Live data from Hacker News

Spam blacklisting is out of control

blog.roastidio.us

31–40 of 430 posts

Re: Spam blacklisting is out of control

#31
I'm dealing with this right now.

Both my personal domain and rsync.net are on a distinct subnet, but that subnet is smaller than a /24 and someone on a different subnet has, apparently, behaved badly.

Enter "abusix" ...

One of my engineers had an enlightening webchat with one of their engineers where we were shown the "offending" IP and it was explained that they have no ability to distinguish subnets (and no interest in doing so). So if you're not wasting an entire /24 (we only need ~10 IPs at this location) you're in danger of this misclassification.

We were also informed that our normal, business communications with paying customers should have unsubscribe notices appended to them. Which is to say, you're a paying customer of a service and we send you some kind of alert or critical announcement ... and it should have an unsubscribe link.

Unbelievable.

Re: Spam blacklisting is out of control

#33

> Or I can leave the current hosting company Yep, that's the one. If your hoster doesn't care about spam spreading from their IP space, you should take your mail server elsewhere. There's literally nothing to think about. And if they do care about this issue, they are likely to be taking steps to remove any of their IP space from the blacklists, without being nudged. PS. I've been running a mail server for close to 2…

When I first started monitoring spam connections years ago, it was almost always home cable+internet providers. They seem to have gotten the message and cleaned up thier acts.

As of last night, the number one source of spam for both the personal and company servers I maintain is Digital Ocean.

Which is a shame, because otherwise I'm a happy Digital Ocean customer. But because of this, I would never move any of my commercial projects there.

Re: Spam blacklisting is out of control

#34
I fought the battle to keep my SMTP server IP off blacklists, and lost.

You can do everything possible, have a perfectly clean IP, have a good amount of outbound email traffic, only send transactional email, etc. Still, there will be edge cases where email does not go through. AT&T email servers would constantly blacklist me and not respond to requests to remove me, gmail/yahoo/outlook would silently put emails in the spam folder, and companies using email firewall products would blacklist me, with an IT Dept too inept to fix it.

The solution was to pay a small fee and proxy all outbound email through a transactional SMTP sender, like Postmark or Mailgun. It's easy to do, with one line of code in Postfix. You can be selective, and only proxy emails sent to certain troublesome domains. If you try an email provider and it's not working out, it's one line of code to change to another provider.

This allows me to still manage nearly all aspects of hosting my email server and control my email data, while not dealing with deliverability issues. I use Postmark and I have not dealt with a deliverability issue in two years.

Re: Spam blacklisting is out of control

#35
post #31

I'm dealing with this right now. Both my personal domain and rsync.net are on a distinct subnet, but that subnet is smaller than a /24 and someone on a different subnet has, apparently, behaved badly. Enter "abusix" ... One of my engineers had an enlightening webchat with one of their engineers where we were shown the "offending" IP and it was explained that they have no ability to distinguish subnets (and no interes…

> We were also informed that our normal, business communications with paying customers should have unsubscribe notices appended to them.

You should have an unsubscribe link. You should also have your business address and identify yourself.

Even if it's not required by the letter of the law, you should add it.

As an example: Amazon automatically opted me into an "alert" when a wishlist I viewed had a new viewer. Since it's an "alert" and a "business communication" it has no unsubscribe. This is spam - this is an ad hidden as a notification.

Re: Spam blacklisting is out of control

#36

> Or I can leave the current hosting company Yep, that's the one. If your hoster doesn't care about spam spreading from their IP space, you should take your mail server elsewhere. There's literally nothing to think about. And if they do care about this issue, they are likely to be taking steps to remove any of their IP space from the blacklists, without being nudged. PS. I've been running a mail server for close to 2…

Any hosting company where some random person can buy a VM for $5 on a credit card has this problem. Mostly I feel sorry for the support and staff at the hosting companies who do not have the time/manpower/resources to deal with it properly, and this is an intentional business decision by the people who own and run the companies.

It's a race to scraping the bottom of the barrel on per customer profit margin and pricing.

Re: Spam blacklisting is out of control

#37

> Or I can leave the current hosting company Yep, that's the one. If your hoster doesn't care about spam spreading from their IP space, you should take your mail server elsewhere. There's literally nothing to think about. And if they do care about this issue, they are likely to be taking steps to remove any of their IP space from the blacklists, without being nudged. PS. I've been running a mail server for close to 2…

>/24 netblock on the second offense.

That seems excessive and abusive, I am not aware of any commercial ISP that is giving out /24 anymore. /29 is most common, I had to practically beg to get a /28 so what is the justification for banning an /24???

Re: Spam blacklisting is out of control

#38
post #31

I'm dealing with this right now. Both my personal domain and rsync.net are on a distinct subnet, but that subnet is smaller than a /24 and someone on a different subnet has, apparently, behaved badly. Enter "abusix" ... One of my engineers had an enlightening webchat with one of their engineers where we were shown the "offending" IP and it was explained that they have no ability to distinguish subnets (and no interes…

Those unsubscribe links should be there, for several reasons.

- The service-based economy means that entities (individuals and businesses) have numerous relationships. For the typical individual the number of password-based accounts crossed the 100 threshold years ago, at a doubling rate of every 2--3 years.

- Responsibilities can be transferred. The person who signed up for your service 5 years ago may no longer be at the company.

- List purging is a Real Thing. A few years back I'd worked for an organisation that had ... numerous relationships ... with individuals and corporations. These received regular email messages. Nominally, requested. Included amongst these was a major Wall Street financial firm whose implosion years earlier hit lead news and headlines worldwide. Despite not existing for years, there remained hundreds if not thousands of addresses being sent email on a regular ongoing basis.

- Mail can be forwarded. It's quite possible that you're sending mail to one address that is is being forwarded, manually or automatically, to others. This raises issues in unsubscribe requests, but might at the least be an opportunity to reach out to your customer to clarify the situation.

- I don't know if revisiting email contact approval on a regular basis (say once every year or two) is yet a recommended practice, but I'd strongly suggest that it be so.

Your hat may be less blisteringly white than you presume.

Re: Spam blacklisting is out of control

#39
post #31

I'm dealing with this right now. Both my personal domain and rsync.net are on a distinct subnet, but that subnet is smaller than a /24 and someone on a different subnet has, apparently, behaved badly. Enter "abusix" ... One of my engineers had an enlightening webchat with one of their engineers where we were shown the "offending" IP and it was explained that they have no ability to distinguish subnets (and no interes…

> We were also informed that our normal, business communications with paying customers should have unsubscribe notices appended to them. Which is to say, you're a paying customer of a service and we send you some kind of alert or critical announcement ... and it should have an unsubscribe link.

You absolutely should. The amount of junk I get because someone else signed up for something and fat fingered their email address is ridiculous. "Mandatory communication" with a company I've never dealt with gets flagged as spam.

Post reply on HN