Is Gmail killing independent email?
tutanota.com
tutanota.com
More directly: spammers are killing independent email. Email's peer-node-trust story is so "version 1.0 Internet" that webmasters are left basically using heuristsics, shared models, and tea-leaves to determine whether arbitrary incoming messages should be trustworthy or not, and "they should not" is a good first-pass guess!
So Google (as the thousand-pound gorilla) is serving as a lightning-rod for a larger network-effect problem, which is "Users generally consider themselves better served if most unsolicited email they receive with no strong trust priors drops into a black hole." But that makes it very hard to be a newcomer who wants to establish trust priors.
Disagree.
In the early 00s, spam was killing email. I was getting thousands of spams per minute to my personal email domain (same one I still have and have had since the mid 90s). It was real bad back then.
Doing aggressive sanity checking on incoming email back then was problematic since nearly all legitimate senders also has badly misconfigured email servers.
Those days are gone. Legitimate senders have well-configured email now, one can do a lot of sanity checking on the SMTP connection and that alone cuts out most of the would-be spam before it is ever sent and none of the real email is impacted.
Sprinkle a bit of bayesian filtering on what remains and spam is mostly a non-issue anymore.
So what it the problem these days? Part of it is a legacy cultural problem. A lot of email admins wear so many scars from the early 00s that they still operate on a mental model that they are willing to throw away a lot of legitimate email just to prevent even one in a million spam to go through. That's highly counterproductive and causes a lot of harm to interoperability.
The other big factor of course is that the very deep pocket email providers (gmail, microsoft) have a strong vested interest in strenghtening their monopoly even further so they are happy to go along anything that decreases interoperability.
That all said, I strongly encourage everyone who can to run their own email. Interoperability can only be saved by exercising it as much as possible. And it still works fine despite the naysayers. I've been running my email infrastructure for a long time and have no deliverability problems anywhere that I've run into.
Or they work at a company that demands it...literally demanding IT remove all spam... and also demanding that nothing important ever gets blocked.
While I have no doubt that doing this is a lot easier and more hands-off than the last time I did this (for a few years during the mid '00s), I just don't have the time or energy for it. Also, email is a critical service, something where I don't want to have to deal with downtime, especially if I'm away traveling or something like that.
I think as a decent alternative for people like myself, it's at least helpful to use an alternative hosted email provider (other than GMail or Microsoft) to help keep the ecosystem open.
I have to say that as the most critical service of all, that's one of the reasons I do host email myself!
I can't and won't take the risk of being locked out by the whims of some third party misconfiguration (we've all surely seen the endless stream of misfortunes by those getting locked out of gmail/etc).
And I concur with the original commenter. I do zero filtering on my SMTP server (no reverse DNS lookups, no blacklists, no nothing), in order to be sure I receive every single email, and SPAM looks like it would not be an issue even if I disabled the bayes classification client side, these days.
I mostly rely on providing unique random addresses to each service. My oldest 18 year old address gets quite a bit of spam so I blocked it and switched to different one, but newer addresses that I use for the last 5 years didn't accumulate much spam, despite being public and crawlable on the web.
The article said people said so on HN.
Once we figure out a way to handle website registration that’s not tied to email (whatever that means) I’m not sure email will be useful for anything.
Most useful conversations have moved to messaging apps.
Email is incredibly heavily relied upon and with great success. People get their pay receipts, their rental applications, notifications of mentions on social media, speeding tickets, music and gig notifications, reminders to get their pet to the vet, X-ray reports, prescription reminders and I could go on.
Not to mention the huge boom in email digests and blogs over the past 5+ years.
I haven't seen - _any_ businesses communication conducted over signal or WhatsApp - ever. I'm not saying it doesn't happen somewhere but it's certainly not common place. And telegram? I didn't even realise that still existed!
That's not a future I'd like to ever live in.
Why? Because all of those are proprietary solutions that don't interoperate with anything and their behavior and existence depend on the whims of a single corporation. No thanks.
Email is standard, interoperable, owned by nobody, accessible to everyone. It's the optimal way to communicate.
If I want you to be aware of a long article I'll send it to you in an email because if I message it, most people will open it, see it takes more than 2 minutes to read and close it and never go back to it.
I was planning to build a pretty sophisticated bayesian filter on top of that but it turned out to be unnecessary. The strategy I ended up with, which has served me well for many years now, is:
1. Block a small number of extremely spammy TLDs. There are about a dozen of these, including .biz, .casa, etc.
2. Anything received from someone I've sent mail to, or a sender I've previously marked as good, is assumed good.
3. Anything received from an address whose name contains an English word on a relatively short list of spammy words (discount, offer, etc.) is assumed spam.
4. Anything received from an address that I have received email from before and not marked as good is assumed spam.
That leaves emails from addresses that are sending me email for the first time. These are overwhelmingly spam, but after the four filters above there are few enough of these that I just scan them manually once a day or so.
The real key here is treating the first email from any given address as essentially a "contact request" with the default action being "deny in the future". That just turns out empirically to work incredibly well. More than 90% of my spam is from repeat offenders.
Anything that reaches addresses that you don't use gets marked as spam.
Common prefixes will work for cases where they're guessing your address, and hidden mailto links will cover situations where they're scraping your webpage.
Honest question: Is there any reason to not just blacklist all emails from TLDs that aren't the Big Four (.com, .net, .org, .gov) and country TLDs (eg: .co.uk, .jp, etc.)?
I can't recall ever needing, let alone wanting, email from the later TLDs like .biz or any of the bloody stupid new TLDs that comprise entire words.
And you left out dot-edu.
And I get a fair bit of ham from other weird TLDs. So I think a whitelist is a bad idea. But that's because I prefer to have some spam get through than have ham get blocked by mistake. Even with my very sloppy algorithm, the only time spam ends up in my inbox is if a spammer spoofs one of my contacts, and that is extremely rare.
