28 ms·
The Perils of an .xyz Domain
- humanistbot 5y ago> One surprising side effect of having a .xyz domain is that the mere inclusion of .xyz inside of a text message will result in a silent delivery failure for many providers. This is wild to me. Tested it out myself and I couldn't send an SMS with a spot.xyz link to/from Google Voice <-> T-Mobile. And no "failed delivery" notice either, just a silent failure. And yet I still get so many texts that are obviously spam or phishing attempts.
- mcny 5y agoOne of the places I worked as a contractor recently, I could not get to abc.xyz on the work network. I tried some more xyz websites and none worked.
- blendergeek 5y agoI have this same problem with "obscure" .net domains. My text messages are silently dropped. The only work around I found is to not include http:// http://, just use the bare domain. Personally, I find this behavior of my SMS provider reprehensible.
- deleted 5y ago[deleted]
- idiotsecant 5y agoIs it reprehensible only when it impacts you or is it still reprehensible when it's blocking hundreds of spam messages a day you might otherwise be receiving?
- epse 5y agoSurely there are better ways to reduce spam than blocking entire TLDs? I also think it's the silent, unfixable nature that annoys most people. Email spam goes into your spam box, where you can still access it. You can mark email as not being spam. No such luck here
- pletsch 5y agoEmail providers absolutely block email, its the edge cases that make your spam folder.
- thaumasiotes 5y ago> its the edge cases that make your spam folder. Well, from their perspective. Not from any reasonable perspective; I have a few obviously-spam emails in my gmail spam folder right now, but I've had plenty of problems with gmail refusing to deliver completely legitimate email to me.
- pasc1878 5y agoIf there was no filtering how many spammessages would you receive? I suspect any more than you see
- d110af5ccf 5y agoThose aren't silently dropped though, are they? The sending server is notified I think.
- greenyoda 5y agoYeah, there's a lot of spam out there. My employer's spam filtering software used to send out weekly statistics telling us what percentage of incoming e-mails (across the entire company) were spam. The spam percentage was remarkably constant from week to week: about 90% of all incoming e-mail was spam!
- thaumasiotes 5y agoWho cares? The only things that make it into my spam folder are obvious spam. Meanwhile, messages from people I know personally aren't even delivered at all. There is no way to characterize this as reasonable or even acceptable. Google is using metrics that are not related to whether an email should be delivered. They need to tune whatever they're doing down to the point that legitimate personal communication at least shows up in the spam folder. If a lot more spam shows up in the spam folder too, so what? A spam folder that contains mostly spam and also some misclassified personal messages is significantly better than a spam folder that contains nothing but spam because it automatically dropped your misclassified personal messages.
- blendergeek 5y agoI should receive 100% of messages from numbers I message. If my carrier wants to helpfully filter my other messages, I should be able to opt out.
- techrat 5y agoI ran into this recently even on Facebook Messenger. A friend of mine was hunting for a short domain name and I had a list of some three character .net and .org domains I recently had found that were available. Cut and pasted the list and the message wouldn't send. Narrowed it down to one. Typed just the bare domain. Wouldn't go through. (It was something incredibly benign like n17.org) Couldn't find a history on that domain name for why it would have been filtered. At least messenger responded with 'couldn't send message' but still no clue as to why... and it took me sending each domain name individually until I found the one that was failing the entire message.
- Symbiote 5y agoIf it was N26, that's a European bank so I could see similar domains being used in phishing scms.
- aaaaaaaaaaab 5y ago>and it took me sending each domain name individually until I found the one that was failing the entire message. A true hacker would have used binary search ;)
- afurculita 5y agoOr a distributed ElasticSearch
- Thaxll 5y agoYou wonder why there is any filtering on sms ...
- Spivak 5y agoBecause spam really is that rampant. There aren't that many communication systems with a small search domain of user ids where anyone can send and receive messages from anyone by default.
- maxwell 5y agoWhy not impose costs instead of filtering?
- indymike 5y agoThey do.
