Anyone from instagram reading?

bzs at bzs at
Wed Dec 2 19:03:13 UTC 2020

Instagram is enabling an harassment attack.

They are sending out "change in terms of use" statements, you've
probably received it.

Apparently they will send them to unconfirmed accounts, en masse.

So for example you own and all email for *
goes to you.

And there are no legitimate email accounts for that domain so can't
possibly be confirmed accounts.

So you are receiving a firehose of "terms of use" emails to
randomstring at apparently being generated by a script,
random+domain at domain like (from the actual emails tho not

 qiuncjhuxeexample at
 mazhjkmthexample at

and so on and so on, each one different.

  SOLUTION: Stop sending your terms of use update messages to
  unconfirmed accounts. It's a trivially abused harassment vector as
  we're seeing.

        -Barry Shein

Software Tool & Die    | bzs at             |
Purveyors to the Trade | Voice: +1 617-STD-WRLD       | 800-THE-WRLD
The World: Since 1989  | A Public Information Utility | *oo*

More information about the NANOG mailing list