This article explains what subscription bombing is, how to protect your forms, and what to do if you are targeted.
| Administrators | ✓ | |
| Company Managers | ✓ | |
| Marketing Managers | ✓ | |
| Sales Managers | ||
| Salespersons | ||
| Jr. Salespersons |
| Tip: Are you looking for information about Constant Contact’s Email and Digital Marketing product? This article is for Constant Contact’s Lead Gen & CRM product. Head on over to the Email and Digital Marketing articles by clicking here. Not sure what the difference is? Read this article. |
Subscription bombing (also known as form abuse, list bombing, or mail-bombing) is an automated attack where spambots submit fake or unauthorized information to your online forms en masse.
The intended use of subscription bombing can include:
An unchecked form abuse attack can have severe and lasting consequences for your email marketing efforts. The chain reaction of damage includes:
List Contamination: Your contact lists are flooded with thousands of fraudulent email addresses, leading to wasted resources and skewed analytics. Sending to these fake addresses results in a surge of spam complaints, spam trap hits, unsubscribes, and hard bounces.
Reputation Damage: Internet Service Providers (ISPs) like Gmail and Yahoo interpret these negative metrics as a sign that you are sending spam. Your sending IP address can be blocked or blacklisted by major ISPs, crippling your ability to deliver emails to legitimate customers and leads.
You have several powerful tools to defend against subscription bombing. Proactive protection is the best strategy.
Use hidden fields. A hidden field is a form field that is invisible to human users but visible to bots. If this hidden field is filled out, you'll be able to identify the submission as spam.
Use opt-in methods, such as double opt-in. Your leads need to confirm that they want to receive your content, known as opting in. This is normally done by having leads click a link to confirm that they want to remain subscribed to your emails. If you have a subscription bombing event, only the confirmation email will be sent. This minimizes the risk of repeated email sends to fraudulent email sign-ups.
Look for data abnormalities. Watch for data abnormalities. Spambot activity often includes:
Gibberish names (e.g., "jdfg sdfg").
A sudden influx of sign-ups from domains in countries you don't serve.
A rapid, unnatural spike in submissions over a short period.
If you suspect your forms are under a subscription bombing attack, act immediately to mitigate the damage. Follow these steps:
Doing this during a subscription bombing event will help to prevent further submissions and email sends. Only after you have cleaned out your database and secured your email forms should you restart your forms and automation events.
Contact Support for more information on modifying Lead Gen & CRM settings or disabling features during a subscription bombing event.
Copyright © 2025 · All Rights Reserved · Constant Contact · Privacy Center