Live data from Hacker News

Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

mailgun.com

111–120 of 279 posts

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#111
post #110

Earlier quoted context omitted.

You're talking about Transactional emails? You cant unsubscribe from TRANSACTIONAL emails. That's why they're transactional...not marketing. It's really important to differentiate that.

Maybe transactional emails don't need an unsubscribe link like marketing emails, but they do need a "not my account; please stop" link to avoid the spam button.

Lack of opt-in into those will have me keep marking those as spam. Just like those US political newsletters that also don’t feel like they need to verify mails.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#112
I get plenty of spam through Gmail, and there is no easy way to report it, it also doesn't seem like they are the least bit interested in tackling the problem.

I wish they took a closer look at themselves and also applied these kinds of rules to themselves.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#113
post #68

How does this interact with transactional emails / 2FA / password resets? If 5000 people request a 2fa code in a month, I have to give them a unsubscribe header as well? Or magic login links? If I don't provide a list-unsubscribe header: do these emails then get blocked and noone can log in ? If I provide a list-unsubscribe header, what is the expected behaviour if they do click the Unsubscribe button? - tell them th…

Its 5000/day for marketing, and if you are sending 5000 emails a day, you probably should have unsubscribe links. https://support.google.com/mail/answer/81126#requirements-5k You also need a link, not just list-unsubscribe, and it is specifically for marketing emails. In my experience, Google is pretty accurate in figuring out transactional versus marketing. They don't tell their heuristics, but you don't think engin…

> Google is pretty accurate in figuring out transactional versus marketing. They don't tell their heuristics, but you don't think engineers who build web crawlers cannot build email classifiers?

Yes, I definitely think that. The engineers can build anything, but where the company focuses matters.

I've seen transactional E-mails get sorted into people's spam/junk/newsletter folders too many times.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#114

Earlier quoted context omitted.

> If you’re sending transactional emails like password resets or MFA, then the emails will have close to a 100% open rate. So I can disable a competitor’s email functionality by triggering a whole bunch of password reset requests for all discoverable usernames?

That could potentially cause them problems, yeah, if you were able to do that endlessly. In practice most companies will have some kind of rate limiting in place around features like that (by IP, cookie, captcha, etc.)

IP and cookie-based rate-limiting are trivially bypassed. In fact, any kind of rate-limiting is ineffective here, especially for smaller organisations, because you only need to generate a small fraction of the traffic they normally send out. If they separate transactional mail from other types of mail (something that is frequently recommended), then how many illegitimate password reset emails do you think an attacker needs to trigger to get to, say, a 5% failure rate? Smaller organisations don’t send out an awful lot of transactional email.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#115
post #112

I get plenty of spam through Gmail, and there is no easy way to report it, it also doesn't seem like they are the least bit interested in tackling the problem. I wish they took a closer look at themselves and also applied these kinds of rules to themselves.

>there is no easy way to report it

If you mean coming to Gmail, three-dots > report spam.

If you mean coming from Gmail, https://support.google.com/mail/contact/abuse?hl=en.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#116
post #68

How does this interact with transactional emails / 2FA / password resets? If 5000 people request a 2fa code in a month, I have to give them a unsubscribe header as well? Or magic login links? If I don't provide a list-unsubscribe header: do these emails then get blocked and noone can log in ? If I provide a list-unsubscribe header, what is the expected behaviour if they do click the Unsubscribe button? - tell them th…

Its 5000/day for marketing, and if you are sending 5000 emails a day, you probably should have unsubscribe links. https://support.google.com/mail/answer/81126#requirements-5k You also need a link, not just list-unsubscribe, and it is specifically for marketing emails. In my experience, Google is pretty accurate in figuring out transactional versus marketing. They don't tell their heuristics, but you don't think engin…

Invoices are in my spam folder regularly. You'd think emails I open consistently month after month, which are followed by receipts would make it through.

Search isn't doing that well either.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#117
post #35

Is there any service that can process DMARC report e-mails? Those mails with zips with indecipherable XMLs inside them are a bit useless. Something that takes the junk, gives a nice human readable dashboard, and informs me if something is wrong, would be nice.

I tried EasyDMARC in the past [1], it's easy to use but the free plan is very limited and the cheapest plan is a bit too pricey for me.

[1] https://easydmarc.com/

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#118
post #87

Earlier quoted context omitted.

Requiring the user to login to unsubscribe also has the nice effect of requiring them to know the password, otherwise they have to go through the reset procedure. Of course you need to be really secure and do 2FA as well. Hey, if this reduces the number of people who successfully unsubscribe, don't blame me, I'm just over here trying to make sure things are secure!

the standard approach is that unsubscribing sends an unsubscribe confirmation mail to the subscribed email address, replying to which confirms the unsubscription. nothing about logins or passwords or the web. this has been standard practice for 25–30 years

I have never seen anyone do that and I believe it has been literally illegal in the U.S. for the last 20 years. From https://www.ftc.gov/business-guidance/resources/can-spam-act...:

"You can’t [...] make the recipient take any step other than sending a reply email or visiting a single page on an Internet website as a condition for honoring an opt-out request."

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#119
post #112

I get plenty of spam through Gmail, and there is no easy way to report it, it also doesn't seem like they are the least bit interested in tackling the problem. I wish they took a closer look at themselves and also applied these kinds of rules to themselves.

>there is no easy way to report it If you mean coming to Gmail, three-dots > report spam. If you mean coming from Gmail, https://support.google.com/mail/contact/abuse?hl=en .

I thought this button isn’t hooked up to anything

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#120
post #100

Earlier quoted context omitted.

If unsubscribing requires even two clicks I always flag it as spam. The rule is one-click to unsubscribe and I ruthlessly enforce it. Make it their problem.

I tried that once with Nextdoor. They will group their mailings into different lists. The unsubscribe button only removes you from that list. To disable them all is 30+ clicks on the site once logged in. It's horrible.

For this kind, my 'unsubscribe' button is labelled 'report spam'
Post reply on HN