Live data from Hacker News

Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

blog.google

171–180 of 420 posts

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#171
The authentication stuff is all standard practice so no big change IMO. However the hard spam limit with Gmail in particular will get interesting. I predict this is going to create some insane headaches for indie Saas startups.

Gmail is the only inbox provider that doesn’t offer a real feedback loop (you don’t actually know if a given email address marked you as spam when sending to gmail users). The FBL in Google postmaster tools is anonymized and unreliable at best.

So essentially, you never know if a Gmail user marked you as spam so you can stop sending to them. Gmail will just by default mark your emails as spam for that user going forward, without telling you. This means your spam complaint level will inevitably rise over time without you knowing why and what email addresses are causing the issue.

Unless Gmail actually starts providing a real FBL like other inbox providers, the hard spam limit is going to snowball into a nightmare for even the most conservative and legitimate senders.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#172
post #127

Can we add a TTL to marketing emails? Max length is two weeks before the email is automatically deleted.

Some mail providers somewhat support this. Fastmail for example allows setting retention limits on each folder including the trash and spam folders. One could make a folder for marketing and make rules for some of the bulk senders and then just keeping adding them as one finds them. Perhaps if enough people asked their mail provider they could add a global check-box for all the common email campaign providers.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#174

> we’ll enforce a clear spam rate threshold that senders must stay under I hope they make it really strict. I'm sick of companies that send you spam ("newsletters") just because you interacted with them once, then when you unsubscribe, you get unsubscribed from that one list, so they keep spamming you just with a slightly different newsletter type. (Edit: Also, everything requiring a notification - by e-mail if they…

This is exactly why GDPR exists. What you are describing is illegal in the EU. Sending marketing communication requires clear opt in consent.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#176

Earlier quoted context omitted.

I have that friend that whenever I don't feel like putting my own email or phone number I just put his. You probably have that friend too, the other way around

Why don't people like you just spend exactly 2 minutes to create a bogus gmail (or etc) account for yourself that you put down when you don't want to put your own email in? I just cannot fathom any reason for you doing this that isn't just malice. Surely nobody is just so _lazy_ that they intend to screw over their friends over a minute or two process making an account.

It's a prank. Meant to be funny. Best when signing up for something which might be construed as embarrassing.

I've also done this where I've donated $25 to U of California in the name of my friend who went to Stanford (rival universities). He's likely still getting calls.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#177
post #139

Earlier quoted context omitted.

I mean... No? You can set up your own mail server all you want, it's just that few people will take your mail. Just make friends with other people who hate managed mail companies, you'll be able to email them just fine.

That's too facile. Email was intended as a federated service that allows anyone to send mail to anyone. Privileging large companies over small companies and individual users is a clear violation of that principle, and a danger to the open and impartial internet. I get that spam is annoying (I hate it too) but letting giant American tech companies decide who is allowed to send email and who isn't is not the solution.…

Eh, opposite experience, Gmail filters out almost entirely spam email for me and extremely rarely legitimate email. The filter learns fast in either direction.

I get daily spam coming from Gmail and Azure tenants especially.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#178

Earlier quoted context omitted.

Exactly, seriously -- I get monthly+ e-mails from a gym and a car dealership and some golf course because somebody else put in my e-mail. I contacted the customer support for all of them and they said they can't do anything about it. To change the customer's e-mail address, I need to prove I'm the customer, and obviously I have no idea who they are. So I gave up and implemented a Gmail filter in the end, but I defini…

I have that friend that whenever I don't feel like putting my own email or phone number I just put his. You probably have that friend too, the other way around

What is wrong with you?

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#179

Hijacking the thread: I do some "bulk" sending for a 501(c)3 I volunteer for. I include unsubscribe links that go to a form with a submit button (because I want the unsubscribe to be a POST request). Each link has a random opaque identifier in the query string. Something like: hxxp://example.com/unsubscribe?id=abcd1234 A couple years ago I noticed that MSFT IPs hitting my unsubscribe links with invalid identifiers on…

Several antivirus scanners and mail providers open links to check for malware. I believe they add some randomness to either bust through cache or to detect if the URL is encoded as an exact match (some exploit kits will redirect to google.com if you alter the URL in any way or after x requests to the same URL).

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#180

Earlier quoted context omitted.

Why don't people like you just spend exactly 2 minutes to create a bogus gmail (or etc) account for yourself that you put down when you don't want to put your own email in? I just cannot fathom any reason for you doing this that isn't just malice. Surely nobody is just so _lazy_ that they intend to screw over their friends over a minute or two process making an account.

It's a prank. Meant to be funny. Best when signing up for something which might be construed as embarrassing. I've also done this where I've donated $25 to U of California in the name of my friend who went to Stanford (rival universities). He's likely still getting calls.

The rival university one seems like a solid prank. The user I replied to did not make it sound like the intent was to be funny.

> whenever I don't feel like putting my own email or phone number I just put his

This sounds more like malice than well thought out humor. If I found out someone I knew and respected was using my primary contact information for spam emails at I would definitely consider not talking to that person much any more. The rival university one however I would let slide because the intent from you is obviously different.

Post reply on HN