Internet Mail 2000
cr.yp.to
cr.yp.to
The only real issue for email today is deliverability. That's getting worse, according to reports from people who have not had a stable verified public IP address for decades.
When the "Unsubscribe" feature fails (about 10% of the time in my experience), then those emails are legitimately spam. None of the spam solutions work for those emails.
If spam is a problem for you in 2022, you have a crappy email provider.
If you sign up for something (e.g. by purchasing goods from a legitimate store), those will virtually never be classified as spam. The reality is that it is hard to get off those lists - a lot of them have an "Unsubscribe" link that purports to get you off their list, but do not actually do so.
If you have a provider that is classifying them as spam, then you have a crappy provider.
I consider the unsubscribe button a courtesy, but the “mark spam” button is the real unsubscribe link. I wish modern email systems had a button which did both - “unsubscribe, and mark any future email from this domain as spam”.
The spam has now filled up my Google storage quota, and I can’t use Google docs with that account any more. (I’ll probably just backup & delete all email in that mail box soon to restore the account)
If gmail’s spam detection is “crappy”, I’m very curious who you consider “good”.
FWIW, I run rspamd for half a dozen users. It correctly classifies upwards of 6000 spam messages, and ~300 non-spam messages per day. A dozen or so false positives get through per week, and I haven't seen a false negative in at least a year.
I'm probably more annoyed by spam than most people are, but it has barely occupied any part of my brain in a decade.
I guess my original comment should have been more specific. Spam detection is a solved problem in 2022, and has been for many years. That some providers implement it poorly is, well, crappy.
Well, that train of thought went downhill pretty fast.
Could it be perhaps that mail is becoming undeliverable precisely because effective anti-spam is so burdensome that only major players can eat the cost, while pushing massive externalities to every other mail provider?
Except when spam filtering effects deliverability and results in mail the recipient wants to receive going to a spam folder, with no way for the recipient to change the filter. For example, I have a friend who has his own domain based on his surname and his mail from that domain goes to Gmail's spam folder even when the recipient marks it as "Not spam".
No, until every spam-filter knows your host is a spamer, that is 30min-2h normally.
On the other hand, disk space is so cheap this doesn't help very much.
"...But I do know that she likes my in your face attitude" -- Bender relaying Leelas remarks on him in Futurama, S1E7.
On a non-related note, I used the hell out of Qmail and DJBDNS for years. I sometimes look out into the darkness before I drift off into unconsciousness and wonder why I do not use them today.
If you need dynamic DNS support, djbdns needs something else to handle it. If you need TLS for your mailserver, qmail needs something to handle it. Greylisting? Something else.
If qmail and djbdns had communities the same size as Postfix and Knot, they would be excellent general-purpose choices.
I run my own email server and have implemented greylisting [1]. Greylisting easily drops my incoming email by 50%, but that 50% was being sent by non-compliant SMTP "servers" (probably, a program running on an exploited box somewhere to spam email). Legitimate email servers will always queue email and try again when they encounter a transitory error.
* a number of the larger services have pools of mailservers; when they retry the send, they retry from a different random host in the pool. Naturally this breaks greylisting completely.
I think you misunderstand. If I'm expecting to log in via 2FA with my email client, I'll have my email client open (and polling for email in IM2K, or in an SMTP-world, my MX points directly at my email client) so the message won't be delayed if I'm expecting it.
I think it's okay to delay unsolicited mail, after all, I have to sleep some time...
> * a number of the larger services have pools of mailservers; when they retry the send, they retry from a different random host in the pool. Naturally this breaks greylisting completely.
I don't think this is true; Can you explain a little why you think this is a problem?
Back in the late 1990s and early 2000s I ran a large mail server (queue on NFS) and had this problem, and I solved it by hashing the authenticated sender and using that to choose the pool of addresses to try for that week. This way, a bad actor might burn 3-4 IP addresses by spamming and get me added to one of the popular blacklists, but they don't take out my entire system, and that gave me time to correct the problem. When Greylisting started becoming popular, I had some slightly longer delays than the more popular single-node mail servers out there, but I tweaked this to simply prefer the same address until seeing some headers then retry on the alternate to see if we get a different answer. Now it's 2022, and I suspect any big mail server knows these tricks and more, and any operator who doesn't know about greylisting in 2022 is going to have other problems.
Even the senders with pools of mail servers hasn't been an issue---the email will eventually get through. As far as I can tell, in the fifteen years I've been using greylisting, that has just not been an issue.
When I first started with greylisting, I set the embargo time (minimum time to reject emails) to an hour. I later dropped it down to 25 minutes, but that's just me being a bit over-cautious. Just a one-time temporary reject is enough to filter out something like 80% of what I catch with 25 minutes.
And it wouldn’t be bad if store-and-forward catches on, because it relieves the storage pressure for big, free services, which would be the largest burden attempting free, anonymized messaging at scale.
