Live data from Hacker News

After self-hosting my email for twenty-three years I have thrown in the towel

cfenollosa.com

291–300 of 744 posts

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#291
post #259
post #222

Earlier quoted context omitted.

You are totally missing the simple fact that the number of blessed email providers to choose from is slowly going down. I've seen ISPs with thousands of clients to give up and move the mailboxes to large players simply because their clients' email was ending up in the spam so often that running the support has gotten too expensive. It's definitely an anticompetitive practice.

It’s just because of spam. All open systems that do not impose a cost to participate are destroyed by spam.

Spam has been a thing forever. Literally forever. Yet people have been dealing with spam far better than the big boys, and doing so for decades.

Want to talk about anti-competitive? Gmail will accept mails, provide a 250 SMTP response, then drop the email internally.

That's not right. At all. You can reject the email easily during SMTP exchange, and people have been doing that literally for 20+ years.

No valid excuse here. None. Zero.

And if your 250 OK accept then drop the message, and provide no way to notify, or discuss, or find out why, you make it impossible for a remote admin to fix the problem.

This is 100% on purpose. Yahoo, outlook/hotmail, gmail, collude to resolve issues like this, while blocking all others to resolve issues their own purposefully broken policies cause.

If you see Alphabet with a policy, or action, you can be 100% sure it is aligned to increase market dominance.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#292
post #288

Earlier quoted context omitted.

Is it that difficult to grasp that there's a "depends" option between "optional" and "not optional"? Nobody really forces you to use HTTPS either, it's not a "monopolizing" standard if someone doesn't trust you without. And again, if you have a way of establishing just as much trust without such a labour-intensive/expensive verification process, please do share.

When the big providers all require VMC to show BIMI, then VMC is not optional, no matter what the spec says. Claiming it is optional is then disingenuous. As I said in the linked post, logo verification is not a problem which can be solved. Identical trademarks can legitimately be issued in different fields, and both still be valid. Let’s say you are a brick manufacturer, and have paid an arm and a leg to a VMC certi…

> When the big providers all require VMC to show BIMI, then VMC is not optional, no matter what the spec says. Claiming it is optional is then disingenuous.

What do you mean "no matter what the spec says", it is the spec we're talking about. It is what you argued against several times.

If you had started with saying "big providers' implementations of BIMI", then it wouldn't be wrong to say it's required but it's still not "monopolizing". Requiring you to prove your claims using a third unrelated party is simply not that.

> As I said in the linked post, logo verification is not a problem which can be solved. [...] and the BIMI system will have trained your customers to trust your logo.

There are caveats to each system. It does not mean the problem is not solvable to a large extent.

Secondly, it's pretty clear who to jail for the attack described. I'd say it's even a positive side of the system if that's the type of attacks we'd get.

> Any fix for this you try to implement will make the system even less usable for its stated purpose, or more suited to only large players and unusable in practice for smaller operators.

That's simply not true. The price of a VMC is really not that high for any business that doesn't only employ one man and his dog.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#293
The range IP bans hit home. Been hit by this more than a few times. You don’t have to be sending spam, but if someone in the range did, ever, you will be blacklisted all the same, and treated like a spammer.

The people who run these blacklists are unreasonable. I can understand why, they tend to interact with the bowels of the internet and the heuristic is effective. Usually people who need to talk to them are doing something naughty, so why bother taking a chance?

Guilty until proven innocent would be an improvement.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#295
post #270
post #259

Earlier quoted context omitted.

It’s just because of spam. All open systems that do not impose a cost to participate are destroyed by spam.

True. But they are not calling for a completely open system. I like this proposal from the author. > Change blacklisting protocols so they are not permanent and use an exponential cooldown penalty. After spam is detected from an IP, it should be banned for, say, ten minutes. Then, a day. A week. A month, and so on. This discourages spammers from reusing IPs after the ban is lifted and will allow the IP pool to be cle…

Is there any actually money to be made in hosting email for people? I genuinely don’t know but my suspicion is that GMail, Yahoo, Outlook, et al are loss leaders for their owner companies. I suspect people at those companies would be quite happy if the protocol got unfucked enough that it small players could participate without negatively impacting the network.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#296
I know a lot of older guys will disagree with me here, the guys that use mailing lists to work on FOSS projects, many of whom I respect very much, but I think email sucks. I only use it for the same reason I have a phone number: because some people need me to have one in order to contact me.

I don't like email. I think the problems with it are shortcomings of the protocol. I'd rather not use it. But I do, as a last resort contact method.

For me, people that use email are like people that primarily communicate over SMS. If I need to talk to you and that's all you'll use, I can. But if there's another way to talk to you I'd rather use that. Xmpp, matrix, signal, shit even telegram and discord if I have to, are preferable to SMS or email. But otherwise, yeah I have some email addresses and a phone number if you insist on doing things that way.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#297
post #270

Earlier quoted context omitted.

True. But they are not calling for a completely open system. I like this proposal from the author. > Change blacklisting protocols so they are not permanent and use an exponential cooldown penalty. After spam is detected from an IP, it should be banned for, say, ten minutes. Then, a day. A week. A month, and so on. This discourages spammers from reusing IPs after the ban is lifted and will allow the IP pool to be cle…

Spam has been been fought for decades, you can rest assured any obvious solution has been tried and either doesn’t have the desired effect or is impossible to implement.

I think we ought to move email (or some future incarnation of email, like matrix) to a completely whitelist (opt-in to receive messages) basis.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#298
My company exists to solve this problem at scale for the web hosting industry. It’s too bad that self-hosting isn’t viable because of IP reputation problems, but it’s a reality that is unlikely to change any time soon.

I’d say if you want to continue self-hosting, just let go of the delivery part. Use a service like SendGrid; it probably won’t cost you anything and it’s easy to set up.

Re: After self-hosting my email for twenty-three years I have thrown in the towel

#300
post #222

Earlier quoted context omitted.

You are totally missing the simple fact that the number of blessed email providers to choose from is slowly going down. I've seen ISPs with thousands of clients to give up and move the mailboxes to large players simply because their clients' email was ending up in the spam so often that running the support has gotten too expensive. It's definitely an anticompetitive practice.

> It's definitely an anticompetitive practice. Or maybe it's an overly competitive protocol? Like playing Monopoly. Even a neophyte can end sweeping the game despite not understanding any of the underlying mechanics that drive the game's outcome. Those remaining mail providers are also fighting back the insanity. They 'just' won. Don't hate the player, hate the game.

I wonder if we can’t build a far simpler postoffice app on http (self hosted domain space) and have a whitelisted encrypted exchange.
Post reply on HN