Live data from Hacker News

Spam blacklisting is out of control

blog.roastidio.us

181–190 of 430 posts

Re: Spam blacklisting is out of control

#181

If you start a new mail server in 2022 (or migrate from a previous address), you have to apply to be whitelisted by outlook.com and the many domains owned by Microsoft. They no longer accept mail from servers they haven't seen before. Companies such as google, microsoft, and facebook would rather that email died, and are actively working to destroy it through neglect, so that people will shift their messaging to prop…

> They no longer accept mail from servers they haven't seen before. Interesting. This tracks with my experiences too, but is there a good source for this that I can reference in the future? I got out of hosting email last year entirely because of intractable deliverability problems with the big three: Google, Microsoft, and Comcast. Comcast's issues mostly appeared intermittent and the result of incompetence. Google…

I contacted Microsoft, actually received an answer from them and got an IP unblocked.

Google can be tough though. If their Algorithms don't like you, good look.

I was responsible for a new IP/Email setup and while all other relevant providers liked our mail and Google Postmaster tools didn't show anything bad, all our mail went to Spam in GMail. I found out why when even mails from completely different senders would usually go to Inbox but hit Spam once our Website or email was included:

Despite showing it as "high reputation", GMail must have considered it as utter trash. Changed to a different, older domain and all has been fine since.

Re: Spam blacklisting is out of control

#182
post #34

I fought the battle to keep my SMTP server IP off blacklists, and lost. You can do everything possible, have a perfectly clean IP, have a good amount of outbound email traffic, only send transactional email, etc. Still, there will be edge cases where email does not go through. AT&T email servers would constantly blacklist me and not respond to requests to remove me, gmail/yahoo/outlook would silently put emails in th…

I was flabbergasted that relaying their mail through a service that does high volume, and enforces abuse policies, wasn't one of his listed options. As the Internet has become, due to rampant spamming, it's become best to just outsource mail relaying.

Re: Spam blacklisting is out of control

#183

Earlier quoted context omitted.

I agree completely with this, but the one problem is that you haven’t addressed how we control spam without these “trusted” intermediaries. “Trusted” here meaning that they aren’t spammers.

Spam has largely been a solved problem for decades IME. You don't need some big-data-crunching mega-mail-host to block it successfully. For my personal mail, I use a small provider that isn't configured to block anything automatically and the built-in tools in my mail software. For my businesses, we have a pretty standard SpamAssassin-style setup. Either way, I see hardly any spam in my inbox despite receiving mail t…

Sure for you, but all of these other mailservers still obviously find value in applying spam filters or they wouldn't keep filtering.

The problem is that it's much easier to send email than it is to receive it. This puts the onus of spam filtering on the recipient. I'm sad that HashCash or some other PoW scheme was never adopted as a way to force rate limiting of mailers.

Re: Spam blacklisting is out of control

#184

Earlier quoted context omitted.

Not everyone can spend $500 on lawyer billable hours per SMTP destination multiplied by N number of destinations. I also think that the likelihood of success in sending legal threats to somebody that demand they accept your SMTP traffic will not stand up in court, if you ever escalated it that far. As somebody who runs postfix MX on the receiving side of things, I can guarantee you that the day I receive a legal thre…

The rationale for involving legal is to place some accountability and consequences where they belong. Currently, countless people essentially commit countless abuses for free because the actor is hidden behind a machine or a process. But somewhere it's a humans decision to institute an abusive protocol, and it seems pretty fair fo me to make that human accountable for their action. Not just email but all kinds of thi…

I'm a dick?

I question whether you or what other percentage of the commenters in this thread represent any specific ASN with its own IP space that it cares about keeping clean, and have bgp relationships with other ISPs.

Or whether they're actually end users only.

Have you actually encountered this problem as a service provider in the past and implemented solutions to it, or are you just sharing your opinion as a possibly-frustrated end user of email?

Re: Spam blacklisting is out of control

#185
Blacklists are fine. If someone wants to make a list based on some criteria then OK, there is no real way to prevent them from doing that.

The people doing the actual blocking based on the list have the responsibility for their actions. If, say, one of the largest email providers in the world is found to be giving preferential treatment to the email of other large email providers then they can't use some list as an excuse. Their actions are still anticompetitive and generally harmful.

We shouldn't forget to go after the entity that runs the email server that is blocking email from our servers. You don't have to care that there is a list. Blame the right people and involve governments if required.

Re: Spam blacklisting is out of control

#186

Earlier quoted context omitted.

I manage an outbound mail server for a mid-sized company. I happen to also use it for my own personal mail. We have had on and off deliverability issues for years (AT&T and Comcast being the worst). As head of IT it fell to me to post whitelisting requests and try to get mail delivering again. I decided after awhile that this really isn't my job, and made a suggestion to the CEO which he took to heart: There is anoth…

Not everyone can spend $500 on lawyer billable hours per SMTP destination multiplied by N number of destinations. I also think that the likelihood of success in sending legal threats to somebody that demand they accept your SMTP traffic will not stand up in court, if you ever escalated it that far. As somebody who runs postfix MX on the receiving side of things, I can guarantee you that the day I receive a legal thre…

> Not everyone can spend $500 on lawyer billable hours per SMTP destination multiplied by N number of destinations.

