There's a reason that people running servers at that level (from that time) are called BOFH.
> (from that time)
Are you trying to imply that 'mail servers' are some sort of ancient devices whose era has come and gone?It would seem to degrade the usefulness of EC2 for anyone wanting to run their own mailserver.
Spam has lead email to basically become this closed ecosystem. If you don't use one of the already established major email providers, ISP's or domain name registrars the reliability of email hits the floor.
Consider the idea of running a mailserver than only accepts mail from a predetermined set of sending addresses. What would be the chances of receiving junk mail?
How is this functionally any different then blacklists? That's just a whitelist instead. So instead of new mail severs "quite likely" being on a blacklist, they are definitely not going to be on a whitelist.
And no, it doesn't matter if isn't a smart idea when you aren't in a position to change anything. Even if you have a perfect technical solution to the problem, you still have to convince every existing major provider to adopt a solution that isn't even a direct problem for them.
I'm afraid there's no need to convince any provider of anything. At this point, Alice and Bob are sending and receiving email without the need for any third party "email provider".
Functionally blacklists and whitelists are the same. They both have the same goal. But they are not the same in their effect. Blacklisting an entire netblock to stop one bad IP address affects many IP addresses who do not need to be blocked. Whitelisting a single known IP address does not have that side effect. For Alice and Bob, handling their own messages may be a desired option. Of course, not everyone may follow Alice and Bob's example. But who cares? The population using email is enormous and diverse. The point is that if someone wants a better solution than what "email providers" offer, she can get it.
The problem to solve is how do you have a fixed address where anyone can contact you, spam doesn't get though and you don't have to maintain personal black/white lists. This is what email currently provides. Granted, the spam part varies depending on the provider.
If everyone had a fixed address with a mail server running, "lookup" i.e. simple MX lookup, might be possible, e.g. if your IP address is 1.2.3.4, anyone could send mail to inquiries@[1.2.3.4] or something like that. But I'm not sure that alone really solves the problem.
Email still works without a worldwide directory. People exchange email addresses and they keep lists of them known as address books.
You claim it's not a closed ecosystem, but it appears to be totally closed and locked off. The only way to get access to it is to be invited in.
> The point is that if someone wants a better solution than what "email providers" offer, she can get it.
Not if they want email.
It's starts closed and it is opened by invitation. Yep. That is exactly how it works.
If you cannot understand that approach, then that just means it's not how you think. It does not mean that the approach makes no sense or has zero utility.
Maybe a stupid analogy can be made if we pretend "Facebook" is the internet (of course it's not, but it does present a messaging system so play along for a moment). On the one hand you could make every Facebook user your "friend" and thus able them to send you messages, and then when people abused that privilege - and we know from experience some would - you could block them. On the other hand, you could only make a select number of people who you know and trust your "friends" and thus only give a select number of people the privilege to send you messages. Chances are, they won't try to sell you Viagra.
On the one hand there are times you may want to enable the entire network to be able to send you messages. On the other, there are times you may only want to allow a small subset to send you messages. Not sure about you, but I don't receive important email from all that many different people. People's social circles are only so big. There is a certain carrying capacity beyond which it becomes unmanageable.
You argue against block listing, but then suggest blocking the entire Internet except the few people you want to send you email.
You say that only people who you have given your email address to should be able to send you email, and then you say there should be a lookup system to get email addresses. (But what's the point of the email directory system if you can't send email to someone because they haven't white listed you yet?)
> but I don't receive important email from all that many different people.
Eh, depending what you mean by "important" I do receive a lot of important email from lots of different people. My email addresses have been used on the public Internet for many years, and I've had a lot of communication to those email addresses, and those communications have brought me great joy. And I also have a variety of people who email me about work related stuff - I won't have prior knowledge of those people.
I think I'm missing something about your system. Please, is it something that you already have well planed out? (Even if not in a state that can be deployed yet) Or is this something that you've just started thinking about?
So long as you're not suggesting Challenge Response we can have a discussion about it.
Discussion is great. But you have to read carefully to understand what's being said. (If I am not being clear, then I apologize.) But if your mind is closed then there's no point reading what I'm typing because I am not regurgitating the usual ideas on email.
Anwyay, discussion is irrelevent when juxtaposed against running code. I'm interested in stuff that works more than getting approval from people in online forums.
This is not some new thing. Anyone can use email this way now. We all have good connections and bandwidth. There is no need for store and forward. What has stood in the way of using email as direct communication is people who can only see email being used one way: daemons that accept commands from any connection, spoofed IP's and all, and email as a service run by someone else, not a small program on the client's machine. If it was impossible to authenticate connections based on any other means besides real-time challenge-response, or DNS run by someone else, then how would people manage to run ssh daemons without the same problems as email?
For example my employer's mail server--which has been sending legitimate person-to-person emails for years (no bulk)--has ended up on blacklists several times because some blacklist operator decided to black-hole an entire netblock at our ISP.
