jrollans.com is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
These are the voyag... uh, things I post about.
Admin email
jrollans@gmail.com
Admin account
@jrollans@jrollans.com

Search results for tag #mastoadmin

[?]Andrew :hokkaido: :famichiki: » 🌐
@piepants@famichiki.jp

JESUS GODDAMN CHRIST.

A bunch of bot signups with the reason "automated protocol delivery probe"

Alt...A bunch of bot signups with the reason "automated protocol delivery probe"

    AodeRelay boosted

    [?]Jeremy ⁂ » 🌐
    @jeremy@mapstodon.space

    Due to the ever-growing amount of LLM-generated subscription requests (that have to be moderated manually), I'm considering setting Mapstodon.Space to invite only.

    I'm not fond of this at all but it's getting more out of hand everyday. Any suggestion on how to deal with this fake accounts crap flood will be very welcome. (Bonus points if you're on the moderation team of another instance and you are dealing, or have dealt with, a similar situation!)

      AodeRelay boosted

      [?]Yehor :dartlang: 🇺🇦 » 🌐
      @yehor@mastodon.glitchy.social

      Oh, so the bot account flood reached as well. I just didn't notice it because I got no emails...

        AodeRelay boosted

        [?]Larvitz :fedora: » 🌐
        @Larvitz@burningboard.net

        We had a big wave of automated Mastodon signups with very predictable usernames.

        I first tried the sledgehammer approach and blocked known VPN ranges at the firewall.

        It worked.

        It also blocked legitimate ProtonVPN users. 😬

        So I replaced that with a tiny custom Mastodon validator that rejects the actual abusive username pattern instead.

        Much cleaner: block the abuse, not the transport.

        How-to + code:
        gist.github.com/chofstede/a422

        @tux @AlienJay @aping

          [?]Michael » 🌐
          @pfitzer@social.main-angler.de

          so far no new registration since 2 days. With an additional filter and 24h block everything calmed down quite nice.

            [?]Paul Chambers🚧 » 🌐
            @paul@oldfriends.live

            I kept getting a 500 error when I tried to post something using a hashtag. Turns out, I was using a misspelled hashtag that I had blocked from being able to be used in a post on my instance. A brief notice did appear and disappear about the hashtag not being able to be used but it came and went much faster than the blue 500 error that popped up. I missed it the first three times I tried to post. .

              [?]Christoffer S. » 🌐
              @nopatience@swecyb.com

              I've noticed significant amount of requests towards the path /packs/*.js files on my Mastodon instance...

              What's that about?

                AodeRelay boosted

                [?]Dominik Bieber » 🌐
                @dbeaver@nrw.social

                RE: mastodon.iftas.org/@iftas/1172

                Wir haben temporär die Registrierung bei uns komplett deaktiviert, weil wir aktuell massive unter Spam-Anmeldungen zu leiden haben.

                [?]IFTAS » 🌐
                @iftas@mastodon.iftas.org

                ⚠️

                Services continue to report a wave of automated account creation using the naming pattern "bp" followed by a series of random alphanumerics, eg "bpc7463204e397374e" or "bpde9af0166700f555".

                To date almost all accounts are created using an email address at the domains:

                docomo.ne.jp
                ezweb.ne.jp

                and to a lesser degree:

                yahoo.co.jp
                au.com

                Requiring approval for accounts using these email domains during this attack will severely minimise your spam account review activity.

                a range of spam accounts visible in the admin interface of Mastodon

                Alt...a range of spam accounts visible in the admin interface of Mastodon

                    AodeRelay boosted

                    [?]Rolle Laukkarinen » 🌐
                    @rolle@mementomori.social

                    RE: mementomori.social/@rolle/1172

                    I looked into the bot issue again today. It turns out the bots aren't cracking Turnstile, they are bypassing it entirely by registering directly through the API (POST /api/v1/apps -> /oauth/token -> /api/v1/accounts). Turnstile, CAPTCHAs, and similar tools only protect web signups.

