Live data from Hacker News

The only safe email is text-only email

theconversation.com

71–80 of 123 posts

Re: The only safe email is text-only email

#71
post #62
post #56

Earlier quoted context omitted.

I feel like I'm making this comment once a week on HN but I host my own email and I haven't had any major issue so far with "big email". The main caveat is that you will have a very hard time getting your email accepted if it comes from a home connection IP range instead of some host provider but if you do have a dedicated server and follow the guidelines (SMTPS, DKIM, SPF etc...) it just works, at least in my experi…

Hosting one's own e-mail server is a totally opaque random crapshot. You may not have any trouble, but some other dude or gal will get their e-mail marked as spam without any way to tell what exactly is wrong and what to change.

First step when getting an ip for a server that will be a mail server is to check if the ip is not already blacklisted.

You can always get it unlisted.

After that don't start to send hundred of email by day. You need to build a reputation for your domain and ip.

As the parent comment says, set up directly spf, dkim and dmarc (also arc if you can). Rspamd can help you do that.

I've been running a personal mail server for 5 years with simply following those rules.

Re: The only safe email is text-only email

#72
post #67

I've noticed that "if it's not plaintext, it gets deleted without being read" seems to be a pretty common rule among Germans on the Internet, who also have a tendency to like specifying very exactly what they want of email to them. Here's a few examples: https://www-user.tu-chemnitz.de/~heha/email.en.htm http://problemkaputt.de/email.htm https://www.gaertner.de/~neitzel/email-to-mn.html http://www.karo-electronics.de…

I would love to only use plain text e-mail. However, how does this work in practice when you are not a well known person (albeit in a niche) that decides the rules? In work I have to accept whatever my colleagues, clients and bosses will send me. For personal communication I use mail with two people. And services that let you choose whether they'll send you plain text are practically inexistent.

Many (most?) emails can be read in plain-text format even if they were written in HTML. The email often comes encoded with an "alternative" plain text version; of course you need a client that will show you that version instead. In my experience most personal email (i.e. not automated/form mails) I receive has a plain text alternative version that works fine.

For emails sent by an evil client that doesn't provide a plain text version, you can consider a tool that attempts to convert HTML to plain text (though I don't have a suggestion for this yet). Fall back on reading the HTML version only if the above fail.

- experience from working on / using my own mutt-like terminal email client.

Re: The only safe email is text-only email

#73

Earlier quoted context omitted.

> Over 99.5% of the email I receive is either plaintext or renders perfectly legible in plain. Is that representative? Where do you get email from? Did you change preferences on things like mailing lists in order to get to that percentage? Also: what kind of client do you use? iOS mail does send plain text emails as text/plain (which is fantastic) but if you look at e.g. inbox (gmail) it doesn't even allow sending pl…

Emails can send in both formats for a single message, so it's possible and even likely that most mailing lists, etc. he receives send in both formats. In my experience, even most marketing e-mails are at least somewhat good about this. I'm 99% sure that Gmail will still send a plaintext e-mail inferred from your HTML content whenever you send, so it's not quite accurate to say it doesn't send in plaintext.

I checked and, at least for a plaintext mesdage, Gmail on Android sends both plain text and HTML.

Re: The only safe email is text-only email

#75
post #62

Earlier quoted context omitted.

Hosting one's own e-mail server is a totally opaque random crapshot. You may not have any trouble, but some other dude or gal will get their e-mail marked as spam without any way to tell what exactly is wrong and what to change.

First step when getting an ip for a server that will be a mail server is to check if the ip is not already blacklisted. You can always get it unlisted. After that don't start to send hundred of email by day. You need to build a reputation for your domain and ip. As the parent comment says, set up directly spf, dkim and dmarc (also arc if you can). Rspamd can help you do that. I've been running a personal mail server…

I've been running a personal mail server for twice as long with simply following those rules and my e-mail is still tagged as spam in Gmail when it's me who initiates contact (once the other party sends me an e-mail, reply or otherwise, I no longer get tagged as spam).

