Hacker News new | ask | show | jobs
by maxspero 38 days ago
Hey! Founder of Pangram here. We use Zerobounce and CustomerIO for email validation. I had no idea this was happening. Not entirely sure which one this is coming from, but this is not intentional on our part. Will dig deeper and eliminate the part of the stack that is sending spam — definitely not good that this is happening.
2 comments

I'm reading the ZeroBounce docs and it seems very relevant. Look at this step:

"We recheck all unknown emails using IPs from different geographical locations". This matches exactly what this article describes as getting these emails from a range of locations.

The step before that is just "Proprietary Technology", which sounds like a good cover for what's going on here. How else are you testing an email address after between "real time SMTP server check"?

Follow-up: our vendors have told us that they do not send any emails as part of the validation process. Either somebody is lying, or there's something even weirder going on. We still have more tests to run to isolate which software package it could be.
Update: this is actually ZeroBounce’s Verify+ feature which we figured out after some escalation. It’s now disabled!