Live data from Hacker News

Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

blog.google

211–220 of 420 posts

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#211

Hijacking the thread: I do some "bulk" sending for a 501(c)3 I volunteer for. I include unsubscribe links that go to a form with a submit button (because I want the unsubscribe to be a POST request). Each link has a random opaque identifier in the query string. Something like: hxxp://example.com/unsubscribe?id=abcd1234 A couple years ago I noticed that MSFT IPs hitting my unsubscribe links with invalid identifiers on…

I thought it was part of CAN SPAM that you can’t require a second action and that was why the big email sending providers moved to that.

Google requires senders to use the `List-Unsubscribe-Post` and `List-Unsubscribe` headers, which use a POST request to avoid this problem.

Details: https://support.google.com/mail/answer/81126#zippy=%2Crequir...

(I work for Google, but on something totally unrelated, and don't speak for them or have any inside knowledge. I was just curious and looked it up.)

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#212

Bulk sending breaks the utility of email. I wish there was a way to say, “Don’t allow my email to receive bulk sent emails.” I can’t imagine how much that would improve my life. I just don’t want to see it. It breaks my attention far too frequently for far too little utility, and I would love it if entire emails I own could be bulk spam free. I don’t really want a better version of our shitty current system.

The issue is: How does a server determine that a message is bulk sent?

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#213

> we’ll enforce a clear spam rate threshold that senders must stay under I hope they make it really strict. I'm sick of companies that send you spam ("newsletters") just because you interacted with them once, then when you unsubscribe, you get unsubscribed from that one list, so they keep spamming you just with a slightly different newsletter type. (Edit: Also, everything requiring a notification - by e-mail if they…

This is exactly why GDPR exists. What you are describing is illegal in the EU. Sending marketing communication requires clear opt in consent.

I don't know the legality of this in the EU but often it is required that you opt-in to these marketing emails to create an account or do other basic things on a website.

And then there's those online stores that cover the entire page in a popup that you can get a 20% discount code if you give your email. Technically I've opted into their marketing. But I always just use the coupon and then report the email as spam without bothering to unsubscribe.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#214

This might be good news, but as it comes from Google and involves email centralisation, I’m sceptical. At MailPace we already enforce DKIM, it’s pretty basic stuff. But list-unsubscribe is optional for our senders. We can make this a requirement and manage lists for senders who don’t / can’t implement a webhook to handle it (we already default to blocking resends to emails that hard bounce). However I am curious how…

Why would you allow users to unsub from transactional emails?

Because I don't need or want:

- confirmation of my order

- my order has been despatched

- my order is out for delivery

- my order has been delivered to locker

- reminder to collect from locker

- my order has been collected from locker

- feedback on customer support chat experience

- my return label has been generated

- reminder to return my item

- my refund is processing

That's Amazon, in case it's not obvious. I don't need any of that by email, I immediately archive it, and if I want to know I look in my account, not my email. I even have the app installed and notifying me with all of the same and more (I'm spared 'x stops away' by email).

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#215
post #95
post #6

Earlier quoted context omitted.

...and saving email at the same time. It's totally unusable without spam filters, and the open models/blacklists don't come anywhere close to Gmail's capabilities.

Any data? Or just "I say so"... Before I decided to leave it due to its horrendous false positive rate, gmail was driving like half of notification emails from my servers and mailing lists to spam, despite me never marking them as such. I was regularly missing important things. It's much better with just regular client side bogofilter and some training on my personal mail/spam archive. And I do zero server side filte…

No, sorry, it's purely anecdotal. And also more applicable to the last few decades, when other email services were still terrible, than nowadays with many adequate options.

I think I have the opposite preference to you: false positives are OK to me if that means less spam gets through. In fact I've seen many of those notifications in my gmail spam and thought to myself, "Huh, you know, maybe I don't need those that badly after all... I'll just let gmail keep it there."

The overwhelming majority of my human contacts use other channels anyway (some chat app, or SMS), not email. I might get like ten real emails from humans in a year, and even then 90% of them are from people already in my contact list (and so bypass spam).

Phone calls are similar these days. Google Fi/Android also applies a similarly strict spam filter to incoming calls, and marks and blocks a lot of them as spam. I check once in a while, but overall I just don't really mind. If someone really needs to reach me they'll find a way... if they don't try, it's a good filter for how important their message really is anyway, lol.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#218

> we’ll enforce a clear spam rate threshold that senders must stay under I hope they make it really strict. I'm sick of companies that send you spam ("newsletters") just because you interacted with them once, then when you unsubscribe, you get unsubscribed from that one list, so they keep spamming you just with a slightly different newsletter type. (Edit: Also, everything requiring a notification - by e-mail if they…

i can't be the only oldskool person on hacker news who knows not to click on unsubscribe buttons because it just identifies you as a legitimate email/mark...

these are spammers, not cases where you ever actually signed up to some kind of legitimate newsletter or discussion group. to pretend good faith is your first mistake...

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#219
post #195

> we’ll enforce a clear spam rate threshold that senders must stay under I hope they make it really strict. I'm sick of companies that send you spam ("newsletters") just because you interacted with them once, then when you unsubscribe, you get unsubscribed from that one list, so they keep spamming you just with a slightly different newsletter type. (Edit: Also, everything requiring a notification - by e-mail if they…

If I'm certain I don't know the company, or I know the company but there is no unsubscribe button, it goes straight to Spam, no questions asked. A decade ago I went to my country's embassy to renew my passport, and they now use my email to subscribe me to the newsletters of any new political party. All unsubscribe links just 404s. Shameful behaviour. Anything I receive from any of their political candidates goes stra…

There's worse. An unsubscribe link that asks you to submit your email. Few things anger me more, because they went through the trouble of pretending to comply, and a decision was made to make my day more difficult.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#220

What’s in it for Google?

The truth is, most small businesses cannot figure out how to add DNS records to their domain. So they will no longer be able to inbox.

And the more complicated and difficult Gmail makes it for companies to access your inbox via open tech like email, the more likely it is you'll be forced to pay for Gmail Ads.

The bonus is Google gets to couch this as being "for the users." Gmail already has fantastic spam filtering and it's highly likely they use all this stuff as spam signals already. I would be very very careful of any claims from a giant advertising monopoly that this is "for the good of all."

Post reply on HN