Live data from Hacker News

Spam blacklisting is out of control

blog.roastidio.us

371–380 of 430 posts

Re: Spam blacklisting is out of control

#371

Earlier quoted context omitted.

Not everyone can spend $500 on lawyer billable hours per SMTP destination multiplied by N number of destinations. I also think that the likelihood of success in sending legal threats to somebody that demand they accept your SMTP traffic will not stand up in court, if you ever escalated it that far. As somebody who runs postfix MX on the receiving side of things, I can guarantee you that the day I receive a legal thre…

The rationale for involving legal is to place some accountability and consequences where they belong. Currently, countless people essentially commit countless abuses for free because the actor is hidden behind a machine or a process. But somewhere it's a humans decision to institute an abusive protocol, and it seems pretty fair fo me to make that human accountable for their action. Not just email but all kinds of thi…

> I say you should be legally culpable for any failure to deliver.

So you think an MSP's advertised policy should be "We guarantee that anything sent to you will be delivered, including spam"? That no MSP should provide spam-filtering, at risk of legal culpability?

If that's not what you mean, then presumably you are requiring all MSPs to block only spam, and to deliver all legitimate email. But that is impossible, because nobody has figured out a way of reliably distinguishing spam from ham.

If I received such a letter from your legal department, I would laugh, and reply: "I am awaiting your writ." If I got the note from a recipient or their postmaster, I'd be much more inclined to try to help, but I never try to negotiate with lawyers brandishing threats.

Re: Spam blacklisting is out of control

#372
post #227

Earlier quoted context omitted.

> Do not ever email me about this purchase again Please send me the order, just don't send me the PDF invoice :)

This actually does cause problems with blocked password resets and things

If I request a password reset, that constitutes an approval to send me that email.

Re: Spam blacklisting is out of control

#373

Earlier quoted context omitted.

> through a transactional SMTP sender, like Postmark or Mailgun. ... cheapest is $10/month. Not paying that for my meager email traffic. Are there other options for personal domains?

I've been using the free tier at MailJet to relay mail for my server for several years and have had few problems. Several others offer free tiers too (SendinBlue, etc.)

Both of those seem to insert their logo in the emails for the free tier.

I'd rather pay a little and get unmodified emails. Guess they all cater to marketers not personal use.

Re: Spam blacklisting is out of control

#374

Earlier quoted context omitted.

Let's not classify all spam blacklists as the same. UCEPROTECT is in a special class of extortionist cowboy, because it's basically just an inaccurate protection racket throwing a wide net across cloud providers who won't play their game. Some other blacklists are updated regularly and only contain IP addresses that have actually sent spam. By contrast, UCEPROTECT3 just lumps ISPs into the list even though an address…

UCEPROTECT is just horrible, full stop. Stuff like [1] read like it's written by a 13 year old. Lots more where that came from; as near as I can tell UCEPROTECT is run by a single person who is consistently vitriolic like this to anyone offering even the mildest of criticisms (supposedly multiple people have involved over the years, but their, ehm, distinct colourful personalities are so alike that I'm inclined to th…

I think I understand a lot more about UCEPROTECT now that I've read the message you linked. This is pretty extraordinarily sexist and unprofessional, and you can really get a sense of how much the author despises anyone who criticizes him.

Re: Spam blacklisting is out of control

#375
post #181

Earlier quoted context omitted.

> They no longer accept mail from servers they haven't seen before. Interesting. This tracks with my experiences too, but is there a good source for this that I can reference in the future? I got out of hosting email last year entirely because of intractable deliverability problems with the big three: Google, Microsoft, and Comcast. Comcast's issues mostly appeared intermittent and the result of incompetence. Google…

I contacted Microsoft, actually received an answer from them and got an IP unblocked. Google can be tough though. If their Algorithms don't like you, good look. I was responsible for a new IP/Email setup and while all other relevant providers liked our mail and Google Postmaster tools didn't show anything bad, all our mail went to Spam in GMail. I found out why when even mails from completely different senders would…

How did you contact them? I had problems getting mail to MS years ago and at the time wasn't able to get anyone to do anything or even respond. At some point later the problem went away, though.

Re: Spam blacklisting is out of control

#376

Earlier quoted context omitted.

