Spam blacklisting is out of control
301–310 of 430 posts
Re: Spam blacklisting is out of control
#302Earlier quoted context omitted.
> Wtf is wrong with putting contact information in the unsubscribe link By law, depending where you are, a unsubscribe link has to be instant. So there can not be an intermediate screen asking for confirmation or showing contact information. Well, you could show contact information, but then the unsubscribe (of in this case service critical mails, thus the service itself) had already happened.
I'm assuming you're referring to the CAN-SPAM Act [1] or equivalent in other jurisdiction [2], but nothing of the sort is implied. The requirement is to make available and process opt-out without charge and promptly (typically in so many days). It is neither dire nor prevents clarification, nor prescribes a specific experience related to unsubscribe links. It's odd to hear the only options are between receiving messa…
Re: Spam blacklisting is out of control
#303Earlier quoted context omitted.
"- Your engineer said to me "we took down 600 old accounts and are reviewing our contact policies going forward" and "there are still plenty of other customers who are listed generically as bouncing so we will have work to do here"." (snip) "That tells me that you knew that you were sending to old accounts and that your bounce handling was either not great or non-existent." Yes, that is exactly right . I have instruc…
> Bottom line: our duty of safeguarding customer data trumps this weeks fashionable spam heuristics. I haven't suggested that you do anything differently to that. Keep the data, keep the accounts, do whatever you feel is best for you and your business. All I've said is to be smarter when it comes to sending email to old accounts that are repeatedly bouncing. I've outlined what was wrong and I worked with your enginee…
The screenshot I got of your conversation with (Dave) was, indeed very well done and was both informative and actionable. You responded to us very quickly and with a high level of professionalism.
Further, participating here in this HN discussion is noteworthy and impressive.
FWIW, we immediately complained to he.net about the bad actor elsewhere in that /24 ... we'll see.
Re: Spam blacklisting is out of control
#304Earlier quoted context omitted.
> antithetical to the principles of the open internet. No. These blocklists are employed by the actor receiving the email. They have a perfect right, even on "the open internet", to decide that they want to limit who can send them messages. There are tons of checks on the people who provide those blacklists, in the form of their users complaining about lack of mail delivery and ultimately not using their list anymore…
> These blocklists are employed by the actor receiving the email. If I send an email to alice@example.com, Alice is the recipient, not Bob the sysadmin for example.com.
This is the way that email is designed to work and the fact that users and service providers have choice is a feature, not a bug. If you don't want your service provider to do this type of filtering, that is your choice. But you have absolutely no right to say that Alice can't get the service she wants from example.com because it's inconvenient for you.
Edit: and just to head off the inevitable "but what about if it's at work and I can't change providers", the domain and email accounts belong to your employer, not you. You are welcome to work somewhere else if you don't like how they configure their systems.
Re: Spam blacklisting is out of control
#305Earlier quoted context omitted.
I think you're trying to use two wrongs to make a right. If we're talking about things Gulf Power of Florida should do differently, then rather than add unsubscribe buttons to bills which is a bad idea, they should confirm people's email addresses before sending them email.
What's wrong with giving the user the ability to remove themselves from any automated emails? The alternative is being hit with the spam button. They should have confirmed their user controlled the email address, too, but why not go with both? And this is hardly confined to Gulf Power. Verizon, Spectrum, countless banks...
Re: Spam blacklisting is out of control
#306Earlier quoted context omitted.
Just guessing, but maybe threatening to sue for damages might work?
But the companies aren't obligated to accept your email are they? What grounds do you have to ask for damages?
An email from legal@companyA.com to legal@companyB.com will be read.
Re: Spam blacklisting is out of control
#307I fought the battle to keep my SMTP server IP off blacklists, and lost. You can do everything possible, have a perfectly clean IP, have a good amount of outbound email traffic, only send transactional email, etc. Still, there will be edge cases where email does not go through. AT&T email servers would constantly blacklist me and not respond to requests to remove me, gmail/yahoo/outlook would silently put emails in th…
I manage an outbound mail server for a mid-sized company. I happen to also use it for my own personal mail. We have had on and off deliverability issues for years (AT&T and Comcast being the worst). As head of IT it fell to me to post whitelisting requests and try to get mail delivering again. I decided after awhile that this really isn't my job, and made a suggestion to the CEO which he took to heart: There is anoth…
1. I don't know how the lawyers worded the letters. Obviously it's not illegal for a host to block inbound mail. But clearly the legal team made someone look more closely at our particular case. If you're not doing anything nefarious, it's easy for someone mid-level to clear you off a blacklist if they want to. The company I work for isn't a household name outside a few states, but it's large and respectable enough that getting a cursory glance from someone with the power to say "take them off the blacklist" is probably enough.