From the blacklist operator's perspective, the broad effect of the block is intended to cause headaches for a ISP as a form of punishment for allowing outbound spam. Our deliverability (and many others) was just cannon fodder for that fight.
If your emplyer knows its recipients (e.g. business partners) and can coordinate with them to run an SMTP service for recieving and sending messages on a different port, would that solve the problem?
Not the type I'm interested in.
> For example my employer's mail server--which has been sending legitimate person-to-person emails for years (no bulk)--has ended up on blacklists several times because some blacklist operator decided to black-hole an entire netblock at our ISP.
You replied:
> If your emplyer knows its recipients (e.g. business partners) and can coordinate with them to run an SMTP service for recieving and sending messages on a different port, would that solve the problem?
That solution introduces a bunch of problems: you're running more software that's open to the Internet and thus introducing insecurity; you're asking people (who might not be technical) to install and run software and use a different mechanism when they want to communicate with a subset of users.
The other solution is to just ask the people that you're sending email to, but who are using a whitelist / block list to add you to the white list or exclude you from the block list.
I do not understand your last sentence. Didn't he say his ISP is blocking outgoing mail? The recipients are powerless to unilaterally change that situation.
Think about this for a moment. Forget the corporate example. Imagine one user has a daemon listening for mail (no setup, it's all been set up for him:- it's "built-in" to his OS). Imagine there is an authentication method e.g. a shared secret and perhaps even some obfuscation like port knocking to hide the open port. Even assuming a determined spammer can get past this, is it worth his time? He will reach a grand total of one user.
We can even use a small overlay, where the IP addresses are private, not routable on the internet. The spammer needs to get into the overlay network first, again defeating things like shared secrets or perhaps private keys to identify machines before he can even get a shot a access to a listening mail daemon. That's not easy to do if the users stay logged in. And again, if the network is small, with a few hundred users or less, maybe only a handful, is it worth his time?
You're basically proposing a whitelist solution, which has many known problems: it does not scale well; it does not handle new or unexpected email partners; it relies on the simultaneous cooperation of all parties; etc. In this particular case it also relies on spammers remaining ignorant of the new port for SMTP--which seems unlikely.
Then we are free to do our SMTP of other messaging as we desire. Each connected machine can choose what ports it wants to listen on, if any.
And what if this does not need to scale? What if it's only being used for a small group of people? What if all the people know each other? A very specific but very common use case. Not everyone is a celebrity with a gazillion "friends". Nor is everyone constantly conversing with new acquaintances. Some people have old friends and family. So I've heard.
Is it worth the spammer's time to try to find an SMTP daemon for each indivdual email address? Under the current system, things are centralized enough that a spammer can spam hundreds, thousands or even hundreds of thousands of recipients via sending to a single SMTP daemon.
Spammers have to send enormous amounts of spam to be successful. Having to do extra work to find an SMTP daemon just to send email to one recipient, and have to do this repeatedly, seems like it would not be worth a spammer's time. At least, not when it's so easy to just spam people that are using email the usual way: allowing some third party to handle their mail.
People chose whether or not to use a block list. Thus your problem isn't really with the person creating the list, but with the mail admin choosing to use that list to filter email. That person feels it works for them.
Very few people should run their own mail server. Email is, now, toxic. Spammers pretty much destroyed email; especially the ability for people to run their own servers for sending.
For a history of a (perhaps overly vigorous block list) look at SPEWS - spam prevention early warning system - which had a few honeypots and which happily blocked large ranges. The Usegroup news.admin.net-abuse.email has very many threads from innocent blocked users and wingnuts screaming "change your ISP!!"
Spammers did not destroy the protocol or well-designed email servers and clients.
"Very few people should run their own email server"
That mindset is why we have a problem, in my opinion. We have actively tried to prevent people from learning.
The history of block lists is a history of the failure of the "email provider" (i.e. "very few people should run email servers") idea. Of course, anti-spam is a career for some people, so "failure" is relative. They've succeeded in trying to exert control over a common internet capability, for profit.
The internet began as peer-to-peer. There was no "DNS". And there were no "email providers". Everyone had a responsibility to learn how to use the network and the basic services it could provide e.g. messaging. Then some people got some bright ideas about how to make money. "Spammers" were not the first ones.
Enjoy that spam in you inbox. It is the product of ignorance.
Yes, everything in the protocol leads to the fact that nothing should drop an email unless it has passed responsibility of it to another server which has accepted the message.
In practice, lots of times things don't work.
Is it possible that someone people might like to use their native SMTP capability for low volume noncommercial email? Does every person who sends email have some overwhelming urge to send spam? Such that we must place pseudo control over sending email, any email whether commercial or noncommercial, in the hands of "email providers"?
Good on you for running your own service.
Is it cheaper for you to get a static IP from a VPS than from your ISP?
That's not what they're saying.
