@Oha bleuch, sorry to see it.
Collating various helper posts here: https://about.iftas.org/2026/09/11/boom-protocol-spam/
@iftas
I set up a rule in Mastodon to require approval for any name with "bp" and after rejecting dozens manually, I finally set up a Cloudflare edge rule. So far it has blocked 59 attempts to open accounts here after running for about 8 hours today (10-Sep)
What is wrong with this person?
The rule I set, which I hope is only temporary, is to block if this is true:
(http.user_agent contains "aiohttp" and http.request.uri.path contains "/oauth")
@iftas@mastodon.iftas.org in NodeBB, after clicking "reject" a million times (or in Mastodon's case, a checkbox, I guess), we added a "Reject All" button.
Does Mastodon not have that?
Now for spam review, we go through the queue and manually accept the ham, and one-click blackhole the rest.
@julian we can review 40 at a time, if the full 40 fill the page we can click twice to reject all, but if you have to pick them out and make sure you're not getting anything caught up in the net...
Also a lot of instances don't have people watching the shop all hours, so they might be off by several hours before they get to cleaning this up.
@julian I also have a bot suspending the most of them personally, but then I can't reject them, unless I unsuspend them... and I have to pick apart which ones were suspended vs which ones didn't trigger the action and are rejectable. Also, if I reject, I lose all data, and I'm trying to collate as much as I can before rejecting...
it's not the simplest interface.
You can use this filter to only select the spam:
%bp in the search field
https://mastodon.com.pl/@m0bi/117253436959799207
@iftas blocked some email domains. Thanks for the heads up!