- SilverRed 5y agoThe latest spam method right now is to get malware on to android phones and have the actual phones do the spamming. So if there is a cost, it gets applied to random people and not the spammers. Also if there was a cost per SMS on phones these days it would be the death of SMS because no other system charges.
- Thaxll 5y agoMakes sense, but then they just blacklist entire TLD, it's a bit weird.
- kop316 5y ago...whoa, yeah same here. tried "test spot.xyz" then "test spot.com" T-mobile <-> T-Mobile. "test spot.xyz" did not send. Even weirder, I got a confirmmation that it was delivered. It looks like T-Mobile looks for ".xyz" within the SMS and will silent drop the SMS (though it will claim it is delivered). ".xxyz" works, "..xyz" or ".xyzz" does not. "xyz" works, so does ".xy".
- DaiPlusPlus 5y ago> though it will claim it is delivered I thought SMS didn’t have delivery receipts?
- kop316 5y agoThey certainly do. In Chatty: https://source.puri.sm/Librem5/chatty/-/merge_requests/786 https://source.puri.sm/Librem5/chatty/-/merge_requests/786 . Some carriers even charge for the service (!!): https://source.puri.sm/Librem5/chatty/-/issues/434 https://source.puri.sm/Librem5/chatty/-/issues/434 MMS has delivery reports too (I implimented support for it myself for mainline Linux Phones). It even has read reports, but no carrier seems to honor using it (which is why I didn't bother to impliment it). I'm not sure if Android/iOS gives the user an option for it (which may be the source of confusion).
- frosted-flakes 5y agoThere is an option to enable delivery receipts on Android (Google and Samsung). I believe it is disabled by default.
- kop316 5y agoRead reciepts or delivery reports? I'm not sure if SMS supports read reciepts, but I didn't think so. The MMS standard allows for read receipts ("MAY" not "SHALL"), I was unable to get it working, and I suspect it's due to no carrier support. I was unable to get read receipts working at all, and I suspect it's because the carrier doesn't impliment it.
- krono 5y agoBlocking of messages/emails and blanket email server/domain/extension blacklisting is the same as a postal service not delivering mail to or from a particular entity/street/town. Doing so silently and without a valid and case-specific reason should not be legally allowed. Edit: Added "street/town" to analogy, and "case-specific" before reason
- maxwell 5y agoThe FCC classified SMS/MMS as unregulated, filterable "information services" rather than regulated "telecommunications services". https://www.fiercewireless.com/wireless/sms-mms-deemed-information-services-removing-them-from-heavier-regulation https://www.fiercewireless.com/wireless/sms-mms-deemed-infor...
- krono 5y agoThey should really update the "Mission and strategy" chapter on their Wikipedia page [1]. In particular the part about "Protecting Consumers & Public Safety" seems horribly outdated! I will have to look up how this works in the EU and here in The Netherlands. Something to do for the weekend. [1] https://en.wikipedia.org/wiki/Federal_Communications_Commission#Mission_and_strategy https://en.wikipedia.org/wiki/Federal_Communications_Commiss...
- wikidani 5y agoI really would like to see what was the legal reason behind that, I know the US has issues with gov't agencies using their opinions as law but I thought mail was constitutionally protected?
- maxwell 5y agoThe FCC just makes decisions, we're talking regulations here, not laws. They justified it with "preventing spam" and enabling competition with unregulated OTT apps. I'm glad that Twilio fought for Title II governance: https://ecfsapi.fcc.gov/file/60001324418.pdf https://ecfsapi.fcc.gov/file/60001324418.pdf Where was everyone else? As far as the sanctity of the U.S. Mail, it only applies to sealed envelopes/packages, and Congress can ban items from the mail (e.g. lottery pamphlets, spurious tokens, gasoline, etc.) https://supreme.justia.com/cases/federal/us/96/727/ https://supreme.justia.com/cases/federal/us/96/727/
- iconjack 5y agoIt was wild to me too. I have an .xyz domain, which seemed appropriate for a non-commercial math site. I'd try to send links of math experiments to friends and colleagues via SMS, so they could tell me if they worked right on their phones or not. Can't tell you how much confusion and frustration it caused that the links were simply not being delivered, though all the conversation around the links went through just fine. No error was reported on either end. A year or so ago, I did a lot of searching trying to find some explanation of this bizarre behavior, but found literally nothing. It's nice to know I'm not crazy, at least. Is there a published list of what domains are not allowed to go through?
