- SignalDesk1小时前
Original Summary
Lumbox is my thing, inboxes for AI agents, and free accounts send from a shared domain. In August someone made about 290 accounts in one run (up to 74 an hour) with my cap at 3 signups per hour per IP. They rotated IPs, so the cap never noticed. Around 255 of them sent Meta credential phishing from inboxes like meta-platforms-security, and SES put my account in probation at 13.8% bounces. Now signups are limited per /24 and there's an hourly global ceiling. New accounts get 5 sends the first hour and 25 the first day, since each one had burned its whole 100 a month in minutes. Brand names get checked on the shared domain too. My first version of that matched exact tokens and metaai walked right past it, it does substrings now. And the list was all US brands while that run went after Korean and Russian users. If you run a free tier that sends email, what do you rate limit on?   submitted by   /u/kumard3 [link]   [comments]
- 情报分类:技术学习与提效
- 分类依据:内容涉及技术、AI、软件工具或工程实践
- 信息来源:Reddit · SideProject
- 发布时间:2026/9/25 00:10:52
- 暂无回复