outis: Fight AI spam by generating and sending a fake "user unknown" bounce emails
Outis fights spam generating and sends a fake "user unknown" bounce for an email you received, so the sender believes your address does not exist. This isn't a new idea: I created a similar program back in 1998–1999, but I decided to revive it because it should work well with the recent trend of automated emails generated by AI, where the sender might expect a reply; it helps remove your email…
Outis is a tool designed to combat spam by generating and sending a fake "user unknown" bounce email in response to received messages. By doing so, the sender is led to believe that the recipient's address is no longer in use, effectively removing them from the sender's mailing list. The name "Outis" is derived from the Greek word for "nobody," as used in Homer's Odyssey when Odysseus feigned this name to the Cyclops Polyphemus.
Outis creates the bounce as an RFC 3464 delivery status notification, following the Postfix format. This notification includes a human-readable section, a message/delivery-status part with status code 5.1.1, and the original email attached as message/rfc822. The bounce is sent to the original Return-Path from MAILER-DAEMON@ your domain, using a null envelope sender when permitted by the SMTP server.
Unlike a real 550 rejection during the SMTP exchange, Outis' bounce is sent after the message has already been accepted. This means the sender's logs will show successful delivery, the mailbox remains accessible for any retries, and the deception only affects the specific sender who receives and processes the notification. The bounce is only credible if it originates from a domain you control, preferably using an SMTP account on that domain set to MAILER-DAEMON@....
Consumer email providers such as Gmail or iCloud often alter the From header, rendering Outis ineffective in those cases.
The tool accepts various input types, including files and directories. Directories are expanded to contain their visible regular files, and any extensions are ignored (excluding recursive processing). Each file is matched to an account individually; unparsable or unmatched files are reported and skipped, while the rest continue processing. A non-zero exit code is returned if any file fails.
Multiple inputs can be provided, resulting in a summary line per file followed by a single confirmation. Each account corresponds to a single domain. If no matching account is found, or if multiple matches exist, the --account flag can be used. Certain providers, like Amazon SES, maintain a suppression list that affects all their customers; a hard bounce can temporarily block all SES senders from reaching a recipient's address.
For domains listed in reply_to_from_domains, Outis sends the bounce to the From header address instead of the default behavior. The default setting for reply_to_from_domains is [ amazonses.com ] and its subdomains, which can be disabled by setting it to [].
Outis' configuration file is typically located at os.UserConfigDir()/outis/config.toml (e.g., ~/Library/Application Support/outis on macOS, ~/.config/outis on Linux). This file can be overridden using the OUTIS_CONFIG environment variable.
Written by urgent.news from Lobsters's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.