Live data from Hacker News

Spam blacklisting is out of control

blog.roastidio.us

81–90 of 430 posts

Re: Spam blacklisting is out of control

#81
post #46
post #39

Earlier quoted context omitted.

> We were also informed that our normal, business communications with paying customers should have unsubscribe notices appended to them. Which is to say, you're a paying customer of a service and we send you some kind of alert or critical announcement ... and it should have an unsubscribe link. You absolutely should. The amount of junk I get because someone else signed up for something and fat fingered their email ad…

That's a (very legitimate and important) reason to do double opt-in unilaterally for all email communications. Companies should make 100% sure that the person who signed up, and the person receiving the email, are the same person, before they associate the email with the account. Otherwise, malicious people can sign up arbitrary third parties for tons of random crap. But it's not a good reason for adding unsubscribe…

For my power to be cut off, I would have to…

1. Forget I had a monthly power bill for a couple of months.

2. Ignore the e-bill that gets sent to my bank bill payment service - ebills have been a thing for almost two decades. I worked on some of the early implementations.

3. Ignore the physical snail mail warnings for a couple of months.

Re: Spam blacklisting is out of control

#82
post #31

I'm dealing with this right now. Both my personal domain and rsync.net are on a distinct subnet, but that subnet is smaller than a /24 and someone on a different subnet has, apparently, behaved badly. Enter "abusix" ... One of my engineers had an enlightening webchat with one of their engineers where we were shown the "offending" IP and it was explained that they have no ability to distinguish subnets (and no interes…

Those unsubscribe links should be there, for several reasons. - The service-based economy means that entities (individuals and businesses) have numerous relationships. For the typical individual the number of password-based accounts crossed the 100 threshold years ago, at a doubling rate of every 2--3 years. - Responsibilities can be transferred. The person who signed up for your service 5 years ago may no longer be…

I strongly disagree. There is absolutely no need to put an unsubscribe link into a transactional email.

All emails should of course contain enough information to make it clear who the message is from, why the message is being sent, and who it was sent to.

But there is no point in adding unsubscribe links to messages and notifications that are essential to the service.

I mean, what are you going to do if the user accidentally clicks "unsubscribe", and then a payment doesn't go through? Should you just cancel their account without informing them? That's absurd.

I'd be really pissed if eg. my backups were deleted because I accidentally unsubscribed from emails from a cloud service provider.

Re: Spam blacklisting is out of control

#83
> Other customers within this range did not care about their security and got hacked, started spamming, or were even attacking others, while your provider has possibly not even noticed that there is a serious problem. We are sorry for you, but you have chosen a provider not acting fast enough on abusers.

What a ridiculously hostile message. Just because a website or mail server or whatever they are talking about got compromised does not mean that the owner "did not care about their security". This sounds like a case of a blocklist operator on a power trip, talking down to people.

Re: Spam blacklisting is out of control

#84
post #34

I fought the battle to keep my SMTP server IP off blacklists, and lost. You can do everything possible, have a perfectly clean IP, have a good amount of outbound email traffic, only send transactional email, etc. Still, there will be edge cases where email does not go through. AT&T email servers would constantly blacklist me and not respond to requests to remove me, gmail/yahoo/outlook would silently put emails in th…

While I am happy for you that you have found a solution, the solution you found is symptomatic of a very dangerous situation: it is increasingly impossible for individuals or SMEs to use essential online facilities like sending messages or transferring money reliably unless they use a broker service as an intermediary. We are allowing small numbers of tech firms to take control of vital functionality that should be u…

I agree completely with this, but the one problem is that you haven’t addressed how we control spam without these “trusted” intermediaries. “Trusted” here meaning that they aren’t spammers.

Re: Spam blacklisting is out of control

#85
post #62

The US federal government should tackle huge email account providers that effectively (by accident or design) use anti-spam as a pretext to sabotage self-hosted email.

Yes because the government involved in technology always makes things better as I click on “allow cookies” on every damn website.

Re: Spam blacklisting is out of control

#86

Earlier quoted context omitted.

