Earlier quoted context omitted.
From a comment below from the other side of the equation it sounds like the email in question WAS indeed marketing for a lifetime promotion. People should have every right to unsubscribe themselves from that, and thus should have some sort of feedback loop attached to the email being sent (to the detriment of your bottom line I fully understand and sympathize with). If this was indeed a marketing email, then I don't…
"People should have every right to unsubscribe themselves from that, and thus should have some sort of feedback loop attached to the email being sent (to the detriment of your bottom line I fully understand and sympathize with)." I agree. We have a flag for such a thing and set that flag when people ask us to. They ask us in a nice email exchange between human beings. We're very responsive to this since they are our…
Spam blacklisting is out of control
351–360 of 430 posts
Re: Spam blacklisting is out of control
#352Earlier quoted context omitted.
> Bottom line: our duty of safeguarding customer data trumps this weeks fashionable spam heuristics. I haven't suggested that you do anything differently to that. Keep the data, keep the accounts, do whatever you feel is best for you and your business. All I've said is to be smarter when it comes to sending email to old accounts that are repeatedly bouncing. I've outlined what was wrong and I worked with your enginee…
An aside: The screenshot I got of your conversation with (Dave) was, indeed very well done and was both informative and actionable. You responded to us very quickly and with a high level of professionalism. Further, participating here in this HN discussion is noteworthy and impressive. FWIW, we immediately complained to he.net about the bad actor elsewhere in that /24 ... we'll see.
> Further, participating here in this HN discussion is noteworthy and impressive.
Thank you - much appreciated.
The quality, morals and perception of our product and how we treat people matters to me greatly which is why I'm always happy to get involved in discussions like this.
As is evidenced from other post on this topic, there are a number of competitors that don't behave in the same way and that leads people to think we are all the same and I absolutely want to challenge that perception when it comes to us.
> FWIW, we immediately complained to he.net about the bad actor elsewhere in that /24 ... we'll see.
Thanks, feel free to refer them to me and I'm happy to provide as much evidence as they need.
Re: Spam blacklisting is out of control
#353Earlier quoted context omitted.
Just guessing, but maybe threatening to sue for damages might work?
You don't even need to threaten. Just a letter of representation from a lawyer is magically effective for things like this. ETA: We refer to it as "6mins and a stamp".
Re: Spam blacklisting is out of control
#354I'm dealing with this right now. Both my personal domain and rsync.net are on a distinct subnet, but that subnet is smaller than a /24 and someone on a different subnet has, apparently, behaved badly. Enter "abusix" ... One of my engineers had an enlightening webchat with one of their engineers where we were shown the "offending" IP and it was explained that they have no ability to distinguish subnets (and no interes…
The inability to generate IP reputation smaller than a /24 is inherent to the way internet routing works. Nothing smaller than a /24 can be publicly assigned or advertised to prevent the route table from becoming too bloated. On IPv6 the smallest advertise able block is a /48 for the same reason. Privately managed assignments in shared or further split subnets aren't publicly visible, verifiable, or accountable to an…
Nonsense. SMTP is not internet routing, and there is no reason at all why some "reputation" system should be constrained by the same /24 limit that the global routing table ended up with.
I find it telling that these "reputation" outfits tend to serve up this sort of poor excuse to justify their businesses; whereas they're often plain old protection rackets. Like the one described in the article clearly is. They take money to solve the problem they created!
Re: Spam blacklisting is out of control
#355I'm dealing with this right now. Both my personal domain and rsync.net are on a distinct subnet, but that subnet is smaller than a /24 and someone on a different subnet has, apparently, behaved badly. Enter "abusix" ... One of my engineers had an enlightening webchat with one of their engineers where we were shown the "offending" IP and it was explained that they have no ability to distinguish subnets (and no interes…
I'm the Abusix engineer in question (and actually the architect of the system in question), and you're being somewhat "economical" with what actually happened here. Here's the actual chain of events in question: - You recently switched ISPs and that meant you moved to a new IP block. - The IP block in question is owned by Hurricane Internet and unfortunately contains a host which persistently sends out a lot of junk…
Re: Spam blacklisting is out of control
#356Earlier quoted context omitted.
When I first started monitoring spam connections years ago, it was almost always home cable+internet providers. They seem to have gotten the message and cleaned up thier acts. As of last night, the number one source of spam for both the personal and company servers I maintain is Digital Ocean. Which is a shame, because otherwise I'm a happy Digital Ocean customer. But because of this, I would never move any of my com…
> home cable+internet providers. They seem to have gotten the message and cleaned up thier acts. By blocking outbound connection to port 25 outright. I don't want my VPS hosting company to "clean up" this way.
Most ISPs submit their domestic ranges voluntarily to certain blocklists, e.g. the Spamhaus PBL.
