Live data from Hacker News

Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

blog.google

311–320 of 420 posts

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#311

Earlier quoted context omitted.

This is exactly why GDPR exists. What you are describing is illegal in the EU. Sending marketing communication requires clear opt in consent.

I just had this experience today. The problem is that at least in the States the regulation is ambiguous enough to be abused to hell and back. Unsubscribe in the States could mean “Unsubscribe from all” or “Unsubscribe from 1 of 20” or it could mean “unsubscribe from all now, but we will arbitrarily resign you up for some new newsletter whenever we feel like it”. I got a spam email today from some no name dropshipper…

> unsubscribe from all now, but we will arbitrarily resign you up for some new newsletter whenever we feel like it

The LinkedIn way.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#312
post #245

Earlier quoted context omitted.

Also needing to log in before you can unsubscribe.

IIRC, CAN-SPAM explicitly says the unsubscribe button needs to be available without logging in. So this would be a violation.

So, who do you contact about that violation?

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#313

Reading all the comments makes me think I'm an outlier. I very aggressively unsubscribe from everything so I get very little mailing list spam. Maybe a few messages a month. What I do get _constantly_ is spam email messages to my inbox from Gmail and Outlook domains. At least one a day for many years. Because it from Gmail, they have very little spam filtering done, yet if any other provider sent these messages then…

...yet if any other provider sent these messages then Google would block the entire domain.

I doubt Google would do that to other big companies.

Some accept user-provided email addresses at face value, without any confirmation, and then refuse to stop spamming you.

Would Google block Paypal?

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#314

Earlier quoted context omitted.

If someone gets forwarded the email and they take action based on another person, or erroneously get unsubscribed by an email scanning tool, those are no-no events according to our lawyers. Keep in mind our webforms you can put whatever email you want in them. But something to do with the fact that we are knowingly storing the information and it crosses to another system.

That shouldn't stop you from including such a link in the header and keep the non-oneclick link in the footer. Nowadays, emails are forwarded embedded, not as EML attachments, so the header link wouldn't be included. You have to jump through hoops to forward as EML.

Yes, that's what we do. We have the one-click through the client at the top, and the link at the bottom takes you to a more robust "preference center" that combines preferences from multiple systems (marketing, sales, product, etc).

That doesn't stop people from sending in a spate of complaint emails every single day. But this is kind of the local minimum we have found and no one really wants to mess with it at this point.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#315

Earlier quoted context omitted.

That's the case for spam sent by illegitimate parties (actual spammers), but any real company (what OP is referring to) will respect the unsubscribe button because they're at risk of being sued otherwise. Clicking unsubscribe in those cases actually does work & doesn't put you at risk of anything.

I get spam from legitimate companies who don't honor the unsubscribe links. The problem is that many of them use third-party services to handle the unsubscription server so you're feeding the data broker ecosystem with confirmation that you're an active address.

This is an irrational reason. When you click “mark as spam” the sender can configure the email so your email provider notifies them that you marked it as spam. (See email feedback loop).

https://en.m.wikipedia.org/wiki/Feedback_loop_(email)

Further, pixels can be embedded in the email so they can see when you open the email and how many times.

The sender has every incentive to properly handle unsubscribe to avoid spam traps. If you get big enough, users WILL come sign up for your service with a known spam trap email. If your operations are as sloppy as you’re suggesting, your email sending capabilities go poof.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#316
post #313

Reading all the comments makes me think I'm an outlier. I very aggressively unsubscribe from everything so I get very little mailing list spam. Maybe a few messages a month. What I do get _constantly_ is spam email messages to my inbox from Gmail and Outlook domains. At least one a day for many years. Because it from Gmail, they have very little spam filtering done, yet if any other provider sent these messages then…

...yet if any other provider sent these messages then Google would block the entire domain. I doubt Google would do that to other big companies. Some accept user-provided email addresses at face value, without any confirmation, and then refuse to stop spamming you. Would Google block Paypal?

[deleted]

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#317

Earlier quoted context omitted.

Why is list-unsubscribe is optional for your senders?

It's transactional email - so generally speaking it's not a subscription list that recipients are on per se. This is in line with the CAN SPAM guidance (although that is a US law it's good guidance to follow globally). Also it requires senders to actually implement it, which is not possible to confirm. Although we could add a catch all service that does this automatically, which I think we'll do.

This is the definition of spam. Unsolicited email with no way to revoke consent. Your user’s recipients should be able to revoke consent whenever they feel like it. If they can’t reply to the email, or unsubscribe, and the only choice to revoke consent is to mark an email as spam … you are sending spam.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#318

> we’ll enforce a clear spam rate threshold that senders must stay under I hope they make it really strict. I'm sick of companies that send you spam ("newsletters") just because you interacted with them once, then when you unsubscribe, you get unsubscribed from that one list, so they keep spamming you just with a slightly different newsletter type. (Edit: Also, everything requiring a notification - by e-mail if they…

> I hope they make it really strict.

I hope they not. Gmail spam filter is far from being perfect and classifies many non spam messages/senders as spam. May be because they heavily rely on user reports (to train AI?) and email users tend to report all kind of emails as spam including clearly ham messages like bank statements, appointment notifications, password reset emails e.t.c.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#319

> we’ll enforce a clear spam rate threshold that senders must stay under I hope they make it really strict. I'm sick of companies that send you spam ("newsletters") just because you interacted with them once, then when you unsubscribe, you get unsubscribed from that one list, so they keep spamming you just with a slightly different newsletter type. (Edit: Also, everything requiring a notification - by e-mail if they…

Just a perspective from the other side of the coin: I host various services for schools like online registration for parent - teacher conferences. When the platform is live hundreds of parents are logging in, choosing their appointments and have to confirm them via email (only one email per person not per appointment) And Yahoo is the Single worst email service to send to. I have correctly configured sfp, dmarc, dkim…

Why confirm via mail at all?

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#320

Reading all the comments makes me think I'm an outlier. I very aggressively unsubscribe from everything so I get very little mailing list spam. Maybe a few messages a month. What I do get _constantly_ is spam email messages to my inbox from Gmail and Outlook domains. At least one a day for many years. Because it from Gmail, they have very little spam filtering done, yet if any other provider sent these messages then…

It is my experience too - about 50% of spam I see on my personal email are dmarc passing messages from gmail and hotmail.
Post reply on HN