eCards: How do you stop abuse?

Options

Has anyone else experienced abuse of their eCard campaigns?

We have noticeed a large amount of fradulent users going to our public eCard page and registering for the site and sending cards. This causes major headaches when we sync the next day to our offline database and we have to delete the new record out of the entity batch.

I was wondering if there is comething like CAPTCHA or some other challenge question that we could add to the eCard campaigns?

Thanks!

Tagged:

Comments

  • Hello,

    Occasionally, people will use the Tell-A-Friend links or eCards to send emails that aren't necessarily intended to tell friends about your site. This is unfortunately a loophole that may allow spammers to use your site for nefarious purposes, while making it appear to be coming from the site directly.

    It is rare for us to encounter these situations, but when we do see them, we take what steps we can to limit the problem. For now we have put in place a limit on the number of eCards or Tell-A-Friend (TAF) any one constituent can send in an hour. The limits in place allow constituents to send up to 3 eCards or TAF an hour and up to 10 email addresses at a time. (This means either 2 eCards and 1 TAF or just 3 TAF or 2 TAF and 1 eCard, etc.)

    Some other limits that we can put on this are:

    1) Turn off Tell-A-Friend entirely or cease to use eCards - the obvious (but not always ideal) solution.

    2) Specify fixed text that appears in the body of the Tell-A-Friend (eCard subjects can be fixed, but not the message body). This would completely remove the ability for someone to change the message sent by the Tell-A-Friend system.

    3) Require that a user be logged in before they can send a Tell-A-Friend. This would let us (at the very least) have better tracking to determine who was causing these - and cause more frustration on the part of the spammer as they try to abuse our system. This can be set via a Sitewide Data Parameter. If you don't have access to this option, please let Convio know, and we'll enable it for you.

    4) Ask Convio to change the Max Messages Per Site setting. This setting effects the maximum number of Tell-A-Friends that can be sent from the entire site in a set time period (default is 1000 Tell-A-Friends every 60 minutes).

    If you encounter a situation where you believe someone may be abusing the Tell-A-Friend, let Convio Support know. If possible, obtain a forwarded copy of one of these emails (preferably with the email header information such as the sender and reply-to addresses) -- this will help Support verify that this is coming from a Tell-A-Friend system.

    Regards,

    Steve

Categories