Live data from Hacker News

Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

blog.google

341–350 of 420 posts

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#341

> Gmail’s AI-powered defenses stop more than 99.9% of spam, phishing and malware from reaching inboxes And what percentage of legitimate mail? > and that they process unsubscription requests within two days This is a laughably lax requirement. Also for fucks sake, stop auto-localizing your documentation based on IP geolocation.

Probably half of legit mail from self-hosted servers... Anyone using them at all?

YMMV but Gmail hasn't been that bad for me. The only problem I (knowingly) had was with a newly registered domain and mails still at least went to the spam folder there. Microsoft has been much more annoying, punishing you for bad IP "neighbors" that you have no relation with. Of course I don't know if all my mails get delivered since I don't do any tracking, just relying of voluntary in-band or out of band replies / receipt confirmations. And being based on black box heuristics (and "AI" lol) there is no guarantee that my experience with Gmails spam filters is the norm - but Gmail rejecting half of self-hosted mail seems a very pessimistic estimate.

Still, just citing numbers for how much spam they blocked is (deliberately?) only showing half of the picture.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#342

Earlier quoted context omitted.

Why confirm via mail at all?

maybe to confirm that the email is valid?

Correct! With schools and students there is always incentive for shenanigans. If I didn't test for emails they could just book-block all teachers.

There would be other ways to clog the system using trashmail providers but thankfully no student cared enough for that yet

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#343
post #245

Earlier quoted context omitted.

IIRC, CAN-SPAM explicitly says the unsubscribe button needs to be available without logging in. So this would be a violation.

So, who do you contact about that violation?

Here you go: https://www.justice.gov/action-center/report-spam

You can probably guess how effective that is. In practice, unless you can get the FTC or a state attorney general to sue an actual company for you, nothing will ever come of it.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#344
None of that seems new. What would be new is if both gmail and Yahoo provided any means of allowing legit bulk senders to actually send properly.

The one-click unsubscribe is from 2017's RFC8058. Everyone that's sending in volume is already doing all the usual stuff - DKIM, SPF, DMARC, matching reverse IPs, etc.

The privacy-first email marketing service I wrote (https://info.smartmessages.net) implements account-wide unsubscribe by default (unsubscribing you from one list unsubscribes you from all). It requires double opt-in, and asks for explicit consent before doing any tracking whatsoever (so no Google Analytics, no cookies, no trackers), which of course is what the (at least EU and UK) law requires. You're not going to see shitty exploiters like MailChimp doing anything like this; abusing your data is just too lucrative.

It's still ridiculously hard to deliver messages at any volume, and there is zero recourse when you are penalised incorrectly. Gmail's spam filtering is just dire - if I send myself an email from gmail, it goes into spam. A large proportion of the spam I receive is sent from gmail.

Google's postmaster tools are a joke. It's entirely normal for them to give you a "bad" spam rating when you have 0 spam reports, 0 auth failures, strict DKIM and DMARC, and every single message has double-opt-in audit trails. This useless feedback makes it very difficult for senders to actually comply with their ever stricter, but ever more opaque requirements.

Proving that subscribers actually want to receive messages from you its difficult. So back in 2017 I wrote an outline proposal https://github.com/Smartmessages/subscriptionproofrfc to create a standard, possibly built on top of DKIM keys, to provide provable subscriptions. This would pretty much solve the entire thing for legit senders, but of course the industry is not really interested in cooperation or complying with any law that might reduce the number of people they send to by even the tiniest amount.

/cynicalrant

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#345
post #322

Earlier quoted context omitted.

Just a perspective from the other side of the coin: I host various services for schools like online registration for parent - teacher conferences. When the platform is live hundreds of parents are logging in, choosing their appointments and have to confirm them via email (only one email per person not per appointment) And Yahoo is the Single worst email service to send to. I have correctly configured sfp, dmarc, dkim…

I seriously don't get why we can't have some sort of licensing authority for this type of thing. Maybe they issue you a secret key to include in email headers, or put your entire domain on some sort of whitelist. And complaints get handled by a human to confirm that it's not a "oh I don't like this, or I don't remember signing up for this" non-sense complaint that would get you blocked or have your license revoked wi…

> I don't remember signing up for this

This is often not a non-sense complaint. A lot of newsletter signups are still via pre-selected checkboxes that are easy to miss.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#346

> we’ll enforce a clear spam rate threshold that senders must stay under I hope they make it really strict. I'm sick of companies that send you spam ("newsletters") just because you interacted with them once, then when you unsubscribe, you get unsubscribed from that one list, so they keep spamming you just with a slightly different newsletter type. (Edit: Also, everything requiring a notification - by e-mail if they…

> I hope they make it really strict. The threshold is "spam rates reported in Postmaster Tools below 0.3%". That sounds pretty low to me, but I'm not in the bulk email business. I guess maybe a very small number of users actually report spam? Or maybe Google is being strict. Source: https://support.google.com/mail/answer/81126#zippy=%2Crequir ... (I work for Google, but on something totally unrelated, and don't speak…

One of the key problems is that both gmail and Yahoo UIs actively encourage users to report messages as spam rather than unsubscribing. Yahoo is particularly bad at this; it's common for me to receive spam reports from yahoo on an entirely double-opt-in social site I run. My reaction there is to remove the reporter from all lists because the amount of damage a single spam report can do is immense; a single spam report can block delivery for weeks at a time to the 10k others that legitimately requested messages. Hotmail/outlook/live is much the same in encouraging spam reporting over unsubscribe, however, their penalties are not as excessive as Yahoo's.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#347

> we’ll enforce a clear spam rate threshold that senders must stay under I hope they make it really strict. I'm sick of companies that send you spam ("newsletters") just because you interacted with them once, then when you unsubscribe, you get unsubscribed from that one list, so they keep spamming you just with a slightly different newsletter type. (Edit: Also, everything requiring a notification - by e-mail if they…

> I hope they make it really strict. I hope they not. Gmail spam filter is far from being perfect and classifies many non spam messages/senders as spam. May be because they heavily rely on user reports (to train AI?) and email users tend to report all kind of emails as spam including clearly ham messages like bank statements, appointment notifications, password reset emails e.t.c.

Even gmail's own marketing messages (that I never asked for!) end up in my spam folder. If google can't even reliably send emails to themselves I don't know how they expect anyone else to succeed.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#348

Hijacking the thread: I do some "bulk" sending for a 501(c)3 I volunteer for. I include unsubscribe links that go to a form with a submit button (because I want the unsubscribe to be a POST request). Each link has a random opaque identifier in the query string. Something like: hxxp://example.com/unsubscribe?id=abcd1234 A couple years ago I noticed that MSFT IPs hitting my unsubscribe links with invalid identifiers on…

This is exactly what the list-unsubscribe-post header from RFC8058 provides: https://www.rfc-editor.org/rfc/rfc8058. The unsubscribe button that gmail, Apple Mail and others displays is driven by that; it's not a gmail feature.

Weirdly, if google thinks you're a dodgy sender they won't display the button, which seems counterproductive to me.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#349

Earlier quoted context omitted.

There's worse. An unsubscribe link that asks you to submit your email. Few things anger me more, because they went through the trouble of pretending to comply, and a decision was made to make my day more difficult.

Also needing to log in before you can unsubscribe.

Or needing to enable javascript to unsubscribe.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#350
I couldn't figure out from the announcement whether these controls are to be applied to people sending bulk to gmail addresses, or from them.

Nearly all the spam I see is from a gmail address. I suspect this new measure is to protect gmail recipients.

Post reply on HN