Everyone seems to agree that email is broken (and yet incredibly useful and almost universal in reach). So moving on from there, how do we fix it? Who is currently working on fixing it? What would a new protocol look like?
Chat services such as Slack, and social media like Twitter, are excellent ways to communicate. It's pretty simple. If you implement a request system so that both parties have to agree to let the other send messages, all of the problems are solved. There's no good reason that we need a system that allows anyone to send an arbitrary number of messages to anyone else.
The Hostile Email Landscape
151–160 of 251 posts
Re: The Hostile Email Landscape
#152That said, silently dropping messages without a notification is probably illegal! And pretty serious! So if you know what you are doing (and you are not a spammer) you should send a cease and desist!
Just make sure you use double opt-in and that providing an e-mail address in sign-ups/etc is optional!
Some will however put your mail in a spam-folder and it's not much you can do about it, just hope your readers complain to their provider.
So basically: setup your smtp relay correctly! Make sure you are not on any black-lists. Add extra headers like dkmi / precedence, add spf (don't froget ipv6) and ptr. Add your relays to white-lists. Publicly publish a privacy and e-mail policy (important! with opt in and optional clause); Link to them and fill out some "email provider" forms at gmail/microsoft. Send out a bunch of test mails. This will take a whole day, but if you do this, you will have no problems unless your IP or domain is perma-banned.
Re: The Hostile Email Landscape
#153I guess big providers has to deal with "newbies" all the time, that don't know how to configure their server and run open relays. And don't know how to add extra headers etc. That said, silently dropping messages without a notification is probably illegal! And pretty serious! So if you know what you are doing (and you are not a spammer) you should send a cease and desist! Just make sure you use double opt-in and that…
Re: The Hostile Email Landscape
#154Re: The Hostile Email Landscape
#155Earlier quoted context omitted.
>And, of course we attempted to identify the problem with the third party. If you read more carefully, you'll find that in my comment. Only after they insisted their classification was correct and refused to remove us from the list did we explore our legal options. My point here is that the recipients of the email and the senders of the email have very different ideas as to what constitutes a "correct evaluation." -…
You are really missing the point here and you have some key assumptions wrong. > recipients of the email and the senders of the email have very different ideas What does that mean? They sign up for our service and expect to get e-mails from us, which they don't receive. We have the same "idea", but the third-party is interfering with that "idea". > if the recipients can't complain, that's a problem I will repeat that…
That's not quite how it works from the end-user's perspective.
Say I buy a product or service from you. Of course, you send me billing emails, etc. and that's fine.
The problem is that companies take this further and start thinking they have the "right" to send all sorts of garbage to that customer.
Now, they of course let the customer opt out... if the customer is willing to spend ten minutes digging through their interface. But most don't.
I know you love those newsletters; they make you money. But don't kid yourself that your customers do. Many are going to click 'report spam' if you send too many. Even if it's not spam by the definition that marketers use, it's still very clearly unwanted email, and marking it as spam is so much easier than going through the unique-to-you opt-out procedure. And if your list is like most, some of the members signed up years ago (or bought something from you years ago) and long ago forgot doing so, so of course they are going to mark it as spam.
If you want to send email to your customers, you need to understand this.
Note, I'm not saying that you can't send that email; you can. I send email to my customers, and some of it borders on being "newsletters" - I'm just saying that you need to be aware of the cost- that cost is that it will annoy some of your users. Getting your email marked as spam is only one part of that cost.
>Even if recipients did know about the third party, do you know the switching costs of e-mail? And, you're suggesting that we should wait until all of our affected members get fed up and change providers (hoping that provider doesn't use the same service, etc.)? All of this, when the problem is obviously being caused by the third-party's error, yet they have no responsibility?
My point is that third party has no responsibility to you. They have a responsibility to their customers, but none to you.
Re: The Hostile Email Landscape
#156Earlier quoted context omitted.
http://cr.yp.to/im2000.html Internet Mail 2000 IM2000 is a project to design a new Internet mail infrastructure around the following concept: Mail storage is the sender's responsibility.
Bernstein is an incredibly smart guy. But he's also an example of how the social stuff matters. His software would run the internet if he put a little more effort into the social/political side of things. The big problem with IM2000 is that it doesn't solve the real problems. It's focused on the economics of storage of mail, which, yeah, are a thing for a few mail administrators, but generally is considered less impo…
That he focuses on the software instead of pandering probably makes his software better than the alternatives that aim to please even the most foolish of users. At least I think so.
Maybe I interpreted the proposal incorrectly, but I always saw IM2000 (minus the "notifications") as a "pull" solution.
By contrast, conventional email relies on "pushing" spam to the recipient (in practice, a middleman called an "email provider").
A smart IM2000 recipient perhaps would not pull spam from the sender's server.
As such, the spam would never enter the network. It would just sit on the sender's server.
Therefore, IM2000 not only conserves storage but also conserves bandwidth.
Re: The Hostile Email Landscape
#157I've managed my own mail server since 1993, and my email address has been the same that entire time. Here are some tips for maintaining sanity: Greylisting still works amazingly well. With a long, long whitelist and greylisting plus DNSBL, I don't even bother running a spam filter, since the little bit of spam and emails from new senders ends up in its own directory as it came from a non-whitelisted sender. Comcast f…
One "could" have a VPS SMTP server transporting inbound mail to a mail server at home and relay outbound mail through e.g. Amazon SES via the same vps-smtp host. But still.. this is bullshit.
It is very easy to set up.
The full setup for inbound mail is - OpenBSD spamd (greylisting) -> internal postfix
Outbound is - internal postfix -> VPS postfix
Re: The Hostile Email Landscape
#158Earlier quoted context omitted.
so... your customers were paying a third party to block you, so rather than working with your customers to figure out what the problem was, you threaten to sue the third party.
That's a rather glib and obtuse way to put it. I'm an Amazon customer. If Amazon can't reach my gmail address because Google started using some third party filtering service, what exactly would you expect me to do? Even if I had the ability, I certainly don't have the inclination to spend time resolving this issue. I'll go so far as to mark something "not spam", but that's about it. The cost to me of not hearing from…
In fact, we learned of the problem when customers suddenly began to complain that they weren't receiving their password reset emails from us.
Re: The Hostile Email Landscape
#159There is a KB explaining that new senders get a high score.
Re: The Hostile Email Landscape
#160Earlier quoted context omitted.
Crossdomain web hosts are also a thing, and HTTPS works fine. (Sometimes with particularly hilarious definitions of "fine", like CloudFlare's former practice of putting dozens of customers' websites in the same certificate, via subject alternative names.) If you're worried about the fact that your mail host and web host can now impersonate each other, we can just define a new X.509 extension for "I can only be used f…
If someone spoofs a CNAME to evil.com in response to DNS query for google.com, your browser will not accept a certificate from evil.com as valid for google.com, whereas if you send mail to gmail.com and someone spoofs an MX record for mx.evil.com, a vaild mx.evil.com certificate will be accepted.
Postfix, for instance, lets you configure what it checks via the "smtp_tls_verify_cert_match" option. If you set it to "nexthop", it'll require google.com. The default, "hostname", will check against mx.evil.com.
http://www.postfix.org/postconf.5.html#smtp_tls_verify_cert_...