From the prospective subscriber’s perspective, that’s your problem to worry about — not theirs.
> We don’t sell any data.
How should users know that? It’s also not just a matter of selling data — almost all companies will spam your email address, even if you check the box asking them not to.
exactly...which is why there are blacklists like the one linked in the OP.
- multiple sign ups using different emails and similar name
- same ip address
- same data
etc.
Don't underestimate greed or laziness.
But some obvious candidates are
1) discontinue free trials.
2) provide enough obvious value to convert the current funnel of free trials into paying customers at a high enough rate that you don't care about the "freeloaders"
3) radically differentiate the support available on free trial accounts.
In the long run, and dev effort/time spend integrating email domain blacklists is just time taken away from building features that add value to the service/company. It's only possible that spending that time adding features will turn the conversion rate up, but its guaranteed that fencing off the top of the funnel will reduce the number of conversions.
Mitigation against abusers of a service is a valid strategy.
I find this very hard to believe. "Spam" has a specific definition; the most important bit of which is that it is unsolicited. Mails landing in your inbox that you'd rather not get, but which are not unsolicited (say, by you signing up for an account and confirming your address), are not spam by definition.
"Almost all companies" would find themselves unable to send email in short order if what they were delivering was spam.
Definitions are important. Let's not misuse them.
For 98% percent of services I use I mainly want my email for one thing: a way to reset my password.
Often I need to unsubscribe from each of them individually and then navigate some sort of "notification preferences" interface. Even after that has been done a lot of them seem to default any new newsletter or preference to on instead of deriving the preference from the closest existing option.
It isn't spam because you don't want it. If you actually don't want it, then click 'unsubscribe' - and if they continue to bother you afterwards (which, FWIW, I've seen a reputable company do a grand total of once in years), then and only then, is it spam.
It isn’t not spam because you want to send it.
You’re departing substantially from both the historical and commonly understood, contemporary definition of spam.
» Your Prime Membership: {{first name}} {{last name}}, discover the latest in deals and entertainment included with Prime
Commercial email, differentiated from spam in that you have a commercial relationship with Amazon that you initiated and agreed to (i.e. solicited), and as such, they are allowed to market to you until such time as you ask them to stop.
I can see my opinion on this matter isn't a common one on HN.
Your opinion isn’t common among anyone other than marketers trying to justify sending spam.
I'm disappointed to see that attitude here.
Did I sign up for a mailing list?
Yes - not spam
No - spam.
Creating an account with a company is not signing up for mailing lists unless there's a choice presented. Yeah, you can hide consent in the ToS that nobody reads, but that's not asking for permission.
The "mark as spam" button gives users the ability to keep their inbox clean and you shouldn't be faulting them for using it.
Not to mention, even if we agree for a minute that the report spam button should only be used for emails that conform to the legal definition of spam, which law should we be following? The US' definition of spam is much more liberal than the EU GDPR's one for example.
solicit, v 1. To ask from with earnestness
unsolicited, adj 1. not asked for
Your justifications hinge entirely on a very unusual and rather tortured definition of “solicit”.
It's not a false positive. The filter needs to be tuned to what your users think is spam, that is what spam filters are for. You are not the gatekeeper of what other people are allowed to think is spam.
That's not what that word means. I didn't solicit marketing emails; the only emails I asked for were the bare minimum to open an account and anything needed for orders that I initiated.
Man, oh, man, you're funny. Even more so as it is apparently unintentional and you're being totally serious.
To the rest of the world, i.e. everyone who isn't a spammer, 'email I'd rather not have in my inbox' is and has always been the exact definition of 'spam'.
HTH!
That conflicting definition is why the people receiving your email marketing get so mad at you. They would rather have not given you their email at all, but they have to, and they don't want emails from you, but they get them anyway. They don't click your link to unsubscribe because they don't think it would work, and probably just make things worse. So they mark your email as spam, send it to their junk folder, and the returns on your email continue declining, and eventually the mail services start blacklisting you.
Some EU countries require that you offer a simple and effective option to opt-out when gathering the contact details. Depending on the content, that can be a required to be an opt-in toggle.
It's not enough to offer users a way to unsubscribe once you've already started spamming them, there should be a way to not have the first spammy newsletter/newsletter group.
Also, it is presicely spam because I don’t want it, whether you have a right or even obligation to send it or not.
[1] https://ico.org.uk/for-organisations/guide-to-data-protectio...
Do you just let it fill up your inbox and essentially make it unusable as it's saturated with marketing spam? Do you read every single incoming email (if so how do you find time and how do you justify spending that time for this instead of other, more productive/fulfilling endeavors)? Do you have some magical, bulletproof AI that can classify and hide these marketing emails with 100% accuracy? Do you outsource the management of your inbox to someone else and if so how do you justify paying for that?