As I said, it's totally opaque crapshot.

Re: The only safe email is text-only email

#77
post #72
post #67

Earlier quoted context omitted.

I would love to only use plain text e-mail. However, how does this work in practice when you are not a well known person (albeit in a niche) that decides the rules? In work I have to accept whatever my colleagues, clients and bosses will send me. For personal communication I use mail with two people. And services that let you choose whether they'll send you plain text are practically inexistent.

Many (most?) emails can be read in plain-text format even if they were written in HTML. The email often comes encoded with an "alternative" plain text version; of course you need a client that will show you that version instead. In my experience most personal email (i.e. not automated/form mails) I receive has a plain text alternative version that works fine. For emails sent by an evil client that doesn't provide a p…

> For emails sent by an evil client that doesn't provide a plain text version, you can consider a tool that attempts to convert HTML to plain text (though I don't have a suggestion for this yet).

I use emacs to read my email, and w3m to render HTML email as text. It does a good job. Newer emacs includes its own web browser (eww) but I have not tried it for HTML email rendering since I'm happy with w3m.

Replies always go out in plain text (my preference) but if you want to send HTML there are ways to e.g. write your email in org-mode markup and have it converted to HTML when you send. But IMO if you want to send "rich" email then just use a client that does that natively.

Re: The only safe email is text-only email

#78
post #62

Earlier quoted context omitted.

Hosting one's own e-mail server is a totally opaque random crapshot. You may not have any trouble, but some other dude or gal will get their e-mail marked as spam without any way to tell what exactly is wrong and what to change.

First step when getting an ip for a server that will be a mail server is to check if the ip is not already blacklisted. You can always get it unlisted. After that don't start to send hundred of email by day. You need to build a reputation for your domain and ip. As the parent comment says, set up directly spf, dkim and dmarc (also arc if you can). Rspamd can help you do that. I've been running a personal mail server…

> You can always get it unlisted.

How do you do that? The vast majority of blocklists I've interacted with have been unwilling to deal with questions, instead responding only that if you fix "something" (not always specified) automated measures will remove it from the list eventually.

In my experience it has also been extremely difficult to deal with people using blocklists. It's easy to find a bunch of people using .tor.dan.me.uk rather than .torexit.dan.me.uk "just to be safe". Frankly, I'm not sure why the former list exists in the first place other than to be an arse? What threats do entry/relay nodes pose to you?

Re: The only safe email is text-only email

#79
post #31

Earlier quoted context omitted.

I'm not sure the ship has sailed. If HSBC switched to only mailing out text-only emails with URLs written out in full, after a while HSBC users would get used to only receiving text correspondence from their bank. I think that would be a step towards reducing phishing attempts, though certainly not a complete answer.

That would require HSBC to value some kind of improved security so much that they'd accept not having the HSBC logo in the email. That's what I think is out of the question. You could maybe see banks having plaintext communication as an optional, but I doubt they'd make it default (allowing users to switch to html). Isn't this problem already solved with certificates online? Shouldn't this be solvable the same way? E…

They could still have the HSBC logo, it would just need to be in ascii....

Re: The only safe email is text-only email

#80
post #72
post #67

Earlier quoted context omitted.

I would love to only use plain text e-mail. However, how does this work in practice when you are not a well known person (albeit in a niche) that decides the rules? In work I have to accept whatever my colleagues, clients and bosses will send me. For personal communication I use mail with two people. And services that let you choose whether they'll send you plain text are practically inexistent.

Many (most?) emails can be read in plain-text format even if they were written in HTML. The email often comes encoded with an "alternative" plain text version; of course you need a client that will show you that version instead. In my experience most personal email (i.e. not automated/form mails) I receive has a plain text alternative version that works fine. For emails sent by an evil client that doesn't provide a p…

Similar to the other child comment: elinks can format HTML as plaintext.

I have this as my .mailcap and it Just Works (TM) with mutt:

  text/html;  elinks -dump %s; nametemplate=%s.html;          copiousoutput
Post reply on HN