If you want to know why there's a new thread each week on HN about why it's impossible to host your own email service, this is why.
If you want to know why there's a new thread each week on HN about why it's impossible to host your own email service, this is why.
I run a mail server on AWS, and we use some blacklists to drop mail. It's quite effective and that's why people keep using them. A properly curated blacklist is a powerful tool, and more accurate than the machine learning mush that people have come to rely upon.
But this is by design[0]
> This blacklist has been created for HARDLINERS. It can, and probably will cause collateral damage to innocent users when used to block email.
And it makes for a perfectly usable blocklist. If you use postfix, the postscreen_dnsbl_threshold and postscreen_dnsbl_sites parameters let you create a simple scoring system:
postscreen_dnsbl_threshold = 10
postscreen_dnsbl_sites =
zen.spamhaus.org*5,
bl.spameatingmonkey.net*5,
dnsbl.sorbs.net*4,
bl.spamcop.net*4,
dnsbl-3.uceprotect.net*3
I made up the numbers, because you will need to monitor your system for a while to see if they make sense, but the principle holds. Also make sure that the dnsbl you are using are working for you.But it isn't really a problem with uceprotect, it's about how DNSBLs are used.
[0] https://www.uceprotect.net/en/index.php?m=3&s=5 [1] http://www.postfix.org/postconf.5.html#postscreen_dnsbl_site...
The article sums it up nicely: IP blacklists have their place, however, please don’t use the overarching neighbouring blacklists such as UCEPROTECTL2 and UCEPROTECTL3.
People have been complaining about this for a very long time; as long as I can remember. In the past they've also just permanently added people's IPs after complaining their IPs were wrongfully listed (not sure if they still do that).
The UCEPROTECT blacklist should be blacklisted by everyone. Yes, we need a blacklist of blacklists.
To be clear: I DON'T think blacklists are the problem. I think the problem is that a half-dozen major blacklists are controlled by unaccountable organizations who make up rules willy nilly, and privilege major email senders while punishing smaller senders / home hobbyists.
No. These blocklists are employed by the actor receiving the email. They have a perfect right, even on "the open internet", to decide that they want to limit who can send them messages.
There are tons of checks on the people who provide those blacklists, in the form of their users complaining about lack of mail delivery and ultimately not using their list anymore. We vote with our wallets, and as a group we have decided that these blocklists are useful.
> and for what?
To make email usable. Full stop.
If I send an email to alice@example.com, Alice is the recipient, not Bob the sysadmin for example.com.
This is the way that email is designed to work and the fact that users and service providers have choice is a feature, not a bug. If you don't want your service provider to do this type of filtering, that is your choice. But you have absolutely no right to say that Alice can't get the service she wants from example.com because it's inconvenient for you.
Edit: and just to head off the inevitable "but what about if it's at work and I can't change providers", the domain and email accounts belong to your employer, not you. You are welcome to work somewhere else if you don't like how they configure their systems.
Alice is not beholden to example.com, she can use any hosting provider she wants. Moving providers isn't even that difficult. It's also totally irrelevant, because again spam is inevitable.