← Artificial Polemics

05 / Artificial Polemics

AI, Connect the Dots; or,
De l’art du spam ingénieux

Engraved portrait of Glen Cantrell in the visual style of the Van Loo Diderot portrait
ByGlen CantrellWriter. Complicator. Localist.

I get a fair amount of email from people who would very much like to help me sell my book. I find this generous, especially since most appear to have discovered the book approximately seven minutes before emailing me.

The pattern is usually obvious. They’ve read the title, possibly the description, and almost certainly nothing else. They’re deeply moved by my important contribution to literature and would like to help me reach the vast audience I so richly deserve. For a fee, naturally.

Most go straight to junk.

Then I got one that made me stop.

It began with the wine bar.

The sender knew that I hadn’t set out to write a book about leadership. The email knew I’d set out to have a glass of wine and, after two, somehow ended up in charge of a small, all-volunteer Chamber of Commerce in California’s Sierra Nevada foothills. It quoted that story back to me.

Okay. That’s on the website.

Then it quoted the reviews. Accurately. Okay, those are on my website too. But, wait, I didn’t quote that excerpt on the website. It was only on the reviewer’s site.

It knew about the “fixer instinct.” Website.

It knew about extension cords. All over, well, everything.

It knew the book publishes November 10. It understood that Embracing the Local isn’t easily contained by “memoir” and identified community leadership, rural development, volunteerism, local economics, and organizational change as overlapping audiences. All there, on the website.

It knew about the elf costume. Wait, the elf costume? That’s not on the website.

Last year, I got way too into the Chamber’s Elf-on-a-Shelf scavenger hunt, bought an adult-sized elf costume, put the damned thing on, and went around town doing photo shoots to promote the contest. There are pictures, plenty of them. They’re on the Chamber’s Facebook page. They have a distressing number of likes. One of the pre-release reviews of my book also mentions the elf costume.

This scammer did its homework.

It then suggested Main Street organizations, nonprofit professionals, community foundations, arts councils, economic development people, and the civic-minded people who somehow end up keeping the Christmas event alive every year.

Dammit.

Those actually are my people.

Then it got personal.

It knew I’d spent more than twenty years in technology. It knew about HP and Oracle. It knew I co-founded a consulting firm. Okay, fine, it connected the right LinkedIn account with the right author.

It knew I lived in Twain Harte with my husband, Michael, and our three dogs. Who doesn’t at this point?

And then it mentioned my Substack.

My what?

Oh, yeah. I have a Substack. I started it in 2023. I wrote five essays for it. I had completely forgotten about it.

My spammer had not.

It had, however, missed one fairly important detail. The email described the Substack as a platform where I “already have a presence” and suggested I build a newsletter there. Five essays in 2023 followed by three years of silence is an interesting definition of presence. It had found the facts and connected them. It just hadn’t noticed the timestamps.

So I went back and reread those old essays, and then, because I cannot leave well enough alone, I fed one of them to ChatGPT. I got high praise: “It’s competent.” It went on: “The central idea is interesting, especially viewed from 2026: AI should augment project managers rather than replace them because the important parts of the work involve relationships, judgment, context, negotiation and leadership.” And then: “But stylistically, this one is Corporate Glen.”

Asshole.

Claude, not wanting to be left out, chimed in that the project-management piece was “competent and generic, the one I’d let stay archived.”

That was the point when this stopped being ordinary junk mail and became interesting. I started checking its work, partly out of curiosity and partly because I was still stinging from my freshly delivered reviews.

I started with the raw email.

The authentication headers showed that it really had traveled through the Gmail account in the signature. SPF passed. DKIM passed. DMARC passed. That doesn’t tell me who was sitting behind the account, but it does tell me someone hadn’t simply spoofed the From address.

The HTML was more interesting. At the very bottom were two separate invisible tracking elements. One loaded from p.mailmerge.eu/trace/mail/, part of an email-tracking service. The other loaded from mailfoogae.appspot.com with the parameter type=zerocontent, which belongs to Streak, a customer-relationship-management system built into Gmail. Both were there to track email opens. The mechanism is wonderfully primitive: put a tiny image with a unique identifier in the message, then record when the recipient’s email client asks the server for it.