The thing is, if you own a good IP in a mixed block with some bad ones, that's no reason for you to be blacklisted. It's pure laziness. It's usually wrong to assume that everything in a /24 is controlled by one botnet, and it's not that hard to check whether it was just one or two particular addresses that were compromised. But if you're an ISP and you want to take the nuclear option to every spam threat, at least be…

> The thing is, if you own a good IP in a mixed block with some bad ones, that's no reason for you to be blacklisted. It's pure laziness. Yes, in that situation it's laziness, but on the part of your ISP. ISPs already spend huge amounts of time and money dealing with spam, hacking attempts, phishing attacks, etc. If your ISP is irresponsible and isn't doing their job keeping those things from leaving their network th…

That seems a lot of rationalisation for a situation where a genuine sender on another system sends legitimate mail to a genuine recipient on your system, that mail is not properly delivered, and it's your fault.

There is a reason that collective punishment is considered immoral by civilised cultures. It hurts the innocent and often fails to achieve its original goal anyway.

Re: Spam blacklisting is out of control

#377

Earlier quoted context omitted.

The thing is, if you own a good IP in a mixed block with some bad ones, that's no reason for you to be blacklisted. It's pure laziness. It's usually wrong to assume that everything in a /24 is controlled by one botnet, and it's not that hard to check whether it was just one or two particular addresses that were compromised. But if you're an ISP and you want to take the nuclear option to every spam threat, at least be…

> The thing is, if you own a good IP in a mixed block with some bad ones, that's no reason for you to be blacklisted. It's pure laziness. It's not laziness; the intention of collateral blocklisting, as with UCEPROTECT L2 and L3, is punitive. It's to incentivize the sending MSP to remove their spammer (or move them to address-space where they can be blocked without causing collateral damage).

It's not laziness; the intention of collateral blocklisting, as with UCEPROTECT L2 and L3, is punitive.

Unfortunately the people it punishes are the legitimate users of both systems who only wanted the system to do its job and let them communicate. The bad actors will just move on and abuse another system instead.

Re: Spam blacklisting is out of control

#378

Earlier quoted context omitted.

> The thing is, if you own a good IP in a mixed block with some bad ones, that's no reason for you to be blacklisted. It's pure laziness. Yes, in that situation it's laziness, but on the part of your ISP. ISPs already spend huge amounts of time and money dealing with spam, hacking attempts, phishing attacks, etc. If your ISP is irresponsible and isn't doing their job keeping those things from leaving their network th…

That seems a lot of rationalisation for a situation where a genuine sender on another system sends legitimate mail to a genuine recipient on your system, that mail is not properly delivered, and it's your fault. There is a reason that collective punishment is considered immoral by civilised cultures. It hurts the innocent and often fails to achieve its original goal anyway.

> That seems a lot of rationalisation for a situation where a genuine sender on another system sends legitimate mail to a genuine recipient on your system, that mail is not properly delivered, and it's your fault.

It's how the internet stays functional. If 0.001% of legitimate mail has to go undelivered in order to prevent overwhelming amounts of spam/attacks from an irresponsible network that's an acceptable loss to most people in our civilized culture. Bad actors have been ostracized from communities for as long communities have existed. If you want reliable service, choose a responsible ISP. Blacklists have enabled the internet and email to remain useful for most users most of the time. Without them, email wouldn't be usable. If you have a better solution for spam, the whole world would love to hear it.

Re: Spam blacklisting is out of control

#379

Earlier quoted context omitted.

Your hosting company is free to allow all the spam they want to leave their network and every other ISP on the planet is free to drop all traffic from your irresponsible hosting company's IP space. freedom sure is nice.

I and I alone is responsible for my act. It is a slippery downward slope once you start outsourcing responsibility.

When your act is choosing and giving money to a host that supports and enables spammers and attackers yes, your are responsible for that. Blacklists can be outsourced, but many ISPs maintain their own internal blacklists as well. ISPs can also subscribe to a 3rd party blacklist, but still whitelist specific blacklisted IPs they know aren't going to cause them problems. There are plenty of blacklists that ISPs choose not to use because they block too much to be useful. ISPs can also use blacklists not to block senders, but to greylist them or give them higher levels of scrutiny before deciding what do accept or block.

In the end, even with 3rd party blacklists networks still maintain control over what incoming traffic/mail they block or allow.

Re: Spam blacklisting is out of control

#380

Earlier quoted context omitted.

I and I alone is responsible for my act. It is a slippery downward slope once you start outsourcing responsibility.

When your act is choosing and giving money to a host that supports and enables spammers and attackers yes, your are responsible for that. Blacklists can be outsourced, but many ISPs maintain their own internal blacklists as well. ISPs can also subscribe to a 3rd party blacklist, but still whitelist specific blacklisted IPs they know aren't going to cause them problems. There are plenty of blacklists that ISPs choose…

You missed my point. I don't want my network to censor traffic. It is email traffic today, it could be web traffic tomorrow. If this trend holds, we would all live in walled gardens, and cede our power to the gate keepers.
Post reply on HN