Gmail, Yahoo announce new 2024 authentication requirements for bulk senders
blog.google
blog.google
I hope they make it really strict. I'm sick of companies that send you spam ("newsletters") just because you interacted with them once, then when you unsubscribe, you get unsubscribed from that one list, so they keep spamming you just with a slightly different newsletter type. (Edit: Also, everything requiring a notification - by e-mail if they couldn't get me to install their app - just to get me to engage with their site.)
Once such behavior has the potential of landing your entire domain in the spam folder, maybe they'll be more careful.
Edit: For example, I can't imagine LinkedIn being able to pull of their "phish people, steal their address book, spam each contact three times with no opt-out" bullshit for so long if strict spam thresholds were in place.
Some large companies even flagrantly violate the extremely lax rules that exist in the States. Guitar Center has infamously been sending me emails that are in direct violation of the one click unsubscribe regulations for almost a decade now. I can’t even sign in to the account to cancel the emails (which is in direct violation of the regulation- it is ambiguous on a lot of things but the one thing that it isn’t is that you aren’t supposed to be required to log in to opt out of email communications) because it was made with my dad’s email from 20 years ago yet I’m the recipient of the spam.
I did report them; but of course nothing must have happened because they are still doing it.
The LinkedIn way.
A few times I've had unsubscribe links absent or not working for whatever reason and done that and a human's replied and sorted it out.
(An attacker used the paypal guest account feature and used my IBAN [european bank account number] and tried to hide the mail within those hundreds of mails. They were successful for some days, until the purchase showed up on my bank account)
And then there's those online stores that cover the entire page in a popup that you can get a 20% discount code if you give your email. Technically I've opted into their marketing. But I always just use the coupon and then report the email as spam without bothering to unsubscribe.
Referring friends and family by sending emails on your own? Who the fuck does that since ~2010? Ever heard of social media and instant messengers?
Edit: Parent was a wall of text when I responded. Stealth editing it to something completely different is not cool.
Social media MAY be an exception, but that's because people are already used to receiving a ton of spam on it, so your "viral post" will be ineffective to begin with, and probably filtered by Facebook and not shown to most people at all. Enjoy.
All the original social platforms such as Facebook and Twitter used ways to invite others by email (famously in Harvard etc.) So now they are burning the bridges behind them and no one can do it anymore.
Also there are separate email marketing laws.
A decade ago I went to my country's embassy to renew my passport, and they now use my email to subscribe me to the newsletters of any new political party. All unsubscribe links just 404s. Shameful behaviour.
Anything I receive from any of their political candidates goes straight to spam now. The hope is that I am training the spam filter so it marks those as spam for all other users as well.
It's simple really: have clearly visible, working unsubscribe link in the body of the email that doesn't require jumping through hoops, and be from a company I know and use. Otherwise the spam filter learns about it.
Lot of people, especially of the older generation, forward all sorts of emails to their friends and family every day. If one person who received a forwarded email doesn't like it and clicks the unsubscribe link, the original recipient (who clearly likes the email enough to forward it around) gets unsubscribed. That's a bug. If you don't like the unfunny newsletter your uncle keeps forwarding you, that's a problem between you and your uncle, not between your uncle and his newsletter!
The email submission form exists to ensure that the person unsubscribing is the person who is actually on the mailing list. It will not prevent an annoyed nephew from deliberately unsubscribing the original recipient, but it will prevent most cases of mistake by third parties.
Similarly, many unsubscribe links require two clicks instead of one, because some email services used to automatically check out every link they found in the body of an email. A one-click link would unsubscribe everyone before they even saw the email. Nowadays we have better protocols and better email scanners, but old industry habits die hard.
That comment explains that there's a scenario where people can be accidentally unsubscribed in the presence of mail forwarding, and the requirement to enter an email address can patch over this.
Thankfully I don't have people forwarding emails to me outside of work...
The page can prompt the email address, and have a simple unsubscribe button. Not perfect, but okay.
Even better, one-click unsubscribe features (e.g. Gmail's App) are presumably set up to work for the current recipient (not the original sender) so the problem is resolved for anyone using an email client with inbuilt unsubscribe.
The forwarding problem is only for html link unsubscribe. Personally I hate trying to play find-the-ubsubscribe-link, so I use the email client feature where possible (which also helps Gmail rate/flag spam).
Mostly I haven't had problems with repeat spammers, except a republican politician (I'm not in the USA so doubly annoying).
I understand the parent's sentiment because we all want to unsubscribe from unwanted emails. But technical standards can't distinguish unwanted emails from business-critical emails. You could legitimately cause someone damages by silently unsubscribing them from an important news feed. (Imagine that you silently unsubscribed an open-source maintainer from all github notifications!) Even worse, this kind of vulnerability disproportionately affects senders who try to follow the rules and make it easier for people to unsubscribe. Spammers don't care and keep spammin'.
Ideally, an email would have both a one-click List-Unsubscribe header and an HTML unsubscribe link in the body. The latter need not be one-click, and in fact, if it's anything remotely important, should not be.
Do open-source maintainers forward around their unsubscribe links in practice?
The other problem with email scanners clicking links automatically can be solved without prompting for the email address. One simple solution is: if the link is clicked within a minute or so after sending the email there's a chance the clicker is an automated system. Instead of unsubscribing right away, serve a HTTP POST form with a single "Confirm Unsubscribe" button. Normal users will rarely see the form, automated systems will hesitate to fire off HTTP POST requests.
It absolutely should be one-click.
I’m a republican (also not in the US sense — I want to get rid of the tie to the monarchy) but I also find that republican politicians seem to be really annoying!
Some people have come up with a trick to hide the unsubscribe link with CSS when it is inside a <blockquote> tag, as in a forwarded email. It doesn't work reliably, though. HTML email is still stuck in the 90s, it's impossible to do anything fancy inside of it. Much easier to send the user to a real web page for an actual transaction.
Email providers autoclicking on links, is the recipient's problem. This is the same flow used for account verification links and yet you do not see them adding an additional step to it.
And then we have the large number of users complaining about this, and yet they feel they simply know better and reserve the right to impose themselves on us?
This decision is purely self serving, let's not pretend otherwise.
You can probably guess how effective that is. In practice, unless you can get the FTC or a state attorney general to sue an actual company for you, nothing will ever come of it.
these are spammers, not cases where you ever actually signed up to some kind of legitimate newsletter or discussion group. to pretend good faith is your first mistake...
https://en.m.wikipedia.org/wiki/Feedback_loop_(email)
Further, pixels can be embedded in the email so they can see when you open the email and how many times.
The sender has every incentive to properly handle unsubscribe to avoid spam traps. If you get big enough, users WILL come sign up for your service with a known spam trap email. If your operations are as sloppy as you’re suggesting, your email sending capabilities go poof.