Unfortunately for them, I use Apple Mail with Mail Privacy Protection enabled. MPP is designed specifically to make this kind of tracking unreliable. Apple can fetch remote content privately without waiting for me to actually open the message, obscuring my IP address and breaking the useful connection between “the tracking pixel was requested” and “Glen read the email.” My approach to email privacy is bring it, nerds.

So after all that research, personalization, mail merging, CRM integration, and invisible surveillance plumbing, their tracking systems may have dutifully reported an open regardless of whether I actually opened the email. Or they may have learned even less. A server request is a server request, not a sworn affidavit that Glen Cantrell was staring at paragraph fourteen at 9:17 p.m.

While Claude and I were dissecting the raw email, I asked ChatGPT whether it could go into my junk folder and open the message 500 times, just to make the tracking data completely useless.

It explained, with considerably more patience than the question deserved, that its Gmail access retrieves messages through an API rather than rendering the email and requesting its tracking pixels.

Fine.

So much for AI-powered countermeasures. My Book Club of AI models has become a detective agency with better impulse control than I have.

I still couldn’t see how the research had been gathered, which model had written the prose, how much of the process was automated, or how much human involvement there had been along the way. But I could see some of the machinery surrounding it.

And most of the factual details were right. The reviews were real. The quotations were real. The professional history was mine. The Facebook photos are really real and out there for anyone to discover. The Substack really existed, quietly fossilizing in a forgotten corner of the internet. Even some of the marketing analysis was reasonable. The book probably does have an audience among people working in nonprofits, community development, volunteer organizations, Main Street programs, and rural civic institutions.

The recommendations themselves were considerably less remarkable: build an audience before launch, start a newsletter, develop relationships with communities likely to care about the book, create a coherent author presence, help people discover your work.

Very standard book-marketing advice had been wrapped in an astonishing amount of information about me.

The email didn’t demonstrate an extraordinary understanding of the market for Embracing the Local. It demonstrated an extraordinary ability to gather information about Glen Cantrell and turn it into something that felt like an extraordinary understanding of the market for Embracing the Local.

I know these tools well enough to recognize the trick because that’s exactly how I use them. Give an AI system a little information and it will give you something generic. Give it enough context and things get interesting.

Throughout the essays in this series, I’ve been trying to describe a way of working with AI that depends heavily on context. I don’t ask a model to “make this better” and accept whatever comes back. I give it the manuscript. I give it earlier drafts. I give it reviews. I explain what I’m trying to accomplish. Sometimes I give the same work to several models and let them disagree with one another. The more relevant context they have, the more useful their analysis becomes.

Context is capability.

Apparently, it also makes excellent spam. It’s the same technology I’ve been using, simply pointed in a different direction. Every useful technology eventually acquires someone willing to use it to sell us something, deceive us, steal from us, or convince us that our boss is stranded and needs us to send him some Apple gift cards.

What strikes me is how thoroughly the old signals have broken down. If someone wrote to me about my book and mentioned the wine bar, extension cords, my Chamber work, my professional background, several real reviews, an elf costume, and an obscure newsletter I abandoned three years ago, I would reasonably assume that person had invested some meaningful amount of time learning about me.

That investment itself used to be a signal.

Research that once required enough human effort to make mass personalization impractical can increasingly be gathered, synthesized, and converted into plausible intimacy at scale. Now I had evidence of the scale part too. The same email that seemed to know an unsettling amount about me had arrived wrapped in mail-merge and sales-tracking infrastructure.

The email didn’t have to know me. It only had to know enough things about me, and arrange them convincingly enough, for my brain to supply the difference.

That’s unsettling precisely because it is so close to what makes these systems useful.

When an AI model notices a connection between something I wrote six months ago and something I’m struggling with today, I find that valuable. When it remembers an argument from an earlier essay and points out that I’ve contradicted myself, that’s useful. When it can look across a body of work and identify recurring ideas I hadn’t consciously connected, that’s one of the reasons I keep using it.

I like machines that can connect dots. Turns out I like them considerably less when someone else chooses the dots.

There’s another irony here, made more delicious because I may have helped create it.

