Live data from Hacker News

Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

blog.google

271–280 of 420 posts

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#272
post #236

Earlier quoted context omitted.

I use fastmail masked email (which is basically the same thing) with the firefox plugin. I love it.

It gets better when you have your own domain and you can register with throwaways using spamco@mydomain.

I've started doing this about a year ago, but I haven't nailed down an easy way to blacklist addresses from my catch-all. Do you know of a painless way to do that?

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#273
post #237

Earlier quoted context omitted.

That exists for a reason, and it's not nefarious at all. Lot of people, especially of the older generation, forward all sorts of emails to their friends and family every day. If one person who received a forwarded email doesn't like it and clicks the unsubscribe link, the original recipient (who clearly likes the email enough to forward it around) gets unsubscribed. That's a bug. If you don't like the unfunny newslet…

I think you are mostly wrong. OP is complaining they sometimes have to enter their email address - that is absolutely unnecessary make-work. The page can prompt the email address, and have a simple unsubscribe button. Not perfect, but okay. Even better, one-click unsubscribe features (e.g. Gmail's App) are presumably set up to work for the current recipient (not the original sender) so the problem is resolved for any…

Not everyone uses Gmail or a modern email client that understands the one-click List-Unsubscribe protocol, so senders must include an HTML unsubscribe link in the body of the email in order to comply with relevant rules in all jurisdictions. That link, unfortunately, can fall prey to the shenanigans I mentioned above.

I understand the parent's sentiment because we all want to unsubscribe from unwanted emails. But technical standards can't distinguish unwanted emails from business-critical emails. You could legitimately cause someone damages by silently unsubscribing them from an important news feed. (Imagine that you silently unsubscribed an open-source maintainer from all github notifications!) Even worse, this kind of vulnerability disproportionately affects senders who try to follow the rules and make it easier for people to unsubscribe. Spammers don't care and keep spammin'.

Ideally, an email would have both a one-click List-Unsubscribe header and an HTML unsubscribe link in the body. The latter need not be one-click, and in fact, if it's anything remotely important, should not be.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#274
post #237

Earlier quoted context omitted.

There's worse. An unsubscribe link that asks you to submit your email. Few things anger me more, because they went through the trouble of pretending to comply, and a decision was made to make my day more difficult.

That exists for a reason, and it's not nefarious at all. Lot of people, especially of the older generation, forward all sorts of emails to their friends and family every day. If one person who received a forwarded email doesn't like it and clicks the unsubscribe link, the original recipient (who clearly likes the email enough to forward it around) gets unsubscribed. That's a bug. If you don't like the unfunny newslet…

They could perhaps pre-fill the email as a middle ground.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#275
post #6

Oh fun so basically no one will be able to setup their own email servers by themselves anymore. Antispam is killing the open internet now.

...and saving email at the same time. It's totally unusable without spam filters, and the open models/blacklists don't come anywhere close to Gmail's capabilities.

using Rspamd i have 0 spam in my private email adress

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#276
post #237

Earlier quoted context omitted.

That exists for a reason, and it's not nefarious at all. Lot of people, especially of the older generation, forward all sorts of emails to their friends and family every day. If one person who received a forwarded email doesn't like it and clicks the unsubscribe link, the original recipient (who clearly likes the email enough to forward it around) gets unsubscribed. That's a bug. If you don't like the unfunny newslet…

They could perhaps pre-fill the email as a middle ground.

Many websites actually do this. It significantly weakens the defense against the forwarding problem because people will blindly click submit. But IMO it's an acceptable compromise for anything not business-critical.

Some people have come up with a trick to hide the unsubscribe link with CSS when it is inside a

tag, as in a forwarded email. It doesn't work reliably, though. HTML email is still stuck in the 90s, it's impossible to do anything fancy inside of it. Much easier to send the user to a real web page for an actual transaction.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#277

Earlier quoted context omitted.

I think they mostly are -- they're all about reminders for upcoming appointments and vehicle checks (the dealership), confirmation of bill payment and notices of rate rises and holiday hours (the gym), and confirmations of tee time reservations or payments or something or other with the golf course.

What definition of transaction relates to a notice about holiday hours?

[deleted]

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#278

Earlier quoted context omitted.

I think they mostly are -- they're all about reminders for upcoming appointments and vehicle checks (the dealership), confirmation of bill payment and notices of rate rises and holiday hours (the gym), and confirmations of tee time reservations or payments or something or other with the golf course.

What definition of transaction relates to a notice about holiday hours?

What's your point?

I'm not sending these.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#279

> we’ll enforce a clear spam rate threshold that senders must stay under I hope they make it really strict. I'm sick of companies that send you spam ("newsletters") just because you interacted with them once, then when you unsubscribe, you get unsubscribed from that one list, so they keep spamming you just with a slightly different newsletter type. (Edit: Also, everything requiring a notification - by e-mail if they…

i can't be the only oldskool person on hacker news who knows not to click on unsubscribe buttons because it just identifies you as a legitimate email/mark... these are spammers, not cases where you ever actually signed up to some kind of legitimate newsletter or discussion group. to pretend good faith is your first mistake...

I don’t think this is a legitimate concern any more. There’s basically zero value in “confirming” an email address is legitimate. Between all of the data breaches and various other ways to get actual email addresses this isn’t a problem. It’s also so cheap to send email there isn’t an operational cost where you need to optimise for sending only to know addresses.

There is definitely a punitive cost for sending emails that are repeatedly marked as spam though. You also can’t just cycle IPs because a brand new IP with zero sender reputation is treated with almost as much suspicion by the big player as one that is known to be a spammer.

It’s much better to give people an option to opt out, and to honour it. Most of the email sending providers (e.g., SendGrid, mailchimp, etc) force you to include the link and automatically block future sending to that address. Some will even provide you the option to provide a reason, where you can specify “I did not sign up for this” which in sufficient number will flag the sender account. I suspect the vast majority of cases where people unsubscribe but continue to get email is actually some incompetence from not having multiple disparate email systems sync back to a shared do not contact list (rather each system is maintaining its own).

Click the unsubscribe button.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#280

> we’ll enforce a clear spam rate threshold that senders must stay under I hope they make it really strict. I'm sick of companies that send you spam ("newsletters") just because you interacted with them once, then when you unsubscribe, you get unsubscribed from that one list, so they keep spamming you just with a slightly different newsletter type. (Edit: Also, everything requiring a notification - by e-mail if they…

I wish Apple Hide My Email features existed 20 years ago. Any new signup now is I use hide my email.

What do you do about accounts where you need to log in on different devices? This is where I end up leaving it at the door.
Post reply on HN