When I get email I don't want from a company I have an account with, I scroll to the bottom and click 'unsubscribe'. I then don't get anymore of those kinds of emails.
What I absolutely do not do is throw a hissy fit and click 'report spam' (which not fucks up my own bayes classifiers and makes false positives more likely, but sends harmful false reports to antispam orgs).
Seems to work quite well. Certainly well enough that I can't comprehend the level of snark and vitriol received here.
> of those kinds of emails [emphasis mine]
Also keep in mind that scummy companies have caught on to that and now have dozens of different categories of marketing emails and unsubscribing merely unsubscribes you from one of them.
Your definition is based on what’s legal under the “established business relationship” exemption in the CAN-SPAM act, not any “commonly-accepted objective standard” of what spam is.
So then it wasn't originally defined as per your preferred legal wording, now was it?
> RBLs came into being in 1997, Spamhaus in 1998.
And did they coin the expression, or was the concept itself around long before that...? (A: AFAIK, at least a decade earlier.)
> You'll note precisely none of these organizations (in any country) blacklisting Amazon, or any other company, because they send marketing emails to their existing customers.
Ah. So it's not actually the legal definition that is important, but the corporate one. OK, gotcha, that is of course so much better. (Blindingly obvious: /s)
[Edit: Added missing quote marker > ]
But, sure, say we go with your wishes and, as someone else suggested, call your spam something else than "spam" -- let's go with their suggestion and call it "trash email". Then the category -- or, now, categories -- of stuff that we want to get rid of from our inboxes become, in stead of just "spam", the more cumbersome "spam and trash email".
I'm sure you see the problem that immediately rears its ugly head: Language is lazy. "Spam and trash email" will in daily speech, inevitably, shortly become... "Spam". You may try to resist that, and as a longtime linguistic prescriptivist I extend you my sympathies... (But, psst, spoiler alert: This quixotic struggle is doomed to fail.)
But, anyway, you are of course perfectly free to keep campaigning for your cause. Only, in the name of all that is decent, be honest about it and call it for what it is: You're not defending spam, "only" trash.
Maybe after a while you'll realise why the rest of the world sees no difference in your distinction.
Maybe if enough scummy companies have to mess about getting de-blacklisted, they might reevaluate whether their emails serve their customers, themselves, or, more likely, neither the company nor the customer but rather someone in between who is using some artificial metric (maybe "clients reached", "tracking pixels delivered", whatever) to angle for a pay rise.
I also don't understand why "marketers" want to put stuff in my email inbox or anything else I use to receive real communications that I just don't want.
I’m just a lowly user. Reporting it as spam is the only recourse I have.
Thanks to years of abuse of my email address by marketers I am all out of fucks to give.
This itself is a redefinition of “spam” to exclude the types of spam businesses want to send.
There’s a two-part test I use to define “spam”, which I think is aligned with both the historic definition, and how most users perceive it:
1) An e-mail is a marketing e-mail if, on the balance, the e-mail primarily benefits the sender, not the recipient.
2) A marketing e-mail is spam if the user did not explicitly opt-in to receiving them.
The legal definition of spam arose as a distortion of the preexisting concept lobbied for by spammers to allow as much spam as politically possible while allowing politicians to be seen as “doing something” about the spam problem.
Merriam-webster (https://www.merriam-webster.com/dictionary/spam)
"e-mail that is not wanted"
Oxford (via google https://www.google.com/search?client=safari&rls=en&q=oxford+...)
"irrelevant or inappropriate messages sent on the internet to a large number of recipients."
Neither is your absurd definition.
And to be clear, entering a business agreement for a product or service you sell, is not me soliciting anything other than that product. Marketing emails, "product updates", etc are not the product or service I am paying for.
Not only do I have zero reason to trust you when you say that (because every person planning on selling my data ways the same thing).
But I also have zero reason to trust you're skilled or resourced enough to adequately secure my data (or have sufficient motivation to do so).
And I also know that one day you'll likely sell your SAAS, and will have no control over what the people you sell it to will do.
If you've got enough traction that people are willing to jump through minor disposable email address hoops to use your product for longer than the free trial, but not enough traction to convince them to pay for it, I reckon you'd be better off building more features that add value and reconsidering your free trial plan - instead of devoting any dev effort into rejecting disposable emails.
That explantion was acceptable to me; if it works for them. I might note that they only send me transactional email (statement of charges for the month) and no marketing.
I have sympathy for businesses out to make a buck: they are the reason I get to put food on my table. But on the scale of balance between users' rights and business rights over the last twenty years, it's no contest: business rights reign triumphant.