                    Because of this, blocking usernames, IPs, or email addresses doesn't help for long, as the bots keep rotating them and they are completely randomized.

                    I added a quick check to our fork in the Api::V1::AccountsController#check_enabled_registrations method: if API_REGISTRATIONS_REQUIRE_INVITE=true is set in .env.production, API registrations will require a valid invite code and return a 403 error otherwise. This does not affect regular signups.

                    The invite code cannot be guessed, so this should put an end to the issue. We could also achieve the same result in Nginx by blocking POST /api/v1/accounts, but I am not entirely sure what complications that might cause.

                    We are in the middle of a server migration, so we're keeping work on this to a minimum right now. We'll look into Anubis or Cloudflare anti-bot protections later.

                    We'll keep an eye on the situation.

                    [?]Rolle Laukkarinen » 🌐
                    @rolle@mementomori.social

                    RE: mastodon.bsd.cafe/@stefano/117

                    We are affected with the same spam wave, even with Turnstile enabled. They must be using Flaresolverr and similar methods.

                    This might not be a coincidence, bots pass CAPTCHAs now: mnews.sbs.co.kr/english/articl

                    [?]Stefano Marinelli » 🌐
                    @stefano@mastodon.bsd.cafe

                    I had to temporarily close the possibility to join the BSD Cafe Mastodon instance. A huge spam attack is in process.

                    For people wanting a new account, please contact me.

                    Tons of spam registration requests

                    Alt...Tons of spam registration requests

                          [?]Michael » 🌐
                          @pfitzer@social.main-angler.de

                          New solution for with lua-nginx-module

                          this image shows a part of a nginx configuration

                          Alt...this image shows a part of a nginx configuration

                            AodeRelay boosted

                            [?]IFTAS » 🌐
                            @iftas@mastodon.iftas.org

                            about.iftas.org/2026/09/11/boo will re-post useful tips, tricks, guidance to combat the wave impacting many service providers.

                              [?]Misty [she/her] » 🌐
                              @misty@digipres.club

                              I have... *1119 accounts* pending registration. Every single one is a "Automated protocol deliverability probe”. I so badly need the ability to just reject everything with the same request reason...

                                [?]spielleitung » 🌐
                                @spielleitung@mastodon.pnpde.social

                                The spam accounts from the last few hours ("Automated protocol deliverability probe") appear to be logging in via their own OAuth app called “BoomProtocolProbe.” So here's an attempt:

                                To prevent “BoomProtocolProbe” from registering, we created a trigger in the Mastodon database that checks the name BEFORE INSERT and blocks the app if it matches.

                                pad.pnpde.social/p/FUloCtoOiNZ

                                CREATE OR REPLACE FUNCTION block_boomprotocolprobe()
RETURNS trigger AS
$$
BEGIN
    IF NEW.name = 'BoomProtocolProbe' THEN
        RETURN NULL;
    END IF;
    RETURN NEW;
END;
$$ LANGUAGE plpgsql;

CREATE TRIGGER trg_block_boomprotocolprobe
BEFORE INSERT ON oauth_applications
FOR EACH ROW
EXECUTE FUNCTION block_boomprotocolprobe();

COPY oauth_applications TO '/tmp/oauth_applications.copy';

DELETE FROM oauth_applications WHERE name = 'BoomProtocolProbe';

                                Alt...CREATE OR REPLACE FUNCTION block_boomprotocolprobe() RETURNS trigger AS $$ BEGIN IF NEW.name = 'BoomProtocolProbe' THEN RETURN NULL; END IF; RETURN NEW; END; $$ LANGUAGE plpgsql; CREATE TRIGGER trg_block_boomprotocolprobe BEFORE INSERT ON oauth_applications FOR EACH ROW EXECUTE FUNCTION block_boomprotocolprobe(); COPY oauth_applications TO '/tmp/oauth_applications.copy'; DELETE FROM oauth_applications WHERE name = 'BoomProtocolProbe';

                                  [?]Christoffer S. » 🌐
                                  @nopatience@swecyb.com

                                  Fellow people. Have you come across this registration bot with account details like this:

                                  Reason: Automated protocol deliverability probe

                                  And account details like this:
                                  bp3de08dafada0d38a
                                  @bp3de08dafada0d38a

                                    [?]Rimuru » 🌐
                                    @Tempest@burningboard.net

                                    Pro tip of the day:

                                    Do not be the next buddy.social.

