Gmail spam-filters Stripe security messages as well
github.com
github.com
Just now, 2 months later, the same issue happened with a security login email from Stripe.
It just happened for the same user, but it seems to be a long standing issue. In the old thread another user was complaining about Stripe emails getting the same treatment: https://news.ycombinator.com/item?id=19100629
Because companies send a LOT of spam emails / promotions etc that they have to come up with alternate domains to send emails. On customer side its very difficult to know the truth.
And I don't see why you'd need to be less tech savvy to use "mark as spam" on automated e-mails sent to you that you didn't ask for and don't want to receive.
The likes of Google and Microsoft have applied embrace-extend-extinguish to possibly the most important communications medium of modern terms, successfully making it less reliable than it has ever been for sending legitimate, actually important stuff. They really should be strongly and publicly criticised for that. False positives in spam detection are, for the most part, more damaging than false negatives.
The "via" next to the sender address in your screenshots (https://support.google.com/mail/answer/1311182?hl=en) suggests that there might be a DMARC problem (on their side or yours) that could be causing this filtering.
https://news.ycombinator.com/item?id=19100332
As mentioned there, the "via" most likely comes from the fact that the recipient address is a Google Groups address that multiple people can receive.
Also, as mentioned in the Github issue, Google's G Suite security staff has checked the headers (in the Paypal case) and come to the conclusion that nothing is wrong with them, and that it's a Gmail issue (and that the fact that the recipient is a Groups address should make no difference for spam filtering).
https://github.com/nh2/gmail-spamfilters-paypal-security-mes...
At least, this has been my experience for a while now.
edit: typo
I've kept those "tags" turned off on every Gmail account I control — I'd rather not risk having something important enter "social" or "promotions".
https://webapps.stackexchange.com/questions/69442/how-to-dis...
edit: and even then they think they know better and trash some mails as regardless.
It kind of sucks that we still use email for password reset and billing stuff. It's like the digital equivalent of certified mail with most of the same problems.
And surely by now Google spam filtering has a pretty good idea what emails can be categorized as "financial institution" likely, and if they aren't conforming to an agreed upon DMARC policy to put those in spam?
Or even better, a mandatory agreed upon tag that indicates the content is 'financial institution account security notification' related (i.e. not marketing spam from that institution), but any emails that use that tag but don't also use the agreed upon DMARC policy always go to spam.
I notified Namecheap, including the DKIM signatures, but they told me they couldn't do anything about most of them because "they are hosted with another company". ¯\_(ツ)_/¯
Though if the registrar deleted quickly these domains AND didn't make them so ridiculously cheap, maybe it would become too expansive for spammers.
If the spammers can only reach an initial small sample and the domain is next to useless after that, even 99ct domains should not be worth it.
* Or whatever is a normal number. I know lots of people just leave the message as 'read' and don't bother marking it. I don't know how many users do this. Maybe one could also keep track of users who regularly mark something as spam and only count the percentage among those.
An issue with this is method is that company A may subscribe to company B's mailing list en masse, and then tag its mails as spam, causing all mails from B to be classified as spam. (Maybe that's what happened to get Paypal and Stripe banned from Gmail, who knows.)
Whether or not additional complexity is justified is something that can be measured in a case like this - and that's exactly what Gmail does, using a variety of different metrics, which allows them to make an informed decision about whether to take on the additional complexity cost.
Should they weight false positives for this message type more heavily in their accuracy metrics? Definitely, these are particularly critical to classify correctly.
And yes, every major consumer email provider tracks complaint and response rate metrics (as well as many other metrics and indicators) and uses those as part of their filtering. A spam ratio of > 2% is often enough to cause filtering - that's actually toward the very top end of the complaint rate spectrum for messages that are delivered to the inbox.
Presumably mail server operators are reporting obvious spammers to (centralised) blacklists, but it would perhaps be possible to better tune a heuristic (and increase the cost to spammers) by sharing information on the number of non-spam messages received.
This could actually be done in a provable and relatively privacy-preserving way, if sending mail servers included signatures of the hashes of the emails they were sending. Every email that was received by a domain of unknown reputation could have its hash+sig sent to a public distributed log somewhere.
If this was combined with some sort of good-behaviour bond that domain registrars required (for domains that send email) and which was paid back after a reputation was established, it would make cheap domains much more expensive for spammers.
If the cost of domains is already such a significant expenditure that they need to look for sub-one dollar registrations, then requiring, say, a $10 bond on all domains with an MX record might erase their profit margins completely.
(There is a question of what constitutes "good behaviour" and whether that can be gamed by having spam domains reporting each other as sending legitimate email, but if these ratings are public then people can choose which ratings to trust. Domain age would probably be a good heuristic there too.)
The expectation is that by the time they try to deliver a second time you'll get "spam" results if you query DNS-based blacklists, etc, as other people have reported it already.
These days greylisting doesn't seem to be so useful, as >50% of the spam I receive is sent from gmail/yahoo/similar. Hosts too big to block (sigh).
[1] eg. today I got a mail from IKEA from an address @ods2.net instead of the usual @ikea.com one; I had no idea I would have had to whitelist
[2] Which happens and will continue to happen as long as most mailboxes are not configured to drop messages without a valid DMARC. Chicken and egg problem.
In the paypal example, the 'via' in the from address line is an indicator the message is not DMARC aligned (but doesn't tell us whether or not the actual originating domain publishes a formal DMARC record - I can't tell that since it's blacked out in the GH post).