For months, I’ve been working to make Embracing the Local more discoverable online. Some of that is ordinary search engine optimization, or SEO: making sure that when someone goes looking for books about civic leadership, volunteerism, rural communities, or the strange collection of people who keep small towns functioning, search engines have some reason to believe mine might belong in the stack.

More recently, that work has also included GEO, generative engine optimization. The acronym is newer and the rules are considerably squishier, but the basic idea is straightforward. You want an AI system to do more than find a page. You want it to understand what the page is about, who created it, how it relates to other things you’ve created, and why any of it might be relevant to the question someone just asked.

So we’ve been making those relationships clearer.

Glen Cantrell wrote Embracing the Local. He is president of a small, all-volunteer Chamber of Commerce. The book grew out of that experience. It deals with civic leadership, volunteer capacity, rural communities, organizational systems, stewardship, and local economics. Here are essays that explore some of those ideas. Here are independent reviews describing the book. Here is the professional background he brought with him when he wandered into all of this.

Connect the dots.

Please.

Well, someone, or something, did.

The same work that makes it easier for a prospective reader to discover my book also makes it easier for a system to assemble a remarkably detailed picture of the person who wrote it. I have spent months carefully arranging breadcrumbs across the internet, then found myself mildly annoyed when something followed them home.

SEO and GEO are doing exactly what I asked them to do. Everything in that email appears to have come from information I made public or that others had published about me or the book. Nobody broke into my computer. Nobody stole my diary. As far as I can tell, the research largely consisted of doing exactly what I have been hoping legitimate search and generative systems would do: find the information, understand the relationships, and put the pieces together.

Then the spam jumped channels.

While I was finishing this essay, a text arrived from an unfamiliar 833 number: “Hi Glen! Is your book reaching the right readers? We help authors grow & work toward bestseller success. Starting at $299.”

They had my first name. They knew I had a book. And they had my phone number.

That last part matters because my phone number is not on the book website, and it is not part of the SEO/GEO footprint I deliberately built. Whatever system produced the pitch had done something more than follow the breadcrumbs I had laid out for readers and search engines. It had connected my public author identity to some other source that knew how to reach me.

Discoverability had become aggregation. Aggregation had become enrichment. And enrichment had become contactability.

The irritating part is that my new discoverability doesn’t come with an audience selector.

I can’t optimize the site so that librarians, reviewers, journalists, civic leaders, nonprofit professionals, and potential readers can understand who I am while instructing every automated prospecting system to please avert its eyes. The better I make the public record legible to machines, the more legible it becomes to machines whose operators want something from me.

I’m still going to do it. I am publishing a book, after all. Hiding is a spectacularly poor marketing strategy. Even I know that much.

But the experience complicates the usual conversation about online privacy. I hadn’t accidentally exposed something private through the site. I had intentionally made public information easier to understand, and somewhere downstream, something had apparently joined that public identity to information I had not published there at all.

Individually, none of it was remarkable. A biography here. A review there. A forgotten Substack somewhere else. A book description. A professional history. A few stories about Chamber life.

The capability came from connection, which brought me back to the thing I’ve learned from using AI in my own work: context is capability.

I just hadn’t spent much time thinking about what happens when I become the context for somebody else’s machine.

So I did what anyone would do on receiving a suspiciously well-informed letter from a stranger, which was to go looking for the stranger.

My first theory was the charitable one, or at least a charitable version of the uncharitable one. The email was signed with a woman’s name and linked to a polished professional website. I assumed that, if something dishonest was going on, someone had probably borrowed a real marketer’s identity to do it.

I’m going to call the marketer Jane Doe, for reasons that will become clear soon enough.

The theory survived about as long as it took to open Jane’s contact page. The same Gmail address that had written to me was listed, with some pride, as the way to reach Jane personally. The email and the website were connected after all, so I stopped asking who was impersonating Jane Doe and started asking whether there was any Jane Doe to impersonate.

The website was thorough in the same way the email had been thorough. It claimed more than ten years of experience, more than two hundred authors helped, and expertise across more than fifteen genres. It laid out a methodology, a biography about stumbling into the work by noticing patterns other people missed, case studies with tidy results, and testimonials whose authors, the site assured me, could be contacted directly to verify the work.