I typically register both a new TLD and a .com, and I use the .com for the email campaigns and reply-to
if it gets flagged that doesnt affect my more official one-to-one emails from the actual domain
so I would say, maybe? because I’m not allergic to “bloody stupid” TLD’s and have already adapted to what you’re wondering about
'top','tv','biz','rocks','ru','science','bid','date','casa','buzz','work'
In many years of doing this at work I think we've had to manually whitelist three domains (our corporate travel provider started sending from a .travel domain instead of their .com without telling us they would make that change...). I don't have numbers handy but it significantly reduced our junkmail intake.
What tools are you using to implement the controls you describe above?
YouTube, Twitter, Facebook, Craigslist, ...
Nearly anything public is bombarded with spam. The big players are far better suited to deal with it than any newcomers, and even they can barely manage it on their own platforms.
Youtube spam comments tend to have highly atypical patterns, using things like unicode characters to avoid triggering keyword and URL filters. Something along the lines of GPT should pick up on these things pretty easily, and could similarly pick up on the actions these comments are requesting of users "message me on telegram", etc. It could also probably detect when spammers are trying to impersonate youtubers.
It's not really the kind of thing that spammers can use LLMs themselves to work around, either. Any attempt to get past the anti-spam LLM is going to look quite unusual compared to the typical comment which would tip it off.
Strangely Google seems reticent to try something in this vein though…
There is probably some critical mass where this would work. Some people would pay to be able to just not have to do combat with the whole world simply to enjoy the Internet.
The death throes of a doomed industry. Be it steel, horseshoes or advertisements, as profit margins drop production rates will increase to compensate. Then as the machine is running as fast an as efficiently as it ever has, suddenly the margin becomes zero and there isn't any more room to optimize. The entire industry suddenly stops overnight. I await that day.
https://www.cbsnews.com/amp/miami/news/change-coming-only-pa...
Meh. I've watched in the hundreds of hours of YouTube videos without ever seeing or receiving any spam.
I guess you must be referring to the comments? If so, perhaps I'm missing out but I've never gone to YouTube for the comments.
Google Drive is infamous for its spam problem.
Yet suddenly my emails go to spam in gmail.
Now, there's no way for me to do anything, because I'm nobody.
As for spam, my bayesian filter works just fine, so if I can successfully filter spammers out, I think Google can as well.
I feel like Google is doing this purposefully to make people like me to simply give up, and observing responses, it is successful.
This is absurd. The problems Google face are orders of magnitude more complex than your individual mail server. Your server benefits from the fact that no one cares about it. No one will develop a custom spam technique to send you spam. They will for Google. There will be whole offices in India dedicated to working out exactly what slips through Gmail.
You benefit from a kind of herd immunity where no one even sends the kind of spam that would reach you because it's blocked by Gmail so not worth sending.
Your personal gmail account has the same risk of receiving spam as mine, but Google has much more tools available to detect spam. For example they can easily see somebody is spamming, when large gmail accounts are receiving the same message. They can easily see which hosts are compromised proxies as they receive tons of mail, and seeing large number of e-mails sent from questionable hosts should be easy to spot.
They didn't really improve spam detection much for for a decade, because blocking small hobbyist mail servers is more likely increase their user base.
Those special farms you're mentioning, wouldn't work, if filtering would be individual per user, as it should be, because each person's mailbox is different and each person has different definition what spam is.
When this happens, gmail informs the sender that the mail wasn’t delivered and they try a few more times before telling the user that no more attempts will be made.
That depends entirely on how the receiving server rejects the mail. If it just drops it into the spam folder or /dev/null Gmail won't be able to know. If it responds with a non-transient error code then Gmail will (correctly) NOT try again and inform the user of that.
If users really want that then they can just dump all email from addresses not in their address book. Some already do that. It turns out that most people actually want to be able to get email from entities they do not yet know.
citation needed for "most". "some" people want emails from unknown entities. I am not sure about how big that fraction is.
I email a car dealer. I expect a response. But I don’t know if it’ll be from Bob or Larry.
And I definitely don’t want to be added to thirty two different email lists they manage.
To implement, establish an email header field for a token. The tokens are one-time use, and can be purchased from some token selling authority. The recipient can check with the selling authority if it is valid. If it is missing or invalid, it goes to the junk folder.
Domain names and IP addresses aren't free. If we just immediately trash all email which doesn't have valid SPF + DKIM + reverse DNS, we place a small upfront payment requirement on sending email. Domains or IPs can be placed on a blocklist if they still send spam, thus making the domain/IP wasted.
The problem is that waaaay too many legit senders still don't know how to configure their email servers, so you end up with a boatload of false positives.
Can't you pay less than a penny a user to run ads in Gmail today ?
The idea is fair though I don't think it's far from where we landed with how the large email broker systems operate with the large email system providers.
Your post advocates a
( ) technical ( ) legislative (X) market-based ( ) vigilante
approach to fighting spam. Your idea will not work. Here is why it won't work. (One or more of the following may apply to your particular idea, and it may have other flaws which used to vary from state to state before a bad federal law was passed.)
( ) Spammers can easily use it to harvest email addresses
(X) Mailing lists and other legitimate email uses would be affected
( ) No one will be able to find the guy or collect the money
( ) It is defenseless against brute force attacks
( ) It will stop spam for two weeks and then we'll be stuck with it
(X) Users of email will not put up with it
( ) Microsoft will not put up with it
( ) The police will not put up with it
( ) Requires too much cooperation from spammers
(X) Requires immediate total cooperation from everybody at once
(X) Many email users cannot afford to lose business or alienate potential employers
( ) Spammers don't care about invalid addresses in their lists
( ) Anyone could anonymously destroy anyone else's career or business
Specifically, your plan fails to account for
( ) Laws expressly prohibiting it
(X) Lack of centrally controlling authority for email
( ) Open relays in foreign countries
( ) Ease of searching tiny alphanumeric address space of all email addresses
(X) Asshats
(X) Jurisdictional problems
(X) Unpopularity of weird new taxes
(X) Public reluctance to accept weird new forms of money
(X) Huge existing software investment in SMTP
( ) Susceptibility of protocols other than SMTP to attack
( ) Willingness of users to install OS patches received by email
(X) Armies of worm riddled broadband-connected Windows boxes
( ) Eternal arms race involved in all filtering approaches
(X) Extreme profitability of spam
(X) Joe jobs and/or identity theft
( ) Technically illiterate politicians
( ) Extreme stupidity on the part of people who do business with spammers
( ) Dishonesty on the part of spammers themselves
( ) Bandwidth costs that are unaffected by client filtering
( ) Outlook
and the following philosophical objections may also apply:
(X) Ideas similar to yours are easy to come up with, yet none have ever
been shown practical
( ) Any scheme based on opt-out is unacceptable
( ) SMTP headers should not be the subject of legislation
( ) Blacklists suck
( ) Whitelists suck
( ) We should be able to talk about Viagra without being censored
(X) Countermeasures should not involve wire fraud or credit card fraud
(X) Countermeasures should not involve sabotage of public networks
( ) Countermeasures must work if phased in gradually
(X) Sending email should be free
(X) Why should we have to trust you and your servers?
