Live data from Hacker News

Spam blacklisting is out of control

blog.roastidio.us

311–320 of 430 posts

Re: Spam blacklisting is out of control

#311
post #229

Earlier quoted context omitted.

You have this all backward. > You actually think that the best answer to a network engineering problem is to make legal threats at third party ISPs? It's not a "network engineering problem" if administrators and managers are the ones making the decisions to provide no reasonable recourse for a ban, on top of actively ignoring or denying legitimate requests for removal. If the third party hasn't broken any rules, then…

> If you are providing an email service and your customers are not receiving the emails they're expecting, all because you refused to acknowledge a removal request, And on this I concur with you, because if the sender of the email is actually sending spam and has ended up on some smtp-receiving deny lists for well founded reasons, they are indeed failing their customers. Failing them through their own lack of procedu…

You're assuming facts not in evidence, such as that we don't have policies for unsubscribing, or that we're sending spam in the first place. To be clear, we've never complained to anyone except on behalf of customers who complained to us that they weren't getting our mail.

Re: Spam blacklisting is out of control

#312
post #34

I fought the battle to keep my SMTP server IP off blacklists, and lost. You can do everything possible, have a perfectly clean IP, have a good amount of outbound email traffic, only send transactional email, etc. Still, there will be edge cases where email does not go through. AT&T email servers would constantly blacklist me and not respond to requests to remove me, gmail/yahoo/outlook would silently put emails in th…

While I am happy for you that you have found a solution, the solution you found is symptomatic of a very dangerous situation: it is increasingly impossible for individuals or SMEs to use essential online facilities like sending messages or transferring money reliably unless they use a broker service as an intermediary. We are allowing small numbers of tech firms to take control of vital functionality that should be u…

The flip side is that before, when the rules were lax and everybody could send email, everyone would get at least 10 spam mails every day, more if your address was online somewhere. Where now most people get one a week.

Re: Spam blacklisting is out of control

#313
post #34

I fought the battle to keep my SMTP server IP off blacklists, and lost. You can do everything possible, have a perfectly clean IP, have a good amount of outbound email traffic, only send transactional email, etc. Still, there will be edge cases where email does not go through. AT&T email servers would constantly blacklist me and not respond to requests to remove me, gmail/yahoo/outlook would silently put emails in th…

I manage an outbound mail server for a mid-sized company. I happen to also use it for my own personal mail. We have had on and off deliverability issues for years (AT&T and Comcast being the worst). As head of IT it fell to me to post whitelisting requests and try to get mail delivering again. I decided after awhile that this really isn't my job, and made a suggestion to the CEO which he took to heart: There is anoth…

Classic example of regulatory burden in action. Any firm small enough to not have a legal team can't compete.

Edit; to be clear I'm not saying this results from some legislation, although you could make that case. Just that scale has many benefits and the principle of regulatory burden obtains!

Re: Spam blacklisting is out of control

#314
It's not a new thing. I was a sysadmin for a small ISP back in the early 2000s and we had a hate relationship with Spamhaus. They were militant, trigger happy, and very difficult to work with. It was an ongoing headache.

I figure that places like spamhaus are a good part of why gmail took over.

Re: Spam blacklisting is out of control

#315
post #249

Earlier quoted context omitted.

People have been making legal threats at, and trying to sue, RBL operators since 1997 or so. It's a well known thing. All I say is "good luck" if you think legally threatening a maintainer of a list of IP CIDR prefixes that are used by a third party is going to solve your problems. It hasn't worked for the last 25 years and I don't see how it'll start working now.

No I think the solution is to not get a $5/month vps and expect it to have a good reputation. Maybe if you went with the $100/month hosting provider you wouldn't have needed to spend $500/month on legal threats. Internet addresses aren't fungible. It's a well known concept in telecommunications. One of the reasons why people have always paid a lot more money to have 212 numbers versus 646 numbers. It's the reason why…

This is completely valid, but if you go hunting for an IP block that has never been used for spam at this point you're going to be looking for a long time. It should not be the #1 consideration when choosing a hosting provider just because someone abused their IP block in the past (possibly before they even owned it). In any case, trying to run mail off a VPS would be stupid and that's not what I'm saying. I'm saying we don't all need to capitulate to paying Amazon or Google to forward our outbound mail, and it would be better if we did not, even considering the struggles attached to bucking the trend.

Re: Spam blacklisting is out of control

#316
post #298
post #257

Earlier quoted context omitted.

From a comment below from the other side of the equation it sounds like the email in question WAS indeed marketing for a lifetime promotion. People should have every right to unsubscribe themselves from that, and thus should have some sort of feedback loop attached to the email being sent (to the detriment of your bottom line I fully understand and sympathize with). If this was indeed a marketing email, then I don't…

"People should have every right to unsubscribe themselves from that, and thus should have some sort of feedback loop attached to the email being sent (to the detriment of your bottom line I fully understand and sympathize with)." I agree. We have a flag for such a thing and set that flag when people ask us to. They ask us in a nice email exchange between human beings. We're very responsive to this since they are our…

Did they request this marketing message through a "nice email exchange between humans"? Or did you automatically sign up this person for marketing then expect them to manually contact you?

