Live data from Hacker News

Spam blacklisting is out of control

blog.roastidio.us

341–350 of 430 posts

Re: Spam blacklisting is out of control

#341

Earlier quoted context omitted.

But the companies aren't obligated to accept your email are they? What grounds do you have to ask for damages?

Lawyers typically will only talk to other lawyers when interacting with other companies (often are ethically compelled to). An email from legal@companyA.com to legal@companyB.com will be read.

But this thread is about companyB.com blocking incoming email delivery from companyA.com :D

You need to involve legal.com.

Re: Spam blacklisting is out of control

#343
Level 2 and Level 3 are not blocklists that are suitable for blocking on their own. They are punitive blocklists. They should only be used as part of a scoring system, such as SpamAssassin.

If your outbound mail is being blocked by some server just because your MTA is in one of those lists, it might be worth contacting the postmaster at the other end, and asking them either to drop those two lists, to use them only for spam-scoring, or to whitelist your MTA.

Re: Spam blacklisting is out of control

#344
post #229

Earlier quoted context omitted.

Not everyone can spend $500 on lawyer billable hours per SMTP destination multiplied by N number of destinations. I also think that the likelihood of success in sending legal threats to somebody that demand they accept your SMTP traffic will not stand up in court, if you ever escalated it that far. As somebody who runs postfix MX on the receiving side of things, I can guarantee you that the day I receive a legal thre…

You have this all backward. > You actually think that the best answer to a network engineering problem is to make legal threats at third party ISPs? It's not a "network engineering problem" if administrators and managers are the ones making the decisions to provide no reasonable recourse for a ban, on top of actively ignoring or denying legitimate requests for removal. If the third party hasn't broken any rules, then…

> all because you refused to acknowledge a removal request

But the receiving MSP can't acknowledge the removal request, in the scenario reported by the author. They are not the ones operating the blocklist. That's UCEPROTECT, not Comcast or whoever.

Re: Spam blacklisting is out of control

#345

> My hosting company is competitively priced, is fast, and has served me well for many years. ... attributes which they achieve by (1) selling services to anyone and anyone and (2) not dedicating any resources to fighting spam. So you got what you pay for.

I don't want my hosting company to dictate what I can do and what I can't do. I don't spam, but I won't hold my moral standard to everyone else.

Your hosting company is free to allow all the spam they want to leave their network and every other ISP on the planet is free to drop all traffic from your irresponsible hosting company's IP space. freedom sure is nice.

Re: Spam blacklisting is out of control

#346

Earlier quoted context omitted.

I manage an outbound mail server for a mid-sized company. I happen to also use it for my own personal mail. We have had on and off deliverability issues for years (AT&T and Comcast being the worst). As head of IT it fell to me to post whitelisting requests and try to get mail delivering again. I decided after awhile that this really isn't my job, and made a suggestion to the CEO which he took to heart: There is anoth…

Not everyone can spend $500 on lawyer billable hours per SMTP destination multiplied by N number of destinations. I also think that the likelihood of success in sending legal threats to somebody that demand they accept your SMTP traffic will not stand up in court, if you ever escalated it that far. As somebody who runs postfix MX on the receiving side of things, I can guarantee you that the day I receive a legal thre…

A decent company and big enough already has at least one lawyer on payroll, so no need to be billed the additional 500$/hour

Re: Spam blacklisting is out of control

#347
post #221

Earlier quoted context omitted.

Did you read the whole article? The OP wasn't being blacklisted by an operator. He was being blacklisted by a company that charges you a $25/month fee to not be blacklisted by lazy operators who program their systems to curl their for-profit blacklist.

People have been making legal threats at, and trying to sue, RBL operators since 1997 or so. It's a well known thing. All I say is "good luck" if you think legally threatening a maintainer of a list of IP CIDR prefixes that are used by a third party is going to solve your problems. It hasn't worked for the last 25 years and I don't see how it'll start working now.

Literally prejudice ad a service, however.

Re: Spam blacklisting is out of control

#348

Earlier quoted context omitted.

Host your mx somewhere that isn't on any blacklists. This means a small to medium sized isp, where you can directly contact the people who run the core network operations there, and who truly do care about kicking off abusive other customers very quickly. Ideally I would go with an ISP in your own region and home business area. That's a nice idea. In fact, it's what my businesses have done for years. I have personall…

The thing is, if you own a good IP in a mixed block with some bad ones, that's no reason for you to be blacklisted. It's pure laziness. It's usually wrong to assume that everything in a /24 is controlled by one botnet, and it's not that hard to check whether it was just one or two particular addresses that were compromised. But if you're an ISP and you want to take the nuclear option to every spam threat, at least be…

> The thing is, if you own a good IP in a mixed block with some bad ones, that's no reason for you to be blacklisted. It's pure laziness.

It's not laziness; the intention of collateral blocklisting, as with UCEPROTECT L2 and L3, is punitive. It's to incentivize the sending MSP to remove their spammer (or move them to address-space where they can be blocked without causing collateral damage).

Re: Spam blacklisting is out of control

#349

Earlier quoted context omitted.

Host your mx somewhere that isn't on any blacklists. This means a small to medium sized isp, where you can directly contact the people who run the core network operations there, and who truly do care about kicking off abusive other customers very quickly. Ideally I would go with an ISP in your own region and home business area. That's a nice idea. In fact, it's what my businesses have done for years. I have personall…

The thing is, if you own a good IP in a mixed block with some bad ones, that's no reason for you to be blacklisted. It's pure laziness. It's usually wrong to assume that everything in a /24 is controlled by one botnet, and it's not that hard to check whether it was just one or two particular addresses that were compromised. But if you're an ISP and you want to take the nuclear option to every spam threat, at least be…

> The thing is, if you own a good IP in a mixed block with some bad ones, that's no reason for you to be blacklisted. It's pure laziness.

Yes, in that situation it's laziness, but on the part of your ISP. ISPs already spend huge amounts of time and money dealing with spam, hacking attempts, phishing attacks, etc. If your ISP is irresponsible and isn't doing their job keeping those things from leaving their network then your ISP is gong to find their entire IP space blocked and that's 100% reasonable. Why should we ever accept traffic from an ISP that refuses to keep their corner of the network clean when it's just going to cause problems for us and our users?

That's the situation for every ISP on the internet. Keep your users in line, keep trash off your network or else no one is going to accept traffic from you. You could call it laziness, but it simply isn't worth it. We'd rather spend our time cleaning up abuse on our own network and working with ISPs who are doing their job than dealing with the problems we get from bad actors.

If you own an IP surrounded by a bunch of spammers and it's giving you trouble step 1 should be to contact your ISP and tell them to get their shit in order or you'll take your business to an ISP who does their job. Step two is to switch to a new ISP if they don't. No one has the right to force us to accept traffic from anyone else. It's every ISPs responsibility to make sure the traffic leaving their network isn't more trouble than it's worth. Good ISPs are rewarded because users will give them their business and stay and bad ISPs are punished because users will drop their service when they see they are blocked.

The goal isn't to punish the poor sucker who signed on with an irresponsible host, but to cut down on the number of bad ISPs on the internet and the amount of work we have to deal with coming from them.

Re: Spam blacklisting is out of control

#350

Earlier quoted context omitted.

Though that may be a nice opinion, your ISP has no business dictating that to you.

Abusix isn't their ISP, they're an email blocklist provider. Telling people what they need to do to not get blocked for being abusive is literally their job.

yea, in an ideal world, the blocklist provider would educate others in how to avoid beeing blocklisted. yet, if this course is met with success then the blocklist provider is out of business.

there seems to be some conflict of interest here.

Post reply on HN