Live data from Hacker News

How Spam Filtering Works: From SPF to DKIM to Blacklists

deliciousbrains.com

21–30 of 65 posts

Re: How Spam Filtering Works: From SPF to DKIM to Blacklists

#21
The great fallacy of spam filtering is that access control SHOULD be probabilistic whenever it is easy to implement that. Let's look at the physical world where implementation is harder. It's very unlikely that I'll arrive home from work at 4:30 AM, AND that I'll be driving a rental car instead of my own car, AND that I'll be wearing new shoes with a sole pattern that my smart walkway hasn't seen before. So, ideally my home security system would automatically call the police. Right?

Re: How Spam Filtering Works: From SPF to DKIM to Blacklists

#22
post #9

The author is still pretty far behind the curve with this info. Unfortunately while these policies are great to have (well these days they are more or less necessary), the simple fact is that they are so often misused or improperly maintained they don't really stop that much; a SPF mismatch is simply treated as another item to score the likeliness that a message should or should not be blocked. A DKIM signature is al…

The new hotness is ARC (arc-spec.org), which I understand came out of DMARC? Not sure though, don't know too much about it.

For DMARC, it's not so awesome :\ https://news.ycombinator.com/item?id=17900765

Re: How Spam Filtering Works: From SPF to DKIM to Blacklists

#24
post #9

The author is still pretty far behind the curve with this info. Unfortunately while these policies are great to have (well these days they are more or less necessary), the simple fact is that they are so often misused or improperly maintained they don't really stop that much; a SPF mismatch is simply treated as another item to score the likeliness that a message should or should not be blocked. A DKIM signature is al…

The new hotness is ARC (arc-spec.org), which I understand came out of DMARC? Not sure though, don't know too much about it. For DMARC, it's not so awesome :\ https://news.ycombinator.com/item?id=17900765

Basically mailing lists break DKIM signatures, and ARC fixes that. It also fixes certain types of automatic message forwarding, e.g. when you have account forwarding turned on, not when you hit the forward button.

Re: How Spam Filtering Works: From SPF to DKIM to Blacklists

#25
post #11

I've been thinking for a while that there should be a movement to allow people running mailservers at their home again. "Again" as in get other actors in the field to allow/ease that: spamlist managers should stop blocking residential address by default and make it easier to appeal. ISPs should make it possible and easy to get a reverse-ptr with every fixed ipv4 allocation. In this monitoring age I want to be able to…

I'd absolutely be all for it - I've been running my mail server since the 90s, and used to run it out of my closet.

There are two major, somewhat interlocking problems, though: home users with compromised machines currently represent the population of home "mail servers" (spam malware) at the moment. Selling this involves convincing mail administrators that not simply blackholing all of what is currently a cesspool is a good idea. That's not easy.

The second problem is that fixed-IPs, open well-known ports and DNS have become a product differentiator for ISPs. Those are "business" features; dumb ole' consumers don't "need" them.

I don't see any compelling argument that would convince either prong of that trap - hell, I agree with you, but as a mail admin both professionally and personally, the first one gives me hives, thinking about the years of work it'll take to re-stabilize a functional antispam infrastructure to handle it.

And after that, you need to convince Comcast to change their revenue-extraction plans and generally be less dickish.

If just you want a mail server now, your best bet is a cheap VM somewhere. It can be really low-end and cheap.

Re: How Spam Filtering Works: From SPF to DKIM to Blacklists

#26
post #25
post #11

I've been thinking for a while that there should be a movement to allow people running mailservers at their home again. "Again" as in get other actors in the field to allow/ease that: spamlist managers should stop blocking residential address by default and make it easier to appeal. ISPs should make it possible and easy to get a reverse-ptr with every fixed ipv4 allocation. In this monitoring age I want to be able to…

I'd absolutely be all for it - I've been running my mail server since the 90s, and used to run it out of my closet. There are two major, somewhat interlocking problems, though: home users with compromised machines currently represent the population of home "mail servers" (spam malware) at the moment. Selling this involves convincing mail administrators that not simply blackholing all of what is currently a cesspool i…

Dynamic IP is a bummer, but outright closing ports is a direct violation of net neutrality. It's baffling that it's tolerated at all.

An ISP's job is to forward IP packets. Not read them. TCP/UDP ports number are the content of those IP packets—not the meta data. Filtering based on such content is already a form of discrimination. What's next, deep packet inspection?

Some ISP filter by default, but they do this at the router level, and you can either configure or change the router. That's okay, possibly even beneficial. Blocking at the backbone level however is just evil.

Re: How Spam Filtering Works: From SPF to DKIM to Blacklists

#27
post #3

Would love to get feedback from the HN community. We're a decently sized sender following what we think are best practices (sending to engaged, dkim, etc.) however our gmail deliverability is rock bottom and it's been difficult to improve. Every other provider is to benchmark or better. One issue may be high hard bounce rates on our very first email sent, but we don't send emails to bounces at all afterwards. (Wouldn…

> One issue may be high hard bounce rates on our very first email sent, but we don't send emails to bounces at all afterwards. This is a big red flag, though. Are you saying it just happened one single time? In that case, change your IP and start over. Or are you saying that you regularly trigger a lot of hard bounces? Because if that is the case, that might explain it all right there. High rates of hard bounces are…

or people putting random emails to get to the next screen/download link

Re: How Spam Filtering Works: From SPF to DKIM to Blacklists

#28
post #11

I've been thinking for a while that there should be a movement to allow people running mailservers at their home again. "Again" as in get other actors in the field to allow/ease that: spamlist managers should stop blocking residential address by default and make it easier to appeal. ISPs should make it possible and easy to get a reverse-ptr with every fixed ipv4 allocation. In this monitoring age I want to be able to…

There should be a home email server called "Buttery Mail".

Re: How Spam Filtering Works: From SPF to DKIM to Blacklists

#29
post #11

I've been thinking for a while that there should be a movement to allow people running mailservers at their home again. "Again" as in get other actors in the field to allow/ease that: spamlist managers should stop blocking residential address by default and make it easier to appeal. ISPs should make it possible and easy to get a reverse-ptr with every fixed ipv4 allocation. In this monitoring age I want to be able to…

It would probably be easier to just build an AMI for one of the existing mailserver-in-a-box systems to proxy email via an AWS t2.nano instance. You can run a t2.nano with a 3-year reserved instance for $30/yr, and then proxy all your mail to and from your home server on non-standard ports.

Re: How Spam Filtering Works: From SPF to DKIM to Blacklists

#30
post #12

Been there, done that. And then Microsoft answers my complaints (after my mails never showed up at my brother in laws outlook.com mailbox): We have reviewed your IP( . . . ) and determined that messages are being filtered based on the recommendations of the SmartScreen® Filter. Email filtering is based on many factors, but primarily it's due to mail content and recipient interaction with that mail. Because of the pro…

Yet, on my hotmail account, I'll receive messages that have a From header similar to the following:

    From: VlAGRA_&_CIALIS 
Post reply on HN