                                    Keep your Fedi site relatively up to date.

                                      [?]Rimuru » 🌐
                                      @Tempest@burningboard.net

                                      This is new. 😅

                                      Messaged @ajroach42 to inform them that their site is using software so old that even the recommended solution is out of date. Made sure my site and their site were connected, and even searched for my username using their site — I found myself, no problem. 😇

                                      Every admin — 100% — I have ever messaged concerning their software being out of date has been friendly and received my message well. 😎

                                      This is the first time someone blocked me. I guess there is a first for everything, lmao. 🤣

                                      Welcome retro.social to security_risk_domains.csv. You're site number 23 added to the list. 🤷 🤡

                                      github.com/Fediverse-Express/F

                                      A screenshot of a message which reads:  @ajroach42@retro.social 

I noticed your site is using Mastodon 4.2.20, which was released on April 2, 2025, and is now discontinued.

That branch (4.2.x) of Mastodon has several known security issues. In fact, it is so old that the final 4.2.x build was 4.2.29, and developers recommend upgrading to 4.3.x. However, that branch is also discontinued and contains security issues (with the last release being 4.3.23).

All of this to say, your software is quite out of date, and your site is extremely vulnerable.

The current release is 4.7.1.

                                      Alt...A screenshot of a message which reads: @ajroach42@retro.social I noticed your site is using Mastodon 4.2.20, which was released on April 2, 2025, and is now discontinued. That branch (4.2.x) of Mastodon has several known security issues. In fact, it is so old that the final 4.2.x build was 4.2.29, and developers recommend upgrading to 4.3.x. However, that branch is also discontinued and contains security issues (with the last release being 4.3.23). All of this to say, your software is quite out of date, and your site is extremely vulnerable. The current release is 4.7.1.

                                      A screenshot showing the admin how now suspended access between my account and their site, so neither the admin or anyone else can see my post.

                                      Alt...A screenshot showing the admin how now suspended access between my account and their site, so neither the admin or anyone else can see my post.

                                        [?]Rimuru » 🌐
                                        @Tempest@burningboard.net

                                        This is new. 😅

                                        Messaged @ajroach42 to inform them that their site is using software so old that even the recommended solution is out of date. Made sure my site and their site were connected, and even searched for my username using their site—I found myself, no problem. 😇

                                        Every admin—100%—I have ever messaged concerning their software being out of date has been friendly and received my message well. 😎

                                        This is the first time someone blocked me. I guess there is a first for everything, lmao. 🤣

                                        Welcome retro.social to security_risk_domains.csv. You're site number 23 added to the list. 🤷 🤡

                                        github.com/Fediverse-Express/F

                                        A screenshot of a message which reads:  @ajroach42@retro.social 

I noticed your site is using Mastodon 4.2.20, which was released on April 2, 2025, and is now discontinued.

That branch (4.2.x) of Mastodon has several known security issues. In fact, it is so old that the final 4.2.x build was 4.2.29, and developers recommend upgrading to 4.3.x. However, that branch is also discontinued and contains security issues (with the last release being 4.3.23).

All of this to say, your software is quite out of date, and your site is extremely vulnerable.

The current release is 4.7.1.

                                        Alt...A screenshot of a message which reads: @ajroach42@retro.social I noticed your site is using Mastodon 4.2.20, which was released on April 2, 2025, and is now discontinued. That branch (4.2.x) of Mastodon has several known security issues. In fact, it is so old that the final 4.2.x build was 4.2.29, and developers recommend upgrading to 4.3.x. However, that branch is also discontinued and contains security issues (with the last release being 4.3.23). All of this to say, your software is quite out of date, and your site is extremely vulnerable. The current release is 4.7.1.