You likely wouldn't do that - just get a template version that gets reused, just like you pay once for a contract / t&c you reuse with multiple parties.

Re: Spam blacklisting is out of control

#187

Earlier quoted context omitted.

Those unsubscribe links should be there, for several reasons. - The service-based economy means that entities (individuals and businesses) have numerous relationships. For the typical individual the number of password-based accounts crossed the 100 threshold years ago, at a doubling rate of every 2--3 years. - Responsibilities can be transferred. The person who signed up for your service 5 years ago may no longer be…

I strongly disagree. There is absolutely no need to put an unsubscribe link into a transactional email. All emails should of course contain enough information to make it clear who the message is from, why the message is being sent, and who it was sent to. But there is no point in adding unsubscribe links to messages and notifications that are essential to the service. I mean, what are you going to do if the user acci…

Yeah, I run my own email server and have the same issues with the same services as the person who wrote the piece this links to.

In my case users are sending estimates and invoices and monthly statements to their clients and while fake invoices may be a spammer thing those clients know who's sending them an invoice, and why and what for, so an 'Unsubscribe" link would be completely out of context because they are not subscribed to any email list.

I've had the same domain name for over 20 years now and none of my users have ever used my apps to send spam. And as spam and email volume go my server isn't even close to sending out a lot of email.

When I set up a new email server last year, with a new IP address, I had to go through the process of getting white listed. All the big email service providers have ways to do that. Google made it very easy. They gave you a unique string to add it to your DNS records and that's it. Microsoft is so convoluted I've still not gotten anywhere with them. Comcast and others had a few hoops and ladders but nothing that got me stuck.

Personally, while it's a bit of a PITA to setup and manage an email server, it's been worth it.

I used "Mail-in-a-Box". It's pretty easy to set one up with that. It has a built-in DNS server and that's a really great thing to have for managing several domain names and as many email addresses as you want. I've setup email accounts for family and friends as well as throwaways for my wife, who signs up for everything she sees on the internet.

I can move the IP address of my email server to the top of the list in my Mac's System Preferences for DNS and start testing new domain names and changes to the DNS immediately. I don't have to wait for those to propagate to whatever my access provider is using.

So I have 3 servers. An Email/DNS server, a database server, and a website/webapp server running on DigitalOcean's "Droplets". It's a bit of work for a small shop but it's much easier to manage once it's setup and I don't have to worry about any 3rd party service selling out or going under or changing their API to something entirely different. All of which has happened to me in the past.

Re: Spam blacklisting is out of control

#188
post #135

Earlier quoted context omitted.

Yes because the government involved in technology always makes things better as I click on “allow cookies” on every damn website.

Punishing anti-competitive measures doesn't have to be always complicated. "Allow cookies" modals are horrible but GDPR gives people in the EU rights to be forgotten and not contacted in the future. Reminding companies about GDPR regulations works very well.

just wait for the new law to outlaw spam filters so anyone can host email.

As soon as they do, email might as well be dead.

The GDPR already caused some sites just to block access to EU countries.

Re: Spam blacklisting is out of control

#189
post #93

Earlier quoted context omitted.

I strongly disagree. There is absolutely no need to put an unsubscribe link into a transactional email. All emails should of course contain enough information to make it clear who the message is from, why the message is being sent, and who it was sent to. But there is no point in adding unsubscribe links to messages and notifications that are essential to the service. I mean, what are you going to do if the user acci…

What about situations where your email somehow (mistype) gets set up for someone else's account? I have 2-3 people with similar emails to my previous email address that would mistype and I'd receive their emails. These weren't spam but the companies wouldn't offer _any_ way to fix this. My recourse is to just flag them as spam in gmail.

You're expecting that a company incompetent enough to attach unverified email addresses to an account to "correctly" deal with unsubscribing from transactional email? This seems entirely futile and counter-productive to me. (Correctly in scare quotes because I can't fathom what a correct automated unsubscribe would look like in this situation.)

Re: Spam blacklisting is out of control

#190
post #79

Earlier quoted context omitted.

Those unsubscribe links should be there, for several reasons. - The service-based economy means that entities (individuals and businesses) have numerous relationships. For the typical individual the number of password-based accounts crossed the 100 threshold years ago, at a doubling rate of every 2--3 years. - Responsibilities can be transferred. The person who signed up for your service 5 years ago may no longer be…

Everything you've said makes perfect sense - for a contact management function. We have that. You can change contact info, set owner/technical/emergency contacts, alert thresholds, etc. But unsubscribe means something totally different: When I click on unsubscribe I want it to be the end of all communications. Period. In this case, that makes no sense. Ceasing communications for all purposes implies service cancellat…

An unsubscribe link doesn't have to immediately cancel all service and communication. It can simply lead to account settings or even to a page explaining how to cancel the account.
Post reply on HN