ProofOfDonation is a self-hosted alternative to CAPTCHAs that verifies user identity by confirming charitable donations through email receipt validation using DKIM cryptographic signatures. Website owners can replace signup puzzles with donation requirements, and the stateless server supports multiple charities without direct integration.
Anomalously high email open rates—exceeding 100%—can indicate compromised accounts rather than successful campaigns. Attackers exploit DKIM replay by sending one authenticated message through a legitimate account, then redistributing that signed message to thousands of recipients, causing the tracking pixel to fire far more times than the original recipient count, creating mathematically impossible open-rate metrics.