( ) Incompatiblity with open source or open source licenses
( ) Feel-good measures do nothing to solve the problem
( ) Temporary/one-time email addresses are cumbersome
(X) I don't want the government reading my email
( ) Killing them that way is not slow and painful enough
Furthermore, this is what I think about you:
( ) Sorry dude, but I don't think it would work.
(X) This is a stupid idea, and you're a stupid person for suggesting it.
( ) Nice try, assh0le! I'm going to find out where you live and burn your
house down!Of course, spammers have significantly moved to using gmail and it just streams right through.
I wonder though, with the advent of new LLM models, it should now be trivially possible to build a zero-shot spam-filtering bot that is self hosted.
A decent first-pass solution to part of this might be to just have email allow every domain in my password manager.
I think the data's there to make this work a lot better, it's just that all the parts aren't talking to one another.
“Webmaster” isn’t a title I’ve heard in about 20-years.
What is the evidence for this claim? Not Microsoft or Google acknowledge they drop email.
I've had to set up someone's mail server last year. All mails sent to gmail were silently dropped until we set up all the current buzzwords for the domain/email server. Then they magically started to show up.
Possibly we were lucky that "just" setting up SPF DKIM etc fixed it.
SPF and DKIM are nowadays the very basic methods used to verify if your emails are spoofed or not. Not having them in place is as good as setting up a spam farm.
We need to stop buying the narrative that they are doing this to fight spam and are doing it as a gate keeping exercise.
People here saying "it's spam, not Gmail" are being distracted from the numerous issues that independent mail services do have with Gmail.
Gmail is extremely uncooperative at accepting email from services that aren't Gmail, Comcast (sometimes), or Microsoft. You can have everything configured correctly, on an IP you've owned for years, and aggressively manage any outbound spam, and Gmail will still hate your guts and bounce your email or file it in the recipient's Junk folder.
Before Gmail got huge, email service providers typically offered an avenue for addressing false-positives in their filtering systems. Gmail really pioneered the "nah, screw you" approach to this.
Meanwhile, Gmail is itself a huge source of spam.
I (maybe perversely) loved hosting my email and email for a handful of other people. It's fun. Gmail took all the fun out of it and turned it into a seething hatred.
- Make a gmail account just for your email server, which forwards anything incoming to your host in case someone emails it directly (you'll be able to discover this gmail address if you dig through delivered emails' headers but it won't be in the From: field)
- Let Gmail authenticate with your SMTP server in Gmail's advanced options, and make sure the options are checked to retain the From: headers of relayed emails
- Generate an App Password and set up your mail server software to use Google's SMTP relay with the email and app password
There are other services to do this too I'm sure, but I'm happy with Gmail for now. And you can always transparently switch it out to another service if Google pulls something.
I plan to write a blog post on the whole process of setting up a mail server to configuring it with a gmail relay like this.
I was hosting email not just for myself but for a few other people, and that gets tricky to route through Gmail;
Gmail could change their policies at any time and give me a really bad day, potentially when I can't respond to it in a timely manner;
If routing email in this way ever triggers Google's abuse mechanisms, then potentially I'm losing access to a lot of the Google network, and while I don't use it for anything personally, sometimes I have to work with companies that do;
After spending tons of hours dealing with Gmail-related headaches despite not using Gmail myself, relying on them to get mail routed felt like a deal with the devil.
I've instead helped a bunch of people get set up with Fastmail. I love Fastmail, they're great, I miss hosting my own email but they're the next best thing. Fastmail must be handling enough traffic that they're hovering above Gmail's piss-off threshold, and really my experience with them has been extraordinarily good. Everyone I've set up over there has been happy with them too, save for one person who got told by the next IT hat-wearer that "everyone's using Google Workspace and you should be too" (and then immediately ran into a problem during setup that snowballed into a big hairy mess).
Why not if you send mail to hell? Who else do you expect to deal with?
There was a time my home IP on Comcast was on some blacklist with good. Every video was run through captcha. Searches too.
Comcast was useless to give me an IP in a new block.
What solved it? I signed up for gsuite free at the time and moved my email (from a colo) from “on prem” to them. Suddenly my home IP that’s used to access their services is cherry and no longer suspicious.
Note: that doesn’t seem to work anymore though. I regularly proxy some traffic through a linode and google does the same thing. Everything behind a captcha that’s stupid difficult to clearly 60% of the time. I hate traffic lights.
The rule is pretty much every interaction you have in the Googleverse is easier if you just pay them something. It's pay to play internet, and yeah, it's a problem.
> It's pay to play internet, and yeah, it's a problem.
1. How much do they charge?
I'm genuinely curious. I don't self host, but use a 3rd party (fastmail). I send very few emails to people I don't know, so personally, I don't run into issues with having my email sent to spam.
2. I don't think paying in itself is the real problem. I think it's more a matter of who you pay and why you pay.
- You have to pay to register a domain name. - You have to pay to host your own server (whether your using a hosting service or hosting from your basement) - You have to pay to have gmail not mark your email as spam - ok, I'll admit, this is a little silly, but you also have to pay (via a stamp) to have USPS send letters to their recipient
3. Perhaps because so many people use and trust (whether they should or not is another question) gmail, it makes sense to pay in some scenarios? But obviously, for personal mail servers, I agree, asking to pay to play is a bit of a stretch.
