Live data from Hacker News

Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

blog.google

401–410 of 420 posts

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#401

Earlier quoted context omitted.

there's a line in the movie the incredibles where robert (the hero) is meeting with the designer (edna) of super suits to design him a new suit even though such activities are technically illegal. The dialogue goes something like this: robert: you know I'm retired from hero work. Edna:As am I, Robert, yet here we are. so now it's 2023. you're telling me it's now safe to click on unsubscribe to the spam emails. yet he…

When you mark an email as spam, the mailing service emails the sender along with all the original headers. See https://en.m.wikipedia.org/wiki/Feedback_loop_(email) Your reasons are not actually rational.

surely this depends on the actual mail provider you use.

i appreciate its impossible to prove a negative (everyone could be doing something they have no evidence or documentation of doing), but given my mail provider both says that you have to mark a selection before they'll share such information with partners and that marking emails as spam still trains your own user specific spam filter, i don't think (and an really hoping) this is not a universal thing.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#402

Earlier quoted context omitted.

When you mark an email as spam, the mailing service emails the sender along with all the original headers. See https://en.m.wikipedia.org/wiki/Feedback_loop_(email) Your reasons are not actually rational.

surely this depends on the actual mail provider you use. i appreciate its impossible to prove a negative (everyone could be doing something they have no evidence or documentation of doing), but given my mail provider both says that you have to mark a selection before they'll share such information with partners and that marking emails as spam still trains your own user specific spam filter, i don't think (and an real…

It’s universal as far as I know.

I worked on an email system that sent billions of emails a month. We used these messages from providers to ensure we never sent them an email again to prevent hurting our reputation. (Marking an email as spam, is by itself, a very low signal on reputation, unless some massive % of recipients mark it as spam. Sending an email to someone who has already indicated you are sending them spam is a high signal that you’re sending spam, however).

It doesn’t even matter when you do it. We had people (outliers) who would go back and hit every single email we sent them for the last 6 years as spam, after a bad customer service interaction, not getting a refund, or whatever pissed them off. We actually investigated all outliers. Most people didn’t report spam on anything older than 6 months.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#403

> we’ll enforce a clear spam rate threshold that senders must stay under I hope they make it really strict. I'm sick of companies that send you spam ("newsletters") just because you interacted with them once, then when you unsubscribe, you get unsubscribed from that one list, so they keep spamming you just with a slightly different newsletter type. (Edit: Also, everything requiring a notification - by e-mail if they…

> I hope they make it really strict. I'm sick of companies that send you spam ("newsletters") just because you interacted with them once, then when you unsubscribe, you get unsubscribed from that one list, so they keep spamming you just with a slightly different newsletter type. Never interact with spam. Unsubscribing just tells spammers that your email address is actively being checked, and that you're the kind of p…

Interacted with the company, as in filed a support request, bought something from them, etc.

They already have my e-mail address, likely even verified. They're also somewhat normal companies, i.e. they have an address where the local DPA can send a friendly reminder, and while they will happily pass your (likely hashed) e-mail address to Facebook for ad targeting, actual selling to spammers is incredibly rare.

I often can't just filter the domain because I might actually need to deal with the company again (if I boycotted everyone who acts like a dick I'd be living in a cave).

Also, for many, unsubscribe actually works.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#404

Earlier quoted context omitted.

> I hope they make it really strict. The threshold is "spam rates reported in Postmaster Tools below 0.3%". That sounds pretty low to me, but I'm not in the bulk email business. I guess maybe a very small number of users actually report spam? Or maybe Google is being strict. Source: https://support.google.com/mail/answer/81126#zippy=%2Crequir ... (I work for Google, but on something totally unrelated, and don't speak…

One of the key problems is that both gmail and Yahoo UIs actively encourage users to report messages as spam rather than unsubscribing. Yahoo is particularly bad at this; it's common for me to receive spam reports from yahoo on an entirely double-opt-in social site I run. My reaction there is to remove the reporter from all lists because the amount of damage a single spam report can do is immense; a single spam repor…

> My reaction there is to remove the reporter from all lists because the amount of damage a single spam report can do is immense

Sounds like it's working as intended.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#405

Earlier quoted context omitted.

