Live data from Hacker News

Spam blacklisting is out of control

blog.roastidio.us

271–280 of 430 posts

Re: Spam blacklisting is out of control

#271
post #117

Earlier quoted context omitted.

How did you contact Google and Microsoft regarding deliverability issues?

Microsoft: 1. Set up on https://sendersupport.olc.protection.outlook.com/snds/ 2. Read everything at https://sendersupport.olc.protection.outlook.com/pm/ 3. Make sure everything is fixed, then use the link to the form hidden under Troubleshooting > "Sender services, tools, and issue submission" (the link's label is "here") to contact support. Make sure all fields are provided, including a website. It may take a few d…

This is a fair reflection of my experience.

Re: Spam blacklisting is out of control

#272

Spam blocklists are run by an unaccountable cowboy cult that somehow has managed to consolidate a ton of power simply for the fact that most people who run email inbox services didn't want to deal with the problem of spam, so they were more than willing to just hand over anti-spam "enforcement" to anyone who was allegedly doing "what was best for the internet." There's no check on these people who run these blacklist…

Let's not classify all spam blacklists as the same. UCEPROTECT is in a special class of extortionist cowboy, because it's basically just an inaccurate protection racket throwing a wide net across cloud providers who won't play their game. Some other blacklists are updated regularly and only contain IP addresses that have actually sent spam. By contrast, UCEPROTECT3 just lumps ISPs into the list even though an address…

I also run an email server. I just used https://mxtoolbox.com/ to check my status and yep, UCEPROTECTL3 is the ONLY one to have my IP range listed.

The article sums it up nicely: IP blacklists have their place, however, please don’t use the overarching neighbouring blacklists such as UCEPROTECTL2 and UCEPROTECTL3.

Re: Spam blacklisting is out of control

#273
post #34

I fought the battle to keep my SMTP server IP off blacklists, and lost. You can do everything possible, have a perfectly clean IP, have a good amount of outbound email traffic, only send transactional email, etc. Still, there will be edge cases where email does not go through. AT&T email servers would constantly blacklist me and not respond to requests to remove me, gmail/yahoo/outlook would silently put emails in th…

I've had a few issues with Mailgun getting blocked over the years. Especially with Hotmail/Outlook.

Re: Spam blacklisting is out of control

#274
post #34

I fought the battle to keep my SMTP server IP off blacklists, and lost. You can do everything possible, have a perfectly clean IP, have a good amount of outbound email traffic, only send transactional email, etc. Still, there will be edge cases where email does not go through. AT&T email servers would constantly blacklist me and not respond to requests to remove me, gmail/yahoo/outlook would silently put emails in th…

> and control my email data Are you though? Aren't you giving your outbound emails to Postmark or Mailgun in that case?

Yes, Postmark keeps a 45 day history of emails for user reporting. After that it's deleted:

https://postmarkapp.com/eu-privacy#security-and-privacy

It's a decision I am fine with. Others may not be.

Re: Spam blacklisting is out of control

#275

We recently ran into this issue and were forced to change email providers. It isn’t that our host didn’t care, it’s that it is almost impossible to play whack-a-mole with dozens of blacklists. We have been with the same provider for 15 years, no problems, ever. It seems that email delivery started to become unreliable about six months ago. After repeated attempts to fix it we had no choice but to move elsewhere.

Who'd you choose?

Re: Spam blacklisting is out of control

#276
post #142

Earlier quoted context omitted.

That's why I said the email should contain info about the sender -- there should of course be a way to contact them. Ideally you should just be able to reply to the message and tell them about the error. If there's no way to contact a company, that's a whole different problem, and not really one that would be fixed with unsubscribe links in important email messages.

> That's why I said the email should contain info about the sender -- there should of course be a way to contact them. That implies a level of manual effort on the part of the recipient that's unreasonable. I have no relationship with these companies. They did not verify the email address before starting to send a stream of supposedly transactional messages to it. They should be happy that I'm willing to click unsubs…

Yup. And is this situation the recipient will just mark it as spam. Because to them that's what it is.

Re: Spam blacklisting is out of control

#277
post #232
post #31

I'm dealing with this right now. Both my personal domain and rsync.net are on a distinct subnet, but that subnet is smaller than a /24 and someone on a different subnet has, apparently, behaved badly. Enter "abusix" ... One of my engineers had an enlightening webchat with one of their engineers where we were shown the "offending" IP and it was explained that they have no ability to distinguish subnets (and no interes…

I'm the Abusix engineer in question (and actually the architect of the system in question), and you're being somewhat "economical" with what actually happened here. Here's the actual chain of events in question: - You recently switched ISPs and that meant you moved to a new IP block. - The IP block in question is owned by Hurricane Internet and unfortunately contains a host which persistently sends out a lot of junk…

Great response, and I was just wondering what went into sending email.