I used to have a bunch of blocklist services in my MTA configuration, with different lists having different weights and so on. Eventually it became clear to me that nearly all true spam that hit any one list would also hit Spamhaus Zen. So I scrapped my list of lists, and relied entirely on Zen. My life became easier.
Note: Zen includes the PBL; so if you block using Zen, then you will block mail from domestic ranges. Zen is pretty safe (unless you are expecting mail from domestic ranges). It's safest to use Zen as part of a scoring system, with something like Spamassassin to add heuristic content scoring.
Re: Spam blacklisting is out of control
#357Earlier quoted context omitted.
From a comment below from the other side of the equation it sounds like the email in question WAS indeed marketing for a lifetime promotion. People should have every right to unsubscribe themselves from that, and thus should have some sort of feedback loop attached to the email being sent (to the detriment of your bottom line I fully understand and sympathize with). If this was indeed a marketing email, then I don't…
"People should have every right to unsubscribe themselves from that, and thus should have some sort of feedback loop attached to the email being sent (to the detriment of your bottom line I fully understand and sympathize with)." I agree. We have a flag for such a thing and set that flag when people ask us to. They ask us in a nice email exchange between human beings. We're very responsive to this since they are our…
So it's not enough to allow them to opt-out with an e-mail exchange or an unsubscribe link, you must allow the user to opt out when you initially gather the contact information.
If that wasn't done, it's illegal (and unethical) to send marketing e-mails, even from a paid service.
Re: Spam blacklisting is out of control
#358Earlier quoted context omitted.
I manage an outbound mail server for a mid-sized company. I happen to also use it for my own personal mail. We have had on and off deliverability issues for years (AT&T and Comcast being the worst). As head of IT it fell to me to post whitelisting requests and try to get mail delivering again. I decided after awhile that this really isn't my job, and made a suggestion to the CEO which he took to heart: There is anoth…
Not everyone can spend $500 on lawyer billable hours per SMTP destination multiplied by N number of destinations. I also think that the likelihood of success in sending legal threats to somebody that demand they accept your SMTP traffic will not stand up in court, if you ever escalated it that far. As somebody who runs postfix MX on the receiving side of things, I can guarantee you that the day I receive a legal thre…
Somebody created a github containing domains he thought should be blocked: https://github.com/chadmayfield/my-pihole-blocklists
A year later I bought a domain that had expired under my country TLD. It turns out that domain for some reason was previously added to that list.
Now, as you can see, the man behind that Github repo has decided to archive that repo and therefore make it read only.
As you can tell from both pull requests and issues on that repo, people has asked him to remote legitimate domains (e.g. *.urbandictionary.com). But those calls remain unanswered. It is fruitless to contact the author.
So this random dude causes real problems for legitimate business and individuals and we should just accept it?
Obviously he doesn't act on friendly geek requests. It seems lawyering up would be the only recourse in this situation. I find it analogous to somebody standing on a soap box in a village and announcing: "Don't trust James. Don't trust Mary either. There's problems with Charles" and James, Mary, and Charles have no way of stopping his libel.
I don't have the funds for legal action, but it is obviously wrong that he can announce "these domains are bad" and offer no way of fixing mistakes. He should take down the repo, but oh that sweet sweet Github karma probably discourages him from doing so.
Re: Spam blacklisting is out of control
#359Earlier quoted context omitted.
Abusix isn't their ISP, they're an email blocklist provider. Telling people what they need to do to not get blocked for being abusive is literally their job.
yea, in an ideal world, the blocklist provider would educate others in how to avoid beeing blocklisted. yet, if this course is met with success then the blocklist provider is out of business. there seems to be some conflict of interest here.
Not all blocklist providers are the same.
Re: Spam blacklisting is out of control
#360Earlier quoted context omitted.
In the real world, reputation matters and some people don't want to talk to you unless someone can vouch for you. This has absolutely nothing to do with someone not wanting to talk to someone else. It has everything to do with some third party having the power to decide whether the other two may communicate. These days it's all so centralized in a few very large players that they really likely just talk to each other…
> This has absolutely nothing to do with someone not wanting to talk to someone else. It has everything to do with some third party having the power to decide whether the other two may communicate. They have that power specifically people people outsource vetting of whether someone's worth dealing with. I'll repeat, this is all about reputation, and how without reputation you're subject to every anonymous person's ab…
That's not true. When you use Gmail you don't opt-in to a setting to "automatically send smaller non-commercial providers to the SPAM folder". Gmail is pretty bad at SPAM handling you still receive lots of commercial advertisement from "reputable" sources, you just don't see the non-scammy non-phishy email you were expecting.
In this specific instance, Gmail is not the worst out there. They're very protective but from what i heard you can get allowlisted in a matter of weeks of harassing their tech support. Meanwhile, Microsoft is a lost cause if you want to get your mail through to an Outlook mailbox...