- schleck8 5y ago> which seemed appropriate for a non-commercial math site They are used by large cooperations too. The Alphabet domain is abc.xyz. Science Corp's is science.xyz.
- mhh__ 5y agoI didn't know about abc.xyz, that's a really nice URL
- samspenc 5y agoQuite likely only investors in Google / Alphabet stock know that site and have it bookmarked because that's where Alphabet publishes its quarterly earnings. I also guess for the same reason, it only gets significant traffic once a quarter during earnings season.
- lrem 5y agoI like to think of it as Ruth's blog ;)
- GoblinSlayer 5y agoSMS has a delivery confirmation feature, my phone indicates delivered and undelivered messages, so you can tell what wasn't delivered.
- Scoundreller 5y agoIf you’re in Canada, and send an SMS containing the string “special message” to or from a Telus customer (or one of their sub-brands), it will be silently dropped. Telus is one of the big3 telecoms here.
- drampelt 5y agoI just tried on Koodo which is part of Telus, no issues sending/receiving
- Scoundreller 5y agoMake sure it wasn’t iMessage
- drampelt 5y agoDefinitely wasn't iMessage, I tried it on my Android phone
- exikyut 5y ago> Ironically, Google Voice also has the same behavior with abc.xyz. This is my new mini-favorite thing. It feels a bit like a redux of "Shirt without stripes" (https://news.ycombinator.com/item?id=22925087 https://news.ycombinator.com/item?id=22925087)...
- tiffanyh 5y agoI wish the Telco's did MORE filtering given the huge amount of SMS spam I get since Twilio has turned this channel into a positive ROI for spammers. (1st biggest spam channel being email, which surprise/surprise - Twilio also dominates via SendGrid)
- aquark 5y agoI have no knowledge of the ROI involved here, but would love to understand this: Twilio is 0.75c to send a text. Is it possible for a spammer to generate >$75 per 10,000 people spammed? I've no idea were the SMS spams I've got link to (not about to find out) but they are so obviously spam. We use SMS for communicating with users and would be happy to more a lot more per text to escape the 'positive ROI for spammers' territory. I'd be happy to do that for important emails too!
- mmerlin 5y agoProbably decent ROI which is why it keeps on happening! They just need one person in each 10k spammed on average, to click the phishing url asking them to pay a fake bill and then charge them $328 instead of the $3.28 displayed o the page. I received (and reported to their scam Dept) a phishing SMS yesterday pretending to be from Australia Post asking for $3.28 to release a delivery package I'm waiting for, which is most people in Australia nowadays with the current slowdown in mail delivery speed. I am only guessing that the $3.28 phishing purchase would have attempted a $328 charge on my card... but that would be wildly profitable if the input costs per successful fraud were under $100...
- callalex 5y agoHow did you determine that these messages are through Twilio and not one of the dozens of cheap unscrupulous knockoffs? This is very easily identified, and you are are slinging serious accusations.
- petercooper 5y agoRelated thing from the past.. Gmail once had a bug(?) where if you sent any email containing a URL with the domain starting "0x", it would go straight to spam. I imagine it was a rule hard coded to block the use of hexadecimal long IP URLs, but it also picked regular domains starting 0x. It was fixed a few years ago.
- ArchOversight 5y agoI own a domain starting with 0x and I spent a lot of time talking to people I knew at Google to get that one fixed because my mail would not be delivered.
- petercooper 5y agoI'm glad to hear another first hand report of this as info was very thin on the ground at the time!
