Want to send a mail from home, as should be the norm? First, you need to get through your ISP's firewall. Many block the outgoing SMTP port, and there is nothing you can do about it. Others forbid you to use that port by contract. Some offer an SMTP relay to compensate, but then you're no longer sending your own email. Plus, they often limit you to 40 emails per day or so, and can spy on you, TLS or no.
Once your mail is sent, it has to pass through spam filters, and they all blacklist residential IP addresses.
This is even worse than manually spying on people: automation gives leverage. Now all we have to do is repurpose these targeted ad engine to deduce things other than buying preferences.
Sure, they have their surface ethic (and Alphabet's employees have their actual ethic), but the tools they have in place for total surveillance is downright chilling.
I don't know what point you're trying to make. Are you assuming everyone uses Google's webmail interface or their apps? Maybe those blur the lines of classic Internet email delivery but when I use Mail.app to send an email, I am the one doing the emailing, not the Google SMTP server acting as a mail transfer agent (MTA).
> Many block the outgoing SMTP port
Comcast doesn't, Time Warner doesn't, Verizon doesn't. My hunch is the large majority of U.S. residential ISP customers can connect to an SMTP server other than their ISP's.
You seem to be confusing the MSA (https://en.wikipedia.org/wiki/Mail_submission_agent) and the MTA. If today your MUA (Mail.app) tried to connect to the destination mail host via SMTP directly it would get rejected. Some early MUAs did actually do that, but today almost all email gets relayed via an MSA and one or more MTAs.
Your MUA would be rejected if it acted as an MTA and connected on port 25 without authenticating. "Using the same host as me" is the case because the mail server knows that it is "your host" because your MUA is connecting to your email server's MSA using SMTP AUTH on port 587 or 465.
In my book, "sending your own email" means you operate your own mail server, without using any third party relay (not Gmail's, not your ISP's).
I'm personally halfway there: I have root access to a virtual machine on the cloud (gandi.net), and configured it to relay my email for me. Next step would be to have physical control, but I kinda abandoned that idea when I learned that residential IPs are blacklisted (Hotmail even made it an explicit policy, it won't even appear in the recipient's spam folder).
Virtually no one else reads that book. To everyone else, the user operating the MUA is sending their own email.
Also, they control your right to send and receive email: if your account is terminated for some reason (they reserve the right to, blah, blah), you cannot move to a new provider, or redirect inbound mail or nothing: they own your email address.
Still think your send your own email? Fool.
Besides, there's more to it than (in)security. For instance, what happens to your various accounts tied to your email if your account gets terminated? You will not be able to redirect your incoming emails, and notifying your friends will be difficult if you relied on the web interface's address book.
Also, it's a hole ecosystem: if you use a big webmail, then you allow your provider to spy on everyone you exchange emails with. If you have the means to avoid those, it is your responsibility to do so. Surely you don't like inflicting this kind of spying on your friends, do you?
So far, the only reliable way to have proper control over our own email is to control our own domain name, and operate our own mail server. Or at least use small, trustworthy providers. In other words, "send our own email".
It's intellectual property/monopoly all over again. One will chose the terms that suits one's side of the debate. I side for privacy, security, and reliability; and argue that webmail providers do not provide any of them. This thread is the first time my "sending one's own email" wording hasn't been an unmitigated success.
The issue here is one of control: relays can basically read every mail they relay, and the likes of Gmail do. Spying on you is how they make money. No targeted ad would be possible otherwise. And the automation only makes it worse (because it scales, and can be repurposed).
And the user can do nothing about it. That total lack of control is why I maintain they do not, in fact, send their own email. Now there's PGP, but that would look conspicuous. If everyone had their own mail server, TLS alone would provide pretty good security.
What angers me the most is, even I don't have a choice: most of my friends use a big webmail provider, which invades my privacy whenever I communicate with them. This would never happen if we all had our own mail servers.
Also, it doesn't hide the authenticated user, envelope mail from or envelope rcpt to values used in the message, unless, like you said, the sender and recipient(s) are using their own SMTP servers.
I run my own mail server. When I send an email via the web interface, would you not agree the MUA is attempting to directly connect to the destination host?
Depending on different factors, it may be classified as spam by the recipient, but from a reputable IP address it shouldn’t normally be rejected outright. Of course there are other factors like SPF, greylisting, etc... but email can be directly delivered.