The only other solution I have thought of is to charge for email. Say a few cents per message would go from sender to receiver. That would definitely reduce spam.
Spam would still come from hacked boxes, being charged to the owner of the hacked box.
> In IM2000, mailing lists are a purely local matter for the receiver's software.
We still need to manage list of users we want to send notifications to, right? ("The message isn't copied to the receiver's ISP. All the receiver needs is a brief notification that a message is available.") Or is it expected there will be no "push" notifications for mailing lists, but I will actively ask about new messages in the list on every inbox refresh? That seems a bit wasteful, especially when this protocol seems to be concerned about efficiency.
Meanwhile every time this subject comes up (and cascades into side topic posts about how it is hard to self host and mutt vs thunderbird) I'm left wondering why we even need internet mail anymore when there are so many other overlapping communication channels already.
You message your normal friends on WhatsApp.
You message your nerdy friends on Signal.
You message your drug dealer on Telegram.
Nobody writes email sized messages anymore just like nobody writes letters anymore.
You message your in-laws from an incognito Facebook tab a couple times a year.
Sometimes when you want to message no one in particular you shout into the void on Twitter.
You communicate with your team by hooking up GPT-3/perl-script to your corporate slack for your first gig and Microsoft Teams for the secret second gig. Just be sure to not send the emojis after work hours.
That open source project you like is now increasingly sequestered on some discord instead of a traditional mailing list.
What is left for internet mail to do? Seems like it mirrors the real life postal service and has been reduced to mostly junk mail and newsletters you aren't going to get around to reading because you're busy slogging through your RSS feeds (what is dead may never die).
Maybe we've been so obsessed with figuring out how to operate our own postal service like in the frontier days we forgot to ask ourselves whether we should want to in the first place.
Neither snow nor rain nor heat nor gloom of night stays these couriers from the swift delivery of plain text messages over an open protocol via the public net. For What?
Isn't there an email on change functionality, heh.
Either way, work email is from the work address on the work mail server. Which is, lets face it, hosted by Google or Microsoft if not some big corp IT. That's already a thing, what is there to fix.
I mean I think you were joking, but just in case you weren't.
When I sign up to get my Electricity bill, what do I give them? My Whatsapp? My Twitter?
Postal address...?
I don't.
> You message your nerdy friends on Signal.
I don't.
> Nobody writes email sized messages anymore just like nobody writes letters anymore.
I do. But I'll grant few do.
> You message your in-laws from an incognito Facebook tab a couple times a year.
I don't.
> Sometimes when you want to message no one in particular you shout into the void on Twitter.
I don't.
The author in this case has also written what was for some decades one of the better MTAs you could run, namely qmail. Granted, I've always despised it for its hostility to administrators not named Daniel Bernstein, and ran Postfix instead for all 17 of the years I spent administering my personal mail hosts. I don't like djb's style, either, and while we've never directly interacted I strongly suspect we would not get along at all. But none of that changes the fact that djb did in fact fix a lot of what was wrong with email, by providing an alternative that at the very least was both a lot faster and a lot more secure than sendmail, back when good alternatives to sendmail were pretty hard to come by.
He's certainly not always correct, but he is at least always worth listening to.
And who knows, you might agree more now that he's changed some too: After ten years of qmail[1], his list of "distractions" is remarkably reflective, and he seems quite willing to admit some of the contortions he did (and put us users through!) to get privilege separation, or to annoy attackers (and the users!) didn't gain anything at all and cost much.
At $DAYJOB we sponsored a hire from another country recently, and their new landlord wanted an email address instead of adding them on WeChat/WhatsApp. It was a culture shock. They created their first email account in 2020 at age ~30.
Email has been EEE'd by the big players - e.g. Gmail conversations and labels don't work properly in plain IMAP (extend) and they block messages from independent mail servers (extinguish).
Email is obviously still popular, but I think it's fair to say most people do not use it. Email is for receipts. I think its demise is closer now than at any point in the past.
>I think its demise is closer now than at any point in the past.
Quite the opposite here (we're b2b in Europe), most of business communication is via email. It's the easiest way to contact a business because virtually everyone uses it, as opposed to the hugely fragmented market of Telegram/Whatsapp/Discord/Slack/Messenger/whatever is the new shiny thing this week.
Our SaaS is about eLearning, we have thousands of clients in US, Europe and Asia, from all sorts of industries. A company usually registers all their employees in our system, and every employee has a profile where they can specify their email (which is optional). I worked with tech support and although I don't have exact statistics, my impression was that the majority of employees have emails assigned, it was the norm, rather than an exception. I've noticed it's usually retail where employees only have a phone number.
We do use Telegram/Whatsapp for announcements, but I don't see email go away any time soon. I can't imagine myself having an official business correspondence on Discord.
So it's a way for small businesses to communicate with customers. Not what I was talking about (business-to-business interactions)
I think email is fantastic.