I use cloudflare's email remailer. i.e emails are mailed from from & to my Gmail via cloudflare. Using a custom email domain. Does this mean that my emails will no longer be sent?
Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs
81–90 of 279 posts
Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs
#82DKIM, SPF, and DMARC are old hat and implemented by anyone serious for years. What's buried in this article is the required https://datatracker.ietf.org/doc/html/rfc8058 support for one-click unsubscribe posts. I don't see many messages in my inbox yet with that.
Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs
#83I use cloudflare's email remailer. i.e emails are mailed from from & to my Gmail via cloudflare. Using a custom email domain. Does this mean that my emails will no longer be sent?
Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs
#84Earlier quoted context omitted.
also it violates longstanding security measures against malicious prank unsubscribes; it means that if you forward an email list message to someone else, they can unsubscribe you without your consent as a prank
What real harm could come from such a prank? I hardly see the need for such "security" measures.
- adding a new member to the list requires a vote of approval of the existing members. bob apparently unsubscribed last week and now he wants to resubscribe. can we take a vote on whether to let him back in or not?
- when someone who isn't a member of the list attempts to post to it, we add their domain to the spam blacklist and report them to vipul's razor. hmm, weird that bob.example.com is on our spam blacklist, how could that happen?
- bob, i'm afraid i have to write you up for having violated the new company policy i posted to the policy-announce-important list last week. well, if you didn't read it, that's your problem
Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs
#85How does this interact with transactional emails / 2FA / password resets? If 5000 people request a 2fa code in a month, I have to give them a unsubscribe header as well? Or magic login links? If I don't provide a list-unsubscribe header: do these emails then get blocked and noone can log in ? If I provide a list-unsubscribe header, what is the expected behaviour if they do click the Unsubscribe button? - tell them th…
Its 5000/day for marketing, and if you are sending 5000 emails a day, you probably should have unsubscribe links. https://support.google.com/mail/answer/81126#requirements-5k You also need a link, not just list-unsubscribe, and it is specifically for marketing emails. In my experience, Google is pretty accurate in figuring out transactional versus marketing. They don't tell their heuristics, but you don't think engin…
We're talking about Google here. It doesn't matter that they have lots of clever people working there; they still occasionally get/guess things wrong, and if you're the unlucky too-small-to-even-notice outfit that happens to get squished by Google today, there's seldom much you can do about it.
Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs
#86DKIM, SPF, and DMARC are old hat and implemented by anyone serious for years. What's buried in this article is the required https://datatracker.ietf.org/doc/html/rfc8058 support for one-click unsubscribe posts. I don't see many messages in my inbox yet with that.
I've seen a perverse dark pattern on one click unsubscribe. The page you land at has a button that lets you resubscribe! It looks non-obvious you've already unsubscribed and it looks like the regular two-click flow needing to enter your email address to confirm. Very sneaky.
Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs
#87Earlier quoted context omitted.
also it violates longstanding security measures against malicious prank unsubscribes; it means that if you forward an email list message to someone else, they can unsubscribe you without your consent as a prank
Requiring the user to login to unsubscribe also has the nice effect of requiring them to know the password, otherwise they have to go through the reset procedure. Of course you need to be really secure and do 2FA as well. Hey, if this reduces the number of people who successfully unsubscribe, don't blame me, I'm just over here trying to make sure things are secure!
Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs
#88Earlier quoted context omitted.
That's very odd to me. Where are you located? I'm in the United States and virtually all my newsletter/marketing emails have one-click unsubscribe these days. The only ones which don't are from foreign companies, e.g. I bought a day planner from Hobonichi and found they put their unsubscribe behind a login, to my irritation.
I’d say somewhere around half of the marking emails I receive in the USA have one-click unsubscribe. It’s still very common to have unsubscribe links that require you to enter your email address and then select that you actually want to unsubscribe from everything, etc. And some of them still require logins, although those are getting rarer. Not sure if it’s actually a loophole, but one of the dark patterns I’m seein…
Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs
#89> These mandates will only affect bulk senders, defined by Google as senders with volumes of 5000 or more messages to Gmail addresses in one day. This is not a requirement for a personal self-hosted email.
Indeed, self-hosted email is commonly rejected despite doing all these things. Google et al have successfully turned email into the domain of a few SaaS, and at half of them blatant spammers can message millions with no record of consent with the most obvious scams and have it delivered into the inbox. Hell, most spam these days I get from hacked Gmail accounts. The game is rigged, as they say.
Re: Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs
#90I use cloudflare's email remailer. i.e emails are mailed from from & to my Gmail via cloudflare. Using a custom email domain. Does this mean that my emails will no longer be sent?