Yes. I explicitly told you I didn’t want any emails from you.

That is gonna lead to all kinds of misunderstandings and complaints.

If I unsubscribed that already told you I didn’t want you sending me emails. Your attitude is the very reason I use “Hide My Email”.

Re: Spam blacklisting is out of control

#87

Earlier quoted context omitted.

Those unsubscribe links should be there, for several reasons. - The service-based economy means that entities (individuals and businesses) have numerous relationships. For the typical individual the number of password-based accounts crossed the 100 threshold years ago, at a doubling rate of every 2--3 years. - Responsibilities can be transferred. The person who signed up for your service 5 years ago may no longer be…

I strongly disagree. There is absolutely no need to put an unsubscribe link into a transactional email. All emails should of course contain enough information to make it clear who the message is from, why the message is being sent, and who it was sent to. But there is no point in adding unsubscribe links to messages and notifications that are essential to the service. I mean, what are you going to do if the user acci…

> There is absolutely no need to put an unsubscribe link into a transactional email.

Agreed. rsync alluded to it below as well.

'unsubscribe'... from what? If I just bought something from service ABC, and I get an email from ABC saying "you just bought foo from us"... what would an 'unsubscribe' even mean? "Do not ever email me about this purchase again?" "Do not ever email me about future purchases?"

Re: Spam blacklisting is out of control

#88
post #79

Earlier quoted context omitted.

Those unsubscribe links should be there, for several reasons. - The service-based economy means that entities (individuals and businesses) have numerous relationships. For the typical individual the number of password-based accounts crossed the 100 threshold years ago, at a doubling rate of every 2--3 years. - Responsibilities can be transferred. The person who signed up for your service 5 years ago may no longer be…

Everything you've said makes perfect sense - for a contact management function. We have that. You can change contact info, set owner/technical/emergency contacts, alert thresholds, etc. But unsubscribe means something totally different: When I click on unsubscribe I want it to be the end of all communications. Period. In this case, that makes no sense. Ceasing communications for all purposes implies service cancellat…

You may have missed that bit in my earlier comment about working for a paid service provider.

Re: Spam blacklisting is out of control

#89
post #37

> Or I can leave the current hosting company Yep, that's the one. If your hoster doesn't care about spam spreading from their IP space, you should take your mail server elsewhere. There's literally nothing to think about. And if they do care about this issue, they are likely to be taking steps to remove any of their IP space from the blacklists, without being nudged. PS. I've been running a mail server for close to 2…

>/24 netblock on the second offense. That seems excessive and abusive, I am not aware of any commercial ISP that is giving out /24 anymore. /29 is most common, I had to practically beg to get a /28 so what is the justification for banning an /24???

> That seems excessive and abusive

Good thing it's my own mail server then, isn't it?

The practical reason is that virtually all Whois lookups of offending IPs return blocks of /24 or larger, so that's a reasonable default. Besides, as I said, this doesn't result in a "ban", just tags emails as spam and passes them through. At my scale an occasional false positive is not a big deal.

Re: Spam blacklisting is out of control

#90

Earlier quoted context omitted.

Yes, just because I use your service doesn't mean I want to see every outage notification status update as an email. Preferably email subscription status would be granular so I can select what I want to get not what some idealized average user would want to get.

I've been a paying customer of rsync's service for more than a decade. The only mail I get is the monthly invoice, and roughly once-per-year notice of infrastructure changes that may temporarily affect availability.

Oh I have no doubts whatsoever the volume is low and the messages sent intended to be genuinely important to the vast majority of customers, rsync seems very reputable based on what I've heard over the years on HN.

It's still nice to have granular subscription though even for rare things you think 95% of users may like to hear about e.g. I've been using a similar service since 2015 and I have 0 interest in receiving their downtime or scheduled maintenance notifications as I don't care enough to take a special action for a failed sync or two in the first place so... I don't opt to receive them and I appreciate that option. I don't get the invoices emailed so I haven't had to think about it one way or the other there.

Post reply on HN