Live data from Hacker News

Spam blacklisting is out of control

blog.roastidio.us

101–110 of 430 posts

Re: Spam blacklisting is out of control

#101
post #34

I fought the battle to keep my SMTP server IP off blacklists, and lost. You can do everything possible, have a perfectly clean IP, have a good amount of outbound email traffic, only send transactional email, etc. Still, there will be edge cases where email does not go through. AT&T email servers would constantly blacklist me and not respond to requests to remove me, gmail/yahoo/outlook would silently put emails in th…

While I am happy for you that you have found a solution, the solution you found is symptomatic of a very dangerous situation: it is increasingly impossible for individuals or SMEs to use essential online facilities like sending messages or transferring money reliably unless they use a broker service as an intermediary. We are allowing small numbers of tech firms to take control of vital functionality that should be u…

This is the real value of cryptocurrencies. Yes, I know HN doesn't like them, yes there's a bunch of get-rich-quick bros and scammers out there, please try and separate the grift from the tech and consider how vital it is that people are able to control their finances without a third party having the ultimate say as to whether a transaction takes place or not.

Re: Spam blacklisting is out of control

#102
post #66
post #46

Earlier quoted context omitted.

That's a (very legitimate and important) reason to do double opt-in unilaterally for all email communications. Companies should make 100% sure that the person who signed up, and the person receiving the email, are the same person, before they associate the email with the account. Otherwise, malicious people can sign up arbitrary third parties for tons of random crap. But it's not a good reason for adding unsubscribe…

the email w/unsub link could be forwarded also, it's often a portal to change notification settings w/o auth and leaks personal preference info - and when there is auth it's impossible to unsub when if were signed up maliciously. it happened to me - someone charged a bunch of stuff to my cc and then registered my email at thousands of sites to bury the email receipts (it didn't work since I have simple filters for th…

Ugh that sucks.

But in the cases where there is authentication, isn't it enough (in most cases) to reset the password and change the email to something disposable?

Of course that's not really practical for the case where you get subscribe-bombed, but maybe for the general case it is, no?

Re: Spam blacklisting is out of control

#103

Earlier quoted context omitted.

I strongly disagree. There is absolutely no need to put an unsubscribe link into a transactional email. All emails should of course contain enough information to make it clear who the message is from, why the message is being sent, and who it was sent to. But there is no point in adding unsubscribe links to messages and notifications that are essential to the service. I mean, what are you going to do if the user acci…

> There is absolutely no need to put an unsubscribe link into a transactional email. Agreed. rsync alluded to it below as well. 'unsubscribe'... from what? If I just bought something from service ABC, and I get an email from ABC saying "you just bought foo from us"... what would an 'unsubscribe' even mean? "Do not ever email me about this purchase again?" "Do not ever email me about future purchases?"

> Do not ever email me about this purchase again

Please send me the order, just don't send me the PDF invoice :)

Re: Spam blacklisting is out of control

#104

Spam blocklists are run by an unaccountable cowboy cult that somehow has managed to consolidate a ton of power simply for the fact that most people who run email inbox services didn't want to deal with the problem of spam, so they were more than willing to just hand over anti-spam "enforcement" to anyone who was allegedly doing "what was best for the internet." There's no check on these people who run these blacklist…

> antithetical to the principles of the open internet. No. These blocklists are employed by the actor receiving the email. They have a perfect right, even on "the open internet", to decide that they want to limit who can send them messages. There are tons of checks on the people who provide those blacklists, in the form of their users complaining about lack of mail delivery and ultimately not using their list anymore…

Absolutely agree. This doesn't fall under the principles of the open internet nor anything in the 'net neutrality' arena. You have no right to expect anyone to receive traffic from your server if they choose not to. It's a major pitfall of running your own relay, but it's not unethical.

Re: Spam blacklisting is out of control

#105
post #93

Earlier quoted context omitted.

I strongly disagree. There is absolutely no need to put an unsubscribe link into a transactional email. All emails should of course contain enough information to make it clear who the message is from, why the message is being sent, and who it was sent to. But there is no point in adding unsubscribe links to messages and notifications that are essential to the service. I mean, what are you going to do if the user acci…

What about situations where your email somehow (mistype) gets set up for someone else's account? I have 2-3 people with similar emails to my previous email address that would mistype and I'd receive their emails. These weren't spam but the companies wouldn't offer _any_ way to fix this. My recourse is to just flag them as spam in gmail.

You can create a Gmail filter to delete or archive them automatically and avoid poisoning the spam filter.

Re: Spam blacklisting is out of control

#106
post #93

Earlier quoted context omitted.

I strongly disagree. There is absolutely no need to put an unsubscribe link into a transactional email. All emails should of course contain enough information to make it clear who the message is from, why the message is being sent, and who it was sent to. But there is no point in adding unsubscribe links to messages and notifications that are essential to the service. I mean, what are you going to do if the user acci…

What about situations where your email somehow (mistype) gets set up for someone else's account? I have 2-3 people with similar emails to my previous email address that would mistype and I'd receive their emails. These weren't spam but the companies wouldn't offer _any_ way to fix this. My recourse is to just flag them as spam in gmail.

