changelog

The firewall is smarter and stronger

August 21, 2025

demo.buttondown.com/settings/basics
This is a live demo. You can view this page on our live demo site, too.

We've been thrilled with the response to the Firewall, and we've been working hard to make it smarter and stronger over the last few months. The game of cat and mouse is a never-ending one, and we're always looking for ways to make it harder for spammers to get through!

To that end, we've added a handful of new checks to the firewall. You don't need to do anything or change anything to take advantage of these new checks, but we're excited to share them with you:

  1. Lookalike IP scoring: We've added a new check to the firewall that looks at the IP address of the subscriber and scores it based on the number of low-quality subscribers associated with that IP address. (If someone subscribers from 41.38.113.62 and that IP address also has 50 other subscribers which have never confirmed their subscription, that's a pretty good indicator that the subscriber is a bot!)
  2. Better domain-level provenance: We've deepened our list of problematic domains to include domains that are not just disposable but also have a history of being used for spam or other bad behavior.
  3. String-based checks: We've added a new check to the firewall that looks for strings in the email address or the newsletter name that are commonly used by spammers. The human eye is great at many things that computers are not; gdkkdkbjjnd@gmail.com is obviously garbage to a human, but it's less obvious to a computer. We've been historically reticent to try and score addresses based purely on the content of the email address itself, but we've found a really strong set of patterns that are high-signal without too many false positives.

Updated on

August 21, 2025

Related changes

Written by

Justin Duke

Justin Duke is a software engineer, lover of words, and the creator of Buttondown.