What Mailchimp does to make sure emails get delivered
wired.com
wired.com
I have this idea for a "bonded email server". The idea is that smaller senders would pay a bond (say, $200) plus a small monthly fee to a bonding company, which has a trusted relationship with Google, Yahoo, Hotmail, etc. The bond ensures that you won't send spam through your mail servers and in exchange, the big hosts agree to whitelist the mail you're sending. After some period of time, you get your bond money back if you've been true to your word. You'd still pay your small monthly fee to the bonding company.
The database of "certified good" hosts could be maintained by means of DNS run by the bonding company.
The problem with the idea is that there's so little incentive for the big mail hosts to accept email from small senders. They'd much rather you use a Mailchimp for bulk sending and their own service (or one of their large competitors) for individual sending because they know that these are reliable partners.
Actually, I'd love a good SMTP service that had a good reputation, but most of what's out there is more bulk-mail oriented. I just want to own my own domain and send email but not be beholden to gmail nor deal with deliverability headaches.
Is it commercial email?
Or are you just interested in sending email to friends and family?
In the case it's both, which one is more important to you?
Let's say a remote mail server connects to mine to deliver an e-mail purporting to be from example.com (your business, which has an EV SSL/TLS certificate for the example.com web site).
The first thing to be done is to somehow verify that the mail is legitimately being send by the company. The best way we have to do this presently is via SPF and DKIM. We query DNS and the IP address of the remote mail server is listed in the TXT RR, so the SPF check passes. We query DNS for the key that the mail is DKIM-signed with, and that passes.
Now what? At minimum, we have to do another DNS query for the A RR for example.com, establish a TLS connection to example.com, retrieve the presented certificate, verify the certificate is valid (date, hostname match, etc.), verify the certificate is chained to a trusted root, and -- somehow -- check that the presented certificate is an EV cert. I don't know enough about EV certs to know if there's an easy, programmatic way to verify that a cert is EV vs. DV, etc., but let's assume that there is. There's also revocation/OCSP, etc., checks to be performed. And so on...
What you're proposing might work. That is, a company with an EV cert is probably unlikely to be sending out blatant spam, but I don't know of any existing tooling to do these types of checks. If it existed and were easily integrated, I would at least be willing to test it and see what the real-world results were (and it would be much more likely to become an acceptable tactic to use for distinguishing spam from non-spam). A plugin for amavis and/or SpamAssassin would probably go a long way towards making this happen.
All that said, do CAs publish lists of EV certs? It would be relatively easy to import a list of domains with valid EV certs and then say "if mail from one of these domains arrives with a valid DKIM signature, assume it is not spam".
Ironport was selling mail filtering appliances. They also sold dedicated spamming engines that were whitelisted by the mail filtering appliances. This playing both sides of the street made them something of a joke, and they had to drop the spam engine business. They were eventually acquired by Cisco after that.
[1] https://groups.google.com/forum/#!topic/news.admin.net-abuse...
If you're sending mail, you're crazy if you don't get your sending mail servers added there. It's easy to do and helps prove you're not spamming.
I'm always amazed at how many people don't know about, or use in reputation checks.
So my point is, lots of anti-spam services check it, but few people sending mail make an attempt to get their server listed in there properly.
Mail Servers get listed in there automatically, but if you go in there and vouch for your mailservers properly you're get a more trusted ranking, which translates into a higher anti-spam ranking when checks are done.
Pricing in general isn't an effective strategy to stop this unless it becomes more prohibitive than the profit margins - and that's a very big number.
I changed IP address in the last 18 months and despite great trepidation, was pleasantly surprised that deliverability was not degraded.
Paying a bond feels like protection money for something I think my domains/hosts already have: a good reputation.
I shall probably, with huge regret, hand over the delivery process to an external operator in the near future.
I haven't had any issues recently, but wonder... Are the failures still well-noticeable? I mean, when Gmail/Hotmail reject the letter - do they do it properly (SMTP 4xx/5xx rejection) or maybe they're now silently discarding it?
When I had the issues (even with large mail providers), my MTA had always generated me a bounce, and it had always contained something sensible and immediately useful - like a message that my DNS records got messed up or IP got in a blacklist. Every error message I saw contained links or clues to how the delivery problem could be resolved. Had this changed?
If you are sending out "legitimate" bulk mail, one of the best things I think you could do is use one of these E-mail Service Providers that will use a dedicated IP address for your email. That is, all mail you -- and only you -- send via Mailchimp/SES/etc. will always be sent from IP address a.b.c.d.
Everyday, I see many IP's belonging to these ESPs that end up blacklisted (either on public blacklists or our own, internal, automated blacklists). If you're using a service that sends out mail from multiple customers from a "shared" IP address, you WILL have delivery problems WHEN (not if) that IP address gets blacklisted or flagged.
