Methodology

This page is a placeholder summarizing the approach described on the homepage. A detailed, technical methodology page will replace it as the investigation pipeline matures.

Evidence chain

Every case follows the same sequence: identify suspicious activity, preserve original evidence exactly as received, verify sending infrastructure and attribution, submit provider-appropriate complaints, record acknowledgments and responses, independently check outcomes, and only then publish a sanitized, evidence-backed summary. See the "Abuse Accountability" section on the homepage for the full sequence.

Attribution confidence

Spam Hunter distinguishes sending networks, forwarders, registrars, and hosting providers from each other, and assigns each attribution an explicit confidence level rather than treating every technical signal as proof. Shared infrastructure operators are never automatically blamed for one customer's abuse.

What "verified" means here

A reported outcome (for example, a takedown) is only published once independently re-checked. A link or page becoming unreachable is not by itself treated as proof that a provider acted on a complaint.

Sample, not census

Any statistics eventually published reflect the sample of messages Spam Hunter has actually analysed — not an estimate of global spam volume.