One question though, what do you mean by 'traps'? I feel like I'm missing some interesting context

Re: Spam blacklisting is out of control

#279
Blacklisting an ISP's ASN or entire network range because the blacklist creator set an arbitrary threshold of acceptable number of spam activity from 1 or more IPs. I'm really not sure about the legal aspects here, but there are so many practices that blatantly approach extortion. And it's skillfully done in the name of "online etiquette" or a "safe internet".

Obviously, legitimate use-cases exist for such services, provided that they are operated faithfully by people/entities with some level of credibility.

Whether or not Spam is legal, many (or most) service providers list it as prohibited in their SLA (Service-Level Agreement). Depending on the type of setup they run--the clientele; company focus/prioritization of ROI--they forward complaints to the account owners, with the understanding that the activity must be stopped. Again, this depends on the service provider, especially as you start thinking on a more granular level. E.g. they can have automated systems handling much of this, or they may have employees handle the communications and provide help to their clients in thwarting such activity. Generally, though, the account owners need to balance the security with compatibility--or the uptime and short-term performance of their services.

Ultimately, however, some of these spam block-lists--UCEPROTECTL3 in particular--are blatantly using a sledge-hammer approach for little benefit to any of their users, in the hopes of spurring controversy; or fear that leads to customers; or outrage from customers toward the service providers. In the end, the intention is purely to get paid, either by clients who sign up for their service or by the internet service providers that can't wait multiple days or weeks until their network gets de-listed. Their accusatory and aggressive language conveys to people that they must be associated with either some amateur company or one that uses, and knowingly profits from, nefarious practices and shady characters if they somehow ended up on their list.

Depending on where you stand, it can be seen as deplorable or underhanded behavior maybe even rising to the level extortion, or it can be considered a shrewd business tactic.

Re: Spam blacklisting is out of control

#280

Earlier quoted context omitted.

This is just the internet moving to match the real world. In the real world, reputation matters and some people don't want to talk to you unless someone can vouch for you. For areas where the general public needs to interact, third party intermediary services spring up to fill this need. This is why for any store over the size of a mom and pop operation in a neighborhood, you can't just tell the owner who you know by…

In the real world, reputation matters and some people don't want to talk to you unless someone can vouch for you. This has absolutely nothing to do with someone not wanting to talk to someone else. It has everything to do with some third party having the power to decide whether the other two may communicate. These days it's all so centralized in a few very large players that they really likely just talk to each other…

> This has absolutely nothing to do with someone not wanting to talk to someone else. It has everything to do with some third party having the power to decide whether the other two may communicate.

They have that power specifically people people outsource vetting of whether someone's worth dealing with. I'll repeat, this is all about reputation, and how without reputation you're subject to every anonymous person's abuse. That's not an issue when the total number of people you're dealing with is manageable. It is when the number of people you expect to have to deal with is the population of a small country or the entire world.

> And thus the single most important method of remote communication in the world today, the method that is frequently akin to root access to our online lives, became subject to arbitrary monitoring and interference by huge, powerful organisations with their own interests and negligible regulatory oversight, legal safeguards or accountability to anyone but their shareholders.

Only for those that opted into that system. Gmail does not dictate what mail servers accept your mail, they dictate whether they themselves accept your mail. They just happen to have a userbase in hundreds of millions billions, so a large percent of the people you might want to contact use it. You can blame Gmail all you want, but they're just doing what their users want, which is reliable email without much spam, and that's how they've achieved it. You're not going to get far telling people when you send stuff to them they're required to accept it. The system only worked the way you wanted it when it was small and offenders weren't as anonymous and social punishments worked against them. When everyone's mostly anonymous, that no longer works.

> Do you really not see why this is a problem?

It is a problem, but it's a problem of people choosing to use them. And there's been ways to keep people from reading your emails for decades at this point with GPG, and if you can't trust the other side to buy into that, or to not use a web based email client, then there's nothing you can do about communication with those people anyway.

Should they be monitoring email? No. Would we be better with laws preventing that? Yes. Is that really the same issue as them being so large that by dictating who they will talk with and how they are effectively dictating rules for running a public mail server? No. Separate issues.

Post reply on HN