Live data from Hacker News

Spam blacklisting is out of control

blog.roastidio.us

401–410 of 430 posts

Re: Spam blacklisting is out of control

#401

Earlier quoted context omitted.

https://dataprot.net/statistics/spam-statistics/ Did you actually read that, and the sources it cites, before posting it? If you had you might have noticed that it's full of the worst kind of junk stats. Several of the sources cited, the ones that supposedly support your arguments here, don't even say what the piece you linked claims. They literally have completely different numbers. Not that it matters since there i…

> As someone old enough to remember the time when that was actually the case, obviously we managed. I'm also old enough to remember that and we managed by blocking huge amounts of IP space. Even massively popular services like AOL have blocked the IP space of entire ISPs or entire countries from being able to send them email. Eventually spam filtering improved, things like SMTP auth, DKIM etc caught on and wide range…

Can you imagine what would happen if we applied your argument to other important communications channels like postal mail or telephone calls? Sorry, someone in your old friend's city was using a robodialler so now none of the local phone service providers available to you will accept calls from anyone in that area code.

We absolutely can regulate the Internet on this kind of issue. We don't have to regulate everywhere in the world to make a big improvement, just businesses above a certain size that operate a commercial email service. If our governments can effectively lean on social networks enough that they add warnings to potentially misleading comments about science, they can lean on email services to do better with this problem. They only difference is that there is an obvious and unambiguous way the mail services could do a better job.

And again, just to be crystal clear, I am not arguing for giving real spammers a free pass. I am only arguing for credible, realistic measures to try to avoid the huge numbers of false positives we get from mail filtering today.

Re: Spam blacklisting is out of control

#402

Earlier quoted context omitted.

Outlook properties seemingly use uceprotect lists. Outlook support even has a page for getting off their block list, but I could never get a reply. And my hosting provider basically said "we're warning against using our servers for outbound email", which amounts to "we're not gonna do anything about your bad neighbors that landed you on the uceprotect lvl2&3 lists" Been running my own email for 18 years, and outlook…

Outlook definitely engage in aggressive blocking of netranges, but I’m pretty sure they don’t use UCEPROTECT to do this since I’ve seen servers caught in Outlook netrange blocks despite all the public RBLs (including UCEPROTECTL3) showing no problem. Just to be sure, you are using the Outlook form[0] and not the Office365 form? Have you signed up for SNDS?[1] All these hoops are pretty dumb, and I don’t think they ha…

I've signed up for SNDS, but there's no mitigation to be done from there, it's purely informative. And that form looks like one I've filled out to no avail.

My email server is very small, so it's not a big deal... But thanks for the links.

Re: Spam blacklisting is out of control

#403

Earlier quoted context omitted.

> As someone old enough to remember the time when that was actually the case, obviously we managed. I'm also old enough to remember that and we managed by blocking huge amounts of IP space. Even massively popular services like AOL have blocked the IP space of entire ISPs or entire countries from being able to send them email. Eventually spam filtering improved, things like SMTP auth, DKIM etc caught on and wide range…

Can you imagine what would happen if we applied your argument to other important communications channels like postal mail or telephone calls? Sorry, someone in your old friend's city was using a robodialler so now none of the local phone service providers available to you will accept calls from anyone in that area code. We absolutely can regulate the Internet on this kind of issue. We don't have to regulate everywher…

> Can you imagine what would happen if we applied your argument to other important communications channels like postal mail or telephone calls?

The only reason we don't is because unlike email, it's the sender who pays not the receiver. Telecoms do monitor and block outbound international calls if the connection times are excessive, if they occur at unusual hours, or if they going to certain "blacklisted" countries where phone fraud is common. They do it because hackers will break into a business's PBX and use it to place a bunch of international calls and the business suddenly gets a massive phone bill. They call their phone company about the changes, the phone company waves the changes (once) but that leaves the phone company on the hook for them. When false positives happen, the business has to call into the phone company and explain the calls were legit and they will be whitelisted and similar outbound calls will be allowed going forward.