In a section of solemn commitments, the site promised no mass outreach and a personal reply to every message from Jane herself, “not an assistant, not a template.” I admired that one, particularly because the site’s own code still identified its canonical address as yourdomain.com, which is what a website template calls itself before someone gets around to filling in the blank.

I know this because ChatGPT caught me making the same mistake on my own website when I asked it to do a technical audit.

Then I found another website for the same business, with the same experience claims, methodology, case studies, and testimonials, but a different name and a different face. Two more followed, each apparently offering a different person’s expertise from what looked very much like the same kit.

The mistakes traveled from site to site as faithfully as the praise did, and they made a much better evidence trail. On multiple versions, an exact-match testimonial attributed to a women’s fiction author suddenly celebrates finding an audience for her LitRPG series, a genre crossover I suspect would surprise both readerships but nevertheless provided a convenient search string.

I discovered a featured client’s displayed email address didn’t match the address hidden underneath the link, and the same mismatch survived on more than one supposedly unrelated site. On one version, a testimonial praising the marketer by first name was signed by a client with that same first name, which is either a remarkable coincidence or what happens when find-and-replace is turned loose on a page nobody reads twice.

Then there was the headshot uploaded under the filename wmremove-transformed (1).jpeg, the kind of name a watermark-removal tool might give the file it spits out. That raises a fairly obvious question about where the photograph came from, which I will simply leave there.

I’ve pointed out elsewhere that I use AI, specifically ChatGPT, Claude, Gemini, and Copilot, to do a lot of the technical work that goes into the supporting activities of publishing my book. They’ve produced a ridiculously professional and technically excellent apparatus around that work. What I was seeing here was just sloppy.

I’d pin it on Grok, but that would contradict most of what I’m about to argue.

Somewhere in the middle of all this, ChatGPT summarized our increasingly strange investigation better than I could. I’ve substituted my pseudonym, but the joke belongs to the machine:

“We didn’t find Jane Doe. We found Jane Does.”

I’m not naming the marketer here, partly because I’m no longer convinced the name belongs to anyone.

The broader pattern, at least, is well established. Writer Beware, the publishing-industry watchdog, has spent more than a year documenting a wave of AI-driven scams targeting authors with many of the same ingredients: highly personalized solicitations, extravagant praise, Gmail accounts, purported marketing professionals, and outreach conducted at volume.

So I wasn’t the object of some extraordinary research effort. I was one more prospect in a system that had figured out how to make ordinary prospecting feel extraordinary.

For reasons that have much higher stakes elsewhere in this series, I wasn’t going to ask an AI detector to settle who had written the email. But by then I had enough evidence to be curious about what it would say. I ran the solicitation through Pangram, which returned 100 percent AI-generated. All 2,014 (!) words. Apparently, when there actually is a witch, the witch detector enjoys its work. That was the joke, anyway. Pangram agreed with the rest of the evidence, and I treated that as corroboration, not authorship proof.

Pangram now offers Gmail integration for incoming mail, so I connected it to the More Taste Than Fortune Gmail account and opened the solicitation in Gmail web. Pangram labeled it 100 percent AI there too. Same detector, same email, another way of seeing the same signal. It didn’t become independent evidence just because I had changed windows.

My AI book club briefly wondered whether running the email through Pangram was ethically analogous to the Falade manuscript situation. No. This was an unsolicited commercial pitch sent directly to me, and Pangram explicitly offers inbox scanning. That is a different ethical category from allegedly uploading somebody else’s unpublished manuscript without permission. I had asked the machines to investigate a sales pitch, and they had opened a second investigation into whether I was allowed to investigate the sales pitch.

Following those duplicate websites also made the other half of the discoverability problem obvious. The people behind the email had my problem too.

Their marketers had to be discoverable and appear credible enough to reassure a suspicious author, which meant biographies and methodologies and case studies and testimonials and contact details and a face. Every one of those was another dot.

They needed context to manufacture that credibility. Context produces connections, and connections can be followed in either direction.

