Pub400.com – Your public IBM I 7.5 server
pub400.com
pub400.com
Liberachat IRC, ##ibmi
Feel free to drop by.
... very curious to know what this sysop considers a "serious mail provider."
A serious mail provider would care about ensuring that this does not happen and handle enquiries sent to the RFC-mandated address postmaster@ and respond promptly to such enquiries.
I might have ignored email complaining about delivery issues if the above wasn't handled if I were running a serious email provider.
To this day is too much effort running your email service. I moved to an account to Infomaniak that works good and I don't dove all my data to Microsoft or Google.
That's why I meant the above as table stakes. They are the cost to even get in the game to get punched with bullshit IP reputation lists.
But if one doesn't have even PTR records, one has no leg to stand on complaining about blocklists.
I send lots of email that is verified with SPF and DKIM to them via relays. But any messages sent directly from "untrustworthy" IP ranges are just blocked with a generic message.
This is in contrast to GMail which rightfully treated my first messages as suspicious. But once a handful of users pressed "not spam" they don't care about what IP it comes from anymore as the domain reputation has taken precedence.
Come on, I have DKIM and SPF on my "just send sign-up and password reset emails" domains...
This is all assuming that the mail is otherwise ticking all the boxes. One too many times I’ve seen someone get on their HN soapbox because their $5 DigitalOcean mail server keeps getting shit-canned, only to find after some polite prodding that they just flat-out weren’t aware of the modern-day complexities of sending email.
Not to say that this is what’s happening here, of course.
No SPF, DKIM, DMARC records. No PTR record for their A address.
As others have mentioned, the domain also does not use SPF, DMARC or PTR address. So it'll also be unlikely that they sign their outbound email with DKIM.
And they suck.
> permanent error (550): 5.7.1 Unfortunately, messages from [{REDACTED IP}] weren't sent. Please contact your Internet service provider since part of their network is on our block list (S3140). You can also refer your provider to http://mail.live.com/mail/troubleshooting.aspx#errors.
The other providers don't seem to be as picky. (At least I haven't seen major issues sending from Digital Ocean which is an ASN with a bad reputation.) It seems that once they had experience with my domain (with SPF + DKIM) they judge messages primarily using domain reputation not IP reputation.
Simply said: if block lists were permanent, we'd be blocking the entire IPv4 space by now. And also, spammers would have almost free reign when using IPv6, since you can get blocks of millions of addresses for free. Large email providers know this, they have been battling spam for decades now.
When enabling DMARC the IP address more or less becomes irrelevant. If the email is not DMARC aligned the email won't be accepted anyway (I'm assuming a 'reject' DMARC policy here) and if the email is DMARC aligned, the domain reputation, rather than IP reputation will be used.
When working with DMARC aligned domains, most email service providers will rely solely on content based spam detection, and how often people flag the email as spam to determine the domain's reputation.
Of course I am generalizing here. What I wrote here is true for most large email service providers, but each have their own implementation. And of course there will always be self-hosted/on-premise solutions that keep using static block lists (for example: Spamhaus).
> When working with DMARC aligned domains, most email service providers will rely solely on content based spam detection
This seems to be true for most major providers. But my experience shows that Microsoft and Apple don't do this. They still apply strict broad IP-based blocking. Sending messages from the same domain via a relay such as AWS SES is perfectly fine. But if the sender IP is in Digital Ocean ASN it is dropped right away. The domain is p=reject
He had manually added over 20,000 IP addresses to the list.
Eventually I find a portal from MS to do exactly that: Appeal. I tried to use the portal but I got an error "event service error" - or something similar. Portal not working. I say "what the heck - I ll try later". I do try later, same outcome. Several times. For days. I google the error, I find several threads on redit since years complaining that the portal doesn't work giving this exact error. Since years. I keep trying nevertheless to respond to the email and go through the portal again for days. Nothing. I try the following: I signup for azure, it asks me for an email address, I say I have none and guides me to sign up to outlook. Outlook asks me for a backup email address, I provide my email address from the blocked server.
I then try to respond again to the original email that outlook has been rejecting - WORKS. Summary again: MS blocks email my mail server for not fulfilling requirements that it actually fulfills. MS portal to object, doesn't work since years. I create an outlook email and set self-hosted mail address as "backup" - my server gets unblocked.
Fun fact: I received "on-boarding" emails from MS Azure to my new MS Outlook account. MS Outlook classified them as "Junk".
Does this qualify as a "serious mail provider"?
--updated wording.
It seems like you and GP both have valid points.
Borrow-words usually (AFAIK) generally have the same meaning in the donor and recipient languages. So referring to the donor-language definition is a good way to figure out intended usage.
IIUC, virgule has different meanings in Latin, French, and English. I'm guessing that's what's throwing us off.
In the beginning (1978) was the IBM System/38, which had a custom CISC CPU architecture with 48-bit addressing (called IMPI), vaguely resembling the 360/370 mainframe instruction set, but incompatible with it, and having some rather high-level abilities like task switching in microcode (similar to hardware task switching on the 386). The System/38 had some very advanced features: single level storage, capabilities and programs compiled to byte code (which the OS then converted to the IMPI physical instruction set). However, IBM also had its System/36 "midrange" line (basically minicomputers but IBM preferred to call their business-oriented minicomputers "midrange"), which was incompatible and more of a traditional system architecture. So in 1988 IBM "unified" them by releasing the AS/400, which was basically a version 2.0 of the System/38, keeping the same basic architecture but adding a System/36 emulation subsystem so it could run most System/36 applications.
