On top of that, SpamAssassin hates it:
X-Spam-Status: No, score=3.7 required=5.0 tests=HTML_IMAGE_ONLY_08,HTML_IMAGE_RATIO_02,HTML_MESSAGE,MIME_HTML_ONLY,NO_RECEIVED,NO_RELAYS,T_DKIM_INVALID
...so they didn't bother to MIME-format the message correctly with a text component. I know from experience that this can cause your message to be blocked completely by some email services.Phooey.
Actually you don't because neither my gmail nor my Android mail clients will load images automatically and the emails sent are super suspicious looking, so I'd never enable it for them.
Also since you don't verify my SMS in any way, I might be using your service to send untraceable text spams to someone (perhaps someone I don't like who pays 10 cents per text) by sending gotcha mails to an inbox I control and then opening the mails.
Also, on the "Trap" page, I would highly recommend you remove the "Chase" and "PayPal" templates. Using those on your site and in the "trap" mails you send is possibly wire fraud and would certainly not be appreciated by either party, regardless of intent of this service.
Spam - good point. We need to work on verification. Currently, it only works 20 times per IP address. But that's 20 times too many.
You'd have the option to warn your friends via a Facebook Status Update to ignore any emails/links they received from you until you verified the intrusion.
We checked all entry points and are confident that no one will ever get access to this db.
good thing that never happens.