From my POV, Yahoo pioneered this way before Gmail. 10 years ago when I was managing outgoing mail infra for a company that probably sent 100k emails per day (mostly purchase receipts and subscription notifications), I was intimately aware of deliverability characteristics for Gmail and Yahoo, which were our two biggest destinations by a large margin (if I recall, Gmail was about 60% and Yahoo was about 30%). Gmail, despite being the overwhelming majority of our traffic, was hardly any problem at all, whereas Yahoo would regularly give us the dreaded 451 response that indicated that your mail was going to be held for 2-24 hours and then randomly rejected or accepted.
BTW, if I were to run my own mail infrastructure again, I'd definitely use someone like Sendgrid with a dedicated outgoing IP with a clean reputation. It makes a very big difference. We eventually ended up with our infrastructure split across multiple IPs by function (e.g. receipt emails were the only thing ever sent from one specific IP because we wanted to ensure deliverability).
Then when your mails to Yahoo got repeatedly blocked by Yahoo and you got tired of having to repeatedly report the false positives and and get unblocked only to get blocked again a few weeks later you have the person in charge of your ad spending call up your ad sales rep at Yahoo.
You asked the ad sales rep "Why should we keep spending $X/month on Yahoo ads to try to acquire customers, when Yahoo mail keeps blocking the receipt emails, setup instruction emails, and response emails to support questions we try to send to those customers which angers those customers and they cancel (or even try chargebacks)???".
What happened then is the sales rep puts your ad manager on hold for a few moments, then comes back with someone high up in Yahoo IT management conferenced in, and explains the situation. The high IT manager puts you all on hold, and comes back in a few minutes with someone who actually deals with maintaining the spam filters conferenced in, explains the situation, and tells the maintainer to add your domain to a special whitelist of mail that is always accepted.
If I were to set up my own mail server, that would send outbound email through Sendgrid, AWS SES, or maybe some other established and trusted sender.
Building trusts with behemoths like GMail or outlook.com is too involved an affair to be worth it in the general case, and not even through some malice on the side of the latter; it's just the reality of a medium not protected from spam.
I mean, you can't reliably send email to gmail from gmail. It's not really the origin that's the issue, it is that gmail spam classification is quite bad. Good emails from known recipients you've corresponded actively for years will continue going to spam in gmail even as you mark them not-spam for the thousandth time.
So yes, sending to anyone @gmail.com has decents odds of ending up in spam for no reason. That's just how gmail is.
But no, sending it from your own email server doesn't make things worse. I run all my own email infrastructure and sending to gmail addresses works just as well from my server as it does from gmail itself.
There's nothing like that actually. I have e-mail server running since 2000s. When gmail appeared, everything continued to work as expected and it did for many years. Around 2018 or 2019 I noticed that my e-mails started going to spam folder. I didn't send any bulk e-mails, I was not on any RBLs, I was not compromised (I actually was very careful to block outbound SMTP from any user except the one running MTA), and of course had SPF & DKIM set up.
It looks like their spam filtering is just arbitrary and feels like done on purpose to discourage running personal mail servers (and looking at comments it works really well).
Honestly, I think some kind of campaign is needed to put them in place, like starting blocking e-mails from gmail (maybe responding with a message encouraging to switch account). I remember in the past steps like that were done, but feels like today people are more acceptable of centralization.
I don't think they explicitly are trying to quash smaller independent mail servers (personal or commercial), they just see what spam statistics show, and update blocking rules accordingly, maybe fully automatically, using ML. The fact that they also quash small-time independent competition is just a nice (for them) side effect.
Sending mail from my domain to my Outlook.com address it kept going into spam seemingly no matter how many times I did any of these things:
• Find the mail in my spam folder and mark it as not spam.
• Whitelist the sender.
• Reply to the mail.
The last time this came up on Hacker News, one of the top comments was something to the effect of "we did double confirmation and a variety of other measures to avoid being marked as spam, but ultimately the entire time we're just one bad email campaign away from being blacklisted".
One bad email campaign? Is there any other kind? That's just spam.
The user didn't say this, but I'd bet money their "double confirmation" starts with a default-checked checkbox with small text asking for permission to send emails.
Every time I've talked to someone who has problems with email deliver-ability, if I dig into what they're doing, it quickly becomes clear to me that they're sending spam, but they're so indoctrinated in corporate culture that they don't even know that what they're sending is spam. Here's some translations for you: Marketing email = spam. Lead generation = spam. In most cases, newsletter = spam. Sale announcement = spam. Promotion = spam.
I'm not claiming my experience is universal. I'm sure that there is a non-zero percentage of sites sending legitimate emails getting marked as spam. But it seems to me that more often than not, the reason your emails are marked as spam is that they are, in fact, spam. And most strategies people discuss for avoiding being marked as spam, are just avoiding the most obviously egregious forms of spam, and finding users with higher tolerance for spam.
We regularly have users flag the email they receive from this process as spam.
I have personally called to follow up in some cases to understand if our service was being abused or what the issue was. It was eye-opening. One user said "oh, yeah, I wanted that when I filled out the form but not when I got the email." Several marked the proposal as spam because they didn't like the final quote that was put together from their requirements.
Several said things like "I get too much email" and when pressed as to why they checked the box that said they wanted their quote delivered as an email replied that they didn't know, or they changed their minds, or they didn't want HTML email, or they didn't want a plain-text email, or their name was not in the subject line of the email, or that their company name was not in the subject line of the email.
This is a very low volume, very expensive, highly technical product. We're talking maybe a dozen requests per day nationwide. So those people flagging the emails as spam have a significant impact on the overall deliverability to services like GMail.
That said, if you can get people on the phone, they tend to be much kinder. I think most people think they're just shouting into some empty void.
How I design my, admittedly not corporate, email delivery system is to require the user explicitly click "Send this to my email" every single time. No email is sent without a user clicking a button painfully explicitly asking for it.
Honestly treating e-mail like sex where it requires enthusiastic continuous consent feels like it should have always been this way. It's really not that hard to have a button and have receipts/tracking to only be on your account page unless they ask for it.
i too run a quote service. only transactional emails, things users have requested. and still get flagged.
my favorite so far is when a user complained they weren't getting email and it's because they already blacklisted us so our mail provider diligently didn't send to them anymore.
