How Spam Domains Are Detected
Spam is an infrastructure problem as much as a content problem. Behind every spam campaign is a set of domains: the sending domains that originate messages, the link domains that spam messages advertise ("spamvertised" domains), and the redirect and tracking domains that sit between them. Blocking this infrastructure stops spam whether it arrives by email, SMS, comment forms, or social media. Our spam category maps more than 6.8 million such domains.
Detection draws on spam-trap networks, honeypot inboxes, and large-scale message telemetry. Domains that appear predominantly in unsolicited bulk messages, that are advertised in spam bodies, or that host the landing pages spam links point to are scored against volume, recency, and reputation. Newly registered domains used exclusively in bulk mailings are flagged rapidly, before they accumulate a long abuse history.
Spammers rotate domains aggressively and use URL shorteners, open redirects, and snowshoe techniques to spread activity thinly across many hosts. Our pipeline follows redirect chains to the true destination, clusters snowshoe domains by shared registration and hosting fingerprints, and correlates sending and landing infrastructure so that an entire campaign can be blocked from a handful of observed messages.