Live data from Hacker News

Spam blacklisting is out of control

blog.roastidio.us

241–250 of 430 posts

Re: Spam blacklisting is out of control

#242
We have the same problem, even our verification email during registration goes to spam sometimes. Should there be a law that a legitimate company register their domain in a registry that spam filters have to ignore? Otherwise, companies controlling spam filters can choke other companies.

Re: Spam blacklisting is out of control

#243
post #31

I'm dealing with this right now. Both my personal domain and rsync.net are on a distinct subnet, but that subnet is smaller than a /24 and someone on a different subnet has, apparently, behaved badly. Enter "abusix" ... One of my engineers had an enlightening webchat with one of their engineers where we were shown the "offending" IP and it was explained that they have no ability to distinguish subnets (and no interes…

Those unsubscribe links should be there, for several reasons. - The service-based economy means that entities (individuals and businesses) have numerous relationships. For the typical individual the number of password-based accounts crossed the 100 threshold years ago, at a doubling rate of every 2--3 years. - Responsibilities can be transferred. The person who signed up for your service 5 years ago may no longer be…

[deleted]

Re: Spam blacklisting is out of control

#244

If you start a new mail server in 2022 (or migrate from a previous address), you have to apply to be whitelisted by outlook.com and the many domains owned by Microsoft. They no longer accept mail from servers they haven't seen before. Companies such as google, microsoft, and facebook would rather that email died, and are actively working to destroy it through neglect, so that people will shift their messaging to prop…

It's actually not that big of a problem. I moved to a new server with a different IP last year, and also the year before, and as long as you have SPF, DMARC, DKIM and reverse DNS set up, generally everything works. I think I just had to got whitelisted from one or two.

A few years ago I did have major problems with hotmail and icloud, but recently it doesn't seem to be an issue. I think I didn't have DKIM set up when I was having problems. I have noticed that google will auto-junk your email if you don't have SPF, DMARC and DKIM set up, and you must set DMARC to "reject".

Re: Spam blacklisting is out of control

#245
post #34

I fought the battle to keep my SMTP server IP off blacklists, and lost. You can do everything possible, have a perfectly clean IP, have a good amount of outbound email traffic, only send transactional email, etc. Still, there will be edge cases where email does not go through. AT&T email servers would constantly blacklist me and not respond to requests to remove me, gmail/yahoo/outlook would silently put emails in th…

> and control my email data

Are you though? Aren't you giving your outbound emails to Postmark or Mailgun in that case?

Re: Spam blacklisting is out of control

#246

Earlier quoted context omitted.

While I am happy for you that you have found a solution, the solution you found is symptomatic of a very dangerous situation: it is increasingly impossible for individuals or SMEs to use essential online facilities like sending messages or transferring money reliably unless they use a broker service as an intermediary. We are allowing small numbers of tech firms to take control of vital functionality that should be u…

This is just the internet moving to match the real world. In the real world, reputation matters and some people don't want to talk to you unless someone can vouch for you. For areas where the general public needs to interact, third party intermediary services spring up to fill this need. This is why for any store over the size of a mom and pop operation in a neighborhood, you can't just tell the owner who you know by…

>This is why for any store over the size of a mom and pop operation in a neighborhood, you can't just tell the owner who you know by name to put it on your account, and instead for credit purchases you use a credit card company which acts as an intermediary and smooths problems over on both sides, and refuses to work with stores and people that are untrustworthy.

Yet, if that store knows you, and wants to extend credit to you, they can. A difficulty with email is that it seems to be increasingly difficult for the recipients to have much control over the email they receive. I know of numerous instances where people are unable to get specific emails they want or need to receive to not be spam-foldered, or to be received at all. They may have no understanding of why this is the case, and even if they do, may have no ability to change it. The systems are often opaque and unchangeable, and involve organization- or provider-level choices before emails ever reach their accounts.

Re: Spam blacklisting is out of control

#247
post #34

I fought the battle to keep my SMTP server IP off blacklists, and lost. You can do everything possible, have a perfectly clean IP, have a good amount of outbound email traffic, only send transactional email, etc. Still, there will be edge cases where email does not go through. AT&T email servers would constantly blacklist me and not respond to requests to remove me, gmail/yahoo/outlook would silently put emails in th…

The funny thing about that work-around is, what stops spammers from doing it either?

A spammer is going to get blocked and then have to send another letter ad infinitum. It's not financially feasible to do that. The respondent should also have evidence available to prove that the spammer is acting in bad faith (if they don't, then maybe they should get some before initiating a block).

Re: Spam blacklisting is out of control

#249
post #221

Earlier quoted context omitted.

Did you read the whole article? The OP wasn't being blacklisted by an operator. He was being blacklisted by a company that charges you a $25/month fee to not be blacklisted by lazy operators who program their systems to curl their for-profit blacklist.

People have been making legal threats at, and trying to sue, RBL operators since 1997 or so. It's a well known thing. All I say is "good luck" if you think legally threatening a maintainer of a list of IP CIDR prefixes that are used by a third party is going to solve your problems. It hasn't worked for the last 25 years and I don't see how it'll start working now.

No I think the solution is to not get a $5/month vps and expect it to have a good reputation. Maybe if you went with the $100/month hosting provider you wouldn't have needed to spend $500/month on legal threats. Internet addresses aren't fungible. It's a well known concept in telecommunications. One of the reasons why people have always paid a lot more money to have 212 numbers versus 646 numbers. It's the reason why if you want to set up a respectable business, you don't rent property in a high crime neighborhood. Browsers and email clients should ideally have more transparency about the ASNs and service providers who host the websites that people are visiting, so that everyone can develop a mental model of which ones are associated with good things, because right now the only people who are able to have any kind of awareness of this thing are operators who regularly monitor traffic.

Re: Spam blacklisting is out of control

#250

Earlier quoted context omitted.

I manage an outbound mail server for a mid-sized company. I happen to also use it for my own personal mail. We have had on and off deliverability issues for years (AT&T and Comcast being the worst). As head of IT it fell to me to post whitelisting requests and try to get mail delivering again. I decided after awhile that this really isn't my job, and made a suggestion to the CEO which he took to heart: There is anoth…

Not everyone can spend $500 on lawyer billable hours per SMTP destination multiplied by N number of destinations. I also think that the likelihood of success in sending legal threats to somebody that demand they accept your SMTP traffic will not stand up in court, if you ever escalated it that far. As somebody who runs postfix MX on the receiving side of things, I can guarantee you that the day I receive a legal thre…

> You actually think that the best answer to a network engineering problem is to make legal threats at third party ISPs?

If the remote mailserver is explicitly bouncing your mails, it's not a network engineering problem.

If you're able to complete a TCP 3 way handshake, it's not a network engineering problem.

If you're being prevented from completing a TCP 3 way handshake because of a filter list on the MX server, it's not a network engineering problem. Admittedly, you can't tell that one without asking a network engineer (on the remote network) to validate that for you, or asking the application owner to advise.

Contrary to popular advice (thanks MSFT), you probably shouldn't contact your network administrator. We probably have priv 15, but we dont necessarily have root.

Post reply on HN