And what sucks about it is there's nothing you can do. People assume it's your fault for being weird and not using Gmail or outlook.com. And there's zero way to contact Google or submit information to convince them you're legitimate.
I believe in an open, distributed internet. I don't think it's good that we're moving towards a world we're the core protocols that defined the internet are being replaced by proprietary versions controlled by a handful of trillion dollar companies.
"Double confirmation" is spammer-speak. The correct formulation is "confirmed opt-in".
There are exceptions, e.g., I sent an email full of research with sources to a family member I've been emailing with for fifteen years and it went to spam, despite it being @gmail.com to @gmail.com. In retrospect, I was misusing email versus sending a document or a link to one with it in.
The times have changed. It's not unreasonable to expect how people use email to have changed, ergo people sending emails full of URLs are statistically more often than not spammers.
Is it a broad stroke? Yup. But I'm willing to bet that I'm a fringe case and it prevents a ton of spam.
It should go without saying that confirmation emails of a user initiated booking is not spam, but let's just say it anyway
[Edit]: Forgot to mention that the IP is home IP, not cloud provider/hosting or something.
And as as sidee note: the problem lies with the users and not with the email sender. For instance, if I send an important email to someone about an item they ordered from my site, and they tell me to send it to their gmail account, I connect to gmail to send the email, but if Gmail rejects it, I have fulfilled my part of the deal. If an email is marked as spam or rejected, it's on the recipient's end, not the sender's. The sender did not flag the message as spam before it is sent, the recipient did it after receiving it.
So 100% certainty of it being spam? Was that the correct judgment, in your opinion?
Some things are just baffling. How can they manage to flag themselves as spam it’s beyond me.
If you were out on a walk and 9 out of 10 people where trying to mug you, you'd very quickly adjust your behavior to only walk in very safe places and let as few people as possible access that area.
There is a significant cost in spam protection by tracking reputation and content for the unending ocean of bullshit flooding the SMTP lines. Most providers want to cut communication with the spam source as quickly as possible to reduce costs.
Consider that email accounts are the go-to account recovery method for most services, and it's ubiquitous in biz. Also consider that you can prioritize specific domains or filter x domains to never go to spam, e.g., your own company's domain.
Any "death" is that people struggle with their own mailserver as a general rule of thumb. Does that thus mean email is dying? No. As the article says, perhaps independent email is, but it hasn't been in a good place for over a decade at this point.
Oh my god, yes. To all appearances they declared defeat in the Great Webspam War some time around '08 or '09 and their results have been markedly worse ever since.
I get dozens of FB Messages weekly trying to scam me out of a verified Facebook Page.
I get dozens of WhatsApp messages per day spamming me.
I get tons of Twitter and Instagram spam to the point that my DMs are useless.
I get Telegram spam weekly.
I've even started getting spam on bloody Matrix protocol.
Just because your experiences are x doesn't mean that it doesn't happen.
I don't ever intend to respond to spam, and have become extremely adept at spotting the patterns and swatting it away. However, it becomes a game of chance, when a service like Outlook puts it right at the top of the app (both iOS and Android) where you would reflexively jab at it, unless of course, you pay the premium to remove it.
For now, I have found a way to stop this nuisance. However, MS are playing fast and loose with their policies and now very legitimate looking spam is leaking into the inbox, escaping any filters. Since last year it is appearing along with the glaringly obvious Unicode riddled ones, with increasing regularity. It seems like a matter of time and co-incidence, where you would end up interacting with a piece of disguised mail you were expecting e.g. an order from Amazon or a service which you use regularly, and possibly respond without checking the header.
This recent episode was probably the worst experience, albeit not the first time it has happened.
https://www.theverge.com/2023/2/20/23607056/microsoft-outloo...
Flip-side, there seem to be more spammy messages sent from @gmail.com addresses than from any of the other email A-listers.
On the other hand, it's simply impossible to satisfy Microsoft. We're irrevocably tainted by being in a netblock of a well-known provider, despite having held the same IPv4 address clean for over a decade.
I followed the process, and then kept insisting a bit by answering the emails saying they were not going to do anything and I had to check if I was complying with their rules etc. After two emails I had a real person answer me, and a few more emails later (basically insisting I was already enrolled in their various bullshit spam reduction programs and there was zero spam problem with my domain) I got told that I had been whitelisted.
https://news.purelymail.com/posts/blog/2019-06-21-deliverabi...
I'm guessing some of the issues are just from Google being random about what it considers spam no matter who it comes from. I remember a comment on a somewhat recent thread from someone who had to move their business mail away from Gmail because Gmail would classify mail from one paid account at their organization to another under the same organization as spam.
It's being sent to an email address I know is not registered with Google.
I'm far from the only one with a similar issue. See https://support.google.com/groups/thread/68075070/i-get-goog... .
Such as a “bonded trust” system.
So a new email provider could use real money as a proxy for trustworthiness, since they obviously don’t have a solid history to rely on. For example, the major providers could demand depositing $1 USD per email/per day they want to send out in exchange for the spam filtering to be turned off for their domain.
That is if they wish to send out 1k emails/day to Gmail addresses and make sure they land in the inbox, they deposit $1k USD with Google.
The catch being that if more then 5% of the emails (or whatever the ideal percentage is) are marked spam, then their bonded money is taken away. And they’ll have to put up a new bond.
That way new entrants can get a foothold without having to jump through so many hoops.
As others have posted, users will spam-report even emails that they intentionally signed up for.
Does this email Spark Joy?
No.
Mark as SpamOr there is no viable business here and we go without the extra emails, a not too bad tradeoff.
Things like hotmail, and then yahoo mail, and then gmail won out because crime decided to fuck it up for everyone else. Thanks crime, you sure did your thing.
net neutrality legislation? That's when the last stubborn ISPs unlocked port 25 in like, idk, was it 2015 maybe? This is not the problem...
If Google wants to receive your traffic at a later date thats their business and not yours. It's an open system where sites set their own policies. Access to a site's eyeballs is not the right of an outside sender!