- foofoo4u 5y agoA lot of systems block anything by default that isn't standard. For example, if you happen to own a domain to serve as your email that doesn't end in .com, .edu, .gov, then many systems will instantly invalidate you saying you don't have a valid email when in reality you do. A lot of companies or programmers don't seem to realize that its 2021 where we have hundreds of domain extensions to choose from.
- devoutsalsa 5y agoI had a .ninja domain for a while, and I had to contact a certain DNS provide to add support for that TLD. They were very responsive, but I still had to ask.
- SilverRed 5y agoI think this mostly applies to TLDs with more than 3 letters. I have email on a .me and a .red and I have never had anything reject me.
- kayodelycaon 5y agoNo issues with my .co domain.
- sytelus 5y agoI am pretty sure this is not intentional. Somewhere some classifier in Google has overfitted onto .xyz. They will probably fix that some day so this will not be true forever either.
- tambeb 5y agoI just tested example.xyz and spot.xyz between my Google Fi and Voice numbers and both were fine.
- pacman2 5y agoPff. That is nothing. Try to run your own mailserver and deliver a mail to a t-online.de address (T Mobile Germany). They basically only accept pre-approved providers. If your have your own domain and infrastructure you have to petition them to whitelist you. Totally insane. If you can read German, this guy who runs a shop decided to block himself all of t-online emails since they basically run email out of specification. https://blog.rolandmoriz.de/2020/09/21/t-online-blockiert-mails-fuer-kunden/ https://blog.rolandmoriz.de/2020/09/21/t-online-blockiert-ma...
- sneak 5y ago> One surprising side effect of having a .xyz domain is that the mere inclusion of .xyz inside of a text message will result in a silent delivery failure for many providers. Why are people afraid to use the real term for this? It's called censorship. Your provider is silently censoring your text messages. In peacetime. You can't expect it to improve when that's no longer the case.
- lopis 5y agoSpam protection is very hard, so xyz was sacrificed because most of it was spam. Filtering out viagra pills junk mail from your inbox is also censorship.
- RyJones 5y agoperhaps it's a parsing error, like the bug yesterday about usernames may not end in MIME types? SMSC[0] is re-implemented many times. 0: https://en.wikipedia.org/wiki/Short_Message_service_center https://en.wikipedia.org/wiki/Short_Message_service_center
- duskwuff 5y agoGiven the context, it's absolutely a spam thing. When the .XYZ gTLD launched, registrars were incentivized to discount it aggressively, sometimes as low as $1 for the first year. Spammers loved this.
- blowski 5y agoLet's say I have a rule to block emails that mention "bitcoin" from arriving in my inbox. Is that censorship? Let's say, so many people have set up a similar rule that the email provider offers a quick way of adding that very rule. Is that censorship? Let's say, so many people use that "quick way" that the email provider turns it on by default. Is that censorship?
- Lammy 5y agoYeah, of course. How would it be possible to have censorship at all if "so many" people didn't tolerate it?
- jordemort 5y agoI have a .haus domain for personal use. I can send and receive email just fine, but I do run into a lot of apps that do some sort of misguided "validation" on the email address and reject .haus as an invalid domain. One retailer lets me use the .haus email address as a login, but once I log in and try to make a payment it requires me to enter a different "valid" email address to send the receipt to. It's very irritating.
- tombert 5y agoI have similar issues with my two main emails, which end with `.app` and `.sexy`. Both of these work fine, but validation will fail a lot of time (particularly for `.sexy`, but even for `.app`), forcing me to defer back to an unwieldy .com that I own.
- dangrossman 5y agoI've been using a .info domain for email for, I don't know, 15-20 years. Maybe 3-4 times in those decades I've run into a service that won't let me sign up with my "invalid email". And once, I was locked out of my smart garage door opener app because a new version decided my already-registered email was now invalid for logins. Customer support kept telling me to just reset my password, but even the password reset form decided my email was invalid. A few months later, another new version of the app decided my email was valid again.
- invokestatic 5y agoI have a .co domain that gets rejected occasionally as well. Highly regret that domain choice since people often mistake it for .com.
