Live data from Hacker News

Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

mailgun.com

151–160 of 279 posts

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#151

DKIM, SPF, and DMARC are old hat and implemented by anyone serious for years. What's buried in this article is the required https://datatracker.ietf.org/doc/html/rfc8058 support for one-click unsubscribe posts. I don't see many messages in my inbox yet with that.

> required support for one-click unsubscribe posts

The article gets it wrong. They imply that emails have to have one-click unsubscribe links, which isn't true. Emails need to include headers (described in your link,) which the mail client can use.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#152
post #87

Earlier quoted context omitted.

Requiring the user to login to unsubscribe also has the nice effect of requiring them to know the password, otherwise they have to go through the reset procedure. Of course you need to be really secure and do 2FA as well. Hey, if this reduces the number of people who successfully unsubscribe, don't blame me, I'm just over here trying to make sure things are secure!

the standard approach is that unsubscribing sends an unsubscribe confirmation mail to the subscribed email address, replying to which confirms the unsubscription. nothing about logins or passwords or the web. this has been standard practice for 25–30 years

That’s gonna catch a report spam from me dawg

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#153
I can't wait for this to take effect.

It seems that every time I buy something or someone gets ahold of my email address, I get added to a SPAM list.

I can't wait for all of these to be blocked.

For example: I recently elected a benefit, and the company added me to a SPAM list for weekly deals 100% unrelated to the benefit. They even ignored the fact that I unsubscribed.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#154
post #100

Earlier quoted context omitted.

If unsubscribing requires even two clicks I always flag it as spam. The rule is one-click to unsubscribe and I ruthlessly enforce it. Make it their problem.

I tried that once with Nextdoor. They will group their mailings into different lists. The unsubscribe button only removes you from that list. To disable them all is 30+ clicks on the site once logged in. It's horrible.

I just went through this with Nextdoor in October. Well, I personally didn't do all 50 clicks, but I asked their customer service to do it and they confirmed I was unsubscribed.

Of course, I got a new message from them yesterday because they've added a dozen different lists since then and automatically opted everyone into them.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#155
post #82

DKIM, SPF, and DMARC are old hat and implemented by anyone serious for years. What's buried in this article is the required https://datatracker.ietf.org/doc/html/rfc8058 support for one-click unsubscribe posts. I don't see many messages in my inbox yet with that.

I've seen a perverse dark pattern on one click unsubscribe. The page you land at has a button that lets you resubscribe! It looks non-obvious you've already unsubscribed and it looks like the regular two-click flow needing to enter your email address to confirm. Very sneaky.

Worse, the unsubscribe link is behind a tracker url so pi-hole blocks it. Drives me nuts.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#156

For those interested in testing their email for SPF, DKIM, and DMARC compliance or eager to learn about these mechanisms that enhance email security and prevent spoofing, check out https://learnDMARC.com . This is a site I developed to promote adoption and share knowledge. It includes a challenging quiz, tough even for professionals. I'd be keen to know your scores on the first attempt – honesty counts!

Amazing site!

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#157
Slightly off-topic: it seems that Outlook has given up fighting spam and isn't even in such conversations. I have a decades-old hotmail.com email address that is getting spams daily in the inbox, while a similarly old gmail.com almost always filters them out. Well, Gmail occasionally flags false positives but never false negatives. This is getting so bad that I have completely moved off that hotmail.com address.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#158

DKIM, SPF, and DMARC are old hat and implemented by anyone serious for years. What's buried in this article is the required https://datatracker.ietf.org/doc/html/rfc8058 support for one-click unsubscribe posts. I don't see many messages in my inbox yet with that.

Unsubscribe links make me nervous. Such an obvious attack vector.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#159
post #68

How does this interact with transactional emails / 2FA / password resets? If 5000 people request a 2fa code in a month, I have to give them a unsubscribe header as well? Or magic login links? If I don't provide a list-unsubscribe header: do these emails then get blocked and noone can log in ? If I provide a list-unsubscribe header, what is the expected behaviour if they do click the Unsubscribe button? - tell them th…

Its 5000/day for marketing, and if you are sending 5000 emails a day, you probably should have unsubscribe links. https://support.google.com/mail/answer/81126#requirements-5k You also need a link, not just list-unsubscribe, and it is specifically for marketing emails. In my experience, Google is pretty accurate in figuring out transactional versus marketing. They don't tell their heuristics, but you don't think engin…

You could have put Google in early ‘00s on this pedestal. But the Google today is not worthy of this.

G is like any other Fortune 500 company now. The amount of products in their graveyard grows every year. Maintenance of “legacy” apps is handed off to offshore teams who have objectives to just keep it running until it’s 86’d.

Google has also made plenty of mistakes with web: look at PWAs, AMP, and Chrome just to start.

Post reply on HN