I barely use email anymore. Everything at work is mediated by Slack or Atlassian. With friends and family it's almost all text messaging. My kids' schools and sports teams use a bunch of different proprietary web and mobile apps to communicate with parents.
I am self hosting my email and had the luck that after setting up DKIM I'm no longer being sent to spam. I think it worths the effort.
Good, the holy abbreviation trinity makes emails closely tied to some identity. Bad, it won't make your identity instantly trustworthy.
It is quite literally a problem without a solution, spam is not too far off from just crimes like littering, it needs legal methods against.
The end condition of this race is only spammers will be able to send mail to Google, no legitimate users will have the time or budget to figure out how to get past all of the blocks.
Basically, you can't block the big providers - Gmail, Microsoft, AWS SES, Mailchimp, Mailgun and friends - because everyone and their dog is using them. But their reaction to abuse reports is spotty at best... you're stuck between a rock and a hard place.
The root cause obviously is spammers and scammers, but governments don't care about putting a final stop to bad actors.
Why? Respectable businesses send from their own domains. Friends and family never send emails nowadays, there are messengers for that. Anything from google goes straight to Junk folder.
B2C email is quite competitive with dozens of services.
Overall I’d say the email ecosystem is relatively healthy. It’s more competitive and interoperable that instant messaging with greater security than SMS.
Is my experience unusual?
I have an account since the beginning of gmail, and I get around 120 spam messages a day (roughly one every 10 minutes)
Also, with self-hosted spam filters, I had issue with false positives - that is my filters flagging proper e-mails as spam.
I hope that the new LLM systems should finally fix all that.
Another issue is that if you self-host, your e-mails are more likely to land in spam in your recipients inboxes. Big providers don't mind that :/
It's been much better since I took the time to set things up so marking and email spam automatically fed it into sa-learn. I still have to have a handful of rules to filter out senders who are "legit" enough to make it through, but ignore unsubscribe requests.
I setup a dedicated server not on a major cloud host, and am not looking forward to all the details involved in the lack of trust starting out. Let alone the dark art of spam detection. But I want to get back into it if only because I don't like how the major parties are cornering things up. I also want to be able to actually handle mail for several domains and not have it nickel and dime me to death. It costs way more for a single email account these days than it does to run a few dozen minor websites.
While it's nice that Google Domains (when you use their DNS) and Cloudflare both have included email forwarding, sometimes you want an actual box to send from too. And with the partitioning that GMail now does, I can't find anything anymore without hunting for it... the only benefit is two of the subtabs, I'm able to just delete all once in a while.
I wish that email were much more reliable and able to actually setup 2-way relationships similar to IM clients. And of course, limit/remove third party info sales/spam in those relationships.
If you're only a small time sender lack of trust is permanent. I've been self hosting for three years now, never sent spam, never had the server breached and GMail and Microsoft both still send mail to spam.
At least Microsoft no longer outright 550 refuse my mail so I have that going for me which is nice.
DKIM, SPF, etc only go so far anymore, and even graylisting doesn't seem nearly as effective as it once was. Again, not really looking forward to parts of this, but I do want to at least try self-hosting as much as I can. I like the cloud offerings from MS/Google, but don't like the companies or their actions in and of themselves. Only one real way to push back, and that's to actually try.
And on the small providers, yeah I can get that. I'm a bit more than a decade removed from self-hosting much of anything, and even then balancing DNS RBL with other factors was at least interesting if not frustrating.
When I moved my email server to a new IP a few months ago, while gmail sent my email to spam, live and icloud straight up blocked them.
I did notice the rate limiting by gmail, it seems to be a relatively recent thing.
Everything else is a “hack”. SPF is irredeemably broken (no possibility of forwarding email - ARC doesn’t work except for (again) huge providers like Cloudflare.
I send a DKIM-signed email? You KNOW it’s legitimate, no matter how it arrives…
Edit: I’ve been running MTAs for decades; first one in 1987 (yes, the UUCP days).
* In fact, I'm still using the filter I installed on my machine in 2003.
Most of the spam I get is via Gmail. I just looked at my spam folder, and everything there is either from gmail or has such blatant spam properties ("Content analysis details: 62.6 points, 5.0 required") that it was easily routed to the dump.
Google is so bad that it's worth soft-blocking anything from gmail.com Reply to any new gmail address with an autoreply that sends the sender to a web page for authentication. If they don't jump through the hoops to talk to you, discard.
Most of the email to my old @gmail.com that I check once in a while are from @gmail.com and a lot of them are not even in spam folder.
I get spam from new startups (in India it’s kosher to spam) mostly in “hyper whatever segment” that I know for a fact are hosted on Google Workspaces and still no amount of marking spam or reporting seems to work.
So at least in my personal experience it’s almost entirely Google screwing email things up.
A friend emails me for the first time in a while? From a gmail account? Spam. An receipt from my ISP? Spam. (these are actual examples)
But I reliably get every stupid newsletter that I've ever signed up for even though after 12 years I've only opened 1 of them.
I have had ZERO issues.
What I believe, but not certain, the issue others may have revolves around the host record, and reverse lookup of an IP address of your mail server. If the reverse lookup points to something other than your CNAME record, Google doesn't like it, and it gets flagged.
For instance, my mail server has a CNAME of host.foo.com, and mail.foo.com, and I have two aliases imap.foo.com, and smtp.foo.com. I have had my service provider change the reverse lookup for my mail address to host.foo.com, where it was xxx-xxx-xxx-xxx.location-att.swbell.com (or something to that affect), as multiple services are on that IP address. I only have a block of 5. The smtp server needs to respond with the reverse lookup name. So for postfix, the smtpd_banner needs to be host.foo.com. Google does do a reverse query to validate the user, and domain, most of the time.
Also, Google maintains their own internal DNSBL. If your email is getting flagged, and the above is correct, then the IP address you've obtained from your ISP has been problematic in the past. Email Gmail to ask to be removed with the new domain, and don't do it until the reverse lookup and pointer records have changed.
You also need to contact the various spam black list sights and get your IP address removed. If you SPAM, you will get blacklisted. I also host a blacklist.
