Live data from Hacker News

Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

mailgun.com

31–40 of 279 posts

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#31

DKIM, SPF, and DMARC are old hat and implemented by anyone serious for years. What's buried in this article is the required https://datatracker.ietf.org/doc/html/rfc8058 support for one-click unsubscribe posts. I don't see many messages in my inbox yet with that.

That's very odd to me. Where are you located? I'm in the United States and virtually all my newsletter/marketing emails have one-click unsubscribe these days. The only ones which don't are from foreign companies, e.g. I bought a day planner from Hobonichi and found they put their unsubscribe behind a login, to my irritation.

I’d say somewhere around half of the marking emails I receive in the USA have one-click unsubscribe. It’s still very common to have unsubscribe links that require you to enter your email address and then select that you actually want to unsubscribe from everything, etc. And some of them still require logins, although those are getting rarer. Not sure if it’s actually a loophole, but one of the dark patterns I’m seeing often is one-click unsubscribe generally only unsubscribes you from a very specific type of notification or topic of the mailing list, and you’ll still get other types of emails unless you fully log into your account and go in your email settings and unsubscribe from everything. Not sure exactly how Google and Yahoo treat those, but it feels kind of like marketers found a loophole that seems to work for them.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#32
How does this interact with transactional emails / 2FA / password resets? If 5000 people request a 2fa code in a month, I have to give them a unsubscribe header as well? Or magic login links?

If I don't provide a list-unsubscribe header: do these emails then get blocked and noone can log in ?

If I provide a list-unsubscribe header, what is the expected behaviour if they do click the Unsubscribe button?

- tell them they can't unsubscribe to this email because it's needed to accomplish what they want to do in the future?

- delete their account? what if it's a bank account or something like that?

Would appreciate some clarify from Google at least...

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#33

DKIM, SPF, and DMARC are old hat and implemented by anyone serious for years. What's buried in this article is the required https://datatracker.ietf.org/doc/html/rfc8058 support for one-click unsubscribe posts. I don't see many messages in my inbox yet with that.

That's very odd to me. Where are you located? I'm in the United States and virtually all my newsletter/marketing emails have one-click unsubscribe these days. The only ones which don't are from foreign companies, e.g. I bought a day planner from Hobonichi and found they put their unsubscribe behind a login, to my irritation.

I'm in Canada, but I don't think that's it.

- Docker Newsletter: `List-Unsubscribe: ` - but missing http post/one-click header

- Java Weekly: link in body but no header Expensify: compliant

- Gradle: compliant

- Confluence Digest: No unsubscribe header

- Apache Mailing Lists: mailto header, but missing required http post / one-click

I think the confusion is that it's not just having a link, it's a specific set of headers, dkim signed fields, and form response that allows a mail client to unsubscribe with no user interaction.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#34
post #30

Earlier quoted context omitted.

That's very odd to me. Where are you located? I'm in the United States and virtually all my newsletter/marketing emails have one-click unsubscribe these days. The only ones which don't are from foreign companies, e.g. I bought a day planner from Hobonichi and found they put their unsubscribe behind a login, to my irritation.

Same. Basically everything that comes from a legitimate mailing list/subscription has it. Even stuff I would personally consider spam like political mailing lists have it. It’s only the worst spam stuff that doesn’t. The obvious scam stuff sent to any email address they can find, containing every language I don’t speak, with lots of bad obfuscation to stop keyword scanners from 2002.

> Basically everything that comes from a legitimate mailing

There's the fly in the ointment. "Legitimate" shades off very slowly into bottom feeding Sanford Wallace-ass spamming. The temptation to become worse and worse is real, economics favor spamming, as it externalizes advertising costs. Until the torches and pitchforks come out.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#35
Is there any service that can process DMARC report e-mails? Those mails with zips with indecipherable XMLs inside them are a bit useless. Something that takes the junk, gives a nice human readable dashboard, and informs me if something is wrong, would be nice.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#36
post #35

Is there any service that can process DMARC report e-mails? Those mails with zips with indecipherable XMLs inside them are a bit useless. Something that takes the junk, gives a nice human readable dashboard, and informs me if something is wrong, would be nice.

Dmarcian, I think.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#37
post #35

Is there any service that can process DMARC report e-mails? Those mails with zips with indecipherable XMLs inside them are a bit useless. Something that takes the junk, gives a nice human readable dashboard, and informs me if something is wrong, would be nice.

Postmark have a free DMARC service [1] that emails you a report once a week. I use it for all my domains. Note that they also have a paid offering, but this one is free.

[1] https://dmarc.postmarkapp.com

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#38
post #35

Is there any service that can process DMARC report e-mails? Those mails with zips with indecipherable XMLs inside them are a bit useless. Something that takes the junk, gives a nice human readable dashboard, and informs me if something is wrong, would be nice.

Mailhardener and dmarcdigests are 2 that I've used. Dmarcdigests also has a free version through postmark that sends you a summary email weekly instead of a dashboard. I personally like mailhardener, I felt the dashboard was better and easier to understand.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#39
post #35

Is there any service that can process DMARC report e-mails? Those mails with zips with indecipherable XMLs inside them are a bit useless. Something that takes the junk, gives a nice human readable dashboard, and informs me if something is wrong, would be nice.

I’ve been using DMARC Digests for a year and haven’t had any issues. Was quick to set up.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#40

How does this interact with transactional emails / 2FA / password resets? If 5000 people request a 2fa code in a month, I have to give them a unsubscribe header as well? Or magic login links? If I don't provide a list-unsubscribe header: do these emails then get blocked and noone can log in ? If I provide a list-unsubscribe header, what is the expected behaviour if they do click the Unsubscribe button? - tell them th…

You're talking about Transactional emails? You cant unsubscribe from TRANSACTIONAL emails. That's why they're transactional...not marketing. It's really important to differentiate that.
Post reply on HN