Live data from Hacker News

Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

mailgun.com

211–220 of 279 posts

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#211
Mandatory DMARC basically breaks all e-mail forwarding services (SPF doesn't survive forwarding due to modification of Return-Path). I think ARC/RFC8617 is supposed to be the fix for that, but it's not even standardized yet. This seems like a rather big issue?

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#212
post #199

Earlier quoted context omitted.

It's also not an email. I've never seen a legitimate email with that string, and all of the illegitimate ones should be triggering other heuristics, such as the existence of an unsubscribe link, or things like "$x off". In any case the false positive rate on that would likely be incredibly low, so it's a good heuristic considering how bad the false negative rate is right now.

Dear site admin, This is as advertisement that appeared on your site yesterday that is a phishing scam pretending to be a bank. Please prevent ads like this showing up on your site. Regards, Client XYZ --- Maybe it's just the positions I've been in, but I've often seen variations of the above email, and I've never seen advertisement emails that flat out say "this is an advertisement" In fact, what I have seen are adv…

Like others, I get people handing my email out all the time by mistake because I grabbed first-initial-last-name 20 years ago, so I get lots of corporate spam that others have signed me up for. If you look at corporate spam, it frequently contains a passage like this:

> This is an advertisement and outbound email only. Please do not respond to it. This email has been sent on behalf of Kia Motors America, Inc. (KMA). To opt-out of receiving marketing/promotion emails from or on behalf of KMA, please click here.

Or this one I got last week from J Crew:

> We want you to hear about what's just right for you. Update your email preferences here. This email may be considered an advertising or promotional message.

For a while I just ignored it, and this kind of thing never went to spam. Now I always mark it as spam, and it's starting to, but their default spam heuristics are apparently awful, and it seems like marking as spam just affects that one sender, so you have to do it all the time for new spammers. I still just got linkedin spam yesterday after I have marked thousands of their messages. It can't be that hard to come up with heuristics for this. The biggest signal is probably that it contains an unsubscribe link since it has to be there by law.

Your example is also a single message. I imagine they look at patterns, and a single sender sending thousands of emails which are 99% similar is probably also a strong signal that it is spam (yes there are transactional emails that are templated; that's why it's a signal). That combined with the "this is an advertisement" heuristic is probably pretty accurate.

The reality is--obviously--that they are not trying to stop corporate spam. They're an advertising company; they don't want to normalize the idea that advertisements are supposed to be filtered.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#213
post #68

How does this interact with transactional emails / 2FA / password resets? If 5000 people request a 2fa code in a month, I have to give them a unsubscribe header as well? Or magic login links? If I don't provide a list-unsubscribe header: do these emails then get blocked and noone can log in ? If I provide a list-unsubscribe header, what is the expected behaviour if they do click the Unsubscribe button? - tell them th…

Its 5000/day for marketing, and if you are sending 5000 emails a day, you probably should have unsubscribe links. https://support.google.com/mail/answer/81126#requirements-5k You also need a link, not just list-unsubscribe, and it is specifically for marketing emails. In my experience, Google is pretty accurate in figuring out transactional versus marketing. They don't tell their heuristics, but you don't think engin…

> but you don't think engineers who build web crawlers cannot build email classifiers?

I’ve seen Gmail put legit update emails coming from Google itself in spam.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#214

Earlier quoted context omitted.

Exactly... Outlook by Microsoft is notorious for being very heavy handed with emails, requiring sites to put warnings to users to whitelist their domains so that they receive invoices or notifications.

At this point with outlook it’s pretty much guaranteed that any important “you just paid a ton of money here is the asset you bought” email (show/bus/etc tickets) will go straight to spam. I check spam before I look in the non-“Focused” inbox.

If I send an email to some business, from the Outlook UI, and they reply, Outlook usually classifies the reply as spam. It’s hard to imagine less spammy email than that.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#215
I find much of the discourse on these changes to be pretty amusing. It's a lot of sales and marketing teams asking how they can tweak things at a technical level so that they can keep doing the same things they've always been doing.

You can't. That's the point. Stop.

I mark all commercial email as spam. I never asked for it, I don't want it. I don't really care if you carefully constructed a form in such a way to be compliant with the laws in my country. I don't care how your BDR found me. I don't ever want to hear from you. If I didn't ask for it, it's spam, I'm marking it spam, and I hope people who use Gmail and Yahoo do the same.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#216

Earlier quoted context omitted.

Lack of opt-in into those will have me keep marking those as spam. Just like those US political newsletters that also don’t feel like they need to verify mails.

US political emails are even more annoying when you aren’t American. I flag all that stuff as spam without hesitation. If you do that, I hope your entire domain ends up flagged as spam.

I had the idea to do a 1 dollar donation and then see the campaign getting flagged for illegal campaign contributions, but that is probably illegal for me as well.

(non-us based not us citizen)

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#217
post #127
post #70

Earlier quoted context omitted.

Forwarding an email should strip this header, probably along with most of the other irrelevant ones potentially containing sensitive information the user isn't aware of. Forwarding an email with GMail only keeps the From, To, Date and Subject headers.

i feel like if we're talking about a header the user isn't aware of, most users probably won't be able to use it to unsubscribe either

Users don't need to be aware of the header, they just need to use a client that knows what to do with it.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#218

Earlier quoted context omitted.

Exactly... Outlook by Microsoft is notorious for being very heavy handed with emails, requiring sites to put warnings to users to whitelist their domains so that they receive invoices or notifications.

At this point with outlook it’s pretty much guaranteed that any important “you just paid a ton of money here is the asset you bought” email (show/bus/etc tickets) will go straight to spam. I check spam before I look in the non-“Focused” inbox.

I'd just rename the spam folder to "Inbox-2" or something. ;-)

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#219
post #205

> Gmail and Yahoo are getting serious about spam monitoring and senders will need to ensure they’re keeping below a set spam rate threshold. Does anyone know what this sentence means? Is this “the user said this is spam”, or “the gmail spam filter false positives 10% of the time; don’t be part of the 10%, or it’ll permaban you”?

Gmail postmaster tools says, "This dashboard shows the percentage of user-reported spam vs emails that were sent to the inbox for active users. Emails delivered directly to the spam folder are not included in the spam rate calculation. Only emails authenticated by DKIM are eligible for spam-rate calculation."

The threshold for the number defined above is 0.3%; that's the point where Gmail starts penalizing the sender by putting their emails in spam folders.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#220

I find much of the discourse on these changes to be pretty amusing. It's a lot of sales and marketing teams asking how they can tweak things at a technical level so that they can keep doing the same things they've always been doing. You can't. That's the point. Stop. I mark all commercial email as spam. I never asked for it, I don't want it. I don't really care if you carefully constructed a form in such a way to be…

Indeed I do. Any email I didn't explicitly ask for that isn't a unique personal email I mark as spam. Although I also stopped using Gmail in favor of Proton.
Post reply on HN