I wouldn't oppose using regulation in the US against US based mail services if it meant forcing them to do a better job preventing spam from leaving their networks, but I'd be hesitant to support legislation forcing them to accept more spam. Maybe the largest ones could be pressured to invest more money in handling the influx of spam after they accept it, but I'm guessing there would be costs to consumers such as long delays in delivery, or "free" services like Gmail suddenly requiring payment or closing their services for good. At the ISP I work for now we stopped hosting our own mail servers and outsourced email services to a third party because spam filtering was too expensive and time consuming, and now we're looking at possibly no longer offering an email product at all and telling all of our customers to migrate to services like gmail and yahoo. Killing our email service today would eliminate a lot of problems in terms of help desk calls, phishing attacks, and spam problems. Make it too much harder for people to provide email service and there may only be giant providers left.

Re: Spam blacklisting is out of control

#404
Managing mail servers is nowadays only possible for million dollars backed companies. It's clearly something we discovered while running Improvmx.com.

Of course it's possible (and quite easy) to set up your own mail server, there are tons of guides out there for that, but this is just the tip of the iceberg! Once you have it up and running, you'll find yourself in a constant battle between those who spam you, and those who consider you spammer, real or not.

Using blacklists to filter out the bad incoming email is one efficient tool, but you need to rely on good, reliable and *honest* blacklist systems. Sorbs and Spamhaus comes to mind, compared to uceprotect and backscaterer. The last two asks you money to delist you regardless of what you did, and this is typically bad player playing on top of bad players. They do a race to the bottom by offering a racketing service.

But the worst is still that popular mail server uses these! Microsoft uses UCEProtect to filter email! So, as a mail provider like OP's, you find yourself in a pickle where you need to decide if you want your email to be delivered to Microsoft's users - that means paying, or not.

That is why managing emails has become a million dollars necessity if you want them to be up and running properly. You need to be close to the big ones, have a seat at the big tables where the decisions occurs and hopefully have your IPs added to whitelists.

To plug one very useful link in all this, I'd share Hetrix! (https://Hetrixtools.com), they monitor your IPs and notify you when they are listed on almost all the existing blacklists, and automatically delist them whenever possible, or provides you all the info to do to delist them. As a mail provider, this is on of the most useful tool there is.

Re: Spam blacklisting is out of control

#405
post #298
post #257

Earlier quoted context omitted.

From a comment below from the other side of the equation it sounds like the email in question WAS indeed marketing for a lifetime promotion. People should have every right to unsubscribe themselves from that, and thus should have some sort of feedback loop attached to the email being sent (to the detriment of your bottom line I fully understand and sympathize with). If this was indeed a marketing email, then I don't…

"People should have every right to unsubscribe themselves from that, and thus should have some sort of feedback loop attached to the email being sent (to the detriment of your bottom line I fully understand and sympathize with)." I agree. We have a flag for such a thing and set that flag when people ask us to. They ask us in a nice email exchange between human beings. We're very responsive to this since they are our…

Your earlier argument about unsubscribe being effectively an informal termination only works if you properly separate that side from all promotional/marketing/new features/etc material, otherwise it seems you are avoiding the main point and purpose of the unsubscribe button

Re: Spam blacklisting is out of control

#406
post #139

> Or I can leave the current hosting company Yep, that's the one. If your hoster doesn't care about spam spreading from their IP space, you should take your mail server elsewhere. There's literally nothing to think about. And if they do care about this issue, they are likely to be taking steps to remove any of their IP space from the blacklists, without being nudged. PS. I've been running a mail server for close to 2…

I have a similar experience: Some hosting providers / AS host shady stuff and I understand that VPS ranges end up on block lists quite easily. I only block AS 4134 and AS 4837, some AS that host services like shodan, and aggressive crawlers like semrush. Anything that sends packets to my server get ratelimited quickly. Still barely noticeable for occasional human interaction. I also started with /24, but I am now up…

> By the way, has anyone ever seen spameri@tiscali.it in the logs? It shows up almost on a weekly basis as RCPT TO address from literally all over the world.

Yes, I see it all the time in my logs.

Re: Spam blacklisting is out of control

#407
post #328

Is anybody using "fail2ban" connected to "badIP"? (as described e.g. here https://www.howtoforge.com/tutorial/protect-your-server-comp... ) (in both modes, download & upload) My root server hosts as separate VMs at least a website and an email server => both are magnets for all kinds of scans and intrusion attempts => I've got logscans + honeypots etc... set up (fail2ban then closes the source IP's connection for a w…

I tried to use F2B and https://voipbl.org on a small 1 core + 1 GB RAM vm and it did not work out very well. I'm pretty sure iptables was crashing because there were so many IPS to block. Your mileage may vary. Probably needs something a little more powerful than what I had.

