Inbound protection against address collectors

Protection AgainstDirectory HarvestAttacks

In a Directory Harvest Attack, an attacker systematically tries addresses against the mail server to uncover valid mailboxes. Conbool MailGuard detects this pattern, throttles the attack and prevents the server from revealing which addresses exist in the first place.

RCPT TO Probing
RCPT TO anna@rejected
RCPT TO info@accepted
RCPT TO m.weber@rejected
RCPT TO service@accepted
RCPT TO xyz123@rejected
Attack throttled

Valid email addresses are the currency for spam and targeted phishing. Directory harvesting is the way to obtain these addresses, long before the first malicious message arrives.

The attack abuses the normal behavior of mail servers. Anyone who targets a non-existent address receives an error message. Anyone who hits a valid address does not. Attackers build a list of real mailboxes from exactly this difference. Effective protection begins by making this difference invisible.

What a Directory Harvest Attack Is

A Directory Harvest Attack, also known as DHA and as a directory attack, is the attempt to determine the valid addresses of a domain. To do this, delivery attempts are sent on a large scale to guessed addresses, for example to common first names, initials combined with surnames or entire alphanumeric sequences. From the server's responses, the attacker deduces which addresses actually exist and fills spam and phishing databases with them.

How a Directory Attack Unfolds

Four phases from the first probe to a finished address list.

1

Guess addresses

The attacker generates large quantities of likely addresses from name lists, initials and fixed patterns.

2

Probe the server

A delivery attempt goes to each guessed address. Often spread across many source addresses to avoid attracting attention.

3

Evaluate responses

A rejection means the address does not exist. An acceptance or another reaction reveals a valid mailbox.

4

Exploit the list

The confirmed addresses move into spam and phishing campaigns or are resold.

Why Directory Harvesting Is Dangerous

The attack itself steals no data, it prepares the actual damage.

Spam and phishing target

Confirmed addresses are deliberately bombarded with malicious messages. Real mailboxes receive significantly more attack attempts.

Load on the mail server

Mass delivery attempts tie up resources and can slow the acceptance of legitimate messages.

Risk to reputation

Uncontrolled error messages and bounces can impair your own deliverability.

Data protection relevance

A harvested list of valid mailboxes is a collection of personal data and a building block for targeted attacks.

Conbool MailGuard

How Conbool MailGuard Protects

MailGuard removes the basis of the attack: the telltale difference between a valid and an invalid address.

Pattern detection

Conspicuous series of delivery attempts to many different addresses are recognized as harvesting and work together with the reputation assessment.

Throttling

Suspicious sources are deliberately slowed down so that probing is no longer possible within a reasonable time.

Uniform responses

Valid and invalid addresses are treated identically in the event of an attack, so the server does not reveal which mailboxes exist.

Recipient verification

Only addresses that actually exist are accepted, without disclosing the existence of individual mailboxes.

Reputation and greylisting

Known attack sources and inconspicuously distributed campaigns are slowed down through reputation and delayed acceptance.

Traceable logs

Detected attacks are documented and available for analysis and audits, without hindering legitimate delivery.

Frequently Asked Questions About Directory Harvesting

What is a Directory Harvest Attack?
A Directory Harvest Attack is an attack that uses mass delivery attempts to guessed addresses to find out which mailboxes of a domain actually exist. The list obtained is then used for spam and phishing.
How does DHA differ from spam?
Spam is the actual sending of advertising or malicious messages. Directory harvesting is the preceding step that first collects the target addresses. Effective protection therefore starts before the wave of spam.
Why is a classic spam filter not enough?
A spam filter evaluates the content of messages that have already arrived. Directory harvesting, however, runs through pure delivery attempts, often with no content at all. It requires a defense at the transport and behavior level, as MailGuard provides.
Does the protection prevent legitimate senders from being rejected?
Yes. The detection targets the attack pattern, not individual messages. Legitimate senders with normal behavior are not slowed down, while suspicious series are deliberately throttled.
Does directory harvesting matter for data protection?
Yes. A harvested list of valid mailboxes is a collection of personal data. Preventing the disclosure of addresses is therefore also a contribution to meeting the duty of care in protecting such data.
Does MailGuard protect even without rebuilding the existing mail servers?
Yes. MailGuard works as an upstream email security gateway. Protection against directory harvesting takes effect without any change to the underlying mailbox service.

Protect Addresses Before the Wave of Spam Arrives

Conbool MailGuard detects directory harvesting and removes the basis of the attack. A conversation shows how protection can be set up for your own environment.