I think this risk is overstated. Individual spam recipients in the United States have no standing to sue under CAN-SPAM; only the FTC does, and there's a high bar to get their attention.
my university spams me. i bought a torch from olight. they spam me. i get food deliveries. they spam me. i bought some tech. they spam me. i look for real estate they spam me. i get a delivery. they spam me.
it's differentiating between the two that's unrealistic.
There is definitely a punitive cost for sending emails that are repeatedly marked as spam though. You also can’t just cycle IPs because a brand new IP with zero sender reputation is treated with almost as much suspicion by the big player as one that is known to be a spammer.
It’s much better to give people an option to opt out, and to honour it. Most of the email sending providers (e.g., SendGrid, mailchimp, etc) force you to include the link and automatically block future sending to that address. Some will even provide you the option to provide a reason, where you can specify “I did not sign up for this” which in sufficient number will flag the sender account. I suspect the vast majority of cases where people unsubscribe but continue to get email is actually some incompetence from not having multiple disparate email systems sync back to a shared do not contact list (rather each system is maintaining its own).
Click the unsubscribe button.
The dialogue goes something like this:
robert: you know I'm retired from hero work.
Edna:As am I, Robert, yet here we are.
so now it's 2023. you're telling me it's now safe to click on unsubscribe to the spam emails.
yet here we are.
no, the strait forward response is to ignore and mark as spam any unsolicited emails you did not explicitly sign up for. don't try to interact through the desired or expected channels of any entity that spams you.
Your reasons are not actually rational.
i appreciate its impossible to prove a negative (everyone could be doing something they have no evidence or documentation of doing), but given my mail provider both says that you have to mark a selection before they'll share such information with partners and that marking emails as spam still trains your own user specific spam filter, i don't think (and an really hoping) this is not a universal thing.
I worked on an email system that sent billions of emails a month. We used these messages from providers to ensure we never sent them an email again to prevent hurting our reputation. (Marking an email as spam, is by itself, a very low signal on reputation, unless some massive % of recipients mark it as spam. Sending an email to someone who has already indicated you are sending them spam is a high signal that you’re sending spam, however).
It doesn’t even matter when you do it. We had people (outliers) who would go back and hit every single email we sent them for the last 6 years as spam, after a bad customer service interaction, not getting a refund, or whatever pissed them off. We actually investigated all outliers. Most people didn’t report spam on anything older than 6 months.
For more shady stuff I have some throwaway mail at some free mail provider.
Unsubscribing from an email just unsubscribes from that one list. They don't show any other lists or categories (or imply there are more) during this process.
Once you login you are greeted with a multi-page disaster to manually untoggle each of the near 100 list types.
Then when they add new notifications it is auto-on for everyone.
So if anyone has ideas for connecting with your local community, I’m still looking…
Which are usually just black people existing or generic "people walking by my house" reports.
At least it’s on brand. Once you start reading you will be so in awe of the insane and sociopathic people who do the bulk of the posting.
The special award though, must go to Wal-mart. That company doesn't exist in my country. I obviously never interacted with them in any way. I still get their "newsletter", and sure enough, it's authenticated to come from their domain.
I started doing this years ago after watching a talk by some Gmail devs on how they think of spam. They said they internally - controversially - redefined spam to be any email the user doesn’t want to receive. Well guess what? I don’t want to receive shitty marketing emails after I unsubscribe. If you send them to me, I’ll get you listed as a spammer.
I encourage everyone else to do the same thing. Life is too short to put up with this crap.
The threshold is "spam rates reported in Postmaster Tools below 0.3%".
That sounds pretty low to me, but I'm not in the bulk email business. I guess maybe a very small number of users actually report spam? Or maybe Google is being strict.
Source: https://support.google.com/mail/answer/81126#zippy=%2Crequir...
(I work for Google, but on something totally unrelated, and don't speak for them or have any inside knowledge.)
I think this is, generally, the correct approach. There isn't really a salient reason to discriminate between "email I don't want from someone I don't know" ("true spam", if you will), and "email I don't want from someone I do know" (aggressive newsletter campaigns et al). Spam is the button to send a signal that you got an email you didn't want.
> My reaction there is to remove the reporter from all lists because the amount of damage a single spam report can do is immense; a single spam report can block delivery for weeks at a time to the 10k others that legitimately requested messages.
This is the system working as intended to me, as the customer of the email service. I like that my email provider is throwing their weight around to put the fear of God into bulk senders and forcing them to think about how this campaign will impact their sendability. I would much rather annoy the hell out of bulk senders than cede emails to spammers like we have with phones.
In most other cases (e.g. newsletters sent based on a tiny pre-checked checkbox or without asking for consent), the spam button is of course the right tool.
Sounds like it's working as intended.
And Yahoo is the Single worst email service to send to. I have correctly configured sfp, dmarc, dkim, reverse dns for the Mailserver and have tested the wording with multiple mail testing services to make sure it doesn't have keywords that get automatically flagged.
And yet after like 50 emails to parents with yahoo email addresses they are giving me errors because of "unusual volume of emails from your domain"
There is no form, no human to talk to and they just block you.
Angry parents come to me or course because they never redeived the activation link so I had to put up a disclaimer stating that if they should not use a yahoo email address if they have a different one
There would be other ways to clog the system using trashmail providers but thankfully no student cared enough for that yet
Am I crazy or just missing some super obvious gap with this path?
You'd also have to do a lot of work to validate new senders long before they send their first message and you start getting complaints or else you're just letting spammers pay you to completely bypass every mail provider's spam filters until they finally get blocked and have to create a new account with you under a different company name.
If you can convince everyone to trust you, and your service, and that it'd be worth it for mail providers to do all that work on their end on top of everything they're doing currently to prevent spam, it really could improve deliverability.
Why would you need to do that? Just work with those that'll pay you for it. The others won't care as they'll just ignore the header.
I suppose that really you'd be able to get a lot of utility by convincing just a handful of very popular email providers (gmail) to trust that your service will never be used to send spam (or that they should let spammers who slip by you right past all of their spam filters). The more email providers you can get to use your service though the more you could charge the mass mailers for guaranteed message delivery.
Such a service could lead to two very bad outcomes though. Parents being told that if they want to get email from the school they'd better sign up for an email account at one of the few supported email providers (gmail) and/or (if it becomes successful) any sender who isn't paying for the privilege of sending email being treated like a spammer.
This is often not a non-sense complaint. A lot of newsletter signups are still via pre-selected checkboxes that are easy to miss.
That would get you added to a "never block mail from this domain" whitelist that had higher precedence than everything else.
Scandalous, it's almost as if the established major providers have a financial interest in making it difficult for smaller providers and individuals to send mail using their own domains!
During the pandemic we had a lot of problems with the confirmation email for our 5000 T.A. in the virtual campus of the university. I had to guess what was happening because I was not part of the administration team, just collecting forwarded messages form the T.A and guessing:
* Gmail: Most of the time it works.
