So some spam signups just happened (all [email protected] format e-mail) This caused bounced mail to increase, causing Mailgun to block our domain to prevent it getting blacklisted.

So:

  • Mail temporarily doesn’t work
  • I closed signups for now
  • I will ban the spam accounts
  • I will check how to prevent (maybe approval required again?)

Stay tuned.

Edit: so apparently there is a captcha option which I now enabled. Let’s see if this prevents spam. Registrations open again.

Edit2 : Hmm Mailgun isn’t that fast in unblocking the domain. Closing signups again because validation mails aren’t sent

Edit 3: I convinced Mailgun to lift the block. Signups open again.

  • Philip@endlesstalk.org
    link
    fedilink
    arrow-up
    26
    ·
    1 year ago

    I ran into the issue on my instance as well, but checking the Captcha option in admin settings, stopped the signups for me.

      • Ruud@lemmy.worldOPM
        link
        fedilink
        English
        arrow-up
        4
        ·
        1 year ago

        I did it in the database, so if you can access your database I can assist.

        • aranym@lemmy.name
          link
          fedilink
          English
          arrow-up
          1
          ·
          edit-2
          1 year ago

          My instance also experienced this. I’m the only active user (I made it a day ago), but the user count is up to 2K now. It stopped after I enabled captchas, but I want to remove these spam accounts so they don’t cause issues in the future.

          I don’t even have a slight clue as to what I should look for in my database.

          • darkfoe@lemmy.serverfail.party
            link
            fedilink
            English
            arrow-up
            2
            ·
            1 year ago

            If you haven’t figured it out yet or got a response yet, hop onto the instance admin group on matrix for Lemmy (details are on the GitHub or join Lemmy page somewhere I believe) and one of the many other folks running instances can probably walk you through it

  • Sorenchu@lemmy.world
    link
    fedilink
    arrow-up
    9
    ·
    1 year ago

    Sounds frustrating. Thanks for doing what you do and letting us join your server! Hope the captcha works out.

  • ThesePaycheckAvenging@kbin.social
    link
    fedilink
    arrow-up
    4
    ·
    1 year ago

    Lucky me, I guess, since I use a masked email address that looks fake too (anon addy). I really dislike to give my email address when testing Reddit alternatives.

  • fsk@lemmy.world
    link
    fedilink
    arrow-up
    4
    ·
    1 year ago

    I solved this problem once. What you do is have a custom captcha that you code yourself. It can be as simple as “What is 2+3?” and have 10-20 questions that you rotate between. Most spammers will be too lazy to update their spambot.

    • Sir_Kevin@lemmy.world
      link
      fedilink
      arrow-up
      1
      ·
      1 year ago

      I made one that phrased it as “The sum of 2 and 3”. Weeds out bots and less sophisticated people.

    • lwuy9v5@lemmy.world
      link
      fedilink
      arrow-up
      0
      ·
      1 year ago

      fwiw - there’s always an arms race between spammers and people trying to not get spammed. It’s often better to use off-the-shelf captcha’s or something as there are people who are able to put a LOT MORE resources into it (like Google, who has billions of dollars on the line to prevent ad-fraud and identify bots)

      • fsk@lemmy.world
        link
        fedilink
        arrow-up
        1
        ·
        1 year ago

        I used a custom captcha for my personal WordPress blog. It eliminated all the spam. (Fun fact: The spammers know how to work around most anti-spam WordPress plugins. If you roll your own, they aren’t going to update their spambot for one blog.)

        I also used a custom captcha at work. We couldn’t use 3rd party filters because it was marking our customers’ comments as spam! The custom captcha also eliminated all the spam.

        There’s also a problem with using 3rd party spam services. You have to give them all your data. You also usually have to pay for it, which can be a problem when you’re working for people with a tiny budget.

  • rastilin@kbin.social
    link
    fedilink
    arrow-up
    4
    ·
    1 year ago

    Last time a website I was managing was bombarded with spam signups, I set up a regular expression to check for the incredibly distinctive format the spammers were using… then it reports success but doesn’t actually create the account or send an email. Spam problem over.

  • EvilMonkeySlayer@kbin.social
    link
    fedilink
    arrow-up
    4
    ·
    1 year ago

    User on kbin here, just tried to sign up to lemmy.world… looks like everything crashed and burned when tried to sign up there.

  • Emanresu@lemmy.world
    link
    fedilink
    arrow-up
    3
    ·
    1 year ago

    I got in just in time! For the record, the sign up date seems to be broken. My account is less than a day old and it says I’ve been here since the 14th. Unless maybe it counts cookies or something?

  • Argyle13 @lemmy.world
    link
    fedilink
    arrow-up
    3
    ·
    1 year ago

    I was trying to open my account just when it was closed earlier. When I pressed the button to create it I only got and enless “charging” animation. But when it reopened again, I just started the process again, and was as easy as a breeze and extemely fast. Glad to be here! (and this is my firts post)