So for the paypal example, you're right, it looks like they're most likely not following best practices. It may be possible that the 'via' domain is simply a different legitimate paypal domain, which is an edge case that DMARC isn't designed to cover - I think we'll see a technical standard emerge in the next 5 years to handle that kind of thing; maybe built on some of what BIMI is doing - https://www.ietf.org/id/draft-bkl-bimi-overview-00.txt
We had a problem with following emails:
- all emails from sns.amazonaws.com are in spam
- all Stripe emails about "Suspected fraudulent payment on your Stripe account" are in spam
They all say "Similar messages were used to steal people's personal information. Avoid clicking links, downloading attachments, or replying with personal information." Anyway, if you depend on G Suite email to receive important notifications from PayPal, Stripe, or Amazon you will need to monitor your spam folder. It seems like there are some keywords (invoice, payment - I really do not know.) which will trigger spam filter.
However some of them do not get spam filtered, only a chunk of them do. It's weird because these come from YouTube, so it's a similar problem where Gmail is filtering Google emails....
Please check your Spam folder, and mark the legitimate emails as such.
Hopefully it'll help the folks (or AI) over at Gmail get better!
I've also repeatedly seen them suddenly spam filter individual messages in long threads of conversation. Like they weren't taking into account that a message was part of a two way conversation at all, even though they have In-Reply-To and Reference headers linking them to those non spam filtered conversations.
They also randomly spam filter transactional emails that we send from our servers that are from our own domain, to the same domain as hosted by GMail, that is fully validated by SPF, DKIM and DMARC. That should never happen. We clearly trust our own domain, so if mail from that domain is authenticated, let the bloody email through 100% of the time!
It's like they spent all their time working on how to blacklist email, and zero time working on when to whitelist it.
The most important part of a spam filter is the whitelisting.
I don't send out bulk or promotional emails, I use SPF and DKIM, and I've still seen a lot go to spam. My mail is hosted by FastMail, not a home server.
Given that banks seem unable to send e-mail that doesn't look like phishing (using non-https links and often separate domains), I don't have high confidence that they can get the basics right.
I am an freelance consultant, and a number of times I have seen my business email (hosted at FastMail) go to spam in a Google hosted mailbox. As a single consultant, I don't send a huge volume of mail because a number of my clients set me up with their internal email for business communication. The mail that I do send is invoices, and setting up contract signing; that sort of thing. The mails are always expected communication. I have SPF and DKIM configured and validated by FastMail. Mail somehow still goes to spam.
I set up with google's postmaster tools, but it shows nothing because I don't send a big enough volume of emails for it to care.
I set up dmarc to get reports when mail is delivered under my domain to a GMail or G Suite hosted address. Every single dmarc report (it's easy for me to keep on top of them because my mail volume is that low) is "spf: pass; dkim: pass".
I really don't like that the only way to get this looked at is through publicly shaming Google like this; I have not seen any way I can talk to somebody at Google to solve the problem. FastMail support said they were unable to help me solve it either, suggesting I need to send mail into the Google garden and have the recipient click "not spam" until their filter learns.
I assume that is the problem because when I reported to Google support about "why this Stripe email is in spam" and I provide them with email body. Then reply from Google G Suite support went to spam (since it had email body in it).
And of course the fact that you use FastMail does not help.
I’m not sure you can do that with a setting, but there is a workaround where you create a filter that excludes messages matching some random UUID, and tick the “Never send to spam” action.
So far to me the trade-off has been worth it (YMMV). Not a huge burden in terms of junk mail influx in my inbox, but one does have to be on alert for high-quality phishing when reading mail (check headers, for example).
P.S. If any Gmail folks are here: There's a bug in Gmail/G Suite that might as well be equivalent to marking an email as spam, since it prevents you from seeing emails: last time I checked, the "Important" section of Priority Inbox seemed to sort based on the timestamp of the most recent important email in the conversation, not the most recent email in the conversation. So if a subsequent email comes that isn't Important, the conversation doesn't pop up to the top -- so if it's not on your screen already, you don't see it as unread.
> Authentication-Results: mx.google.com; spf=softfail (google.com: domain of transitioning {user@domain} does not designate {IP} as permitted sender)
So I guess you can use that to blame the domain owner, but I feel like the fact that it was a reply to my own email should've been enough to allow it through? Moreover, there are other emails around that time that weren't replies but still softfailed SPF, and they were still let through.
include:_spf.google.com
... in order to send outbound mail from Gmail effectively. Many people don’t realize that Gmail sends mail to itself over SMTP, not some special magic protocol, and it doesn’t exempt itself from SPF checks and whatnot.Also for a minor correction (not that I think this matters):
It's not free, it's paid for, because it's a G Suite account.
Here are some of them:
1. The likelihood of you clicking and opening such an email is higher than regular emails
2. Phishers and scammers know this (point 1 above)
3. Malicious content is embedded in such emails
4. It is very effective, even against tech-savvy individuals
Isn't that what content scanning is supposed to check for? I mean, it's not like they're not scanning the email body for keyword extrapolation, anyways, right?
To be fair, though, Stripe should change their SPF record to hard-fail (-all).
;; ANSWER SECTION:
stripe.com. 600 IN TXT "v=spf1 ip4:173.193.210.51/32 ip4:166.78.69.60/32 ip4:198.2.180.60/32 ip4:13.111.2.227/32 include:spf1.stripe.com include:greenhouse-outbound-mail.stripe.com ~all"
stripe.com. 600 IN TXT "docusign=4a93db58-af07-4632-a881-b569d41a6c57"
You can't spoof those addresses convincingly unless you compromise a legitimate mail server listed in the SPF, or hijack BGP to impersonate a legitimate mail server in the SPF.
Google is filtering known trustworthy senders for dubious reasons.
> Why is this message in spam? It is similar to messages that were identified as spam in the past.
Oh really Google? You've identified your own emails as spam? Well then!
It’s sad and annoying.