* Yahoo: The server receives a few hundred emails per day and the other are delayed. These were confirmation emails with half an hour tolerance, if they were lucky to pass the next day they were not useful. (After a week the sending server stops retrying.)
* Hotmail: Sometimes the email is received and sometimes it just disappears. No spam folder. No bounce email. It just evaporate. (Try sending an email from hotmail to the no-reply address and cross your fingers.)
* Others: No enough data to have a good guess.
Gmail will do this too. Happened a few months ago with a single (important) message from a private individual sender on Hotmail, one unknown to my Google account. The fix was adding the Hotmail address to a Google Contact.
I hope they not. Gmail spam filter is far from being perfect and classifies many non spam messages/senders as spam. May be because they heavily rely on user reports (to train AI?) and email users tend to report all kind of emails as spam including clearly ham messages like bank statements, appointment notifications, password reset emails e.t.c.
Never interact with spam. Unsubscribing just tells spammers that your email address is actively being checked, and that you're the kind of person who clicks on links found in unsolicited messages. It can even end up getting you more spam (as you've noticed), and what looks like an innocent unsubscribe link can actually take you to a malicious website instead. You've really got nothing to gain by touching spam at all.
The best way to deal with the spam that makes it into your inbox, especially spam that comes from specific senders with predictable subject lines/body content like newsletters, is filtering. For example, just auto-delete anything from a domain you never want to hear from again. You never see it, and you leave them spending at least a little time/effort shouting uselessly into the void.
I tend not to auto-delete directly, but have things filtered into specific folders just in case. It takes almost no time to clear out when they get very full. Most filters are set once and forget.
Yet there are people here on HN telling us that we have some kind of responsibility to watch ads, not block them, and support the kind of people who do this slimy, evil, unethical bullshit.
This only applies to scam emails like newsletters from sketchy domains that you never signed up for, which are sent out specifically to find active email addresses. For those, clicking the "unsubscribe" link is indeed counterproductive.
For actual businesses like Linkedin though, it makes more sense than not to unsubscribe from unwanted emails anytime they're sent. On occasion you'll find yourself back on a different newsletter list, but it's relatively rare and more often than not just incompetence rather than malice; legitimate companies want to send their emails out to people who buy stuff, not people who mark them as spam and lower their reputation.
Why? What's in it for you?
You filter them = never see the spam they send you again
You unsubscribe = pray that it's not a phishing email disguised as linkedin spam, hope that if it's real they don't just start sending you different spam, and that maybe they haven't agreed to sell your (now confirmed as more valuable) email address to 3rd parties (aka, their "partners") now that you've made that email address worthless to them otherwise.
The absolute most you can ever hope for in the "unsubscribe" case has the exact same outcome as the "filter" case, while the filter case has less risk and as a bonus lets the spammers waste their time.
They already have my e-mail address, likely even verified. They're also somewhat normal companies, i.e. they have an address where the local DPA can send a friendly reminder, and while they will happily pass your (likely hashed) e-mail address to Facebook for ad targeting, actual selling to spammers is incredibly rare.
I often can't just filter the domain because I might actually need to deal with the company again (if I boycotted everyone who acts like a dick I'd be living in a cave).
Also, for many, unsubscribe actually works.
At MailPace we already enforce DKIM, it’s pretty basic stuff. But list-unsubscribe is optional for our senders.
We can make this a requirement and manage lists for senders who don’t / can’t implement a webhook to handle it (we already default to blocking resends to emails that hard bounce).
However I am curious how Google will track this. Just because the header is set, it doesn’t mean it’ll do anything. In fact it can be used by spammers to identify legit email addresses and spam them separately.
Edit: I suppose it does say "unsubscribe from commercial email in one click". But it's hard to say exactly what they mean. They also don't define Bulk Senders - is that the domain or the sending SMTP server?
On one of my SaaS apps workers receive details on their shifts via email. If I allow them to one-click unsubscribe, I know there will be many who do so accidentally, with no idea how to resubscribe.
Currently they need to sign in and manage their contact methods in settings (email, SMS, etc). Thus they know how to re-enable it if they disable it.
I can see many support requests from managers saying "X worker isn't getting emails". Sigh.
Perhaps you could notify the manager when a user unsubscribes? Puts the ball in their court to notify the user (their employee) they aren’t going to get critical emails. Make sure any unsubscribes show up in a log available to your customer.
“Hey. You unsubscribed. Here’s a link to resubscribe if you happen to want to!”
Right after someone unsubs.
It’s already pretty standard practice to send an email notifying that the unsub request was processed.
A big part of why I’m stuck on/with gmail is that filtering redirects about 90% of those to spam.
That doesn't really make sense? If you used an address on your own domain, other people would be pretty unlikely to enter that email address instead of their own. The problem with misaddressed email should be limited to domains with really high username density; nobody else than the Gmails and Outlooks of the world need to solve the problem because nobody else also has the problem.
For example, email clients generally allow you to use multiple accounts at the same time. Configure your client to read emails from both accounts at the same time, and any time an important email arrives at the legacy account try to update the sender.
(I mean, I'm sure that xkcd.com/1172 applies, but still this seems like an odd thing to be blocked by.)
I'd rather begrudgingly keep taking advantage of Google's spam filter over adopting the added workflow branch that is perceivably likely to trail me for another decade-plus.
My name is common in certain areas, and I consistently get transactional email from banks, telecoms, and insurance companies around the world.
These businesses do not verify that their customer’s email is truly their own prior to sending emails.
Framing custom domains as the solution to this problem is a bit rash, no?
At this point something as simple as ordering something online means I get 4-7 emails and then some growling "please rate us" shit. And if I am stupid enough to do so, but only rate it 4 our of 5, another "we are sorry, please tell us what we did wrong" email.
Hostile? A bit, but after contacting services and complaining, nothing would get done anyway.
I ended up changing email providers because of that.
I contacted the customer support for all of them and they said they can't do anything about it. To change the customer's e-mail address, I need to prove I'm the customer, and obviously I have no idea who they are.
So I gave up and implemented a Gmail filter in the end, but I definitely wish that parallel with the traditional unsubscribe, there was a way to say "this isn't that person's e-mail". Where I don't have to prove I'm the person, I just have to demonstrate I receive the e-mails.
I have in the past had very good data on how often a russian guy got a haircut.
I've also done this where I've donated $25 to U of California in the name of my friend who went to Stanford (rival universities). He's likely still getting calls.
> whenever I don't feel like putting my own email or phone number I just put his
This sounds more like malice than well thought out humor. If I found out someone I knew and respected was using my primary contact information for spam emails at <insert random pet supply store or random restaurants' rewards programs here> I would definitely consider not talking to that person much any more. The rival university one however I would let slide because the intent from you is obviously different.
Have you tried doing this recently? Creating an email address has become a fairly draconian process.