I’d spent months making myself legible to machines and discovered that I couldn’t choose which machines got to read me. Whoever built these identities had made theirs legible enough to sell something, and in doing so made them accessible enough to investigate. Discoverability doesn’t come with an audience selector for them either.

That experience changed the good-AI/bad-AI distinction for me. Over here, an AI helps an author research an essay. Over there, an AI helps someone research the author before sending a deceptive solicitation. The machine may be doing almost exactly the same work.

I’ve now run that experiment from both ends.

The system used against me found things, connected them, summarized them, inferred from them, and turned the result into prose. When I turned AI back toward the operation, it found things, connected them, summarized them, inferred from them, and helped me understand what I was looking at.

On one end, someone wanted a stranger to feel understood well enough to reply “interested.” On the other, I wanted to know whether the stranger who understood me so well existed at all.

The moral difference lives in the asking.

That’s been one of the recurring arguments in this series: what matters is what the human asked the tool to do, what judgment the human retained, and what responsibility the human accepts for the result. The principle survived contact with my junk folder, which this time supplied the demonstration.

There was one final indignity waiting in the Substack.

One of those five forgotten essays, published in May 2023, was called “Project Management is a Human Endeavor.” I had some surprisingly confident opinions about the limits of artificial intelligence back then. May 2023 was a different country.

AI, I wrote, had done “a pretty okay job” of identifying project risks, but I’d “often found its suggested mitigations for those risks to be uninspired.” Word for word. Embarrassingly.

Three years later, an apparent AI-assisted operation had performed a remarkably sophisticated analysis of me, correctly identified a real marketing problem, and suggested I start a newsletter.

So 2023 me underestimated the technology, though I may have had its number anyway. When I asked my own AI for a countermeasure, the best it could offer was a patient explanation of why its Gmail access doesn’t render tracking pixels.

I’ll also admit, having spent this entire essay reading other people’s prose for tells, that my earlier essay has not aged gracefully. It marches through five tidy headed sections, each ending on some version of “AI lacks,” toward a closing line about a brave new world, and read today it has precisely the cadence people now flag as machine-written, which makes 2023 me a fairly strong candidate for the witch trial I described in “AI! Burn Him.”

Another essay from that little time capsule was about hiring. I argued that managers should read résumés themselves, and that there is a bright line between what a machine can evaluate programmatically and the subjective judgment a human ought to retain, because standout candidates write standout résumés and a creative layout or flash of humor is lost on an AI screener. The human signal I was arguing for was the particular, idiosyncratic mess that doesn’t fit a template, the evidence that a person with a life had made choices about how to present it.

Three years later, I was staring at a collection of purported book-marketing professionals with different names and different faces but the same experience, the same methodology, and the same testimonials. They had every component of professional identity except that particular mess. The only consistent particulars were their mistakes, which kept traveling intact from one supposedly distinct person to the next. I’d gone looking for the human detail that escaped the template and found the errors nobody had bothered to remove from it.

The junk mail didn’t convince me to hire anyone, didn’t get my money, and didn’t even get a reply. It did make me read all 2,014 words and inspect the headers for SPF, DKIM, and DMARC, pull apart tracking pixels, check what Apple Mail Privacy Protection does to them, and trace the mail-merge and CRM infrastructure. I followed duplicate websites through testimonial inconsistencies, hidden email mismatches, and a suspicious image filename, read Writer Beware, consulted Pangram, connected its Gmail integration, and even checked whether using it crossed some line. Somewhere in there I also thought differently about SEO and GEO and reread essays by a version of myself who thought he had artificial intelligence pretty well figured out. I had turned “check my work” into a lifestyle disorder.

So I suppose the spam failed, although that may be giving me too much credit. It did earn several hours of my time and an entire essay.

And it remembered my Substack before I did.

___________

Postscript: While I was polishing the final draft of this essay, four more highly personalized solicitations about Embracing the Local arrived in my junk mail. One from a “book club” told me it had selected the book as its October reading pick and invited me to discuss it with members. Embracing the Local publishes November 10.

They still haven’t noticed the timestamps, but my SEO/GEO is working. Yay.

The moral of the story, kids: if you’re going to email me, make sure you wrote it. Or don’t. AI detectors aren’t 100 percent reliable anyway.