One of the key problems is that both gmail and Yahoo UIs actively encourage users to report messages as spam rather than unsubscribing. Yahoo is particularly bad at this; it's common for me to receive spam reports from yahoo on an entirely double-opt-in social site I run. My reaction there is to remove the reporter from all lists because the amount of damage a single spam report can do is immense; a single spam repor…

> One of the key problems is that both gmail and Yahoo UIs actively encourage users to report messages as spam rather than unsubscribing. I think this is, generally, the correct approach. There isn't really a salient reason to discriminate between "email I don't want from someone I don't know" ("true spam", if you will), and "email I don't want from someone I do know" (aggressive newsletter campaigns et al). Spam is…

There is one case where differentiating makes sense: Sometimes users sign up for newsletters, want the newsletters, would re-confirm if asked... and later change their mind and no longer want those newsletters. Here, marking as spam is unreasonable.

In most other cases (e.g. newsletters sent based on a tiny pre-checked checkbox or without asking for consent), the spam button is of course the right tool.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#406

Earlier quoted context omitted.

I think that's pretty standard for everybody who runs its own mail server (like "shared webhosting"-running even). Owning your mail should also be standard for everybody in tech, you don't want to rely on Google for something that important.

I mean, electricity is also very important, but that doesn't imply that everybody in tech should be configuring their own wiring. It's fine to do that if you want to, but it is completely reasonable to expect that most people should be able to rely on someone else to do the work of ensuring that the key infrastructure runs well, and not think about it so that they can focus on the specialization they want to handle.

We're not talking about running bare metal in your garage but paying Hetzner or alike 2,50 Euro/month so you're independent from the shenanigans of the automated, AI-"improved" systems of Google. That's a fair price to pay if you value your electronic communication abilites.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#407
post #205

Earlier quoted context omitted.

Phone number is draconian.

Google doesn't require a phone number if your ip / whatever they are doing to profile you has good reputation

Not that it’s really all that draconian anyway. Tying an address to some other piece of verifiable information is valuable when they probably have to respond to abuse complaints for thousands of gmail addresses every week.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#408
post #252

Earlier quoted context omitted.

I think some crawlers run JS, because a lot of the web simply won't work without JS to initialise the page state these days. You can use captcha or similar, one workaround I've seen has a submit that is hidden so never clicked by real people then a visible submit that sets a hidden input and clicks the other one which requires the hidden input... not foolproof but avoids some accidents.

A crawler that follows links found in emails and sends POST requests / submits forms will cause so much havoc. It could buy things, validate account sign-ups, delete data, etc. I have a hard time believing the answer isn't to ask users to switch to a normal email provider.

I know web search at least runs JS to get better results. Not sure about email pre-fetch but I assume they do. I don't think crawlers click buttons though unless they are malicious so it's probably fine for unique email links.

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#409
post #273

Earlier quoted context omitted.

Not everyone uses Gmail or a modern email client that understands the one-click List-Unsubscribe protocol, so senders must include an HTML unsubscribe link in the body of the email in order to comply with relevant rules in all jurisdictions. That link, unfortunately, can fall prey to the shenanigans I mentioned above. I understand the parent's sentiment because we all want to unsubscribe from unwanted emails. But tec…

> The latter need not be one-click, and in fact, if it's anything remotely important, should not be. It absolutely should be one-click.

Since when are GET requests with side effects a good thing?

Re: Gmail, Yahoo announce new 2024 authentication requirements for bulk senders

#410
post #237

Earlier quoted context omitted.

There's worse. An unsubscribe link that asks you to submit your email. Few things anger me more, because they went through the trouble of pretending to comply, and a decision was made to make my day more difficult.

That exists for a reason, and it's not nefarious at all. Lot of people, especially of the older generation, forward all sorts of emails to their friends and family every day. If one person who received a forwarded email doesn't like it and clicks the unsubscribe link, the original recipient (who clearly likes the email enough to forward it around) gets unsubscribed. That's a bug. If you don't like the unfunny newslet…

Email senders are trying to solve a problem no one asked them to solve. Me unsubscribing from emails from my grandma is her problem and eventually someone should/will help her find another way to share. Let's not pretend that email senders care about my grandma.

Email providers autoclicking on links, is the recipient's problem. This is the same flow used for account verification links and yet you do not see them adding an additional step to it.

And then we have the large number of users complaining about this, and yet they feel they simply know better and reserve the right to impose themselves on us?

This decision is purely self serving, let's not pretend otherwise.

Post reply on HN