Live data from Hacker News

Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

blog.google

291–300 of 420 posts

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#291

Earlier quoted context omitted.

It gets better when you have your own domain and you can register with throwaways using spamco@mydomain.

I've started doing this about a year ago, but I haven't nailed down an easy way to blacklist addresses from my catch-all. Do you know of a painless way to do that?

In fastmail, rules for specific addresses take priority over catchalls. So if I have a catchall and tell it to bounce emails to spamco@, the bounce rule applies properly.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#292

This might be good news, but as it comes from Google and involves email centralisation, I’m sceptical. At MailPace we already enforce DKIM, it’s pretty basic stuff. But list-unsubscribe is optional for our senders. We can make this a requirement and manage lists for senders who don’t / can’t implement a webhook to handle it (we already default to blocking resends to emails that hard bounce). However I am curious how…

> Just because the header is set, it doesn’t mean it’ll do anything. True, but I think when you're processing the volume of email that Gmail is, you'll have enough data to be able to infer whether the unsubscription was processed.

All it would take is one human to review the email, but sadly given Google's aversion to humans in the loop I predict it will be inferred by an algorithm and subject to false positives with no practical way to escalate for review.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#293
post #249

Earlier quoted context omitted.

There is no "mistake" in wanting to unsubscribe from a mail list. This is just dark pattern to increase friction, whatever scenario they try to come up to justify.

I share your frustration, but there is no evidence that you read the comment you're replying to. That comment explains that there's a scenario where people can be accidentally unsubscribed in the presence of mail forwarding, and the requirement to enter an email address can patch over this.

Upon re-reading the comment, I understand the scenario now. Thanks for clarifying.

Thankfully I don't have people forwarding emails to me outside of work...

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#294

This might be good news, but as it comes from Google and involves email centralisation, I’m sceptical. At MailPace we already enforce DKIM, it’s pretty basic stuff. But list-unsubscribe is optional for our senders. We can make this a requirement and manage lists for senders who don’t / can’t implement a webhook to handle it (we already default to blocking resends to emails that hard bounce). However I am curious how…

> Just because the header is set, it doesn’t mean it’ll do anything

But they can track proxy metrics for this. For example people using GMail's builtin unsubscribe feature more than once with the same unsubscribe link for different emails is a pretty good indicator the unsubscribe did not work.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#295

Earlier quoted context omitted.

i can't be the only oldskool person on hacker news who knows not to click on unsubscribe buttons because it just identifies you as a legitimate email/mark... these are spammers, not cases where you ever actually signed up to some kind of legitimate newsletter or discussion group. to pretend good faith is your first mistake...

I don’t think this is a legitimate concern any more. There’s basically zero value in “confirming” an email address is legitimate. Between all of the data breaches and various other ways to get actual email addresses this isn’t a problem. It’s also so cheap to send email there isn’t an operational cost where you need to optimise for sending only to know addresses. There is definitely a punitive cost for sending emails…

there's a line in the movie the incredibles where robert (the hero) is meeting with the designer (edna) of super suits to design him a new suit even though such activities are technically illegal.

The dialogue goes something like this:

robert: you know I'm retired from hero work.

Edna:As am I, Robert, yet here we are.

so now it's 2023. you're telling me it's now safe to click on unsubscribe to the spam emails.

yet here we are.

no, the strait forward response is to ignore and mark as spam any unsolicited emails you did not explicitly sign up for. don't try to interact through the desired or expected channels of any entity that spams you.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#296
post #185

Earlier quoted context omitted.

Honestly sounds like I'm on the side of Gmail here. Think about this from the perspective of an actual spammer. You get a notification that address XYZ is marked as spam by user ABC. Well, now you just email user ABC from a different address.

Not even spammers want to waste time & money emailing people who have already marked their emails as spam (that's as clear a signal as any to move onto the next victim). The real problem is, for legitimate senders, the people who send less emails actually get higher levels of spam complaints! This is because humans are human and they forget who you are. I would argue this actually incentivizes sending more emails. Th…

Right - spammers (and legit marketers) do not want an old or out of date email lists to work with. Wastes time and reduces the lists ROI.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#297
post #243

Earlier quoted context omitted.

NextDoor is the absolute fucking worst with this. They sign you up to 10+ lists each in over 9+ categories that results in what feels like 100 different "notification types". Unsubscribing from an email just unsubscribes from that one list. They don't show any other lists or categories (or imply there are more) during this process. Once you login you are greeted with a multi-page disaster to manually untoggle each of…

Yes I ran into this the other day when I tried Nextdoor out for the first time. I was actually so in awe of the insane and sociopathic dark pattern that is their email/notification subscription system that I immediately deleted the app. I don’t want to be a user on a platform that treats its users with so little respect.

I did the exact same thing a few days ago. I thought NextDoor would be social media that connects me with my local community. Nope. It’s overwhelmingly “recommend me someone for ”, camera footage of shady people or crime reports, and complaints about neighbors. The excessive emails were the final straw that took me from indifference to actively excising NextDoor from my phone.

So if anyone has ideas for connecting with your local community, I’m still looking…

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#298

Earlier quoted context omitted.

I thought it was part of CAN SPAM that you can’t require a second action and that was why the big email sending providers moved to that.

It's not really common for clicking a link to immediately unsubscribe, almost everyone requires you to click a button after navigating to the unsubscribe link. Otherwise you have issues with link scanners unsubscribing your recipients without their knowledge. There are some more complex ways to approach this with JavaScript checks for "real browser" but IMO these are more likely to create frustrating friction to unsu…

> unsubscribe pages that require you to type your email address in again

These are fine for me if the email is prepopulated.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#299

Earlier quoted context omitted.

i can't be the only oldskool person on hacker news who knows not to click on unsubscribe buttons because it just identifies you as a legitimate email/mark... these are spammers, not cases where you ever actually signed up to some kind of legitimate newsletter or discussion group. to pretend good faith is your first mistake...

That's the case for spam sent by illegitimate parties (actual spammers), but any real company (what OP is referring to) will respect the unsubscribe button because they're at risk of being sued otherwise. Clicking unsubscribe in those cases actually does work & doesn't put you at risk of anything.

I find the venn diagram of spammers and "legitimate" companies increasingly overlaps and it's impossible to cleanly differentiate the two.

my university spams me. i bought a torch from olight. they spam me. i get food deliveries. they spam me. i bought some tech. they spam me. i look for real estate they spam me. i get a delivery. they spam me.

it's differentiating between the two that's unrealistic.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#300
post #7

Oh fun so basically no one will be able to setup their own email servers by themselves anymore. Antispam is killing the open internet now.

Did we read a different article? DKIM is a simple DNS entry. One-click unsubscribe should be standard.

Most people that want to self host their own email server for personal use (e.g. on a VPS on their own domain) don't have the infrastructure for reverse DNS zones, so I'd argue that DMARC and DKIM are kind of pointless because their email lands in spam anyways once the PTR query on the IP fails to resolve to the same domain because 99% of the time it will be something like ipv4.somehosting-company.com
Post reply on HN