Sources & Notes

Writer Beware: AI-driven scams targeting authors

Victoria Strauss, “Return of the Nigerian Prince: A New Twist on Book Marketing Scams,” Writer Beware, August 1, 2025, with subsequent updates. Strauss documents the emergence of highly personalized, AI-assisted book-marketing solicitations designed to convince authors that the sender has closely read and researched their work.

https://writerbeware.blog/2025/08/01/return-of-the-nigerian-prince-a-new-twist-on-book-marketing-scams/

Victoria Strauss, “Production Companies, Literary Agents, Foreign Languages: AI-Driven Scams Continue to Morph,” Writer Beware, August 28, 2026. This follow-up describes the expansion of the same scam ecosystem after more than a year of reports, including highly personalized approaches, lavish AI-generated praise, Gmail accounts, and outreach conducted at volume.

https://writerbeware.blog/2026/08/28/production-companies-literary-agents-foreign-languages-ai-driven-scams-continue-to-morph/

Victoria Strauss, “Return of the Nigerian Prince Redux: Beware Book Club and Book Review Scams,” Writer Beware, September 19, 2025. Strauss documents fake and impersonated book clubs offering author features or spotlights, including a solicitation that uses one club name at the start and another in the signature—the same kind of sloppiness discussed here.

https://writerbeware.blog/2025/09/19/return-of-the-nigerian-prince-redux-beware-book-club-and-book-review-scams/

Apple Mail Privacy Protection

Apple, “Protect email privacy in Mail on Mac.” Apple explains that Mail Privacy Protection hides a recipient’s IP address from senders and privately downloads remote content in the background when a message is received rather than when the recipient views it. This is why a request for a tracking image is not reliable evidence that I opened the message at that moment.

https://support.apple.com/guide/mail/mlhlp1205/mac

Streak email tracking

The raw HTML of the solicitation contained a zero-content request to mailfoogae.appspot.com, a domain used by Streak, a customer-relationship-management platform integrated with Gmail. Streak’s email-tracking system uses remotely loaded content to record message views. The original email also contained a separate tracking element loaded from p.mailmerge.eu/trace/mail/.

https://support.streak.com/en/articles/2447759-how-does-email-tracking-work

Pangram AI detection

Pangram describes its detector as a machine-learning classifier trained on human-written and AI-generated documents. I include its 100-percent classification of the solicitation as one piece of evidence, not proof of authorship. As discussed elsewhere in this series, classifier output cannot independently establish who or what wrote a particular text.

Pangram’s Gmail integration offers scanning and labeling of incoming mail. I connected it to the More Taste Than Fortune account and opened the solicitation in Gmail web, where it also showed 100 percent AI. Both results are my observations of the same service examining the same email, not independent tests of authorship.

https://www.pangram.com/research/how-it-works

https://www.pangram.com/solutions/gmail

Original solicitation and raw email

The solicitation discussed in this essay was received September 23, 2026. I retained both the original message and its full raw source. The raw headers show successful SPF, DKIM, and DMARC authentication for the sending Gmail account. The HTML contains the tracking elements discussed above. Names, email addresses, domains, unique message identifiers, tracking identifiers, and other information that could identify the purported marketer have been intentionally omitted here.

I have also chosen not to identify the collection of substantially similar marketing websites discussed in the essay. My interest is in the pattern and the technology that made it possible, not in attaching a potentially fictitious identity, or an identity appropriated from someone else, to an accusation in search results.

The Open Door

You read the whole thing.

Then you are the sort of reader this house is built for. The Open Door is how we say when there is another one — an essay, a book worth finding, something we learned the hard way. No schedule. Only when there’s something worth passing along.

Optional. Tell us roughly where you are and we’ll let you know when one of our authors, books, or questionable decisions turns up near you.

Ravens are slow, unreliable, and arrive at inconvenient hours. We keep watch anyway, so you don’t have to. Even at night. Even in winter. Winter is Coming!

No schedule. Unsubscribe whenever you like. Email signup uses Buttondown; this website uses Google Analytics.

Have something to say? Email me at essays@moretastethanfortune.com