Live data from Hacker News

Spam blacklisting is out of control

blog.roastidio.us

1–10 of 430 posts

Re: Spam blacklisting is out of control

#2
There is a typo in their title. If intentional please instead consider words like block reject and deny for the people that do not speak English as a first language.

I've dealt with real time blocklists as long as they have existed. They are not going away any time soon. I agree that the paid exception lists are a bit shady but I also see the validity of their methods of temporarily punishing everyone on a hosts network to put pressure on the ISP/platform provider to police it's own network and remove spammers. The best one can do today aside from securing ones own server is to research an ISP's IP space ahead of time to see how dirty they are. There are plenty of providers that cleaned up their act some time ago. Linode is a great example of change. New accounts can't even send email unless they open a ticket and prove they made some effort to comply with can-spam. More providers need to follow that example so that we don't run into this problem of dirty networks that real time block-lists like UceProtect have listed. It's an imperfect solution to an old ugly problem.

Re: Spam blacklisting is out of control

#3
I too have had issues with that particular blacklist, which, I believe, is gaining notoriety as a scam. In my case I was setting up outgoing email for a customer's WordPress website. In the end, rather than spending the time and money dealing with the blacklist, we routed their mail through Sendgrid. Not an especially happy ending, but their email works now.

Re: Spam blacklisting is out of control

#4
> I can complain to my hosting company and hope they evict the bad user from the network. But then why should my hosting company do so?

The answer to this is the other option, leaving the hosting company. In this manner, every hosting company gets a choice - either they will kick out legal-but-immoral things like spammers, or they will not and rightly lose their above-board customers.

This is essentially how the global e-mail community self-polices by establishing a norm that a host either has to work to exclude bad actors or will get boycotted/excluded for allowing them.

Re: Spam blacklisting is out of control

#5
This post meanders between complaining about RBLs and vaguely whining about the big email hosts, but I don't see the connection. There is zero useful information contained in the RBLs and the big hosts don't use them.

Re: Spam blacklisting is out of control

#6
Fortunately for the author, I haven’t noticed any email servers that use the UCEPROTECTL3 RBLs to reject mail—which is to say, I’ve noticed some servers I administer end up on UCEPROTECTL3 incidentally and it has never caused a delivery problem.

On the other hand, some VPS providers are still allocating multiple customers to the same IPv6 /64 using SLAAC by default, and this will make it impossible to deliver mail on IPv6 since reputable RBLs always blacklist the whole /64.

As far as the argument about spamming being immoral but not illegal, I’ve never seen a reputable ISP that didn’t prohibit unsolicited bulk email in their terms of use, so the grounds for reporting it is that a customer is violating the terms that they agreed to follow when they signed up.

And to answer the question of whether or not RBLs are useful: in my experience, yes, they are quite useful. The biggest problem I’ve noticed with them is not typically false positives on small providers, but false negatives on giant companies like Google who cannot ever end up on an RBL because they process so much mail but don’t do a good enough job of preventing their servers from being used to send spam.

Re: Spam blacklisting is out of control

#7
Spam blocklists are run by an unaccountable cowboy cult that somehow has managed to consolidate a ton of power simply for the fact that most people who run email inbox services didn't want to deal with the problem of spam, so they were more than willing to just hand over anti-spam "enforcement" to anyone who was allegedly doing "what was best for the internet." There's no check on these people who run these blacklists, and the system they've built is entirely a black box, antithetical to the principles of the open internet. And if you're not a huge corporation that can afford professional management of your email deliverability, good luck – the individuals and small organizations are just out of luck. It's a miserable racket and for what?

If you want to know why there's a new thread each week on HN about why it's impossible to host your own email service, this is why.

Re: Spam blacklisting is out of control

#8

There is a typo in their title. If intentional please instead consider words like block reject and deny for the people that do not speak English as a first language. I've dealt with real time blocklists as long as they have existed. They are not going away any time soon. I agree that the paid exception lists are a bit shady but I also see the validity of their methods of temporarily punishing everyone on a hosts netw…

Yeah except we've had this recently with Linode's IP range landing on that exact blacklist and being blocked by Microsoft and other major mail providers, knocking out our ability to send to huge chunks of our customers. I've had to get the mail server moved off Linode to another hosting company as paying the ransom fee did nothing. UceProtect does seem at least as morally dubious if not more so that the spammers it alleges to protect against.

Re: Spam blacklisting is out of control

#9
UCEPROTECT is a scam. Blocking innocent people and asking them for money has nothing to do with security. The good thing is that most email servers do not use it because it's just bad. The bad thing is that Hotmail uses it (or at least was at until recently). It does mean that, as a Hotmail user, there's legitimate email that you won't receive.

I do wonder if the guy behinf this scam is randomly blocking whole ip ranges to make a living, having enough people agreeing to the racket.

Re: Spam blacklisting is out of control

#10
RBLs are useful, but there are a few that are not what they appear to be. The particular one in question, UCEPROTECT is

a) not worth paying

b) should never be used by a production mailserver to block messages.

From the beginning there have been enterprising RBLs that are clearly overbroad, and offer to accept money. The money is not for getting off the list, it is always for something else so as to appear legitimate and a side effect is getting your domain off the list. This model is unethical at best, and is right up there with companies that snail mail over-priced domain renewal notices.

Post reply on HN