Live data from Hacker News

The Hostile Email Landscape

liminality.xyz

91–100 of 251 posts

Re: The Hostile Email Landscape

#91
This is a true story:

I rent some servers from the Rackspace cloud for personal use. I have my own sites on these machines, and my own email servers.

Meanwhile, I have a day job, and lately it has been consuming 12 hours a day. We missed a deadline and we have all been working like crazy to catch up. I have fallen behind reading my personal email.

Roughly a month ago, my friends who use Gmail stopped getting my email. Or rather, they did not know I was sending them email, because all of my email to them was going to spam.

After a few weeks, I finally had a free weekend to catch up on my personal life, so I did some investigations. Turns Rackspace had switched over to IP6 in a way that impacted my email. I did not have a Sender Policy Framework for IP6, only IP4.

It's likely that Rackspace sent me an email about this, though I never read it because I was busy.

This was easy to fix: I added a SPF for IP6.

However, these kinds of issues do make it harder to maintain a personal email server. Its tough for us to keep up with the changes.

Re: The Hostile Email Landscape

#92
post #83

Earlier quoted context omitted.

The minute you say bitcoin is the moment you cut out 99% of the population; unless it is in the background and one does not have to interact with it directly. Other than that, I agree paying to send will reduce spam. But also look at your postal mail box. There is arguably more spam there than in your digital inbox, and that one costs (stamps).

I get far more spam than legitimate mail in the US Postal mail.

Me too. Take the contents from one spam envelope and place it in the return envelope of another spam. Keep 'em churning.

Re: The Hostile Email Landscape

#93
post #16

I've run into similar issues with a similar setup. It's frustrating. You can convince gmail user A to whitelist your messages, and so they'll get through to user A, but gmail user B probably still won't see messages from you unless you tell him to dig them out of the spam trap. And your messages to A might still be classified as spam if they have attachments or hyperlinks in them. (Even if you've been corresponding w…

The email deliverability issues we have had as a legitimate business are insane. Moving to an ESP years ago has helped, but it's far from perfect. I've wondered how a small business without the tech resources could manage this. For instance, several months back some of our account holders suddenly stopped receiving important account info as well as newsletters from us. Tracked it down to a third party filtering servi…

so... your customers were paying a third party to block you, so rather than working with your customers to figure out what the problem was, you threaten to sue the third party.

Re: The Hostile Email Landscape

#94
I feel like this is a solvable problem without making any changes to email whatsoever. The problem is the email recipient hosts are suspicious of the sender (as opposed to the message itself being suspicious). So the solution is to have a standardized way for senders to acquire an instantaneous reputation by tying their real-world identity to it (which lets them be held accountable if they do spam), and perhaps by throwing some money at it too. If there was some company that did identity checks, similar to how EV certificates are given out, then that ties your real-world identity to it (this could in fact be done by literally requiring an EV certificate for the hostname of the sender). This company could also take a decent-sized deposit (so you're staking money on not being a spammer) and hold it in trust for a set amount of time. Once the time has passed, and you've sent enough emails for recipients to draw meaningful conclusions, if you have in fact not spammed, then you get your deposit back (minus a service fee). Then all the big email hosts would pay this company to query it about senders the host doesn't already trust, and similarly they'd report any spam from these hosts back to the service.

Heck, this doesn't even have to be a new company. A big host like Google could just start offering this service anyway, as a way to simplify their own handling of unknown senders, although I'd feel more comfortable if this was done by someone else.

Re: The Hostile Email Landscape

#95
post #34

>This isn't how the internet is supposed to work. The email architecture was started back when it was a smaller network of researchers at universities, governments, etc. Everybody basically trusted each other. Once the "internet" is available to the general public and commercial interests, it becomes vulnerable to the "bad actors" problem (e.g. spam abuse). That's why we have the inevitable situation today of a few e…

Combining a notify/pull system with a requirement for a valid domain certificate from a pre-approved list of CA's, similar to those already in the browsers, would go a step farther... increasing the costs for operating a a badly acting domain only to be blacklisted relatively quickly.

Unfortunately, that would be less than decentralized, but it may turn out to be the best option in combating spam.

I've just opted to pay for sendgrid for my small hobby BBS server's outbound email, because it's easier than setting up an appropriate outbound system myself, and as TFA points out, even then odds are you'll be bitbucketted before you even start.