                                        A screenshot showing the admin how now suspended access between my account and their site, so neither the admin or anyone else can see my post.

                                        Alt...A screenshot showing the admin how now suspended access between my account and their site, so neither the admin or anyone else can see my post.

                                          AodeRelay boosted

                                          [?]Rimuru » 🌐
                                          @Tempest@burningboard.net

                                          1,112 accounts spreading spam or participating in scams, along with the people who promote, defend, or otherwise amplify their existence on the Fediverse.

                                          You'd be amazed at how much more user-friendly and cleaner Mastodon or Misskey feels once you take out the trash.

                                          Save as a CSV file, for example, block.csv, import (upload) the file, and merge it with your current block list.

                                          github.com/Fediverse-Express/F

                                            [?]don Elías (como los buses) 🥨 » 🌐
                                            @donelias@mastodon.cr

                                            RE: lsbt.me/@christin/117248376636

                                            We're receiving Spam registrations too.

                                            Reason for joining:

                                            Automated protocol deliverability probe

                                            Example of username chosen:

                                            bp7db8296eb763dff7

                                            Example of entry in web server log:

                                            180.4.59.44 - - [10/Sep/2026:16:40:02 -0600] "POST /auth/confirmation HTTP/1.1" 302 5493 "-" "Python/3.10 aiohttp/3.14.3"

                                              AodeRelay boosted

                                              [?]Meerjungfrauengrotte.de » 🌐
                                              @admina@meerjungfrauengrotte.de

                                              Irgendwer (Bot oder KI offenbar) torpediert gerade Mastodon-Instanzen (möglicherweise auch andere Plattformen im Fediverse) mit Registrierungsanfragen.

                                              Gemeinsame Merkmale:

                                              • Usernane bp + 16 hex Zeichen
                                              • Begründung "Automated protocol deliverability probe"
                                              • Verschiedene IP-Adressen
                                              • Verschiedene Mail-Provider
                                              • nicht existierende Mail-Adresss
                                              • deswegen bounct die automatisch versendete Bestätigungsmail
                                              • Admins werden nicht über neu registrierte Konten benachrichtigt

                                              Hintergrund ist unklar.

                                              Die betroffenen Instanzen torpedieren ungewollt mehrere Mailserver mit nicht zustellbaren Mails, was womöglich zu Blacklisting führt.

                                              Ich habe vorübergehend Registrierungen auf meiner Instanz deaktiviert.

                                                [?]Michael » 🌐
                                                @pfitzer@social.main-angler.de

                                                If your are facing lots of registration attempts in the last hours, you can configure to allow only n calls of the sign up page for an IP.

                                                The example is for 3 calls/min and then 404 for 10 min

                                                  [?]Tech Field Day Admin » 🤖 🌐
                                                  @admin@techfieldday.net

                                                  @ben OMG I am getting a TON of these suddenly! They're definitely not legit (as in new users) and despite the "automated protocol deliverability probe" description I don't think they're "legit" bots. I think it's just spammers.

                                                    [?]Ben Hardill » 🌐
                                                    @ben@bluetoot.hardill.me.uk

                                                    This looks ominous.

                                                    Anybody else seeing lots of new sign up attempts?

                                                    (I need to get it passing the correct IP address from the upstream proxy)

                                                    Screenshot of Mastodon Admin showing list of new account requests all with reason listed as "Automated protocol deliverability probe". They appear to be using a mix of gmail and hotmail email addresses

                                                    Alt...Screenshot of Mastodon Admin showing list of new account requests all with reason listed as "Automated protocol deliverability probe". They appear to be using a mix of gmail and hotmail email addresses

                                                      [?]Michael » 🌐
                                                      @pfitzer@social.main-angler.de

                                                      Hatte die letzten Tage ein Spamwelle an Bot Registrierungen mit Email Domain docomo.ne.jp
                                                      Was ein Fun

                                                        [?]Ilkka Tengvall » 🌐
                                                        @ikkeT@mementomori.social

                                                        Hooray! We have successfully got mastodon database live replica streaming! Size of db is btw ~220GB in mementomori case. Replica is in other DC.