The author of this article should have known about this, and wrote a very misleading article.
I used to run independent email. It took constant work to get close to gmail's level of spam blocking. So I switched. Found most alternatives weren't anywhere near good enough, and I don't have enough hours in the day even for my own email.
> I used to run independent email. It took constant work to get close to gmail's level of spam blocking.
This is very contrary to my experience on both fronts.
gmail spam filtering is mediocre. Spam gets through and good emails are flagged as spam. It's not very good.
For my own domain where I self-host my email, my spam filtering is quite a bit better. Approximately nothing is ever mis-flagged as spam (has not happened in years) and the spam that gets through is a tiny fraction of what my gmail address gets. So for me my own spam filtering is much better than gmail.
And no, it doesn't take constant work. In fact doesn't take any work at all. I set it up years ago, the bayesian filtering goes through all the mail but it takes zero effort from me.
I wish this myth that gmail has some incredible filtering technology that nobody can replicate would just die already. Gmail isn't terrible at spam/ham filtering, but it's not that good either, just mediocre. You can do much better with minimal resources on your own.
This has been getting consistently worse over the last few years, in my experience. At least on the user end, i.e. far more false negatives getting through.
Years ago I owned a one bedroom condo, had a baby, and moved to a larger rented space.
We were ~10 emails deep with a prospective tenant in our old place. I was using fastmail through a private domain (me@mywebsite.ca), the tenant was using gmail.
Everything was finalized, and I gave some particulars about how the tenant could pay us. This was enough to be dropped into their spam folder and, except for a chance encounter at the grocery store, the tenant would have believed we had ghosted and missed out on the condo.
The silent drop after established back-and-forth is frustrating enough, but the worst part was that we never managed to reestablish email communication. Marking my emails as not-spam, adding me as a contact, etc etc. No future mail from my address to his ever landed in his in-box.
I consider myself lucky that my email address was only locally blocked - gmail users in general can still receive email from me.
So my employer, for instance, "has our own email" but it's just Gmail and we never have problems sending or receiving because we're piggybacking on Gmail's "This is a corporate account with several years of good behavior under its belt" trust signal.
Duelling anecdotes!
Had more experience with XMPP, which had similar problems. If you're going to make a federated protocol, it has to be strict, otherwise a big player will lay down the law instead.
Modern messaging revolves around the ego if it's creators, as a result it is very difficult to have it become an actual standard that others on the internet agree with and that is independent of their infrastructure and CI/CD mindset/process. As a result all possible replacements are only usable by tribes of people who fancy a client.
Naive hostility against censorship and corporate/government middle-ware also means these modern protocols are consumer grade or only usable by entities that agree with (in principle) the political convictions of the protocol creators.
I block repeat offenders with crowdsec. I wrote some details down recently at https://jan.wildeboer.net/2023/04/Daily-Bot-Blocking/ FYI
There's the Dark Mail Alliance[0] effort, but almost nobody talks about it, while it should be a priority to get a new email standard finished and deployed.
"blackmail" means something else, so it is good they avoided that name.
Do we really have to pay attention to these? I have an email account set up just to receive these. 50,000 unread dmarc summaries later... all useless spam that says all the messages passed.
For now, I may not be one of their enslaved user anymore, but in interop with self-hosted smtp server, gmail is probably one the less worse out there: - they don't block (many smtp admin abuse of the broken and toxic spam-haus list by blocking instead of using grey-listing). - they have IPv6. - A few years ago it was fine to send them email with a pure IP smtp (yep, smtp was made to be able to work without the DNS mafia).
But there is a catch: you end-up in their spam folder, DNS SPF and legit email exchanges doing nothing about it (DKIM is excessive overkill). Here, the real issue is non-tech-savvy people must be aware that legit emails WILL end-up in their spam folder: gmail should have such a warning right next to "spam name" like "spam(must be checked for legitimate emails)".
This is saying that the problem is unsolvable. This is patently untrue.
My email servers are configured to do all filtering on whether the connecting server is properly set up:
1) Does the HELO / EHLO name resolve in DNS to the address of the connecting server? If the answer is no, then reject as spam.
2) Is the connecting server's IP on any of a number of more conservative anti-spam DNS-based blocklists, like those that are based on dynamic IP pools, or on spam honeypots? If so, reject as spam.
3) Does the SPF for the sender's domain fail? If so, reject as spam.
The amount of spam this eliminates is tremendous, and most spam that still gets delivered comes from the big spammers: Google, Microsoft, Amazon.
I do not filter content because I'm adamantly anti-spam and and talk about and share spam with other anti-spam advocates, so content filters would be stupid.
Speaking of stupid content filtering, the number of abuse addresses which have anti-spam content filters is ridiculously high. Companies should be embarrassed that they don't know how to run email servers properly and can't accept abuse complaints properly at their abuse addresses.
Google is one of these.
Also, Google doesn't appear to do the tiniest thing with abuse complaints sent to them.
Finally, Google doesn't give people information about their spam filtering, nor ways to adjust it, so as long as Google applies arbitrary both to server reputation and to content filtering, with no ability to adjust, self hosting and smaller email servers will suffer.
Google knows this, and they COULD change this, but there's no profit, no business motivation to do the right thing. They have an interest in NOT doing the right thing, so we can't expect them to care.
What we can do is we can remind people who use Google for email that their email is non-deterministic. Nobody can say for sure whether email will be delivered or received consistently, because no regular humans know Google's rules for filtering, nor do we have access to Google's email logs.
When there are problems, we have to remind Google email users that the problems are with their choice of email hosting, and that's the price of giving up freedoms for "free" email.
I'd be curious to know if someone disagrees, and particularly what part anyone things is wrong. I have years of evidence, but the evidence is from running my own server. I'd love to hear perspectives from people who have different sources of evidence.
Downvotes without saying why just seem... emotional. I admit I downvote people who make generalizations without backing them up, but I'm not sure what's happening here.
That is a very bold (and false) generalization. Spam is not primarily a technical problem, it's a human one. Human problems have mitigations, workarounds, not solutions.
https://craphound.com/spamsolutions.txt
> 1) Does the HELO / EHLO name resolve in DNS to the address of the connecting server? If the answer is no, then reject as spam.
