Spam is back
theoutline.com
theoutline.com
Last week, one of my organization's user email accounts was hacked. It started getting used to send out spam. We caught it pretty quickly and updated the password so that the spammers couldn't use it anymore. But it was too late, we got listed on several spam blacklists. As such, all emails from our mail server started going into recipient mailbox spam folders. OK, we just get ourselves off of the spam blacklists, right?
Most of the spam blacklists gave us one of two options. First option was to manually request removal, some of them required sending an email to confirm what had happened and why we're confident the problem didn't exist anymore. Easy. Second option was to wait as their service monitored our email services to confirm if we were still sending out spam. If after a few days they confirmed that the spammy behaviour had stopped, we'd be automatically removed from their blacklist. Annoying wait, but reasonable methodology.
Then the annoying ones. One spam blacklist would not remove us for a week, though we could expedite the process by paying them $106 USD. Otherwise, we have a week of going into people's spam folders. It's a friggin racket. Dare I say even extortion? The other annoying spam blacklist said that we could not get removed from their list because we were on several other spam blacklists, including the blacklists that required us to wait a few days for them to monitor our email behaviour, AND the spam blacklist that wanted us to wait a week if we didn't pay $106 USD. So we're on one spam blacklist for a week due to not willing to pay extortion fees, and on the other spam blacklist for a week because they're too meta to develop their own spam blacklisting mechanisms and just follow what other blacklists are doing. The meta blacklist annoys me more than the extortioner. Why are they checking whether we're on other spam blacklists? They should be depending purely on their own capability to identify spammers, not the capability of other organizations. Why do they even exist? There's no value added by being meta here.
It really annoys me.
But unlike in the case of a website using Cloudflare's DDoS protection to fend off attacks, someone who gives up running their own mail server and signs up for Gmail isn't doing so in order to get any direct benefit from Gmail's spam filter. (Open-source spam filters have gotten good enough that they often do just as good a job as Gmail, if not better.) It's almost entirely because of the insane hassle of dealing with third-party blacklists as you said. Google and Microsoft should give them a medal or something.
Many of the blacklist operators are highly moralistic, too. You'd think they were on some sort of holy crusade against the ultimate evil. Of course you are partly at fault for e.g. not enforcing strict password policies on your users, but a small percentage of users are going to get hacked no matter what. I wish the blacklists would redirect at least 10% of their moral outrage at the danger of centralization that they're so willingly facilitating.
I don't like black holes, they're impossible to debug when something goes wrong. All email should be either rejected at the SMTP level or delivered to a mailbox (even if it's the spam folder) so there's a clear indication of what happened to it.
Also as a stopgap you can switch to a smarthost until you get delisted (SendGrid is decent).
Even $100 is really high for a person who runs a private mail server.
> but it's basically one-time.
Until they add you again.
Do I think this could be abused in a number of ways? Yes.
But as long as they only add you if you have actually sent spam this should be ok.
And if I did this I guess I'd try to come up with an free (but annoying so it would still be a punishment) way to get off tell list. Something like: go to this web address that is only reachable for 5 minutes at some random time. It will then give you instructions to actually send the removal request. ;-)
What's this mean though? How are they judging? I've worked for a company that soley sent transactional email from the domain and IP address in question (basically just receipts and password reset. Not even our (fully-opt in, optted-out-by-default) newsletters was ever sent from this domain and IP. Every few weeks we'd have to contend with some blacklist because a user had (mistakenly?) marked one of our emails as spam.
From my experience, it's an extremely inexact and sensitive, but neither precise nor accurate, process.
(Not to mention the time one of the major providers just began blackholeing the same server despite SPF and DKIM. No rejection message in the logs, just many, many, many customer support calls about missing receipts.)
> Do I think this could be abused in a number of ways? Yes.
> But as long as they only add you if you have actually sent spam this should be ok.