Separately, IBM had its RISC Unix RS/6000 line, which spawned POWER and PowerPC. And then in 1991, IBM came out with a new version of the AS/400 based on PowerPC instead of proprietary IMPI CISC. The fact that applications compiled to bytecode meant most applications could be ported to RISC seamlessly, since the new OS version translated the bytecode to PowerPC instructions instead of IMPI instructions. At the same time, much of the core of the OS was rewritten in C++ (having previously been in a proprietary PL/I dialect.)
But still, although RS/6000 and AS/400 now used the same CPU architecture, they were still physically different hardware. Originally, the AS/400 used its own PowerPC chips with additional instructions the RS/6000 ones lacked. Even after they unified the two lines on the same CPU models, they still had different firmware.
In 2000, there was a marketing-driven decision ("eServer") to rebrand RS/6000 to pSeries and AS/400 to iSeries. This was part of an attempt to present IBM's four distinct server platforms (mainframe, AS/400, RS/6000 and PC) as some kind of cohesive strategy (mainframe became zSeries and PC servers became xSeries).
Then, in 2006, the iSeries (formerly AS/400) and pSeries (formerly RS/6000) hardware lines were merged completely, to become IBM Power Systems. Now there was no physical difference between the hardware, it is just which OS you install on it. The IBM i (originally OS/400 and later i5/OS) operating system uses certain firmware features which AIX doesn't use – but all IBM Power Systems have that code in their firmware, it is just AIX and Linux don't call those functions. (There are now low-end Linux only machines which refuse to run AIX or IBM i, although possibly that's just a flag in the firmware license as opposed to distinct code.)
I write some more about it here:
https://www.devever.net/~hl/ppcas
Interestingly this functionality is actually unlocked on the Raptor Talos II/Blackbird systems so you can play with it in full.
But you are right, and in that it has something in common with sandboxing of Java applets, for example – which didn't work out as well as its inventors had hoped.
That said, although classic applications all run in a single shared address space, newer versions have added support for isolated per-process address spaces (teraspaces), which have in turn used been to add an AIX compatiblity layer (PASE). If you write your apps against AIX compatibility layer, you get process-based security just like you do on AIX. And in that layer you aren't just limited to calling (a subset of) AIX APIs, you can also call into IBM i native APIs which don't exist on AIX – albeit at some performance cost, since the call has to be marshalled into the single shared address space.
IBM's original JVM ran in the classic single shared address space, and was deeply integrated into the OS. Then they replaced it with J9, their JVM for AIX/Linux/Windows/etc, and J9 runs under the AIX compatibility layer. Given they encourage Java for developing new apps – a lot of apps now contain a mixture of legacy RPG/COBOL/etc code along with Java code to implement web UIs and SOAP/REST APIs – more and more stuff is running outside of the shared address space.
Now that must be the most diplomatic understatement I've come across in a long time.
I has a fancy memory architecture, very smart disk controllers (essentially distributed intelligence, like an octopus), a virtual instruction set (that has been used multiple times to almost seamlessly jump huge under-the-hood processor changes), and historically a reliability record second to none (the old box in the wiring closet running for years upon years, completely untended). Z has even more toys, including some of the strongest clustering, partitioning, security found anywhere. Sysplex, LPARs, and RACF are all impressive, especially given how many decades ago they started. We won't even talk about the DBMS and transaction monitors, which are their own brand of crazy strong.
Those immersed in the higher-volume, standard microprocessor, Unix/Linux or Windows, cloud mainstream don't give "proprietary systems" much thought or respect. But we probably should. Those who knew the IBM I or Z, or the DEC VAX/VMS, HP MPE, Tandem NonStop, etc.—they were too expensive, too few in number, too quirky—but what they did well, they did outstandingly well in their purpose-focused, allopatrically speciated ways. Better in many cases that we can do today with the latest 2024 gear.
I think this is the biggest problem, plus the fact these systems tend to be tied to proprietary - and also very expensive - hardware platforms. If I want to learn about GNU/Linux or BSD, all I need is a computer (PC in most cases, but other options exist) and an Internet connection. These days, most people (at least in Europe and North America) have these anyway, so it's really easy to get started in the comfort of one's own home.
Having a free account on a public machine is cool, but it's not the same as having your own system, especially if you want to learn about system administration.
The killer, of course. As they say: anyone can build a bridge that stands, but it takes an engineer to build a bridge that barely stands. In this game, a solution that's too expensive is often not a solution at all.
It's an interesting introduction to the AS/400, up to the POWER transition.
There's also Fortress Rochester by the same author that goes into the iSeries / POWER4, but I haven't found a copy on line.
In the workshop, blue collar workers can bang out commands and instructions faster than a grey beard computer scientist at MIT running their entire life in EMACS.
Only one or two people know where that AS/400 lives. It's power supply was hot swapped 21 years ago.
[1] https://www.ibm.com/docs/en/POWER5/iphan_p5/iphanbook.pdf
[2] https://community.ibm.com/community/user/power/discussion/ib...
Hot garbage that obliterates our production times, as far as I can tell.
keep in mind the system used this as a safety feature. to make sure that you dont blow off your foot with incorrect access to the file.
In the 1990s, my dad worked in a pharmaceutical factory. The whole factory was run by a single AS/400. Being the pharmaceutical industry, it was all very clean, no dust anywhere to be seen. Their server room, complete with raised floor, seemed rather barren – all it contained was the AS/400, a tape drive, and a couple of Netware servers. The operator sat in an adjoining room, able to observe the servers through a large glass window. In high school my dad got me an unpaid internship for two weeks in their IT department, but sadly they refused to give me a login to the AS/400. Closest I got, was they had a contractor writing RPG code in the cubicle next to mine, and he let me look over his shoulder.
Gives me cyberbunker vibes and memories.