Again, too bold.
> 3) Does the SPF for the sender's domain fail? If so, reject as spam.
Bold and incorrect.
> I do not filter content because I'm adamantly anti-spam and and talk about and share spam with other anti-spam advocates, so content filters would be stupid.
Only works on a very small scale.
> Finally, Google doesn't give people information about their spam filtering, nor ways to adjust it, so as long as Google applies arbitrary both to server reputation and to content filtering, with no ability to adjust, self hosting and smaller email servers will suffer.
Any provider with any significant size won't give you the full details. It'd be the spammers' dream.
If you read what I wrote, you'll see I was talking about this problem: "that Google has no way of differentiating between a server not being well known and messages having spam content"
What you call too bold and incorrect I have years of data showing otherwise. From where do you get your data showing that HELO / EHLO checking and SPF failure rejection are detrimental?
What part of not using content filtering works only on a very small scale? Very small scale of what? What does the scale have to do with the kind of filtering?
So you believe that if providers shared their criteria, it'd be "the spammers' dream"... Except that hasn't happened. Many providers explicitly state their criteria, because they inform their customers what kind of spam protections are in place. Only large providers play games with random, unseen and unknowable rules.
But if you have evidence about how spammers have been in dreamland when learning providers' criteria, please do share.
Google thinks they're too big to either be a responsible Internet presence or to inform their users that they're going to do whatever the hell they want, and the rest of the world can go screw itself.
I honestly can't say I've ever received any SPAM. Not sure what they're doing on their end, but it's been seem less.
I get chills when I see someone's gmail opened on a browser and they have 4,000 unread messages in their ads folder.
I only use it to get auth codes nowadays... Not even Gmail algos can handle the avalanche of spam I get. It's unbearable...
Sites demanding corporate email addresses and/or major email providers kicks all other users out is inane, corporate tyranny.
For comparison, below two precent of domains implement SPF/DKIM/DMARC properly. That certainly hinders identifying the non-spam.
Also, I wouldn't be surprised if less than two percent of all domains are non-junk domains anyway.
This will stop only if/when EU gives Google an appropriate fine of a few billion $$$.
Odds are strong they won't, based on history. E.g., Postini: <https://en.wikipedia.org/wiki/Postini>
Check this other submission:
If you get attacked by an angry Internet mob (thousands of legit email addresses flooding you) you can have their security support clear them out for you, too. Pretty cool.
Finally, Betteridge's law of newspaper headlines is letting us down :)
I've had a bit of a email server for my family in 1999-2002 era, as a high school and university student. I've looked into it several times recently and it seems like the barrier to (effective, practical, reliable) entry is so much HIGHER than it used to be, unlike with almost all other technology.
> Betteridge's law of headlines is an adage that states: "Any headline that ends in a question mark can be answered by the word no."
I think it's funny that we eventually got a technical/market based solution that was a result of gradual cooperation and centralization of e-mail control that required sacrifice of some of our e-mail freedoms (philosophical concessions).
It turns out that e-mail seems to have been a tragedy of the commons only capable of being solved by a regulating body and that as the regulating body functioned, people preferred it to libertarian e-mail.
The copypaste:
Your post advocates a
( ) technical ( ) legislative ( ) market-based ( ) vigilante
approach to fighting spam. Your idea will not work. Here is why it won't work.
(One or more of the following may apply to your particular idea, and it may
have other flaws which used to vary from state to state before a bad
federal law was passed.)
( ) Spammers can easily use it to harvest email addresses
( ) Mailing lists and other legitimate email uses would be affected
( ) No one will be able to find the guy or collect the money
( ) It is defenseless against brute force attacks
( ) It will stop spam for two weeks and then we'll be stuck with it
( ) Users of email will not put up with it
( ) Microsoft will not put up with it
( ) The police will not put up with it
( ) Requires too much cooperation from spammers
( ) Requires immediate total cooperation from everybody at once
( ) Many email users cannot afford to lose business or alienate potential employers
( ) Spammers don't care about invalid addresses in their lists
( ) Anyone could anonymously destroy anyone else's career or business
Specifically, your plan fails to account for
( ) Laws expressly prohibiting it
( ) Lack of centrally controlling authority for email
( ) Open relays in foreign countries
( ) Ease of searching tiny alphanumeric address space of all email addresses
( ) Asshats
( ) Jurisdictional problems
( ) Unpopularity of weird new taxes
( ) Public reluctance to accept weird new forms of money
( ) Huge existing software investment in SMTP
( ) Susceptibility of protocols other than SMTP to attack
( ) Willingness of users to install OS patches received by email
( ) Armies of worm riddled broadband-connected Windows boxes
( ) Eternal arms race involved in all filtering approaches
( ) Extreme profitability of spam
( ) Joe jobs and/or identity theft
( ) Technically illiterate politicians
( ) Extreme stupidity on the part of people who do business with spammers
( ) Dishonesty on the part of spammers themselves
( ) Bandwidth costs that are unaffected by client filtering
( ) Outlook
and the following philosophical objections may also apply:
( ) Ideas similar to yours are easy to come up with, yet none have ever been shown practical
( ) Any scheme based on opt-out is unacceptable
( ) SMTP headers should not be the subject of legislation
( ) Blacklists suck
( ) Whitelists suck
( ) We should be able to talk about Viagra without being censored
( ) Countermeasures should not involve wire fraud or credit card fraud
( ) Countermeasures should not involve sabotage of public networks
( ) Countermeasures must work if phased in gradually
( ) Sending email should be free
( ) Why should we have to trust you and your servers?
( ) Incompatiblity with open source or open source licenses
( ) Feel-good measures do nothing to solve the problem
( ) Temporary/one-time email addresses are cumbersome
( ) I don't want the government reading my email
( ) Killing them that way is not slow and painful enough
Furthermore, this is what I think about you:
( ) Sorry dude, but I don't think it would work.
( ) This is a stupid idea, and you're a stupid person for suggesting it.
( ) Nice try, assh0le! I'm going to find out where you live and burn your house down!
Doing the Right Thing should not be preempted by making a buck.