Emails should be confirmed before being used for ongoing communication. Simple as that. It’s easier to get right up front than it is to clutter and confuse in the cases already illustrated.

Re: Spam blacklisting is out of control

#107

My personal experience with UCEPROTECT was that they had blacklisted 2 or 3 IPs in my /24 that were not routed to anything, nor had they ever been routed to anything, a fresh new block from RIPE NCC too. Of course they offered to unblacklist them in exchange for payment, or wait. Waited 2 weeks and they dropped off. I've yet to hear about anyone using their DNSBL for anything serious in 2020/2021/2022 I only knew abo…

> a fresh new block from RIPE NCC too

While I personally don't use UCE (and personally think that they're not good at what they're doing), unless you've get that IP range before 2012, I doubt it's a new one. Many spammers do often exploit RIPE's unallocated IPs for their spamming operations (either using BGP hijacking or just asking RIPE nicely for a range), which unfortunately is a perennial problem.

Re: Spam blacklisting is out of control

#108
post #34

I fought the battle to keep my SMTP server IP off blacklists, and lost. You can do everything possible, have a perfectly clean IP, have a good amount of outbound email traffic, only send transactional email, etc. Still, there will be edge cases where email does not go through. AT&T email servers would constantly blacklist me and not respond to requests to remove me, gmail/yahoo/outlook would silently put emails in th…

I manage an outbound mail server for a mid-sized company. I happen to also use it for my own personal mail.

We have had on and off deliverability issues for years (AT&T and Comcast being the worst).

As head of IT it fell to me to post whitelisting requests and try to get mail delivering again. I decided after awhile that this really isn't my job, and made a suggestion to the CEO which he took to heart:

There is another solution besides changing IPs, using a paid sender, or filling out whitelist requests into the void: Get your legal department involved. We have repeatedly been taken off various public and private blacklists by having lawyers do their job. Once we went this path, it was like magic. Same day responses from those companies, and we haven't been on any blacklists for a couple of years.

Re: Spam blacklisting is out of control

#109
post #31

I'm dealing with this right now. Both my personal domain and rsync.net are on a distinct subnet, but that subnet is smaller than a /24 and someone on a different subnet has, apparently, behaved badly. Enter "abusix" ... One of my engineers had an enlightening webchat with one of their engineers where we were shown the "offending" IP and it was explained that they have no ability to distinguish subnets (and no interes…

Those unsubscribe links should be there, for several reasons. - The service-based economy means that entities (individuals and businesses) have numerous relationships. For the typical individual the number of password-based accounts crossed the 100 threshold years ago, at a doubling rate of every 2--3 years. - Responsibilities can be transferred. The person who signed up for your service 5 years ago may no longer be…

Those unsubscribe links should be there, for several reasons.

In some jurisdictions there is information that businesses are legally required to provide to their customers in a permanent form and email is the conventional (and potentially the only) way of satisfying that requirement.

IMHO, it is not helpful for anyone to have a system where recipients may not understand this and may treat that mail as spam, yet businesses are compelled to send it anyway.

Re: Spam blacklisting is out of control

#110

> Or I can leave the current hosting company Yep, that's the one. If your hoster doesn't care about spam spreading from their IP space, you should take your mail server elsewhere. There's literally nothing to think about. And if they do care about this issue, they are likely to be taking steps to remove any of their IP space from the blacklists, without being nudged. PS. I've been running a mail server for close to 2…

I have run my own mail server about as long, run an RBL, and a transactional mail service too. This is a hard line approach and blacklisting a /24 on a second offense that never expires just doesn't work long term but at least you are not completely blocking it and accepting it but as spam.

Lets be real there is spam coming from gmail and hotmail/outlook as well and places like abuseix specifically state they don't block these ranges. So the large providers get excused for clean up because they are too big. Sure blocking colo crossing probably won't get any one to complain, but Digital Ocean is probably going to get some collateral damage. For your own mail server fine, don't accept it, send to spam - but there is a reason real RBL lists are very careful to skip the big providers or make sure they expire. Spamcop always had the best method - expire when the spam stops. Does it keep getting listing? Keep it longer. Rspamd also has a good method where an RBL increases the score. The hard line approach gives gmail and microsoft a large share of the email market and hurts smaller providers when they are not held to the same standards as everyone else. If gmail emails start bouncing when they have a heavy spam hit, then maybe gmail users will change isps and help gmail clean up. These are two trillion dollar companies that also have spam problems.

As far as UCEprotect. Their level1 is actually reasonable, especially for spam traps. The timestamps easily allow for you to find exactly what the spam is from with the smtp response and time frame. Their scanning methods are less so. Dos prevention measures can get you listed there and are not valid. The level2/3 lists are utter shit.

Post reply on HN