You are wayyy to smart not too see the abusive asymmetrical theater of that scheme.

Re: Spam blacklisting is out of control

#317
post #131

I have been running my own mail server for two years on my private ISP and have less problems than expected - even with the dynamic IP address (in practice, it changes once in 6-12 months) and no PTR. I also switched the ISP once. I have SPF, DKIM, DMARC. Edit: The nice thing about running the mail server personally and without a relay (like mailgun) is that mail is to-my-end encrypted. If the other party is running…

I like running my own mail server but I don't want to waste time on filtering spam so mismatches with ptr and hostname are an instant rejection from me.

A PTR match is a very strong signal that I am looking at a hosted server or business connection which is configured to send email and not a compromised windows PC on consumer dsl which used to be a huge problem. ISPs supply those dsl ranges to blocklists as well.

When I first started hosting my own mail it was on an old repurposed linux PC on ISDN in the early 2000s and even then my ISP offered configurable PTR records along with static IP in a small business package.

I moved my family email vps to a different region recently and it took me a few seconds to update the ptr records for ipv4 and ipv6. It seems a very low bar for such a strong signal that you are dealing with a mail server and not some random compromised machine.

Re: Spam blacklisting is out of control

#318

Earlier quoted context omitted.

1. Host your mx somewhere that isn't on any blacklists. This means a small to medium sized isp, where you can directly contact the people who run the core network operations there, and who truly do care about kicking off abusive other customers very quickly. Ideally I would go with an ISP in your own region and home business area. Best chances of success if it's a hosting ISP where random customers cannot sign up onl…

Host your mx somewhere that isn't on any blacklists. This means a small to medium sized isp, where you can directly contact the people who run the core network operations there, and who truly do care about kicking off abusive other customers very quickly. Ideally I would go with an ISP in your own region and home business area. That's a nice idea. In fact, it's what my businesses have done for years. I have personall…

The thing is, if you own a good IP in a mixed block with some bad ones, that's no reason for you to be blacklisted. It's pure laziness. It's usually wrong to assume that everything in a /24 is controlled by one botnet, and it's not that hard to check whether it was just one or two particular addresses that were compromised. But if you're an ISP and you want to take the nuclear option to every spam threat, at least be willing to listen to your own customers when they complain that they're expecting mail, and there's absolutely NO reason to assign "group punishment" to everyone using the same service provider. I think the thought was that that would make service providers more accountable, but it's totally unfair to use everyday customers as pawns in a war between ISPs.

Re: Spam blacklisting is out of control

#319

Earlier quoted context omitted.

I manage an outbound mail server for a mid-sized company. I happen to also use it for my own personal mail. We have had on and off deliverability issues for years (AT&T and Comcast being the worst). As head of IT it fell to me to post whitelisting requests and try to get mail delivering again. I decided after awhile that this really isn't my job, and made a suggestion to the CEO which he took to heart: There is anoth…

Classic example of regulatory burden in action. Any firm small enough to not have a legal team can't compete. Edit; to be clear I'm not saying this results from some legislation, although you could make that case. Just that scale has many benefits and the principle of regulatory burden obtains!

Yes, but - if more small-ish companies did this, it could have an outsized impact. The company I work for is to AT&T what like an amoeba is to a whale; not much bigger than a single phytoplankton (e.g. an end user).

Re: Spam blacklisting is out of control

#320

Earlier quoted context omitted.

In the American legal system, if somebody spends the money to take the time to have their lawyer hand craft and send me a letter about something such as this, I'm going to take it as a threat whether or not it specifically contains one. The implication is that if you do not do whatever is demanded in the letter, the next step will be the client of said lawyer escalating the situation to paying their lawyer to actuall…

The fact that you would automatically react in this way is itself a reason to send it to the lawyers and have it go through a different department and chain of command. Make it a legal and business decision instead of a technical one. And find an audience that knows the practical benefits of quick resolutions to reasonable requests. And I say this as a person that would likely respond in a similar punitive and/or pri…

>> Make it a legal and business decision instead of a technical one.

I'd go further and say that choosing to unblock some IP addresses out of a block you don't like is always going to be a business decision. The whole rationale for blocking in the first place was that a sender is untrustworthy.

Untrustworthy senders generally don't have a team of lawyers, and if they do (and they're actually sending spam) you can show what spam they sent and keep them blocked.

All the legal letter does is force someone who's otherwise too busy to look at this particular case for the 5 seconds it takes to determine that it's not a threat. Sad to say that being head of IT for a company for a decade doesn't get you the same level of respect; it might if they even bothered to open your email, but there's something about postal and legal letterhead.

Post reply on HN