I've managed and ran my own servers for years, including mail servers. I've never ran into any issues that so many others seem to when doing this, but I always make sure that I follow best practices and do things The Right Way(TM). This includes, nowadays, SPF, DKIM, DMARC, DNSWL, and so on.
We're fairly small and yet I can detect and put a stop to "spam outbreaks" quickly when they happen (such as when an e-mail user responds to a phishing e-mail, gives out their credentials, and their account is hijacked to send out spam), so these other providers (especially those who provide/specialize in e-mail services) certainly should be able to as well.
https://postmarkapp.com/blog/the-false-promises-of-dedicated... (Edit to add url)
They present several arguments both for and against dedicated IPs. From my own experiences, I don't believe that the "cons" outweigh the "pros".
FTA:
> By offering a dedicated IP for the majority of customers the ESP is basically saying “You do what you want, if you get blocked it’s your fault.” It also places a lot of heavy lifting on the customer, which defeats the purpose of paying for an infrastructure product in the first place.
No, by offering a dedicated IP the ESP is saying, "I don't want ONE customer to ruin things for all other customers". It doesn't one you can be careless or not take basic safeguards. It means that any "fallout" is contained and collateral damage is minimized.
> In addition to this, new dedicated IPs are just as bad as IP addresses with a bad reputation, since it has no reputation at all.
I'm not sure that's the case. Anecdotally, I've brought up additional mail servers at times and put them into service without doing any "warming up" and not ran into issues. My servers aren't sending out any bulk mail, however, so perhaps this is why it hasn't been an issue.
> The other misconception with dedicated IP addresses is that each one is completely independent. For instance, if one customer gets blocked, all other IPs are fine, right? Wrong. ISPs and blacklists will monitor entire IP ranges and domains. If one IP causes enough problems, traffic from the entire subnet or domain could be blocked.
Yeah, some of the RBLs as well as myself sometimes block ranges. That typically only happens when there are $bignum IPs in that range that have already been blocked. Pretty much everyone blocks individual IPs at first. If it happens that, for example, I end up blacklisting 15 IPs out of a /24 (allocated to somewhere in China, perhaps) then yes, I'll often just list the whole /24 instead. That's not the first step, however.
> The final reason, and this one is important, is that ISPs are starting to place a lot of weight on domain reputation, not just IP reputation. My guess is that over time IP reputation will slowly fade away while more weight is given to domain reputation along with authentication standards like DKIM.
I certainly agree that domain reputation is becoming more important. It's not an "either or", however. While the reputation of the sending domain (assuming valid DKIM signatures) is certainly one factor to consider, IP reputation isn't going away any time soon. Domain reputation is just an additional attributes that will be considered when making the "spam/not spam" decision.
One certainly shouldn't use IP reputation, in isolation, to make that "spam/not spam" decision but as just one variable in the whole formula. The first time I blacklist an IP, it's automatically removed after 12 hours. Shit happens sometimes, even with many protective measures in place. Every subsequent time a "repeat offender" gets listed, however, the length of time it remains listed grows until, eventually, it just stays on the list. In addition, as mentioned above, ranges sometimes gets listed as well. A quick glance shows that the largest netblock I've listed is a /12, as well as a handful of /15s and /16s, but those are exceptions. The overwhelming majority (of ranges) are /24s or smaller.
Any large-scale sender for whom deliverability is critical should be using a dedicated IP. By virtue of hosting multiple customers, shared IPs appear to send more frequently, and any behavior on a shared IP resulting in a blacklist entry affects everyone else on that IP.
We're pretty aware of this problem at SendGrid. Even though we make every effort to cull bad senders from our shared pools, our enterprise senders nearly always prefer dedicated IPs, which let them build up a trusted reputation without interference from others.
We're using Mandrill, but we am looking at alternatives longer term.
Dedicated IP packages won't be affected by the sending habits of other users. They are more cost-efficient for high-volume senders, but we do have dedicated IP tiers starting at the $80/mo. mark, which allows up to 100k mails a month.
With either option, we're always happy to work with you if you're having deliverability issues - and that includes checking IPs for blacklist status.
That said, there is a case to be made for very large senders to have their own IPs. We agree with that. Our point is mainly that the vast majority of senders don't need it, and should rather use the stellar reputation of our shared IPs to ensure good deliverability.
If anyone would like to chat more, I'm happy to jump on a call - https://calendly.com/rianvdm/postmark-customer-calls/
- SendGrid
[I am not in anyway affiliated to Mailchimp, and don't even use their services. We use Amazon SES]
How do they know if you open the email (aren't third party images etc specifically blocked or cached for this reason)?
