6 ms·
This could likely be the reason for poor IPv6 support but highlights the importance of shifting (much more) to domain based reputation. If a domains reputation
by adevx 5y ago
This could likely be the reason for poor IPv6 support but highlights the importance of shifting (much more) to domain based reputation. If a domains reputation is at risk, you can bet domain holders will be extremely careful not to allow outgoing spam.
- syshum 5y agoOr more strict enforcement by the world on SPF, DMARC and DKIM policies The problem of spam is actually solved, the problem is no one setups any of these security parameters correct, large and small companies alike all have bad SPF Records, bad or no DMARC, etc etc etc
- jtchang 5y agoHow is that solved then if no one setups any of the security parameters correctly? That sounds like the exact opposite.
- teknopaul 5y agohttps "solves" Internet security, your bad of you don't use it.
- friendzis 5y agoGo to any internet-related forum and search history for those keywords. You will find countless stories of seemingly technically people who in the end give up on self hosting and switch to managed mail provider. Because even if you solve those policies perfectly, a personal mail server will have such a low rate of outgoing mail that all the big players will effectively treat it as history-less server and will occasionally route the mail into the black hole. There is no recourse for that. If 99% of contacts you want to send mail to are on google/yahoo/microsoft you have to play by their rules. And those rules are effectively "send mail internally or gtfo".
- nanidin 5y agoI have self hosted personal mail for over a decade. There are occasional hiccups with deliverability to new gmail addresses, but that is it. In those cases, once a recipient marks me as not spam once, there aren’t any more problems. I think maybe once in the last 3 years I ended up in someone’s spam box, total. In fact I just sent to a new gmail address and to a university I have never contacted before this week and both were delivered without issue. Setting up DKIM/SPF/etc isn’t that hard and it’s fairly easy to verify with existing tools FYI.
- generalizations 5y agoIt would be amazing if those of you who have successfully self-hosted would get together and make a comprehensive write-up of how to self-host without getting blacklisted. I frequently see comments on both sides of this ("I can't send anything!" vs. "You just have to do it right") and it seems like if there could be some resource (that cuts down the complexity as far as is reasonable) on how to do this from the ground up, there could be much more wide-spread adoption of self-hosting. Personally, I'm hesitant because I don't know if the end of all my effort will be constant blacklisting. If I could be confident that if I do it right I won't get blacklisted, I probably would.
- tomschlick 5y agoThe biggest thing people do wrong with self hosting email is using residential IPs which are almost universally black/grey listed. Using a provider like linode, and checking the IP reputation ahead of time gave me better results when I self hosted.
- Dah00n 5y agoThat's not them doing something wrong though. There's nothing wrong in hosting a server at home. The problem is clearly the black/grey lists if they black/grey list residential IPs just because.
- judge2020 5y agoI don't see why this is downvoted. Domains assign reputation to mail instead of the source IP, and it's fairly obvious that just buying a new domain and spamming from it would tank that domain's reputation for quite a while, even with proper spf/dkim and dmarc p=reject. If all of these are set up, you won't have issues sending from bad shared IPs like the default SES ones.
- Avamander 5y agoSpammers have no trouble making those perfect, you're massively inexperienced on the topic.
- throw0101a 5y ago> If a domains reputation is at risk, you can bet domain holders will be extremely careful not to allow outgoing spam. Generating domains is fairly cheap though. lsjfdlakj.com There, I just generated a new one with a clean reputation. Just spend US$ 10 to register it and off we go.
- wrycoder 5y agoIt has no reputation. That's different from a 'clean' reputation, which takes history to establish.
- adevx 5y agoYou often have to build a domain reputation first. Certainly for Microsoft hosted email. I for instance show users with a Microsoft email a plain mailto:support@domain.tld link on my contact/support form. This way the first email is from them to me which helps building reputation and minimizes the chances of my response going straight into the spam box or worse, silently dropped. Regular users can fill in a proper form and submit it from the support page.
- amichal 5y agoI like it. I've always wanted to promote mailto: links over silly contact us forms (and all the hoops you have to jump through to keep them functional and not abused) but never had a really good argument for non-techy folks and lots of pushback that mailto: is "not standard" and "does not work for some people" with very little evidence. This is a nice story for the 'pros' column.
- teknopaul 5y agoI get more spam from Microsoft and other tech giants than anyone else. It's the companies whom you rely on for email that are the worst abuser e.g. airlines need to inform you about delays and abuse this trust with holiday adverts incessantly. Any company that claims to require your email for two factor auth should be given automatically generated fines for every email they ever send that is not auth related. That would shake up Oracle sales dept. :)
- rinron 5y agoSpammers and scammers already use domains as a disposable commodity creating them or using hacked ones for single campaigns and moving on. Part of filtering based on IPv4 is not only scarcity but accountability. When the owner of the netblock reassigns the ip and its already blacklisted it can create a problem for them and incentivize them to police their own network. Domains are also worse in that its easier to use fake information and be untraceable. its also understandably easier to get a response legal or otherwise from a co-location or isp than a domain registrar. Maybe ipv4 will always be preferred for email just because its more difficult/expensive and therefore less appealing for temporary malicious use.
- kmeisthax 5y agoDomains are less scarce than addresses. By design you can create as many subdomains as you like. (e.g. `abc.spam.com` is too low-rep? Now let's try `def.spam.com`...) You might imagine negative reputation to travel up to parent domains, but that causes problems with public suffixes and TLDs. (e.g. is `microsoft.com` a bad domain because it's got the same TLD as `spam.com`?) The whole point of using a scarce identifier is to allow for a "neutral" reputation for new identifiers. If identifiers are less scarce, then known-bad actors can get free reputation (from bad to neutral) by just starting over with a new one. Which means that you have to distrust neutral reputation more. Without some level of scarcity of identification, introductions don't really work, because I have no idea if the new host I'm being talked to from today is just the one I banned yesterday wearing a different mask. This ultimately implies e-mail moving to some kind of federated whitelist system rather than the current system of federated blacklists.
- Ruphin 5y agoSubdomains are not as much a problem as you would think. There is a resource ( https://publicsuffix.org/ https://publicsuffix.org/ ) that lists all public suffix domains. All direct subdomains of these are in full control of all their own subdomains, and thus can share the same spam reputation. e.g. when .com is on the list, and .somesite.com is not on the list, mail@somesite.com is from the same entity as mail@subdomain.somesite.com
- kelnos 5y agoDidn't publicsuffix effectively get DoSed by one of Apple's new requirements, causing a ton of people to apply to have their suffixes added to the list? From what I gathered from that, publicsuffix is a poorly-funded semi-volunteer org that shouldn't be relied upon for anything critical.
- cormacrelf 5y agoIf this is how MS/Google want to do email anti-spam, they should fund the public suffix list. Same with Apple for their App Store and WebKit uses. (Btw I’m pretty sure almost everyone is already using domain-based spam scoring.)
- tikiman163 5y agoFiltering based on domain reputation has the same problem as trying to filter based IPv6 address reputation. They can easily change thier domain name at any time, and most spam operations do it every 15 minutes or so. This also has a secondary problem for legitimate domain buyers. If the domain name they buy was previously used for spam that reputation will affect thier business for quite a while. There's actually a market where people buy domains with bad reputations, setup small legitimate businesses and get the reputation cleaned up, then sell the site domain and business for a substantial profit because a site with a good reputation history and established line of business will show up higher on internet searches.