Simple, we create a blacklist for spam blacklists, any spam blacklists that misbehave are added to the spam blacklist blacklist and require a $100 fee to be removed from the blacklist blacklist.
I can already guess what your next question will be "But what monitors the spam blacklist blacklist?"
But don't bother asking - it's blacklists all the way down.
Then wait for a week.
It's all clean, except on http://www.spamrats.com (specifically the RATS-Dyna list, and I am not using a home connection.)
I know my mail server is not ideally configured, so I checked the details there. Turns out not only my IP is listed as spam, the whole C network is. "Worst Offender Alert", they call it. Apparently they want nothing to do with me because my neighbours look crap. As a result, I can't even request being removed. Now what, I quit my provider because he gave me the wrong IP?
Seriously, this is getting closer and closer to not even being allowed to send email yourself.
Meanwhile, I receive plenty of spam from gmail and yahoo accounts. I doubt this affects the rating of Google's and Microsoft's servers. I guess their size an money makes them legitimate, somehow?
(I reckon being a paying customer may mean they do not collect data. I don't trust them not to, though.)
That particular list is very well known for doing this. Essentially no one uses them, but they get a bunch of free traffic by being listed on mxtoolbox.
Their removal requirements are fairly absurd anyway (must provide them with a full customer list of everyone using your IPs)
It's extortion, plain and simple.
I would even make the price higher, so people would pay more attention to their information security practices. Like, sorry dude, if you're hacked -- it's your problem, not problem of all the innocent people who received the spam from your hacked accounts.
Once the fees become higher, there will be insurance plans for it, and insurance companies will require some basic level of security controls. There are already talks about it in IoT community.
It really annoys me when people think it's someone else to blame when they neglect their own information security and get hacked.
It really annoys me when random stranger know-it-alls proclaim all the answers that are already obvious and tried, acting as if others are incompetent.
Never mind that I clearly stated that I was most annoyed with the blacklist that was a meta list riding the coattails of other blacklists, more than the blacklist that wanted payment anyway.
> It really annoys me when people think it's someone else to blame when they neglect their own information security and get hacked.
Seriously, when did I ever say it's someone else to blame? It also really annoys me when people put words in other people's mouths.
Finally, if you knew anything about maintaining live systems, you'd know that technical issues are the smallest and easiest concern to handle when protecting infrastructure.
Please: do not animate things like that. Animation can be good when triggered by user interactions, to signify state transitions, but simple gratuitous animations can be quite annoying.
But the "spam is dead" message is totally misleading. Email spam is still pretty much alive and well. Try running an email server yourself or even publishing an address handled by Mailgun online.
Or, if you want some laughs, look at https://spa.mnesty.com/
I'm gonna start to block too.
The spam calls are ridiculous. I have to keep do not disturb on 24/7, but some have caught on that they can call twice in a row to get through.
If you block 500 numbers and then you apply for a job and the person who wants to call you back about the job just got a new prepaid phone, you might be blocking their number.
As a small email system operator, I have seen spam fluctuate greatly. In my case it accounts for around 99% of connections, and 95% of successful connections (valid reverse dns, working STARTTLS), but today it only accounted for about 10% of successful connections. Miraculously, I have seen penny stock spam in 2017.
"chase?" no, "wells fargo?", no, "bank of america?" no and then the person hung up on me.
Though I do want to make a comment on the advertising in this site - I really, really like it. They're big graphics for those Macallan Rare Cask ads, but they are designed nicely and aren't "in your face", even though they are extremely prominent.
I like this.
And every other website asking to push notifications on the desktop ?
And every Messenger bot ?
I take it that Google Calendar must've automatically imported them?
Ah well, I nuked that account anyway in my annual data spring cleaning
The first step is to start adopting standards that aren't free either in cost or in compute. For email, this could be as simple as requiring proof of work before accepting an email. For private telcos requiring the ability to charge the company connecting to my number would solve most of these problems too. I'd love spam if I had the equivalent of an 80's era 976 number.
:-(