That's a lot of effort to go through to avoid paying for something. And I guess you can't keep your data or configuration, if the app has any.
I argue that maths is negative for your business and a better approachbis to make it easy tonget started, but show them clear benefit of switching plans. Maybe a cheap entry level plan with a small set of convenience features, not available to the test account.
* Reduce the trial period for users with a disposable email.
* Don't allow data import/export so that creating a new account is more work.
* Reduce cookie lifetime so that a login is needed more often.
And yes, it is not a meaningful number of people that do so, but over time this is very ugly and frustrating (as it requires manual intervention) and you block the disposable Email provider they used ...
Missing the forest for the trees and all
This seems like an ego issue honestly. Like you feel like you are being taken advantage of. If only a very small numbers of users are doing this then I don't see it worth the dev time to block the email providers they use possibly hurting valid customers. Just leave it alone. I use Relay for services I genuinely pay for but don't want to give out my email address in case of leaks.
Suggest using the Standard plan but with significant rate limiting. Like 5/day.
If they want to remove that, enter credit card details which you verify.
You can still have the trial expire and the credit card isn't ever charged; but you can track people on trials more easily.
I think that someone who doesn't want to give their real email address to try out a service is even less likely to trust an unknown service with their credit card number. There are just too many "free trials" that promise to not charge your credit card and then make you jump all sorts of hurdles (e.g., having to call) to cancel the free trial.
I think you'd be surprised. Credit cards are easier to dispose of then email addresses, and they offer greater protection with fraud and billing dispute processes. Some banks even offer virtual cards that let you set limits on duration or amount.
And that's OK. The problem as I understand it is that people are signing up with disposable email addresses, using the API key they receive for 7 days, and then signing up again. They are leeches, exploiting the generous free trial.
If they stop signing up, no problem. Other people who sign up with a disposable email address can test within the restrictions, and once they trust the service have a choice to enter card details or not. If they are planning to do business with the service, they're going to have to trust it with card details.
Besides, the whole idea of a "disposable email blacklist" is ridiculous. Are you going to block Gmail? Gmail addresses take like 1 minute to make. If not, you've already lost the battle, so do us all a favor and stop this blacklist nonsense.
At most you may send reminders, but even then, those may end up in a spambox?
Even once you've verified the email, you have not much of a guarantee it will stay verified/working long. That's more the subscriber's problem, if they want to continue to use your product.
People may exploit paid services by creating many new accounts -
1. Free trials: When trail period ends, create a new account.
2. Services with metered billing: Use the service, then refuse to pay. Then create a new account. Then refuse to pay. Then create a new account...
Of course, (theoretically) if the service provider has enough resources (i.e., money, time, knowledge...), they can always find a better solution than banning all disposable emails.
The difference between real and disposable is manufactured. A novice could register a domain, sign up for email hosting, and set up a catch all for cheap.
"Would have paid for the service" vs "Are actively working to use the service without paying for it" are two different things.
I worked for a company that had some free tools on the web, with no published API. Those tools were scraped well above the T&C limitations to be mined by other companies.
We had a "free forever" account that you could use to monitor a single domain. Within the user table there were multiple instances of 20 to 300 (worst case) myaccount+<domain>@mycompanydomain.com trying to abuse the single domain rule without paying for it. In one case, the results were being packaged up to be shown in somebody else's product.
I'm certainly not advocating for spam or selling data (the company I mentioned didn't do this either), but abuse it the more common use case that web businesses deal with. To combat abuse, 90% of the battle is to identify where the abuse is coming from first.
So, make it worthwhile to pay for the product.
If it is now mainstream to basically feel you're entitled on setting the terms for other businesses or stealing their software then nobody needs to complain when any email relay service gets just blacklisted. If people now think it's okay to abuse multiple accounts to avoid paying for software that they use and that costs money to build then nobody needs to be surprised that everything gets an identity verification.
It's exactly how it works, if you want to succeed. If you don't offer value that enough people are willing to pay, you still own the product, but it's worthless.
Yes, it really is how it works.
> If you create something and unless you license it permissively that product is yours and you get to set the terms and conditions.
And if you want people to pay for it, you have to offer enough marginal value over not paying for it so that they choose to do so. The concrete, social, and personal moral consequences of violating social norms can provide part of that value by weighing negatively on the “not” side, in the case there is an available but “not permitted” mechanism which gives the benefits without paying. But that doesn't change the basic fact that you have to provide adequate value if you want people to voluntarily pay.
> If people now think it's okay to abuse multiple accounts to avoid paying for software that they use
Then models where you give the full service for free for each account with the limits actually applied that people are exploiting that way probably isn't the right model for that SaaS.