I'm not sure, are you implying that it is not worth doing this, and you would rather instead just pollute the inboxes of people that happen to know you? If so, would you like to be friends? I'd be happy to receive your junk emails if in exchange I can come by your place and just leave my trash in your front yard/driveway.
If you want an account for random garbage that demands an email address, use mailinator.
I'm not sending these.
Oddly, on the cash app thing, I have a very basic username and seem to constantly have folks sending me money, sometimes good amounts. I never use the app, and eventually I hope the money goes back if I don't collect it.
More annoying on email but much less than it used to be - I think more systems require email verification now so a bit less common to get the misdirected order emails etc.
But yes, if I can't unsubscribe - then I block and report spam - even if it looks like transactional email (some is a lead-in to a scam where they will refund you for the "bogus" purchase).
Anyway, the job applications have died down, but I still get plenty of others for people who are creating accounts. I unsubscribe when I can, and "mark spam" when I can't.
Think of it the same way Canada’s anti spam law (CASL) works. https://emailkarma.net/2016/09/qa-transactional-emails-unsub...
- confirmation of my order
- my order has been despatched
- my order is out for delivery
- my order has been delivered to locker
- reminder to collect from locker
- my order has been collected from locker
- feedback on customer support chat experience
- my return label has been generated
- reminder to return my item
- my refund is processing
That's Amazon, in case it's not obvious. I don't need any of that by email, I immediately archive it, and if I want to know I look in my account, not my email. I even have the app installed and notifying me with all of the same and more (I'm spared 'x stops away' by email).
The vast majority of Amazon customers do not have its app installed. And those who do have the app can disable Amazon emails or create filters in their own mailbox, it's not exactly difficult.
No you can't, that is the point that is being discussed.
True, but I think when you're processing the volume of email that Gmail is, you'll have enough data to be able to infer whether the unsubscription was processed.
Reason I'm asking is Unsubscribe rarely works for me due to my catch-all not SENDING emails from the address it was received on. It sends it from my actual address. Very annoying.
If we build this as a mandatory feature at MailPace, we'll use an HTTPS webhook with a unique identifier for the email, so if you unsubscribe from a list sent via us, it will work for you.
Also it requires senders to actually implement it, which is not possible to confirm. Although we could add a catch all service that does this automatically, which I think we'll do.
Are you asking to be blacklisted from all future transactional email from a particular service? That’s something very different to being unsubscribed. You’re asking to be added to a list, permanently.
As I was writing this message, Florida Power and Light sent me yet another "transactional" message I can't unsubscribe from because they're under the mistaken impression I'm their customer.
A couple examples of such nuancing qualifiers:
- "unless prior permission has been obtained or unless there is a pre-existing commercial relationship between the parties" (UK)
- "for the purposes of direct marketing" (EU)
You may read this table to get more examples of local definitions and the associated regulations, per country: https://en.m.wikipedia.org/wiki/Email_spam_legislation_by_co...
I'm not excluding transactional emails because to someone who doesn't want your email ... it is not transactional.
You are making a bunch of leaps of logic:
1. The person you are emailing is the same person using your service.
2. The person you are emailing consents to you emailing them about your service.
Consent can be withdrawn at any time, it doesn't matter if it is "transactional" or not, "legally spam" or not. This is just basic human decency and if you cannot follow it ... then this is why we need laws, I guess.
That's my concern as well. Ah well, we'll just mark them as arc=pass and sit back and relax.
However if email blocking becomes too aggressive then it can easily result in mails containing information that senders are literally required by law to provide to the recipient being silently dropped, which essentially means the mail service has caused the sender to unknowingly break the law. The penalties for not providing required information under consumer protection rules can be extremely serious in jurisdictions like the EU.
And Joe Random can be a real customer who you are really required to provide with information but can still hit the "this is spam" button if they don't particularly care or want to see it so reading too much into self-reported spam flags is a bit of a slippery slope. Combine that with mandating one-click unsubscribe but possibly without recognising types of emails that again the subscriber literally can't legally not send (at least not without sending the same information to the same recipient some other way instead) and there could be some real danger here.
But they can track proxy metrics for this. For example people using GMail's builtin unsubscribe feature more than once with the same unsubscribe link for different emails is a pretty good indicator the unsubscribe did not work.
I very aggressively unsubscribe from everything so I get very little mailing list spam. Maybe a few messages a month.
What I do get _constantly_ is spam email messages to my inbox from Gmail and Outlook domains. At least one a day for many years. Because it from Gmail, they have very little spam filtering done, yet if any other provider sent these messages then Google would block the entire domain.
These particular spam messages get on my nerves, and these are the only ones making it through to me.
Whereas quite a few of these quasi-spam marketing emails from a company that I once had some interaction with. The worst is hotels - you stay at 10 hotels during the course of a trip, then you get added to 10 email lists for the rest of your life.
Never unsubscribe from anything you haven't subscribed for (or at least where you haven't gave your email address to the sending party), because I believe any interaction with unsolicited emails provide spammers with a clear signal that their spam is not just delivered but also read and interacted with, so they get more agressive.
But more importantly even if I provide some signal that my email is active it's not going to change that much. They can send more, but that just helps train filters.
Lastly default Gmail settings loads remote images. Just opening the email is enough to create some signal. Having remote images turned off is enough to stop most engagement pings.
I doubt Google would do that to other big companies.
Some accept user-provided email addresses at face value, without any confirmation, and then refuse to stop spamming you.
Would Google block Paypal?
That’s what I have done on my outlook.
Are they actually from Gmail accounts, or are they simply spoofing the sender? My bet is on the latter, because Google has heavy restrictions on Gmail that make it impractical to use for sending bulk spam.
> I am not sure what a big improvement this will be for the average user.
It's not going to be particularly noticeable for the average user, except for the second part (single-click unsubscribe, as opposed to a multi-step flow, is slightly stricter than what's required by CAN-SPAM). It will probably make Google's work easier, though, by having a publicly-known policy of rejecting emails without DKIM, as opposed the the status quo of having that be merely an open secret.
BUT, Why does IP reputation matter so much these days when you have DKIM, MTA-STS, DANE and other mechanisms that provide verification of the sender?
Say I want to startup a Email Service Provider, I need to go and source a bunch of IPv4 typically to have a premium upsell for end users to really ensure cross sender reputation does not impact other tenants. Crazy.
IPv6 historically at least was anecdotally punished by the likes of GMAIL, Yahoo, Hotmail, Office365 etc. Does anyone know if IPv6 hosted email severs still suffer additional spam scoring?
Gmail is the only inbox provider that doesn’t offer a real feedback loop (you don’t actually know if a given email address marked you as spam when sending to gmail users). The FBL in Google postmaster tools is anonymized and unreliable at best.
So essentially, you never know if a Gmail user marked you as spam so you can stop sending to them. Gmail will just by default mark your emails as spam for that user going forward, without telling you. This means your spam complaint level will inevitably rise over time without you knowing why and what email addresses are causing the issue.