2. We've had these IPs for > 5 years. Our reverse DNS, DKIM, SPF are all in order. The mail comes from the same IPs as the company's main website/app services. The company uses Constant Contact for marketing emails, so our outbound server only sends things like receipts for purchases, service agreements, confirmations of renewal/cancellation, verification codes for login (password reset / new signup / new device), and intra-company mail which sometimes goes to employees' personal addresses. Being able to firmly state that we never send marketing off this server, and we regularly assess exim logs and we are sure we've never been hijacked has usually gotten good results, even without lawyers.
3. When we first got these IPs, around 2015, there were more problems. I don't know who they belonged to before. For the first year it was whack-a-mole with the blacklists. But truthfully, I've never had a problem personally getting us taken off any of the public blacklists shown on mxtoolbox. It's the private blacklists of mail providers like AT&T, Comcast and AOL that caused repeated issues. There's no public way to check if you're on these, and as far as I can tell their removal forms are black holes. The removal form for AT&T looks like it hasn't been updated since the '90s, and I've never received even an automated response from using it.
4. We did, for awhile, advise customers to get other email addresses. Unfortunately, the customers with an @comcast or @att account are also probably the least tech-savvy. It's just not feasible to have customers calling their local retail outlet and having a manager spend an hour trying to walk them through why they didn't get their signup verification code, and three days later this bubbles up to corporate and finally to me. And it isn't a good look for us as a company to say "sorry, Comcast doesn't like us for some reason."
5. For awhile we had customers write to Comcast and AT&T asking why they were bouncing important emails from us. Overall this had basically no effect. The customers would get back automated emails telling them how to configure Outlook. However, one such customer was a lawyer who I ended up corresponding with personally (through my gmail account, since he couldn't get my emails), who got such a bug up his butt about it that he seemed to get AT&T to unblock us, which only lasted a month or so. This was where I got the idea to approach the CEO about unleashing the legal department.
6. Variations of "Don't waste $500/hr. on a lawyer". IMHO lawyers are pretty terrible to have against you, and pretty awesome to have on your side. I'm glad I work for a company whose philosophy is to keep as much of our infrastructure as possible in-house, and which also refuses to pony up something that feels like a ransom, even if it would be more expedient. I personally don't have $500/hr. to pay a lawyer, and it would be a much worse uphill battle for a sole proprietor or small company these days trying to manage their own email server than it was ten years ago, or is now even with the backing of a larger company. But it's important to us that we don't get pushed around by big providers, and retain as much autonomy as possible in our business dealings with customers. That's part of the philosophy I brought to the company, it's why we run dedicated hardware, and I'm the one who pushed to spend the money to have the lawyers get involved. If more mid-sized companies took this approach, and if other IT leads pushed for running their own metal and their own mailservers (granted, yeah, it's an endless pain in the ass), then big email providers would be forced to actually take things on a case by case basis the way they did ten years ago, rather than block blacklisting whole /24s with the assumption that every company and individual will eventually cave and be forced into their monopoly. So to whoever says that decline is inevitable, save your money, lawyers suck, etc, without offering any positive solutions: you're welcome.
Re: Spam blacklisting is out of control
#308Earlier quoted context omitted.
From a comment below from the other side of the equation it sounds like the email in question WAS indeed marketing for a lifetime promotion. People should have every right to unsubscribe themselves from that, and thus should have some sort of feedback loop attached to the email being sent (to the detriment of your bottom line I fully understand and sympathize with). If this was indeed a marketing email, then I don't…
"People should have every right to unsubscribe themselves from that, and thus should have some sort of feedback loop attached to the email being sent (to the detriment of your bottom line I fully understand and sympathize with)." I agree. We have a flag for such a thing and set that flag when people ask us to. They ask us in a nice email exchange between human beings. We're very responsive to this since they are our…
Re: Spam blacklisting is out of control
#309Re: Spam blacklisting is out of control
#310Earlier quoted context omitted.
I manage an outbound mail server for a mid-sized company. I happen to also use it for my own personal mail. We have had on and off deliverability issues for years (AT&T and Comcast being the worst). As head of IT it fell to me to post whitelisting requests and try to get mail delivering again. I decided after awhile that this really isn't my job, and made a suggestion to the CEO which he took to heart: There is anoth…
Not everyone can spend $500 on lawyer billable hours per SMTP destination multiplied by N number of destinations. I also think that the likelihood of success in sending legal threats to somebody that demand they accept your SMTP traffic will not stand up in court, if you ever escalated it that far. As somebody who runs postfix MX on the receiving side of things, I can guarantee you that the day I receive a legal thre…
The number of people using anything other than google, apple, microsoft or yahoo for personal email these days is vanishingly small; and of the remainder, almost all of them are on major broadband providers. If you were some local ISP blocking us, that wouldn't be worth the trouble of sending a legal letter. I'd just tell that particular customer to contact you and ask why you weren't delivering our mail.
This only leaves other corporations that provide their own mail services to people who work there, and if those people want to get their mail they can call IT.