Live data from Hacker News

Spam blacklisting is out of control

blog.roastidio.us

211–220 of 430 posts

Re: Spam blacklisting is out of control

#211

If you start a new mail server in 2022 (or migrate from a previous address), you have to apply to be whitelisted by outlook.com and the many domains owned by Microsoft. They no longer accept mail from servers they haven't seen before. Companies such as google, microsoft, and facebook would rather that email died, and are actively working to destroy it through neglect, so that people will shift their messaging to prop…

Another fascinating fact is that forwarding Outlook spam to abuse@outlook.com will get you shitcanned ... as a spammer!

You can't make this up. They pass all abuse reports throuh their spam filter and this affects your server's reputation. Then at some point they start rejecting emails from you with a 5xx code that stands for "your IP is on our blacklist". Contacting "Hotmail sender support" will yield "We see no problems on our end, kindly fuck off". You have to then go through a ritual of summoning a manager, taking anywhere from 2 to 5 days, at which point they will say "we put a mitigation in place, will take up to 48 hours to propagate", but it works right away. If it doesn't, it means that they mistyped your server address and the next chance to ask them to fix this will be, you guessed it, in 48 hours. So a week of bounces in total.

Ran into this 3 times in a course of a year, then took a closer look at the logs and - yep - in all three cases it was triggered by sending a report to abuse@outlook.com.

It's just such a magnifecent clusterfuck it's jaw-dropping.

Re: Spam blacklisting is out of control

#212
F*k UCEPROTECT!

I got listed as well (layer 3 only), because there were more than 32 cases of spam in an ISP that maintains more than 4 /16 networks across the whole country. With the whole AS blocklisted, I fail to see the point of UCEPROTECT and agree with the OP that they are mere thieves.

On topic of protecting people, they have a trivial XSS right on the input field where one checks if their IP address is listed - yes, a GET variable is printed directly to HTML.

Re: Spam blacklisting is out of control

#213
post #208

Earlier quoted context omitted.

In the American legal system, if somebody spends the money to take the time to have their lawyer hand craft and send me a letter about something such as this, I'm going to take it as a threat whether or not it specifically contains one. The implication is that if you do not do whatever is demanded in the letter, the next step will be the client of said lawyer escalating the situation to paying their lawyer to actuall…

I mean, not really. In the world of companies talking to other companies lawyers are involved all the time. In some scenarios (real estate transactions, or M&A, for example) it would just be completely routine for two companies on exceedingly good terms to communicate back and forth via attorneys. Your main premise seems to be that the recipient should take all this very personally. But it’s not personal, these are b…

An intentionally initiated transaction where everyone already knows each other, and knows in advance that lawyers will be involved (as you say, m&a, real estate, etc) is a very different thing than receiving a demand letter from a previously unknown party out of the blue.

Like I said in my original reply here, we are talking about sending threats to third-party isps, with which the originator of the smtp traffic has no existing business or contractual relationship.

Re: Spam blacklisting is out of control

#214
post #207
post #146

Earlier quoted context omitted.

>Get your legal department involved. We have repeatedly been taken off various public and private blacklists by having lawyers do their job. What's the particular law that makes those curators of blacklists pay attention to your company's lawyers? Do you have example text of those legal requests?

Just guessing, but maybe threatening to sue for damages might work?

But the companies aren't obligated to accept your email are they? What grounds do you have to ask for damages?

Re: Spam blacklisting is out of control

#215
post #207
post #146

Earlier quoted context omitted.

>Get your legal department involved. We have repeatedly been taken off various public and private blacklists by having lawyers do their job. What's the particular law that makes those curators of blacklists pay attention to your company's lawyers? Do you have example text of those legal requests?

Just guessing, but maybe threatening to sue for damages might work?

You don't even need to threaten. Just a letter of representation from a lawyer is magically effective for things like this.

ETA: We refer to it as "6mins and a stamp".

Re: Spam blacklisting is out of control

#216
post #34

I fought the battle to keep my SMTP server IP off blacklists, and lost. You can do everything possible, have a perfectly clean IP, have a good amount of outbound email traffic, only send transactional email, etc. Still, there will be edge cases where email does not go through. AT&T email servers would constantly blacklist me and not respond to requests to remove me, gmail/yahoo/outlook would silently put emails in th…

The funny thing about that work-around is, what stops spammers from doing it either?

Re: Spam blacklisting is out of control

#218
post #217

Earlier quoted context omitted.

But the companies aren't obligated to accept your email are they? What grounds do you have to ask for damages?

[deleted]

If someone threatens to sue for damages for something where they are clearly not entitled to damages, why would your lawyers advise you to act on that?

If I wrote to you now threatening to sue you for damages unless you delete your comment would you delete it? Why?

Re: Spam blacklisting is out of control

#219
The UCEPROTECTL blacklists self-clear after a while and it's not nearly as bad other "real" blacklists. Considering all the other hassles one must engage in for self-hosted mail, this one is not high on my list of worries. My host occasionally pops up on these for a few days and usually clears without incident. But yes it's frustrating that my mailhost can be guilty by association despite being in good standing otherwise.

And of course the side-benefit for Gmail to enforce more anti-spam provisions is that it increases the reliability of the data they can mine from your mail, and my mail too since so many people still use Gmail.

Re: Spam blacklisting is out of control

#220

Spam blocklists are run by an unaccountable cowboy cult that somehow has managed to consolidate a ton of power simply for the fact that most people who run email inbox services didn't want to deal with the problem of spam, so they were more than willing to just hand over anti-spam "enforcement" to anyone who was allegedly doing "what was best for the internet." There's no check on these people who run these blacklist…

> antithetical to the principles of the open internet. No. These blocklists are employed by the actor receiving the email. They have a perfect right, even on "the open internet", to decide that they want to limit who can send them messages. There are tons of checks on the people who provide those blacklists, in the form of their users complaining about lack of mail delivery and ultimately not using their list anymore…

> These blocklists are employed by the actor receiving the email.

If I send an email to alice@example.com, Alice is the recipient, not Bob the sysadmin for example.com.

Post reply on HN