Unless Gmail actually starts providing a real FBL like other inbox providers, the hard spam limit is going to snowball into a nightmare for even the most conservative and legitimate senders.
Think about this from the perspective of an actual spammer. You get a notification that address XYZ is marked as spam by user ABC. Well, now you just email user ABC from a different address.
The real problem is, for legitimate senders, the people who send less emails actually get higher levels of spam complaints! This is because humans are human and they forget who you are. I would argue this actually incentivizes sending more emails. This is why marketers all recommend sending garbage emails daily/weekly/monthly.
The truth is, the companies with full-time spam (marketing) departments will do just fine with these changes. It's the little guy who is going to have to navigate these complexities (likely unsuccessfully), and get shut out from yet another technology that used to be open.
On top of that, Google has started to offer perks for senders within Gmail for a $1,500 per year fee (VMC). They're basically one step away from collecting rents on all of email by way of their monopoly.
I also don't think it's complicated for the "little guys". The solution to avoid getting banned is simply to not send mass spam. It's not rocket science, don't mass email people knowing that they get mad at you when see your emails in their inbox.
hxxp://example.com/unsubscribe?id=abcd1234
A couple years ago I noticed that MSFT IPs hitting my unsubscribe links with invalid identifiers on the quest string. Anybody ever seen that?
That was my understanding at least.
I don't read clicking a "confirm" button as a second action. The attorney didn't either. He also said CAN SPAN doesn't apply to a 501(c)3. I still try to comply to be a good citizen.
What you can't do is take them to a page that says "to unsubscribe, send a certified letter to our headquarters and wait 90 business days". The entire transaction must be completed at the page you link to.
Bonus points when contacting support requires me to log in to "my account" too.
I've seen this pattern of unsubscribe link, then click button approved as CAN-SPAM compliant more than once so I don't think there's a legal concern. The CAN-SPAM rule seems more targeted at the systems you used to see a lot that required the user to log into their account, type in their email address, or figure out a complicated "communications preferences" list to use the unsubscribe form.
check out https://www.ecfr.gov/current/title-16/chapter-I/subchapter-C...
It's a little fuzzy to me how exactly to interpret this but I think you could reasonably read it as allowing even unsubscribe pages that require you to type your email address in again (even though I detest these and don't think the problem they're intended to solve is a meaningful one).
These are fine for me if the email is prepopulated.
Details: https://support.google.com/mail/answer/81126#zippy=%2Crequir...
(I work for Google, but on something totally unrelated, and don't speak for them or have any inside knowledge. I was just curious and looked it up.)
https://techcommunity.microsoft.com/t5/security-compliance-a...
Please report back if you try it :-)
Please try to make the world a better place instead of doing the legal minimum.
One click unsubscription is presumably what they want.
My experience is that every unsubscribe goes to a form w/ a submit button. Shitty ones make you type your email address. (Mine doesn't.)
Just did a bit of unsubscribing and sydneytools.com.au, abc.net.au, squabblr.co, bundlehunt.com, and healingstreams.tv all one click unsubscribe.
No idea if this holds if/when the email crawler bots start executing JS on crawl.
This allows everything to be "one click" (which honestly is a good thing) but prevents crawlers from accidentally triggering the unsubscribe.
Not sure this still works today and obviously this is not legal advice.
---
Okay, HN. Go ahead and explain what's offensive here.
The question that was asked: "I noticed that MSFT IPs hitting my unsubscribe links with invalid identifiers on the [query] string. Anybody ever seen that?"
The question the parent commenter seems to have hallucinated: "Does anyone know how we can keep mail services from unsubscribing folks in error when these mail services scan our subscribers' emails, but also still offer our subscribers 1-click unsubscribe?"
You can use captcha or similar, one workaround I've seen has a submit that is hidden so never clicked by real people then a visible submit that sets a hidden input and clicks the other one which requires the hidden input... not foolproof but avoids some accidents.
Turns out, dealing with Unicode beyond 2 bytes (i.e. anything above ASCII and the common Latin characters) is still a problem in 2023.
If I get another email from that org, I click "report spam".
If it's in the querystring then they essentially fuzz it by changing some part(s) of the value. I noticed this because I use signed tokens and it raised an exception in Sentry when the signed token was invalid.
I ended up moving the signed token into the URL itself and the problem went away. eg. /unsubscribe/abcd1234/
Weirdly, if google thinks you're a dodgy sender they won't display the button, which seems counterproductive to me.
Not only I keep receiving almost the same email suggesting to buy 5,000 email addresses of Atlassian customers with always the same fields, but it’s always from different domains.
I didn’t think of submitting an Atlassian ticket for each spam I receive. That would teach them.
NEVER give your true email to Atlassian.
Happened to the disposable email address I sent to the International Manufacturing Technology Show, the A3 Automate show, and the Advanced Manufacturing Expo.
I understand giving my business card or email address to a new vendor I meet at the show. That's the point of the thing.
I do not understand why these shows sabotage themselves by selling their reputation to spammy marketers.
Would love for an "Unsubscribe Sunday" unofficial holiday to catch on to the same degree as "Cyber Monday".
I don’t ever remember subscribing to anything. Almost all email is undesired, apart from password reset emails.
Keep in mind our webforms you can put whatever email you want in them. But something to do with the fact that we are knowingly storing the information and it crosses to another system.
That doesn't stop people from sending in a spate of complaint emails every single day. But this is kind of the local minimum we have found and no one really wants to mess with it at this point.
There are three requirements. The first requirement - DKIM - is already a de facto must-have when sending emails to avoid getting marked as spam. The second is also a legal requirement in the US for all commercial email under the CAN-SPAM act[0]. And the third is more or less how email delivery has worked for the last 20 years or so anyway.
[0] The "one click" and "within two days" parts are a little stricter than the bare minimum CAN-SPAM requirements, but not much, and they are not difficult for any legitimate sender to implement.
CAN-SPAM is ignored for the most part anyway, e.g. LinkedIn requires recipients to authenticate in order to unsubscribe and openly violates the letter and spirit of the law to the point scripts are required: https://github.com/chengyin/linkedin-unsubscribed
There are several known-bad actors. LinkedIn isn't even the worst offender - Amazon is much more brazen, though they get less flak for it because the number of violating non-transactional emails they send is lower.
Regardless, I stand by my point that this isn't a big shift. Google stating publicly that they will penalize people who are violating an law that turns 20 years old this year, and which has generally been implemented by almost all legitimate bulk email providers[0], is not something I'm particularly surprised about or worried by.
Again, the first and third bullet points in this press release are already de facto policy at Gmail, and have been for over a decade. The news is that Google is stating this publicly, not that they're doing something new.
[0] The notable exceptions notwithstanding, it's quite rare to find a bulk email sender who violates this, because very few legitimate mail providers will allow it, and it's pretty difficult to set up your own mail server with decent inbox delivery rates.
