What is Snowshoe Spamming?

Mary McMahon

Snowshoe spamming is a spamming technique in which the spammer uses a wide array of IP addresses in order to spread out the spam load. The large spread of IP addresses makes it difficult to identify and trap the spam, allowing at least some of it to reach email inboxes. For companies which specialize in trapping spam, snowshoe spamming is particularly noxious because it is difficult to trap it with traditional spam filters.

Snowshoe spammers use several IP addresses to spread spam.
Snowshoe spammers use several IP addresses to spread spam.

The snowshoe is actually an excellent analogy to describe this spamming technique. Snowshoes are designed to spread a large weight across a wide area so that the wearer does not break through crusts of snow and ice, and snowshoe spamming distributes a broad load of spam across a varied array of IP addresses in much the same way. Like all spammers, snowshoe spammers anticipate that some of their unwanted emails will be trapped by spam filters. Snowshoe spamming gives more email a chance at getting through to an inbox, where it can reach a computer user.

Setting up a snowshoe spamming operation requires some resources and knowledge, as the spammer must have access to an array of IP addresses. Snowshoe spammers typically use an assortment of domains, which may be linked to different servers and providers to further spread the spam load. In a sampling of emails sent by a snowshoe spammer, repeating IP addresses are fairly rare, which means that filters must focus on the content, rather than the sender, to trap spam.

Legitimate providers of email services use a very narrow range of IP addresses for sending email. This is generally viewed as a mark of integrity, as is the use of clear disclosure about who owns the originating domain. By contrast, snowshoe spamming often involves domains which are hidden behind layers of anonymity, making it difficult to track down the owner and report abuse. Especially in nations with anti-spam legislation, tracking down the parties responsible for spam, spyware, and other malicious activities can be extremely difficult, because perpetrators are good at covering their tracks.

Several anti-spam attempts have focused on targeting specific domain registrars and hosts. Certain registrars are infamous for harboring spammers, and by identifying large numbers of spam sites in their client lists, anti-spam advocates hope to take down those sites or humiliate the registrar into tightening its terms of service. Snowshoe spamming sometimes exposes a systemic problem with a particular host, as anti-spam advocates realize that large amounts of spam originates from domains managed by the same company.

Mary McMahon
Mary McMahon

Ever since she began contributing to the site several years ago, Mary has embraced the exciting challenge of being a EasyTechJunkie researcher and writer. Mary has a liberal arts degree from Goddard College and spends her free time reading, cooking, and exploring the great outdoors.

You might also Like

Discussion Comments


@Zeak4hands: It's possible that the free guys are selling your address, but more likely, you're just getting hit by a dictionary type attack, where they send to al, alan, allan, albert, alexis, etc., etc.

In the past two days, my spam filter has blocked almost 4,000 emails, almost all of which were 1 of 2 subjects. The first went along the lines of to: george at domain.com subject: hi george, my name is monica. The next message would be to: george at domain.com subject: hi georgina, my name is joeseph, and so on, totally approximately 2800 messages. Today we caught another 1200 or so, all with the subject "This company is about to go big." Maybe 3 percent of them target email accounts that actually exist on my server in both cases.


Spam really is a kind of arms race, with spammers trying to develop the most efficient way of annoying people, and email companies and network security staff trying to stop them.

And I really don't understand the point. Does anyone, ever click on all those many thousands of spasms? I know once they set up a program, like with snowshoe spamming, they probably don't have to do much to send out to thousands of people, but I still don't see how they could possibly be making enough to justify the effort.

I mean, all they could do is one sale, and if the product is good enough to justify repeat customers, wouldn't they be better off just holding legitimate advertising campaigns?

I'm sure they must make money though, or they wouldn't bother. And I know a lot of spam really exists to insert malicious software onto your computer, so there is that aspect as well.


@zeak4hands - Spammers have all kinds of methods for finding email addresses. Sometimes they just create a program to go through a bunch of random dictionary words in order to find as many emails as they can.

I think using email addresses that you've paid for is a good idea, just because it's harder for them to find them, with a less common domain name. But, it's still possible, of course.

The best defense against spam is to have a decent spam filter.

I still use Gmail and find that it works just fine, because the spam filter is quite sophisticated. I almost never get any spam in my inbox, although I am not all that careful about giving out my email address.


Spam is so annoying! They find your email now matter how new it is -- I did a test.

I went to several email websites and made completely new email addresses. Then I let them sit for a week -- I didn't use them for anything and I didn't sign up for anything.

At the end of the week, I had one spammer on one email address and two on the other. I have no idea how they found the accounts, I suspect that the free email places give their emails out or something. How else could they find my new emails?

I only use email addresses that I pay for now.

Post your comments
Forgot password?