Show HN: Make senders work to get into your inbox (captchainbox.com)
The one thing AI reliably does is generate noise. Half the tools I see launch are just machines for producing more noise across more channels. And people are starting to see this in the form of emails in their inboxes as spam filters are struggling.
There used to be a useful signal in email: the effort a sender put into customizing a message was a rough proxy for how relevant it actually was. AI killed that. Now it's customized slop with the appearance of effort with none of the cost. It is painful that the open internet / open channels have been abused like this.
Captchainbox applies the idea of proof-of-work to email. If a sender is willing to do a bit of work to reach you, the message is more likely to be worth your time and the sender more likely to be real. The work is a traditional captcha. You can also set a pay-to-deliver amount if you want more friction. The proceeds of the delivery payment after transaction costs go to the Internet Archive and the EFF. The tool currently works by authing with your Gmail or Outlook and during launch time I make this completely free as a lifetime deal (with optional payment if you wanna support).
How it works: Captchainbox builds a whitelist automatically from the metadata of your past correspondence. If you've emailed an individual address, that sender can reach you. If you talk to several people at the same domain, we whitelist the whole domain. If one transactional-looking sender has sent you more than 10 emails, we treat it as a transactional domain and let it through. This whitelist is for you to change whenever you want. It continues to build organically as you converse with more addresses.
Incoming mail is checked against that whitelist. Senders already on it land in your inbox as normal. Anyone else gets archived (never deleted) and is sent a challenge. This can be the captcha or the payment link. Once they solve it, their email is pulled out of the archive and put back into your inbox.
if you want to see what this looks like from a sender's point of view, send me an email here: doerpfelix15@gmail.com
The service only ever reads metadata, never message content. And since nothing is ever deleted, you can't lose a message. There is a legitimate risk / downside: if you sign up to a new service, these emails also land in the archive. Since we do not process the content, a first-time sender who can't solve the challenge (say an automated activation email) will sit in your archive until you spot it.
Happy to answer anything! :)
32 comments
[ 3.4 ms ] story [ 46.5 ms ] threadA few years ago I emailed a local freelancer I'd met in person, because I had a client asking for coding (which was more his bag than mine). I got an automated response that he was using something like this, with a link to some third party service to fill out a form and click a captcha if I wanted him to see my email.
Why would I? I just told the client sorry, I don't know anyone.
Most tech companies I've seen gate and filter customer support on web not email, then only sales and external interfacing employees need external emails and the bigger problem is phishing not spam.
For my personal email I would never use this, because I myself would never solve a captcha to reach someone's inbox and I can't expect different from others.
I know the situation here in Germany kinda sucks for non-incorporated founders (or simply any website administrator trying to commercialize anything [0]), but gating imprint/Impressum behind a login wall makes it not legally compliant. It needs to be easily accessible from anywhere (that’s why most people place it in the footer), without auth or signup; and if you put it behind either Outlook or Gmail logins, you may as well just not include it at all (realistically, who’s gonna complain if you don’t include “made in Germany”).
All the best for your project, though!
[0]: Personally I’ve given up and just include my name and address on the public web in projects now, which I guess is what the federal government wanted to achieve.
This feels like a cool modern iteration of it.
[0]: https://en.wikipedia.org/wiki/Hashcash
I think this concept would work if taken a step further, with a new protocol that requires encryption, but only with a key provided by a block chain that cost some nonzero amount. the email server would drop message payloads whose hash wasn't on the chain, limiting DoS attacks.
When the recipient reads the mail, it starts a process of refunding that micro payment that is a 4h cycle that can be interrupted. So if you click "spam", it blocks the refund and you keep the micro payment. Anyone sending bulk emails would go bankrupt.
Anyone using email for normal purposes would only have to buy once to have enough tokens to send a few emails. Most of the time tokens would only be used inside the system, but they would need some monetary value to do their job, so they could be pegged at say $0.10.
As others have said, a lot of the useful emails I get are still ones where the sender probably wouldn't have paid to send them. IM2000's fairly old-school-yet-elegant approach would probably lead to a better outcome too.
[1]: http://cr.yp.to/im2000.html
[0]: https://trog.qgl.org/20081217/the-why-your-anti-spam-idea-wo...
Sorry if it's obvious but it didn't make sense to me!
The bit I don't understand, is what about where you need the automated-stuff-to-human, like, authenticating a new account? Would this just block those types of emails? Is the expectation if you used this, that you'd have seperate emails for contacting people vs accessing online services?
O365 is handling 90% of it on our corporate mail; my personal address (which is far older) is hosted at Fastmail and it traps nearly all the spam there, too.
In 2026, I'm much more annoyed by PHONE spam -- though Apple's "who the hell are you and why should ubermonkey take your call" feature has done wonders. (I assume something similar exists in Android.)
Somehow I doubt this determines whether a contact is trusted.
Or they just really want to sell you something.