I wouldn't be surprised if Gmail spam is higher-effort (like those individual SMS spam apps that politicians use) but higher-breakthrough.
I would be willing to wade through a number of additional spam emails to avoid losing important ones but of course this is Google so there is no user facing dial to adjust the sensitivity. Users just have to trust that Google's generalized approach is well calibrated for them.
I now skim my spam filter regularly because of this, but not everyone realizes they should do this.
Same, but I feel like it's almost kinda socially acceptable now. Happens to everyone and it's not something to get upset about... "oh, it wasn't me, it just went to spam." Like Gmail managed to alter our public norms instead of ensuring a zero false-positive rate :)
It sounds like a lot of people here check their spam folder regularly, which is good, but I don't know how widespread that is. I remember Gmail early on deemphasizing the spam folder since, in their view, the filtering was so good people didn't need to check it.
In the spam folder I just scroll down the list as fast as I can skim, and then close the tab if there's nothing.
If they were all just in my inbox I'd have to manually mark each one (and risk accidentally doing it to a real message while going through hundreds of messages).
There's no perfect solution here. Just personal preferences. I think I'd prefer a clean inbox with a 1% false positive rate vs having to manually flag a bunch of missed spam all the time.
I disagree with you. I use Postfix with rspamd plugged into it for my personal email account. I get way more spam to my gmail than I do to my personal account, and I sign up to everything with my personal account.
rspam also dkim signs my emails when I send them etc, verifies SPF/DKIM/DMARC on recipet etc.
Now to counter that - I am a TINY mail server - Probably 100 emails a day tops.
"I run my own mail server and get better spam results than Gmail"
Using Postfix+Rspamd gave me good insight into SPF, DKIM and DMARC and how to use them effectively.
rspamd is very, very impressive. I guess most of the hard work I've put into it is adding some of the not-turned-on-by-default things, like Pyzor and Razor. Also adding some other RBLs that weren't included by default (I spent a lot of time personally researching them and only picking ones that I believed to be of high value) The other big thing that I think is important is the RBL whitelists - DNSWL.org and HostKarma have a whitelist as well.
About one a week I spend 10-15 minutes looking at the logs of what it's accepted/rejected during the week to see if I can spot any obvious mistakes - it's pretty rare. If I do spot something I make config changes to address it. That said there's been months before where I haven't done this and none of the users of my platform have complained about spam (or missing email)
rspamd really is that amazing. I don't understand why more people don't scream it's praises from the rooftops.
Before I decided to leave it due to its horrendous false positive rate, gmail was driving like half of notification emails from my servers and mailing lists to spam, despite me never marking them as such. I was regularly missing important things.
It's much better with just regular client side bogofilter and some training on my personal mail/spam archive. And I do zero server side filtering, it's just all content based.
I don't care about capabilities, I just want near 0 false positive rate on the kind of email I receive (and not some common model), even at cost of some false negatives, and Gmail doesn't deliver there at all. And I don't want any arbitrary 5xx rejections for my senders, since I know how annoying that is on the sender side. Gmail will not guarantee that.
I think I have the opposite preference to you: false positives are OK to me if that means less spam gets through. In fact I've seen many of those notifications in my gmail spam and thought to myself, "Huh, you know, maybe I don't need those that badly after all... I'll just let gmail keep it there."
The overwhelming majority of my human contacts use other channels anyway (some chat app, or SMS), not email. I might get like ten real emails from humans in a year, and even then 90% of them are from people already in my contact list (and so bypass spam).
Phone calls are similar these days. Google Fi/Android also applies a similarly strict spam filter to incoming calls, and marks and blocks a lot of them as spam. I check once in a while, but overall I just don't really mind. If someone really needs to reach me they'll find a way... if they don't try, it's a good filter for how important their message really is anyway, lol.
I really wish Github had a DM feature =/ It feels so weird these days to email someone out of the blue.
And if you use non-GMail email providers, you would know they do fine. Not perfect, and of course it differs among providers, countries and accounts, but it's generally fine.
No it isn't.
> So today, we’re introducing new requirements for bulk senders — those who send more than 5,000 messages to Gmail addresses in one day
If you run an email server for personal use, you are quite unlikely to send more than 5k messages per day.
I avoided DKIM till 2018 when google started accepting my mail but silently sending it to the spam folder; so I wouldn't even get a reject message. I thought it'd be to onerous to implement but rspamd's dkim signing feature made it easy to use with my locally generated self-signed certs (and postfix).
It's been a long time since you've been able to set up your own email servers without DKIM and expect that your emails will get reliably delivered to Gmail users, especially for bulk mail.
The second requirement is more or less already a legal requirement in the US, and the third is literally how anti-spam has always worked - the only difference is that Google is now saying that they'll publish the threshold publicly, rather than keeping it a secret.
This is technically news, but it's hardly a major shift.
- non residential IP (I had to proxy through my VPS) - SPF - DKIM - use TLS with a modern cipher
And even with this, I still had to "favorite" (or whatever) AND set up a rule to "never send to spam" for my alerts@ sender address because I would still get them going to spam for no reason that I could find - I'd check the message and would see that SPF and DKIM PASSED and yet it was still going to spam.
I ended up switching to using webhooks to send alerts to a discord channel for a server that only had me in it. It works fine. It's a lot more surefire than trying to figure out email delivery
I have no problem with email deliverability to gmail/outlook. I think the difference is that my emails are two-way communication. I email someone, they email back or vice versa. Not a continuous stream of unreplied emails from my personal server to some gmail address (which does look like spam).
I imagine if you set up a script to reply to these emails from your gmail account with lorem ipsum and then deleted those replies after a few days, your problems will disappear.
I get spam messages once in a blue moon on my iPhone (specifically, on iMessage, I get recipients with a string of random letters ending in gmail.com). Ironically, it's ALWAYS a gmail.com or hotmail.com address. Funny how the overwhelming majority of spam I can remember comes from Gmail and Outlook, both of which love sending everyone else's messages straight into the spam tray, despite having DKIM + DMARC set up, static IP not on any Spamhaus blocklist, etc.
Imagine you live in an apartheid state and the people in power say: “White people will now refuse mail coming directly from black people. If black people want their mail to be received, they are required to send it through a trusted white liaison. If you're black and you don't like it, just make friends with other blacks and the tiny minority of whites who will accept mail from undesirables like you."
The above analogy is exaggerated of course, but I think there is a fundamental truth for it: large tech companies like Google have cornered the market by offering free solutions, and now they are imposing an apartheid system where mail sent through big companies is given priority over mail sent by real people who run their own email system.
(Personally, I've disabled all spam filters in Gmail since I've noticed that Gmail is likely to filter out legitimate email while the amount of spam I receive is actually very low.)
I get daily spam coming from Gmail and Azure tenants especially.
