
SpamLabs (discontinued)
Protect your business against spam users and content
Time to shut down this project!
After a few weeks of actively trying to validate this idea, which included a slight direction pivot (in the same problem space), I was not able to definitely confirm the demand.
I got some verbal encouraging posts from some indie hackers, but it was just in the usual "indie hacker encouraging indie hacker" vibe.
I didn't even manage to get some verbal commitments (which are worthless, by the way) that somebody would say they would pay for something like this.
I slowly realized that the problem I thought was a huge problem was in fact just a slight annoyance that took maybe a few seconds every few days from people. Not enough to justify a 20€/month price tag. And I couldn't go lower with the pricing either due to all the OpenAI API and infrastructure costs.
So here I am now, shutting down the SpamLabs experiment, and moving on to the next idea. When it comes to ideas, I have a ton, but we all know they are worthless without execution.
After recently pivoted the direction of SpamLabs from being an email address analyzer API to a spam filter targeting cold emails, I decided to continue validating this new approach.
The problem is real, I am dealing with it myself: on my work email I am getting some annoying cold emails, trying to sell me all kinds of services: outsourcing, SEO optimization and whatnot.
In the outreach I did previously with the initial idea of SpamLabs, an usual response I was getting was in the lines of "I don't have a problem with fake users, but I am getting spammed by bad grammar SEO sellers all the time". So that was the direction I went by.
How big is this new problem?
Only to find out later than even this problem isn't that big. These cold emails are at best a mild annoyance, and they appear after a certain scale and only if you expose your work email address on a website somewhere.
And in the best scenarios, people are dealing with a few of these cold emails every day. But they get resolved in a few seconds.
So they would in fact save a few seconds of work every day, maybe a few minutes per year. But to do that, you would have to pay at least 20€ per month (a hefty price point, will talk about it later), and offer access to your whole email inbox to some 3rd party. Not a very appealing proposition.
The price
During my product iterations, I integrated ChatGPT to aid in determining whether some email message is trying to sell something. It worked somewhat well, the only problem being that it sometimes changed its answer, depending on how obvious the sell attempt was.
So for some messages, calling the OpenAI API 5 times with exactly the same content, I would get 3 positives and 2 negatives, or other combinations. It was not an exact science.
Do mitigate this, I started doing multiple OpenAI calls for the same message and computed an "average" of positive rates for the message. If it was above a threshold, it would be flagged as being a cold email. Otherwise, it was either negative or ambiguous.
Doing these repetitive checks meant that the usage of the OpenAI API will quickly scale up. I did some estimations, and for the small plan of 1000 checks, I would end up spending ~12€ for the OpenAI chat, in the most pessimistic case. And that is with the gpt-3.5-turbo model, the cheapest one. I would use gpt-4, the cost would ramp up to about 60€ per month. HUUUUGE costs in both cases. The cheapest plan I could offer was 20€ in order to also cover the database and other hosting costs, plus labor. And with these costs I was doing 4 checks for each API call.
With some more optimistic scenarios, I could bring the costs down to about a third of the ones mentioned above, but the average would be somewhere in between.
So... not great...
The validation?
At this point, with the second round of validation for SpamLabs, I have to say that even though the problem is there, it seems to be more like a slight annoyance rather than a huge problem needing solving. So the demand is very small, and I wasn't able to get some excitement out of anyone. At best some courtesy "nice product!" from some fellow indiehackers, and some "meh" attitudes from potential customers (which I would have thought to have high chances of converting).
The truth is that I didn't have the final solution in place, just an API, but even though, the idea itself wasn't sparking a lot of genuine interest. Nor the talks about the problem itself. It was all pretty "meh" and dull, so not a great sign.
At first I was excited to seeing there are not many competitors (or any competitor), but now I am starting to understand why: the demand just isn't there.
I think I am ready to close down this chapter, and I am pleased I reached this conclusion without purring hundreds of development hours into it (something that I did with other attempts). I put up some MVP, and looked to start conversations about the problem. Learned a lot from this experience, and I am looking forward to the next one!
1 Like
Comment
The initial outreach to gather feedback about an API that validates email addresses based on various analysis (DNS analysis being the main one) didn't turn out the way I hoped. Sent about 40 cold emails about gathering feedback to gauge the interest in such a service. Although the sample is pretty small, I just ran out of ideas of getting prospects for "targets". Even though, I targeted only the "ideal clients" that I thought had the best chance of needing such a service: newsletters, communities and SaaS businesses that offer a free tier.
The responses were mostly negative such as
- "not a problem for us"
- "our platform already handles it pretty well"
- "we are not big enough to care"
- "we handle it manually pretty well, the volume is not that high to justify a dedicated solution"
I asked the same questions and pushed the same pitch across some other dedicated communities such as Shopify shop owners and discord server admins. The responses were negative, but a big part of them outlined a new need I had no idea it existed: getting blasted by cold emails, trying to sell all kind of unsolicited services, mostly SEO optimization services.
Then a light bulb popped over my head: what if instead of targeting the spam senders, we instead target the spam/unsolicited content, mainly cold email outreaches?
I spent some time to read about it, and from some generic numbers, it appears that from 100 sent cold emails, 10 are opened, and 1 responds positively. That means the that at least 90 cold emails sent will annoy 90 different people. Especially ones that have a work email.