"Very many spam emails come from people running an email server on a dynamic IP. Some companies were happy to host spam sending companies, and would put them in dynamic ranges so they could continue to get money from those spam sending companies and keep changing the IP address. The ratio of good email servers to bad email servers on dynamic IPs is so poor that blocking all dynamic IPs is, unfortunately, the only reasonably solution".
You can be on a dynamic IP and send email. Just don't send that email from a server on a dynamic IP.
Email could be even more decentralized than it already is in practice. This could potentially make spam far more difficult.
Reading that quote (from SpamHaus?) two things come to mind:
1. We are entrusting the rules on our mail delivery to someone who begins sentences with "Very many" and lacks the attention to detail to spell "reasonable" correctly. Make of that what you will.
2. The "problem" is not the existence of "bad email servers" on dynamic IP's, it is the lack of "good email servers" on dynamic IP's. Why the heck aren't the millions of people on dynamic IP's using this capability? Answer: They do not know it exists.
To "replace email", we do not necessarily need to fundamentally change anything about how email works. What we need to do, perhaps, is replace the people controlling it and instruct "good" people how it works. As it stands, in general, the only folks who understand how email works are a. email providers (e.g. ISP's), b. spammers and c. spam fighters.
If the vast majority of email sent directly to recipients from dynamic IP's was low volume and noncommercial, the "bad apples" would be overshadowed by the good ones. And so would the anti-spam zealots be overshadowed by reasonable people who just want to communicate with each other (not necessarily trying to sell ED treatments to the whole of humanity).
Education is the way forward. People arguing against any sort of consumer education on something so basic as internet messaging are an interesting spectacle to behold. Their attitude should fuel the fire of anyone working on this "dangerous idea" of "replacing email". You know who you are.
It's not a quote from spamhaus. It's me re-wording your text.
> Why the heck aren't the millions of people on dynamic IP's using this capability? Answer: They do not know it exists.
No. Millions of people have no interest in running their own email server. What benefit do most people get from running their own server? (Where most people are those who have one or two email addresses, which they use for a couple of hundred contacts.) What benefit do small businesses get from running their own email server, rather than paying someone else to host the server?
> If the vast majority of email sent directly to recipients from dynamic IP's was low volume and noncommercial, the "bad apples" would be overshadowed by the good ones.
You clearly have no idea just how many spam emails were being sent. Something like 90% - 95% of all email was UBE. Much of this was sent from botnetted machines, and many of those would have been on dynamic IPs.
> anti-spam zealots
Conversation is fruitless if you attack the people who have the same aims as you.
> People arguing against any sort of consumer education on something so basic as internet messaging are an interesting spectacle to behold
But you're not suggesting to educate people on internet messaging. You're suggesting that people are educated on installing and maintaining a mail server.
What is an "mail server"? At its essence it's just a program that listens on a port for an incoming or outgoing message. Then you have programs for storing, delivering, forwarding, etc. And maybe you have perceived issues of being able to handle lots of messages. But you don't necessarily need all that if you are not providing email for other people. What if you're just a casual user who wants to send or receive a message to/from your friend? If I have an email daemon (or a "service" in Microsoft parlance) listening on a local port, I can type some text and "hit send" (or whatever method I choose to send the text to the daemon) and the mail is sent. No email provider needed. If the recipient has her email daemon listening for messages from my IP address (and only my IP address), she gets the message "immediately". There is no third party email provider. This is how email works.
There is also no spam if we do it that way. Her daemon is not open to the whole internet. It's only open to me. Why is this so baffling?
Neither third party email providers nor some rule that "no one wants to run an email server" or "no one should run their own email server" are a part of the email protocol. Those are your observations of what people have done so far and your opinions. They do not set limits on what can and cannot be done. Are we in the business of startups and trying new things or are we here to preserve status quo?
Email is internet messaging, one of the oldest forms of it. Email is a message sent in a specified format* over the internet. What could be more simple?
*Granted the format is rather rigid, but it's not too difficult for anyone to learn. It's like writing a business letter.
Millions of people have an interest in sending messages to each other over the internet. And millions of people have no interest in sending bulk email for commercial purposes. That's all I need to know. A project is born.
There is a need for an "email replacement" as many others have voiced and as pg identified in his list, but I'm afraid it's not going to come from anti-spam zealots. I appreciate what they try to do, but I do not appreciate their mindless, blunt-force methods and ideas about "good guys" and "bad guys".
There is an enormous amount of bulk email sent every minute of everyday. Just because it is "opt-out" doesn't make it any less impersonal and unwanted (or any less of a huge drain on the world's computing resources). Can we accept that some people have little interest in receiving bulk email, and that there may be a market (besides you) for email inboxes that are not open to marketers, but only to known contacts? Alas, that's not what the anti-spam zealots aim to address. They do not want to curb bulk email. They just want to stop certain senders.
This does not really move me toward my vision of email. It's just the same old thing. An inbox full of garbage.
Considering the majority of spam these days is probably sent through botnets, that's a pretty good assumption.