There is no such thing as the open and impartial internet. It's a melange of fiefdoms which only works through loose agreements between giant providers that tacitly allow all kinds of shit to happen in the hopes that they'll recoup the cost through their own business plans. The internet is quasi-open; open enough at the level that you interact with it that it "feels" open, sometimes. And it most certainly is not impartial. Competing interests have been warring over pieces of the pie for decades, and use whatever control they can grasp to make as much money as they can, while they can. Nerds running self-hosted servers and railing on about the inequities of corporate control on forums have absolutely no say.
> I get that spam is annoying (I hate it too) but letting giant American tech companies decide who is allowed to send email and who isn't is not the solution.
Again, they aren't. They have their own e-mail system, and you can use it or not. They aren't telling you you can't send your own e-mails or run your own systems. You are just upset that they have their own party and won't let you choose the music. You could throw your own party, but you don't want to do the work that entails, while you do want to force the people who are doing the work to do it your way, despite everyone else in the world not giving a shit and not wanting to deal with the problems anymore.
E-mail is not state sponsored racism. Again, you can choose what e-mail provider you use, and run your own mail system, and do whatever other asinine navel-gazing techno bullshit you want. Nobody is stopping you. They just aren't going to accept what you make. That's not oppression, that's called competition and free choice.
I'd be curious what you think of the telephone. Was that too intended to be some kumbaya international symbol of freedom that anyone could do anything they wanted with? Are you looking to run your own switchboard, and upset that AT&T won't carry your calls without forcing you to pay to hook up to their equipment? How dare they be able to reject your homemade lines to connect to their customers?
You want to know what actually not having a choice means? It means you can't even run your dinky mail server at home because the service is deemed illegal. That has not happened, and will not happen, because literally nobody cares about you and your e-mail service. You are the only person who cares about this. You are obsessed with a principle for the principle's sake, and the funny thing is, that principle isn't even being violated.
You want an end to the "tyrrany"? Use that engineering genius to come up with a solution to spam that doesn't revolve around IP reputation. Companies around the world will gladly take your mail if you can come up with a solution that doesn't require them to spend millions to mitigate spam.
Yes, you need to configure authentication (DKIM, rDNS and preferably DMARC) but you should be doing that anyway, the hard requirement doesn't change that.
One-click unsubscribe is required for bulk email, but you probably don't want to be sending bulk mail from your self-hosted solution anyway.
Anti-spam isn't killing the internet, spammers did.
This will be a pain for legit use cases but will net to a better place for the ecosystem.
Much like strong KYB/KYC for bulk text messaging.
Is Marcel Becker, supposedly the "Sr. Dir. Product at Yahoo", according to this article, the only person working at Yahoo handling email these days? I'm only half joking - Yahoo is incredibly unresponsive when it comes to abuse.
I was shocked to find out that maybe 1/3 of all recipients had to find my emails in their SPAM box. Eventually, I paid for a service that allows to send SMS in bulk so that I could inform people to check their e-mail and spam box for the login details.
I hope these new measurers will mean that less email is earmark as spam. The fact that is sent out 300 mails with identical text and multiple links in it, is in no way a sign that it is spam.
It got so bad in facts that some people reported not even seeing my mails in their spam box (or, many older folks don't know how to find/open their spam folders). So eventually, I asked them to send a mail to me first, to which I would simply reply.
If so, sounds good to me.
The cynic in me thinks it's a prelude to stuff like BIMI because that lets them add a large annual cost for anyone that wants decent deliverability. It's a way for large senders to use their market position to invent a new industry with a service we all have to pay for. Free money!
BIMI does solve some issues with DKIM, so I can see why Google prefers it. Requiring what should be a minor fee for any company to do bulk email will also make it difficult to set up a thousand different spam domains.
The one-click unsubscribe is from 2017's RFC8058. Everyone that's sending in volume is already doing all the usual stuff - DKIM, SPF, DMARC, matching reverse IPs, etc.
The privacy-first email marketing service I wrote (https://info.smartmessages.net) implements account-wide unsubscribe by default (unsubscribing you from one list unsubscribes you from all). It requires double opt-in, and asks for explicit consent before doing any tracking whatsoever (so no Google Analytics, no cookies, no trackers), which of course is what the (at least EU and UK) law requires. You're not going to see shitty exploiters like MailChimp doing anything like this; abusing your data is just too lucrative.
It's still ridiculously hard to deliver messages at any volume, and there is zero recourse when you are penalised incorrectly. Gmail's spam filtering is just dire - if I send myself an email from gmail, it goes into spam. A large proportion of the spam I receive is sent from gmail.
Google's postmaster tools are a joke. It's entirely normal for them to give you a "bad" spam rating when you have 0 spam reports, 0 auth failures, strict DKIM and DMARC, and every single message has double-opt-in audit trails. This useless feedback makes it very difficult for senders to actually comply with their ever stricter, but ever more opaque requirements.
Proving that subscribers actually want to receive messages from you its difficult. So back in 2017 I wrote an outline proposal https://github.com/Smartmessages/subscriptionproofrfc to create a standard, possibly built on top of DKIM keys, to provide provable subscriptions. This would pretty much solve the entire thing for legit senders, but of course the industry is not really interested in cooperation or complying with any law that might reduce the number of people they send to by even the tiniest amount.
/cynicalrant
Now who could you mean by those.
> The privacy-first email marketing service I wrote
Oh right, spammers.
Steps to reproduce:
* Search for a gym on Google maps.
* Click a Planet Fitness result that's somewhere nearby.
* Expand to their website link, follow it, and browse several pages on their site.
* Do NOT give them your email.
* Wait a few days and check your email.
* Watch your email through the next couple weeks for follow-up emails that continue to urge you to action.
This will probably require you to use a browser with an extensive history. EG, not one with temporary container tabs or other such privacy considerations. Something you've used the email on in a variety of scenarios, enough to have it linked to your identity with some sufficiently large advertising agency.
It's illegal, a complete violation of CANN SPAM act, but I imagine it makes them more money than they'd lose if they ever actually got slapped down.
I just wonder which information provider they're using that has 'sold the goose', so to speak. By giving an email address they no longer sit between the company and the user's marketing efforts, so it must be fairly expensive to do. But it enables these kinds of follow-up campaigns.
For clarity, I am not against anti-spam measures, but I do worry about centralized services being overly strict and doing damage to their customers, especially if it is so draconian that it prevents delivery of important communications as retaliation.
Adding systems in place to handle unsubscribing from transactional emails will mean quite a bit of engineering time/effort for many companies.
This has all gotten completely out of control. Yet again, regulation seems to be about a decade behind.
The main webmail platforms do not benefit economically from spam. They have every incentive to turn it to their advantage by diverting ad dollars from bulk email and forcing it into their own ad platforms.
1. Is it the news that Google still accepted bulk volumes of unauthenticated mails in 2023? If that's true - finally, good riddance. Although I believe most spam those days comes from legit hacked domains.
