Live data from Hacker News

Cloudflare Email Service

blog.cloudflare.com

171–180 of 217 posts

Re: Cloudflare Email Service

#171

Earlier quoted context omitted.

Blog author chiming in here: We have reserved IPs for Email Service and will be protecting the reputation and fighting spam from originating on Email Service. If we did not do so, our IPs would get flagged and then emails end up in spam or not delivered. That defeats the purpose of having a transactional Email Service. We're well aware of this.

Agent-produced emails are by definition spam. Everyone should be reacting to this news by immediately blocking your service.

Recent outreach after creating an AgentMail account:

"Thanks for being a user of AgentMail - a lot of people use AgentMail for outbound (spin up and warm up inboxes, send sequences, handle replies), ..."

Yes, that's right. The first use case mentioned is to send automated outbound emails. "Cold prospecting" workflows are likely going to be a big slice of usage on the new Cloudflare service, as it seems to be on AgentMail.

Re: Cloudflare Email Service

#172

Earlier quoted context omitted.

> problem is that the Spanish government doesn't want to bother doing things the lawful way because that takes too long In Spain, what they are doing, is the "lawful way", it's literally happening via the courts and judges. Do you think ISPs are blocking Cloudflare specifically just for fun, out of their own accord? > Actual illegal sports streams are not impacted by Cloudflare being down, and Cloudflare is not the o…

The specific blocks don't go through courts and judges.

Yes, the specific block of blocking Cloudflare in Spain during La Liga matches literally has gone through a court and been ordered by a judge, I'm not sure how you could have missed this. Judges have also dismissed the requests from Cloudflare and others to remove the "dynamic block" as there is collateral damage.

Re: Cloudflare Email Service

#175
post #132

Earlier quoted context omitted.

What structural changes could we make to improve the situation?

It's simple, there's a standard, a new one, which takes into account SPF, DKIM, DMARC, ARC, and even DANE along with upcoming and purposed SPKF, DKIM+, DMARC2, and ARCv4. It should fix just about everything.

Obligatory https://xkcd.com/927/

Re: Cloudflare Email Service

#176
post #107

Earlier quoted context omitted.

I run an email sending service at scale (billions of messages per month, tens of millions of end users, thousands of customers). Most of our software development and operational effort revolves around abuse mitigation. That has been the case for 15 years. It's a cat-and-mouse game with two different mice: the senders, who are constantly trying to figure out how to get you to deliver their garbage; and the receivers,…

Right, I won't disagree with any of that, but I'm not sure how it's related to what I wrote either. Maybe I should have been more specific that I'm talking about hosting your own email, not hosting emails for others, which brings out a lot of other types of problems.

Apologies. When you said "email services" I thought you were implying "email services for use by others". Yeah, you can definitely run your own mail server in 2026 and I think the internet community should always strongly endorse being able to do so. Unfortunately, large email receivers have to make do with imperfect signals when making filtering decisions, and your traffic from a lonely IP that happens to have a bad neighbour might get blocked as collateral damage.

One long term hope: That domain name reputation eventually overtakes IP address reputation entirely.

Re: Cloudflare Email Service

#177

Earlier quoted context omitted.

The specific blocks don't go through courts and judges.

Yes, the specific block of blocking Cloudflare in Spain during La Liga matches literally has gone through a court and been ordered by a judge, I'm not sure how you could have missed this. Judges have also dismissed the requests from Cloudflare and others to remove the "dynamic block" as there is collateral damage.

My understanding was that cloudflare was being blocked by the same IP blocking list as everything else. And while that system went through courts, the list didn't.

There are also direct actions against cloudflare, but that's not what's taking everything down, is it?

Did I misunderstand something?

Re: Cloudflare Email Service

#178
Pushing agent workflows over email has some risks not present for HTTP. Transit security is still a problem for email as we're stuck in the opportunistic encryption stage. If you decide to use email-based agents, look into MTA-STS as a way to prevent downgrade attacks. It looks like Cloudflare supports this, but it isn't enabled by default or called out in the on-boarding process.

https://developers.cloudflare.com/email-routing/setup/mta-st...

Re: Cloudflare Email Service

#179

Earlier quoted context omitted.

Yes, the specific block of blocking Cloudflare in Spain during La Liga matches literally has gone through a court and been ordered by a judge, I'm not sure how you could have missed this. Judges have also dismissed the requests from Cloudflare and others to remove the "dynamic block" as there is collateral damage.

My understanding was that cloudflare was being blocked by the same IP blocking list as everything else. And while that system went through courts, the list didn't. There are also direct actions against cloudflare, but that's not what's taking everything down, is it? Did I misunderstand something?

The sites are directed to be blocked by IP and DNS, this is the list I suppose you're talking about, I'm not sure of any specific "system vs list" distinction. Since some of the sites are behind Cloudflare, some of the IPs are IPs used by Cloudflare for any customer, not just the streams, so then Cloudflare gets blocked wholesale, the collateral damage that we get to joyfully experience every game.

Remains to be seen if the block will remain in place or not, you could argue it goes against some other laws, but it has to be argued legally, just like how the block initially happened because La Liga went through the courts. So far us developers or people who visit more American websites tend to be hit the worst, since they're talking about "protecting" other matches too, in other sports, I'm guessing it'll get worse before it gets better.

Re: Cloudflare Email Service

#180

While we’re adding antiquated and shitty ways to interface with your agent, can we add fax support? Maybe direct-to-mail service for postcards and flyers?

This has been possible for many years, before agents were a thing. They will open the mail and scan the contents into a pdf for you, requires filing a form with the post office. It gets expensive because they nickel and dime you where they can. There are many more services should you wish to send snail mail. https://www.virtualpostmail.com/

As an aside, this company's services seem incredibly sketchy - they let you have fake residential or commercial addresses so you can pretend to have a US office or other address
Post reply on HN