Something interesting the latest spammer used, is this service. It’s basically a zero sign up NIP-05 service. It’s actually pretty cool.
What it does mean however is that having a NIP-05 and even being a validated NIP-05 means nothing regarding trust that can be given to a NIP-05 verification.
And just to clarify, not saying that applies to all NIP-05 domains, just that having any valid NIP-05 in of itself isn’t useful without further validation by other means.
In this case, the spammer created a kind0 metadata event and got a fully verified NIP-05 without any further effort - but their posts looked more authentic in client apps… which is something to ponder if this is app good UX.
#[0]