2. Am I reading this right that List-Unsubscribe and/or unsubscription link is going to be required for high-volume senders, marketing and transactional? That's good to hear, although - again - it's hard to believe this is a requirement only now. I thought everyone with at least a sliver of honesty already had those for a long while.
3. Enforce low spam report ratio? It's news to me that the "report spam" buttons didn't behave that way already, I assumed that if users actively report then domain gets blocked (unless it's whitelisted, e.g. to defend from a false reporting DoS attack).
Apparently so. I just read through this earlier today, and it's kinda insane how broken email is. Kinda remains me of the "You go to jail" meme, believe it or not, straight to inbox.
Nearly all the spam I see is from a gmail address. I suspect this new measure is to protect gmail recipients.
It's trying to be dead-simple, and also blocks the alternative ASNs these spam providers have in reserve. Haven't found a fully automated way yet because whois protocol is kinda broken, but I'm working on it.
Does that include the spam I get from Google? Because you guys have been sending non CANSPAM compliant emails lately with "Account Updates" which are thinly veiled marketting emails.
We should all stop using email providers who are known to massively compromise our privacy, build profiles of our online activities, manipulate us through ads, pass lots (or all) information to the government, and consolidate ownership of too much of Internet communications and activity.
Specifically, we should stop using GMail (and Yahoo), and encourage our friends to leave that email service as well. There are plenty of fine alternatives.
I can’t imagine how much that would improve my life. I just don’t want to see it. It breaks my attention far too frequently for far too little utility, and I would love it if entire emails I own could be bulk spam free.
I don’t really want a better version of our shitty current system.
Any 1:1 communication with real people pretty much exclusively happens elsewhere for me.
I don’t want any. You do. Why not give users the ability to control what they want? It’s not a technical challenge.
Strange there's no mentioned about transactional emails. Since we wouldn't include unsubscribe link for transactional emails.
I like letting most of my email land in my inbox, because I don't want to need to check (and purge a bunch of folders). But email of declining value will automatically get moved to folders after a certain amount of time. for example:
* Monitoring alerts go to trash after 4 hours (if it's still broken, I'll get more emails, after all).
* shipping notices from amazon etc go to trash after 3 days (long enough for the item to arrive on time)
* Notices from ups/fedex about "your item is arriving today" go away after 24 hours
* Marketing I don't mind seeing but has a shelf life - I have 2 or 3 time intervals setup for those
* Mailing lists I'd like to read (but often don't get back to) delete after 2 weeks
* Utility bills move to a folder for utility bills after 24 hours
etc. It's awesome - but oddly enough, nobody I ever tell about it gets that excited.
And what percentage of legitimate mail?
> and that they process unsubscription requests within two days
This is a laughably lax requirement.
Also for fucks sake, stop auto-localizing your documentation based on IP geolocation.
Still, just citing numbers for how much spam they blocked is (deliberately?) only showing half of the picture.
We have toi jump through hoops to send email to the big email providers already, and some (outlook, hotmail, yahoo) take months before allowing any volume of email to be sent to our own customers!
Wow, I almost missed that!
Apparently even Google has to start their blog articles with SEO crap like this
Normies don't understand that big tech will basically control our elections from now on (and they won't understand how) unless we get the government involved.
And the more complicated and difficult Gmail makes it for companies to access your inbox via open tech like email, the more likely it is you'll be forced to pay for Gmail Ads.
The bonus is Google gets to couch this as being "for the users." Gmail already has fantastic spam filtering and it's highly likely they use all this stuff as spam signals already. I would be very very careful of any claims from a giant advertising monopoly that this is "for the good of all."
I'm someone who a) uses Google Suite (or Workplace, or whatever it's called) b) runs a newsletter service [buttondown.email] that sends millions of emails every day, most of them to Gmail.
The amount of cold email I get from prospecting/outreach tools that is nigh-impossible to unsubscribe from is _infuriating_. Any legitimate bulk sender is already conforming to DKIM + one-click unsubscription, and anything we can do to cut down on obvious spam is a win in my book.
There's a lot of things Gmail does as de facto tsar of email that I don't love — initiatives like AMP for email come to mind — but this is an unalloyed positive in my mind.
But spammers already do that, why would enforcing that even help ?
What really happens is this: when GMail receives a lot of email from domain xyzzy.com, and a lot of it seems to spam (either it's marked spam explicitly by the recipient, or maybe Google uses some weird AI or whatever to identify messages as spam) then GMail will start marking email from that domain as spam. Obviously if you own xyzzy.com and you're not a spammer you want to avoid this. So what can you do?
SPF and DKIM are ways to prevent unauthorized senders from delivering mail that appears to come from your domain. SPF is a way to list IP addresses authorized to deliver mail on your behalf, and DKIM contains cryptographic keys needed to sign email coming from your main. That means if you have SPF and DKIM enabled, the only people able to send mail that appears to come from your domain are people that are authorized to do so (there are a few more bears on the road, but broadly this is true).
It's true that spammers can register their own domains for the sole purpose of sending spam, and they can enable SPF and DKIM on those too, but if they use domains exclusively to send spam, they will still be marked as spam domains by GMail, at least eventually.
But this doesn't explain why GMail should be distrustful of domains without SPF and DKIM records. There are literally hundred of millions DNS records worldwide, and only the tiniest minority (think, 1% or less) of those have SPF/DKIM records, and not having those records isn't evidence of being a spammer per se. But look from the perspective of spammers. If GMail adopts the policy that email from rare domains without SPF/DKIM records is accepted so long as they don't send high volumes of spam, then it's trivial for spammers to collect 100 million domains without SPF/DKIM and send literally 1 message from each, which results in a 100 million spam messages being accepted by GMail.
That's why GMail wants you to add SPF/DKIM records to your domain if you're not a spammer. It allows GMail to block email from the >99% of domains that don't have SPF/DKIM enabled. And for the remaining 1% of domains, it can either delete email outright (if it's forbidden by SPF/DKIM), or else it can reliably identify a domain as being spammy.
If you really want to fix email spam, create a micro-payments system. One cent for every email you send, the user has two options after they open the email: mark it as spam and keep the penny, mark it as legit and give the penny back. If they don't act on it within a week you get your penny back.
Legit senders won't be harmed because they will get their pennies back, spammers won't be able to afford sending messages anymore. The real interesting part would be stuff like LinkedIn notifications -- if people find them useful they'd give the penny back, but companies would have to decide how many people might actually find it useful for their cost analysis.
Jokes aside, why wouldn’t you just farm pennies by marking all emails as spam?
You could say, “well you could detect people that abuse the system” - and now the mouse is chasing the cat.
Edit: no idea why I only get democratic spam, maybe people with my name in the USA too dumb to enter their actual email don't like republicans. But I have no acceptance for spammers, no matter their politics.