The slight pivot I did was to convert the direction of SpamLabs from a email address validation API to an email filter that identifies cold emails and marks it as spam.
I integrated some ChatGPT + some algorithmic checking, I put together about 50 examples of spam/not spam from my own inboxes and tested the service. Got about 60% success rate, which is too low to feel comfortable to release it.
So, right now I'm going back to the drawing board and try to get the success rate to at least 90% before I release it. It is surprisingly hard to tell apart cold email attempts from various promotions that you subscribed to (for example, it's surprisingly hard to differentiate the "These games from your wishlist are on sale" from Steam from a cold email, because it tries to sell you stuff, and it's kind of hard to pinpoint if it is legit or not without whitelisting everything that comes from @steampowered.com.
Gotta keep on grinding these algorithms, because ChatGPT doesn't seem to be reliable enough to accurately say if an email is a cold email or not (being a statistical language model, it changes its answer). I will explore its fine tuning capabilities to get to a model that performs good enough for this task, and then iterate from there.
Cheers! Hit me with any question/curiosity you have, let's discuss!
2 Likes
2 Comments
2 Comments
-
1
Just out of curiosity, I’m not sure if I’m right. But you are tying to build an email spam filter based on ChatGPT? Email programs already have spam filters, and there are millions of other solutions out there.
Nevertheless, I like the general idea of SpamLabs combatting spam.
I’ve been trying to find specific people who need help with spam related issues, but it’s almost always on Insta/X or on wordpress.
-
1
Yes, pretty much. I am not targeted the regular spam that gets flagged nowadays pretty well, I am targeting the unsolicited sales emails. This usually happens more in with the business emails, and they more than often go through spam filters because they come from a legitimate email (company emails) and are different/professional/personalized enough to be considered not spam.
I know I am getting a lot of unsolicited emails from tech hiring agencies and SEO agencies trying to sell me their services, after they grab my work email from the company website.
-
We launched and we're ready to go!
Although there are a million things I would still want to do, I bit the bullet and made launched the MVP of SpamLabs: an API that tells whether a user is spammy or not based on the email address and generated content. As the popular saying goes "If you are not embarrassed of your product when you launched, you launched too late". I'll tackle the missing (or ugly) pieces one a time, while I gather feedback and iterate on it.
Usually, user generated platforms use concepts such as post, comments, direct messages, etc which are mediums that a bad user can use to spam.
The current 2023 anti-spam landscape seems to be focusing solely on email spam. There are no tools for this new age content format.
That was the situation up until today. SpamLabs is crafted specially for this kind of structured user generated content based on modern concepts: posts, comments, direct messages.
Check it out at https://spamlabs.io
1 Like
Comment
For the indie hackers out there that say that tech stack doesn't matter, I say: it actually matters.
But not in the way you'd think. It doesn't matter for the success of the company because some stacks are flashier or more optimized for performance.
It matters for development speed. If you, as a technical indie hacker, can develop, iterate and deliver fast, then the tech stack is good enough. More than often, that means traditional boring technologies. For me, it is Python, React, Bootstrap and Postgres.
It is crucial, especially before you have a proven business model, to choose the technologies that you are most comfortable with.
And don't waste time building non-mission critical features.
I spent way too much time in the past:
- developing user management flows
- manually developing OAUTH2 flows for social logins
- developing fully automated flows for payments
- almost building my own customer support tools inside the products I was building.
Now, with SpamLabs, I do it differently:
- integrate already existing user management (Clerk.com) which already supports out-of-the-box social logins
- use customer portal and payment links to manage payments. No callbacks and fully automated flows yet.
- use Crips.com for customer support.
Let's go 🚀
5 Likes
10 Comments
10 Comments
-
-
1
You might want to take a look at this featured IH article that was posted a while back that talks a lot about the answer to this question directly: adding-auth-to-your-project-everything-you-need-to-know-plus-recommendations
-
1
Thank you.
-
-
1
I fiddled around with firebase and it lacked the UI part. With Clerk.com they also provide official ready-to-go UI for register, login, user management, emails, etc. which was a big plus for me. For firebase I only found some open source projects offering that but they seemed pretty unmaintained to be comfortable using them.
Also, firebase often pushes you to use them as an ecosystem, including their other services. I just wanted an auth system that works.
-
1
Thanks for the details.
-
-
-
1
That's a great point, use the tech stack that allows you to move fast.
I will even add one controversial point: avoid testing in the beginning. It will slow you down. Build what your users will see as fast as you can and avoid what is not user facing.
-
1
Which services are you using specifically for payments?
-
1
Right now just Stripe, more precisely their customer portal + pricing tables.
-
-
1
I totally agree with you. Why would anyone should deal with something like auth when we got so many awsome solutions out there that we can use for nearly free at the beginning.
Use whats good for you and don't follow any "hey you must try this out"-Trends if itsnot usable for you.
For me I use most of the time Angular, Angular Material, NestJS and Postgres-
1
100% agree. Using a familiar stack and using integrations/already made solutions where it makes sense is way better than trying things out. Of course, that is if you want to ship.
-
About
A lot of communities, small online businesses and content driven platforms suffer from spam users just coming in and link farming. I want to aid in their fight against spam behavior.







Comment