Re: The Hostile Email Landscape

#96
post #16

I've run into similar issues with a similar setup. It's frustrating. You can convince gmail user A to whitelist your messages, and so they'll get through to user A, but gmail user B probably still won't see messages from you unless you tell him to dig them out of the spam trap. And your messages to A might still be classified as spam if they have attachments or hyperlinks in them. (Even if you've been corresponding w…

The email deliverability issues we have had as a legitimate business are insane. Moving to an ESP years ago has helped, but it's far from perfect. I've wondered how a small business without the tech resources could manage this. For instance, several months back some of our account holders suddenly stopped receiving important account info as well as newsletters from us. Tracked it down to a third party filtering servi…

> Here they were, a third party with whom we had no agreement, yet they were interfering with our ability to do business (and profiting from it).

Well... that's an oversimplification. You don't have an agreement, sure, but your recipient has an agreement with them --- your recipient has decided that it's with paying the spam filtering supplier to filter their mail for them.

I realise that this doesn't help you, and frankly they don't sound like they're doing their job very well, but it's important to remember that the recipient chose to use their service.

Re: The Hostile Email Landscape

#97
I've managed my own mail server since 1993, and my email address has been the same that entire time. Here are some tips for maintaining sanity:

Greylisting still works amazingly well. With a long, long whitelist and greylisting plus DNSBL, I don't even bother running a spam filter, since the little bit of spam and emails from new senders ends up in its own directory as it came from a non-whitelisted sender.

Comcast finally started blocking residential mail server ports inbound a few years ago, so I had to migrate to a smarthost environment using a VPS as email server for $15/yr.[1]

Last year for a few months, Gmail was dropping everything I sent into the spam folder, even after recipients were marking it not spam. I eventually discovered the "Authentication-Results:" header that Gmail adds to every inbound message. It is under the "Show Original" dropdown menu. That showed that I "hadn't changed anything"(!) on my mail server, but suddenly Gmail was connecting to my mail server over an IPv6 interface, and I had never bothered to put the IPv6 block into the SPF record. Gmail was nice enough to explain exactly what it didn't like about those emails.

[1] http://lowendbox.com/blog/top-provider-poll-2014-q3-the-resu...

Re: The Hostile Email Landscape

#98
post #74
post #59

Earlier quoted context omitted.

http://cr.yp.to/im2000.html Internet Mail 2000 IM2000 is a project to design a new Internet mail infrastructure around the following concept: Mail storage is the sender's responsibility.

Because spammers can't afford a couple of TB of disk space?

What do you mean? A single message/template sent to a million people would be a couple KB... only the ongoing operational costs of hosting the server... Beyond that, blacklisting would be more affective if there was a pull based email model.

Re: The Hostile Email Landscape

#99
It may be infeasible to run a new SMTP-based mail service from "residential IP's" that can interact with the existing email empire, dominated by store and forward middlemen who expect to make money from the "free" email service they provide.

That empire amounts to a junk email delivery service and later a way to gather information about email users. The later purpose is probably why you want to run a new email service?

However it is certainly feasible to run a new SMTP-based email service from residential IP's that does NOT interact with the existing email empire. One with no middlemen. The sender's SMTP server talks directly to the recipient's SMTP server. You decide what port you want to use. There are thousands to choose from.

There are multiple ways to do this, but I rarely if ever see this option discussed. I suspect it's because like DNS most users are not comfortable configuring mail servers nor with NAT traversal.

If indeed the motivation for running your own mail service is because you do not want your mail stored on third part servers (whether in the sender's mail folders or the recipient's), then the ability to interact with the existing store and forward email providers seems a counterproductive requirement.

Re: The Hostile Email Landscape

#100
post #84

I sometimes see similar tales of woe, and I can only say that this does not match my experience. I’ve done this many times, you set up the mail server, configure DNS correctly (including reverse lookup), and that’s it. Never had problems being blacklisted or mail getting classified as spam. I suspect that people having trouble are sending a lot of mail , like “newletters”, etc. But I can’t prove this hypothesis.

Mail reputations are very real and pose an issue with mail servers. I had a gaming server for years and had many issues with Gmail, Microsoft and Yahoo, to name a few, filtering or blocking emails. Just last week, I setup a mail server using mail in a box on a new server I spun up on Digital Ocean using an IP that was on no blacklists and still had issues with sending emails to various Gmail subscribers.

Even when I used to work at HostGator and handled many of their abuse issues, they had many issues with being blacklisted just because RBLs didn't recognize new HostGator IPs or the rate of email being sent from their new gateways.

So, at least with my personal and professional experience, I can attest to the issues with using self-hosted mail servers.

Post reply on HN