Thanks - yeah, I did think that that list might be quite long... .

Re: Spam blacklisting is out of control

#408
post #384

Earlier quoted context omitted.

> all because you refused to acknowledge a removal request But the receiving MSP can't acknowledge the removal request, in the scenario reported by the author. They are not the ones operating the blocklist. That's UCEPROTECT, not Comcast or whoever.

You have this backward, as well, because that's not how any of this works. The UCEPROTECT list is a literal text file that gets ingested by the mail provider. The provider is under zero obligation to use the entirety of the list and, in fact, is still 100% responsible for maintaining their own list in a way that complies with international laws, ICANN rules, service agreements, etc. UCEPROTECT even offers a very blat…

> The UCEPROTECT list is a literal text file that gets ingested by the mail provider.

I don't know whether that is true; but I do know that it is usually used as a DNSBL - a DNS lookup for an IP address, that answers whether that address is or is not in the list. In general, mail providers do not "ingest" entire blocklists.

> responsible for maintaining their own list in a way that complies with international laws [etc.]

Actually, anyone can publish a list of anything; unless that publication amounts to a contract (statement of purpose, assertion of fitness for purpose), then I'm not aware of any international "law" that says you can't put anything you like in a publicly-acccessible list. And anyway, there's no contract without an exchange of considerations - baiscally, you have to cough-up if you want to assert a contract.

> even offers a very blatant disclaimer on their site

Have you ever read a FOSS licence? UCEPROTECT are simply stating that as a free user, you can't hold them responsible for the accuracy of their lists; in the same way that FOSS authors disclaim responsibility for fitness-for-purpose.

Re: Spam blacklisting is out of control

#409

Earlier quoted context omitted.

> The thing is, if you own a good IP in a mixed block with some bad ones, that's no reason for you to be blacklisted. It's pure laziness. Yes, in that situation it's laziness, but on the part of your ISP. ISPs already spend huge amounts of time and money dealing with spam, hacking attempts, phishing attacks, etc. If your ISP is irresponsible and isn't doing their job keeping those things from leaving their network th…

That seems a lot of rationalisation for a situation where a genuine sender on another system sends legitimate mail to a genuine recipient on your system, that mail is not properly delivered, and it's your fault. There is a reason that collective punishment is considered immoral by civilised cultures. It hurts the innocent and often fails to achieve its original goal anyway.

> and it's your fault

Or maybe your policy?

> There is a reason that collective punishment is considered immoral by civilised cultures

Rejecting email submissions isn't punishment, collective or otherwise. It's something you have to do if you run a mailserver. In the same way, I'm not punishing trespassers if I secure my front-door with a deadlock.

Re: Spam blacklisting is out of control

#410

Earlier quoted context omitted.

> That seems a lot of rationalisation for a situation where a genuine sender on another system sends legitimate mail to a genuine recipient on your system, that mail is not properly delivered, and it's your fault. It's how the internet stays functional. If 0.001% of legitimate mail has to go undelivered in order to prevent overwhelming amounts of spam/attacks from an irresponsible network that's an acceptable loss to…

It's how the internet stays functional. [citation needed] If 0.001% of legitimate mail has to go undelivered in order to prevent overwhelming amounts of spam/attacks from an irresponsible network that's an acceptable loss to most people in our civilized culture. 1. It's way more than 0.001%. Like, several orders of magnitude more. 2. What overwhelming amounts of spam/attacks? Those of us using traditional mail system…

> What overwhelming amounts of spam/attacks?

The majority of all email has been spam, for more than a decade.

> You don't get to decide what's acceptable to everyone else

If you operate a mailserver, you do actually get to decide what kind of stuff you are willing to accept, and from who. "Everybody else" does not get an automatic right to inject data into my computer.

> The kind of policy you advocate punishes small ISPs

Not at all (perhaps you meant MSPs?) Blocklisting Google was a reasonable policy, at one time. Blocklisting MailChimp is perfectly reasonable now.

> Block actual spam sources

Of course, good plan. Unless the sender's ISP is in the habit of moving spammers from one address to another, so they can evade blocks. Then you have to block the ISP, or eat their spam.

Postmasters can't inspect every inbound spam!

Post reply on HN