Live data from Hacker News

Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

mailgun.com

71–80 of 279 posts

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#71
post #52

DKIM, SPF, and DMARC are old hat and implemented by anyone serious for years. What's buried in this article is the required https://datatracker.ietf.org/doc/html/rfc8058 support for one-click unsubscribe posts. I don't see many messages in my inbox yet with that.

also it violates longstanding security measures against malicious prank unsubscribes; it means that if you forward an email list message to someone else, they can unsubscribe you without your consent as a prank

It would be nice to have something you can put in the footer which email clients recognize and strip when you are forwarding an email

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#72
post #52

Earlier quoted context omitted.

also it violates longstanding security measures against malicious prank unsubscribes; it means that if you forward an email list message to someone else, they can unsubscribe you without your consent as a prank

What real harm could come from such a prank? I hardly see the need for such "security" measures.

Malicious compliance, to make unsubscription more annoying, so spam can continue to flow.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#73
post #46

Earlier quoted context omitted.

I’d say somewhere around half of the marking emails I receive in the USA have one-click unsubscribe. It’s still very common to have unsubscribe links that require you to enter your email address and then select that you actually want to unsubscribe from everything, etc. And some of them still require logins, although those are getting rarer. Not sure if it’s actually a loophole, but one of the dark patterns I’m seein…

Github unsubscribe is behind a login. Very annoying. We have an account with a company e-mail that is an alias to admins and it was subscribed to a few issues. One morning I got so annoyed with Thunderbird's not working message filters that I took the time to look up the password, login, unsubscribe and disable all nuisance e-mail communication.

That is not marketing email though

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#74

As a self-hoster for over a decade, setting up SPF, DKIM, and DMARC are pretty much once-and-done and free, so there's pretty much no downside. I'd be shocked if most self-hosters haven't set these up long ago.

Agreed, self hosting for the last year now. It’s to do took me about a week to get it all working.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#75
post #63

Please describe ‘easily unsubscribe’ - subjective terms like this don’t work when you’re dealing with the profit focused marking department of scumcorp. I don’t want to log into your service or explain why I want to unsubscribe or chose which mailing lists I want to unsubscribe from (read: All of them) nor do I want to deal with your dark patterns such as colouring the ‘cancel my request to unsubscribe’ button green…

Senders will need to implement a single-click unsubscribe link within emails if they haven’t already, to allow recipients to easily opt out. It does in the article. The industry has clear definitions for things like one click unsubscribe versus two click confirmation.

I know it’s not possible to implement a literal double click in web but hear me out - if someone told you they interpreted that as ‘a link which you only have to click once to open the unsubscribe website which may have additional clicking’ - would you think they’re malicious or incompetent?

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#77
post #52

Earlier quoted context omitted.

also it violates longstanding security measures against malicious prank unsubscribes; it means that if you forward an email list message to someone else, they can unsubscribe you without your consent as a prank

Requiring the user to login to unsubscribe also has the nice effect of requiring them to know the password, otherwise they have to go through the reset procedure. Of course you need to be really secure and do 2FA as well. Hey, if this reduces the number of people who successfully unsubscribe, don't blame me, I'm just over here trying to make sure things are secure!

Yep.

Don't want these marketing emails? Unsubscribe here.

Oh, you need to login in order to do that.

No, that's the wrong password for your account. Forgot password?

Hm, we don't see your account existing. Probably a different email address?

... sigh... sent a couple of emails to the data protection contact listed, but after 5 years, I still get the emails and I occasionally try to login again.

So I just automatically mark it as spam every time.

But probably because they're a small provider and don't have the resources; this is the largest telecommunications provider in Germany.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#78
I’d say the only real worry for “black hat emailers” is the spam rate monitoring. Everything else is fairly trivial to comply by, but lowering the spam compliance threshold could really put a wrench in a lot of sales outreach campaign.

The market(Google and others) was forced to act because how laughably easy the Can-Spam act is to stay compliant while legally mass spamming.

Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs

#80
post #63

Earlier quoted context omitted.

Senders will need to implement a single-click unsubscribe link within emails if they haven’t already, to allow recipients to easily opt out. It does in the article. The industry has clear definitions for things like one click unsubscribe versus two click confirmation.

I know it’s not possible to implement a literal double click in web but hear me out - if someone told you they interpreted that as ‘a link which you only have to click once to open the unsubscribe website which may have additional clicking’ - would you think they’re malicious or incompetent?

Incompetent. But I think those decisions are often made by neither the people who send nor receive the emails.
Post reply on HN