Live data from Hacker News

Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

mailgun.com

51–60 of 279 posts

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#51
post #48

Earlier quoted context omitted.

I "know" that. I'm asking how does Google differentiate between a transactional and a non transactional email? They also say in their guidelines > *Marketing messages and subscribed messages* must support one-click unsubscribe, and include a clearly visible unsubscribe link in the message body. So how is Google determining what is a Marketing/Subscribed message? If they're not, then am I required to tack on this head…

If you’re sending transactional emails like password resets or MFA, then the emails will have close to a 100% open rate. This is (likely) an important factor that Google uses to judge whether email is transactional, or more generally whether it is desired by recipients, alongside other factors like having a very low complaint rate.

100% open rate on transactional emails feels too high to me. Something like an e-commerce purchase might kick off multiple emails (purchase made, shipped, arrived), none of which the user opens

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#52

DKIM, SPF, and DMARC are old hat and implemented by anyone serious for years. What's buried in this article is the required https://datatracker.ietf.org/doc/html/rfc8058 support for one-click unsubscribe posts. I don't see many messages in my inbox yet with that.

also it violates longstanding security measures against malicious prank unsubscribes; it means that if you forward an email list message to someone else, they can unsubscribe you without your consent as a prank

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#53

DKIM, SPF, and DMARC are old hat and implemented by anyone serious for years. What's buried in this article is the required https://datatracker.ietf.org/doc/html/rfc8058 support for one-click unsubscribe posts. I don't see many messages in my inbox yet with that.

That's very odd to me. Where are you located? I'm in the United States and virtually all my newsletter/marketing emails have one-click unsubscribe these days. The only ones which don't are from foreign companies, e.g. I bought a day planner from Hobonichi and found they put their unsubscribe behind a login, to my irritation.

A lot of the spam from the US I get (I'm in NZ), for things like US Political fundraisers for politicians, to car dealerships in the US in various states have links to click, but you often then seem to have to enter your email address when I do click them before submitting the form.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#54
post #52

DKIM, SPF, and DMARC are old hat and implemented by anyone serious for years. What's buried in this article is the required https://datatracker.ietf.org/doc/html/rfc8058 support for one-click unsubscribe posts. I don't see many messages in my inbox yet with that.

also it violates longstanding security measures against malicious prank unsubscribes; it means that if you forward an email list message to someone else, they can unsubscribe you without your consent as a prank

What real harm could come from such a prank? I hardly see the need for such "security" measures.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#56

How does this interact with transactional emails / 2FA / password resets? If 5000 people request a 2fa code in a month, I have to give them a unsubscribe header as well? Or magic login links? If I don't provide a list-unsubscribe header: do these emails then get blocked and noone can log in ? If I provide a list-unsubscribe header, what is the expected behaviour if they do click the Unsubscribe button? - tell them th…

use different subdomains for transactional and marketing emails.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#57
post #52

DKIM, SPF, and DMARC are old hat and implemented by anyone serious for years. What's buried in this article is the required https://datatracker.ietf.org/doc/html/rfc8058 support for one-click unsubscribe posts. I don't see many messages in my inbox yet with that.

also it violates longstanding security measures against malicious prank unsubscribes; it means that if you forward an email list message to someone else, they can unsubscribe you without your consent as a prank

Requiring the user to login to unsubscribe also has the nice effect of requiring them to know the password, otherwise they have to go through the reset procedure. Of course you need to be really secure and do 2FA as well.

Hey, if this reduces the number of people who successfully unsubscribe, don't blame me, I'm just over here trying to make sure things are secure!

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#58

> These mandates will only affect bulk senders, defined by Google as senders with volumes of 5000 or more messages to Gmail addresses in one day. This is not a requirement for a personal self-hosted email.

No, but many of us are using Twilio Sendgrid and there it will apply to, especially if you don't have a dedicated IP.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#59
post #48

Earlier quoted context omitted.

If you’re sending transactional emails like password resets or MFA, then the emails will have close to a 100% open rate. This is (likely) an important factor that Google uses to judge whether email is transactional, or more generally whether it is desired by recipients, alongside other factors like having a very low complaint rate.

100% open rate on transactional emails feels too high to me. Something like an e-commerce purchase might kick off multiple emails (purchase made, shipped, arrived), none of which the user opens

Kicking off a chain of emails a user cannot easily opt out of could well be the sort of emails users want to lose. There probably should be a one-click 'stop emailing me' button, for this and future purchases. Which would be a support burden, yes.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#60
post #48

Earlier quoted context omitted.

I "know" that. I'm asking how does Google differentiate between a transactional and a non transactional email? They also say in their guidelines > *Marketing messages and subscribed messages* must support one-click unsubscribe, and include a clearly visible unsubscribe link in the message body. So how is Google determining what is a Marketing/Subscribed message? If they're not, then am I required to tack on this head…

If you’re sending transactional emails like password resets or MFA, then the emails will have close to a 100% open rate. This is (likely) an important factor that Google uses to judge whether email is transactional, or more generally whether it is desired by recipients, alongside other factors like having a very low complaint rate.

I open way less than 100% of password resets - because some are malicious.
Post reply on HN