                                                        @ry

                                                          [?]Veera Laukkarinen » 🌐
                                                          @mustikkasoppa@mementomori.social

                                                          Minä eilen ja tänään.

                                                          Mementomori.socialiin iski bottitsunami rekisteröinnin kautta.

                                                          Alt...Whac a Mole cat box GIF

                                                            [?]Ilkka Tengvall » 🌐
                                                            @ikkeT@mementomori.social

                                                            What is this nuicanse bot that creates constantly members to instances?

                                                            "Automated protocol deliverability probe"

                                                              [?]Paul Chambers🚧 » 🌐
                                                              @paul@oldfriends.live

                                                              @mookie Something else I have noticed is, since the v4.5.17 upgrade, my SideKiq has no dead jobs, which I find very odd, almost impossible. oldfriends.live/@paul/11723910

                                                              [?]Paul Chambers🚧 » 🌐
                                                              @paul@oldfriends.live

                                                              Since Mastodon v4.5.17, the only news that trends are news links that originate on my self-hosted instance... Anyone else having that issue?

                                                                  [?]Rolle Laukkarinen » 🌐
                                                                  @rolle@mementomori.social

                                                                  RE: mastodon.bsd.cafe/@stefano/117

                                                                  We are affected with the same spam wave, even with Turnstile enabled. They must be using Flaresolverr and similar methods.

                                                                  This might not be a coincidence, bots pass CAPTCHAs now: mnews.sbs.co.kr/english/articl

                                                                  [?]Stefano Marinelli » 🌐
                                                                  @stefano@mastodon.bsd.cafe

                                                                  I had to temporarily close the possibility to join the BSD Cafe Mastodon instance. A huge spam attack is in process.

                                                                  For people wanting a new account, please contact me.

                                                                  Tons of spam registration requests

                                                                  Alt...Tons of spam registration requests

                                                                      [?]Paul Chambers🚧 » 🌐
                                                                      @paul@oldfriends.live

                                                                      Since Mastodon v4.5.17, the only news that trends are news links that originate on my self-hosted instance... Anyone else having that issue?

                                                                        [?]Rimuru » 🌐
                                                                        @Tempest@burningboard.net

                                                                        1,085 accounts identified as participating in spam and scam activity — along with accounts that actively promote, defend, or amplify them.

                                                                        github.com/Fediverse-Express/F

                                                                          [?]🌈 Barbapulpe 😇 ᴹᵃˢᵗᵒᵈᵒⁿ » 🌐
                                                                          @barbapulpe@gayfr.social

                                                                          RE: gayfr.social/@barbapulpe/11720

                                                                          Bumping this, am I really the only one?

                                                                          Sidekiq processes are multiplying as hell, and I didn't find any issues in the github. Really surprised nobody else is affected? Do I need to open an issue?

                                                                          Nothing else changed on my side, happening since upgrade to 4.7.0 (still there in 4.7.1).

                                                                            [?]Rimuru » 🌐
                                                                            @Tempest@burningboard.net

                                                                            Just sent 61 messages to admins running very outdated copies of either Mastodon or Misskey.

                                                                            No one should be using, for example, Mastodon 3.x. There is a vulnerability that allows someone to obtain limited access to the owner account.

                                                                            A few people were using 4.2.x, which is so old and discontinued that the final release at the time suggested upgrading to 4.3.x — which is also now discontinued and has several known security vulnerabilities.

                                                                            If you're using Mastodon 4.4.0, as legacy, know that 4.4.24 already recommends you upgrade to at minimum 4.6. or newer, The current release is 4.7.1.

                                                                            No one is saying you need to always run the bleeding-edge release. But if you're going to host other people, you should attempt to keep your site relatively current. The older the site, the harder it can be to upgrade, so not falling too far behind is good planning. If you cannot do that, you really should consider joining someone else's site as opposed to running your own.