yeti, mcafee, dicks sporting goods.

👤 ggeorgovassilis
I observed that when leaving those emails alone they disappear after a few hours. I suspect gmail crowdsources spam detection more now than it used to.

👤 xchip
Same here, I joined Orkut in 2004 and I still get spam in Portuguese.