I wonder what solution would be better.
I use MailChimp to keep in touch with customers. They love it.
I ignored the rest of it.
Resent: feel bitterness or indignation at (a circumstance, action, or person): she resented the fact that I had children.
I think the second one fits better, you resent that the parent poster called MailChimp "spam"
http://tvtropes.org/pmwiki/pmwiki.php/Main/IResembleThatRema...
It's why I don't blacklist MC; in my experience they are trustworthy, and bulk mail does have limited, legitimate use.
MailChimp does have a nice WYSIWYG editor that SES is missing. But I can not justify paying many thousands a year extra just for a nice WYSIWYG editor.
Disclosure: I'm an engineer there. Let me know if you have questions.
Delivery is an ongoing issue though.
Does anyone have any experience with deliverability, comparing Amazon SES to something like Mailchimp? Are the deliverability rates of Mailchimp really that much better?
Not sure if SES offers this. The other guys will. That alone could be reason to try it out? Shouldn't be hard to with gateways for 1 blast and see how it performs.
Our emails sent through SES, often ended up in people's spam folder despite doing the requisite verifications (SPF, DKIM).
We switched to Mandrill and noticed significant improvements. We don't send alot of emails, but for transactional emails, it's important those are delivered.
Sending emails without images, in plain text, also does improve delivery especially to corporate emails.
We were exploring dedicated IPs, but those require warming up, so frankly we don't send many emails.
Love to hear any other advise for improving email delivery.
Spam filters are so aggressive & dumb that they can't filter out a false spam report. Moreover, if I've explicitly added a contact to my address book & that contact has done the same for me, and we've been mailing for 10+ years, almost daily, often multiple times a day, then it's really annoying & unexpected for our email to end up in spam.
Hate spammers who've made a simple communication so complex for everyone.
/rant
TL;DR of this comment: Mass email is almost a lost cause, and even MailChimp cannot really help everyone because of the players in email platforms.
I have a very limited experience where I tried MailChimp for a small set of committed people (about 100) who had voluntarily given their email addresses for receiving notifications for a specific purpose. It didn't really work for the first (and important) email and we had to resort to just mailing people in BCC and hoping they'd receive it. The content was also reviewed a few times to make sure it didn't look like a spammy email.
There were multiple problems, and I didn't know (and there was no way to know) if the problems were on MailChimp's side or Gmail or both. Worse, there is no way to help oneself in such situations to increase the email delivery rate.
1. On follow up, several recipients said that they didn't even receive the mail. It wasn't in the spam folder or the "Promotions" folder of Gmail either. MailChimp's statistics didn't indicate any delivery issues or that it wouldn't deliver them (am not referring to the mail opening click tracking/beacon tracking). It showed all of them as sent.
2. Gmail by default seems to classify emails as promotions when they come from Mailchimp or other providers. This means, for all practical purposes, the emails are invisible to people using the web interface. People aren't used to checking anything other than the inbox there and ignore that increasing count of unread mails in promotions.
3. For most people who now check emails on mobile devices, they do not look at the spam folder at all. With every person having multiple email addresses, they seem to have a list of inboxes they look through and act. All the other folders in every mailbox are ignored. So any email that goes into spam is more likely to be missed, and later gone forever after the limited retention period of the providers.
4. Though email is the only (?) federated, widely and easily available communication platform, providers like Gmail have cornered the market and dictate with a very heavy hand what ought to be delivered and what oughtn't. At least in my case, I may have had better luck using Google Groups instead of trying MailChimp just for the templates, personalization and all the nice features that can never trump emails being delivered to the recipients. But even that may not have worked.
5. In my observation, Gmail doesn't trust users sending mails to multiple people and likely doesn't deliver mails or puts them in the spam folders. I can't imagine that at its scale, Google seems incompetent in differentiating one person, using Gmail from a specific location boundary (IP address range, browser, OS) for quite sometime who wants to send a mail to several people, from spammers and bots. It ends up punishing everybody.
To MailChimp's credit, the free tier is generous for people with very low to moderate frequency and subscriber needs. MailChimp's website has a lot of useful information on email campaigns.
Overall, mass email of any kind is fraught with more problems in getting the message to others than other media like the walled garden variety of chat and social media platforms. I wouldn't rely on MailChimp or any other platform for anything that needs time bound and reliable delivery. You might as well collect people's phone numbers and call them instead.
People have been foolishly saying for a long time that "email is dead" every time they see a new social network or a chat platform, but I'd say that "mass email is dead" for most people (personal emails, small businesses, organizations and small communities) without them even knowing what went wrong or what they could do to change things.