Live data from Hacker News

Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

mailgun.com

121–130 of 279 posts

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#121
I hope this also applies to T&C spam - the thing where a company reminds you that they exist once a month by e-mailing you about a minor change to the wording of their terms and conditions, and because it's "important legal information" it overrides your opt-out preferences. If I think someone is taking the piss, I flag these as spam, and if more than 0.3% of the population did this then companies would think twice about this tactic.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#122
post #35

Is there any service that can process DMARC report e-mails? Those mails with zips with indecipherable XMLs inside them are a bit useless. Something that takes the junk, gives a nice human readable dashboard, and informs me if something is wrong, would be nice.

https://URIports.com/dmarc offers services starting at just $1 monthly for up to 3 domains. It's GDPR compliant and includes features like notifications, hosted MTA-STS for protection against Man-in-the-Middle (MiTM) downgrade attacks, and much more.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#123
post #110

Earlier quoted context omitted.

You're talking about Transactional emails? You cant unsubscribe from TRANSACTIONAL emails. That's why they're transactional...not marketing. It's really important to differentiate that.

Maybe transactional emails don't need an unsubscribe link like marketing emails, but they do need a "not my account; please stop" link to avoid the spam button.

Why would you be receiving transactional emails for an account that isn't yours?

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#124
post #87

Earlier quoted context omitted.

the standard approach is that unsubscribing sends an unsubscribe confirmation mail to the subscribed email address, replying to which confirms the unsubscription. nothing about logins or passwords or the web. this has been standard practice for 25–30 years

I have never seen anyone do that and I believe it has been literally illegal in the U.S. for the last 20 years. From https://www.ftc.gov/business-guidance/resources/can-spam-act... : "You can’t [...] make the recipient take any step other than sending a reply email or visiting a single page on an Internet website as a condition for honoring an opt-out request."

this is not 'taking any step other than sending a reply email' and it's the standard way mailing lists managed with mailman or majordomo or ezmlm have worked for quite a bit longer than 20 years

also, according to that page, the can-spam act only applies to 'any electronic mail message the primary purpose of which is the commercial advertisement or promotion of a commercial product or service', not to mailing lists

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#125
post #52

Earlier quoted context omitted.

also it violates longstanding security measures against malicious prank unsubscribes; it means that if you forward an email list message to someone else, they can unsubscribe you without your consent as a prank

I think unsubscription without requiring login should be already mandated by some regulations (CAN-SPAM law and maybe GDPR).

according to https://www.ftc.gov/business-guidance/resources/can-spam-act... the can-spam act only applies to 'any electronic mail message the primary purpose of which is the commercial advertisement or promotion of a commercial product or service' so it's irrelevant to mailing list discussions

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#126
post #107
post #84

Earlier quoted context omitted.

- we're just about to discuss a contentious topic and vote on it. i bet bob and lauren will be opposed to our suggested solution. wouldn't it be nice if they accidentally happened to get unsubscribed for a few days without notice, so they can't rebut our arguments? - adding a new member to the list requires a vote of approval of the existing members. bob apparently unsubscribed last week and now he wants to resubscri…

So in other words, there is no plausible scenario.

if you think these are unrealistic, i've got news for you; the world is a lot bigger than you think it is

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#127
post #70
post #52

Earlier quoted context omitted.

also it violates longstanding security measures against malicious prank unsubscribes; it means that if you forward an email list message to someone else, they can unsubscribe you without your consent as a prank

Forwarding an email should strip this header, probably along with most of the other irrelevant ones potentially containing sensitive information the user isn't aware of. Forwarding an email with GMail only keeps the From, To, Date and Subject headers.

i feel like if we're talking about a header the user isn't aware of, most users probably won't be able to use it to unsubscribe either

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#128
post #68

How does this interact with transactional emails / 2FA / password resets? If 5000 people request a 2fa code in a month, I have to give them a unsubscribe header as well? Or magic login links? If I don't provide a list-unsubscribe header: do these emails then get blocked and noone can log in ? If I provide a list-unsubscribe header, what is the expected behaviour if they do click the Unsubscribe button? - tell them th…

Its 5000/day for marketing, and if you are sending 5000 emails a day, you probably should have unsubscribe links. https://support.google.com/mail/answer/81126#requirements-5k You also need a link, not just list-unsubscribe, and it is specifically for marketing emails. In my experience, Google is pretty accurate in figuring out transactional versus marketing. They don't tell their heuristics, but you don't think engin…

Google routinely flags my genuine AWS invoices as possibly dangerous, despite me routinely clicking the "this isn't dangerous, I know what it is" button. So yes, I think it's totally possible that engineers who build web crawlers can't build reliable email classifiers.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#130
post #87

Earlier quoted context omitted.

Requiring the user to login to unsubscribe also has the nice effect of requiring them to know the password, otherwise they have to go through the reset procedure. Of course you need to be really secure and do 2FA as well. Hey, if this reduces the number of people who successfully unsubscribe, don't blame me, I'm just over here trying to make sure things are secure!

the standard approach is that unsubscribing sends an unsubscribe confirmation mail to the subscribed email address, replying to which confirms the unsubscription. nothing about logins or passwords or the web. this has been standard practice for 25–30 years

You keep talking about a particular style as though it is standard practice that's essential for security, even though it is both unusual and now illegal in many parts of the world.

I have not seen such an unsubscribe flow in more than a decade, at this point. I assume you're thinking of mailman or some other similar solution that was already dated two decades ago, let alone now.

Post reply on HN