- abdusco 5y agoI had a .co domain, and it was a pain to spell it out to people. "It's like .com, but without m" and people usually got confused, or thought it was a typo and "fixed" it as .com. I have a .dev domain now and everything seems to be running smoothly, plus it's +20% cheaper.
- SilverRed 5y ago
- kiwih 5y agoOh. As someone with a blog on a .xyz, this is disappointing news (but extremely good to know). Guess I should look at migrating...
- Dig1t 5y ago> initial email open rates rose from 70% to 86% I know this is common knowledge, but it still really creeps me out that companies can track this.
- taftster 5y agoDisable auto-image loading, and it will cut down the ability for companies to do this. Unfortunately, this often times leads to direct phone calls along the lines of, "Hey taftster, did you get my email? It shows that you haven't opened it yet." This side-effect is also very annoying.
- DaiPlusPlus 5y agoWho gives companies their personal phone number?
- sodality2 5y agoPerhaps this is from a nosy colleague who has enabled read receipts. I learned this the hard way when I "didn't see" an email I had in fact opened.
- techsupporter 5y agoI get unenrolled from electronic statements from Capital One and a local credit union if I go 12 months without “opening” an e-mail from them. I do open and read their e-mails but since I don’t have image loading enabled, they don’t know that so they “helpfully” start sending me paper bills again, and stop sending me the e-mails to say that the bills are ready. It’s incredibly annoying.
- msh 5y agohey.com and icloud email blocks this by default.
- plumeria 5y agoWhat about .app domains?
- maxwell 5y agoThe .app TLD is owned by Google, requires HTTPS, and I haven't run into any issues in practice. Whereas my corporate VPN blocks all .xyz domains.
- jonny_eh 5y agoYa, these issues seem to be on a case-by-case basis. If the owner of a TLD is careless, it can get a bad rap and become useless.
- profmonocle 5y ago> requires HTTPS I've always felt conflicted about this. I generally support moving everything to HTTPS, and requiring it for new TLDs isn't a terrible idea because there's no chance of breaking anything legacy.[1] On the other hand, Google owns the TLD, controls the HSTS preload list, controls the most popular browser. The idea that an entire TLD could be added to the HSTS preload list was a completely unilateral decision by Google. It makes me uneasy. [1] ...unless you were using the domain internally assuming it would never be added to the root zone, which bit some people when they did this with .dev
- davefp 5y agoFunnily enough, I've found that the .email TLD is often rejected as an invalid domain when I'm filling out my email address online.
- jitl 5y agoThese are also good reasons to avoid using .so domains. You can also expect mail delivery issues and blanket corporate firewall blocks on .so. The rising prominence of https://notion.so https://notion.so is changing the cultural situation somewhat, but very slowly. (Edit: I work at Notion)
- wlesieutre 5y agoNotion said they were switching to .com "as soon as our engineering team has the bandwidth", but it's been a year so they might've changed their minds on disrupting the branding https://www.reddit.com/r/Notion/comments/f6x9mk/why_the_so_domain/ https://www.reddit.com/r/Notion/comments/f6x9mk/why_the_so_d...
- jitl 5y agoI don’t think we consider ‘.so’ part of the brand.
- akvadrako 5y agoI have been exclusively using a .so domain for about 10 years and never experienced any of these issues. What specific network blocks it?
- jitl 5y agoYou can see a bunch of users reporting this issue in the link the user above posted: https://www.reddit.com/r/Notion/comments/f6x9mk/why_the_so_domain/?utm_source=share&utm_medium=ios_app&utm_name=iossmf https://www.reddit.com/r/Notion/comments/f6x9mk/why_the_so_d...
- akvadrako 5y agoI don't see any mentions of who's actually blocking it, just some guys work and a VPN provider. There isn't any indication the blocking is worse than most other TLDs.
- 5y ago
- eigengrau5150 5y agoI associate ".xyz" domains with the alt reich. In fact, I consider any TLD that isn't .com, .net, .org, .edu, .gov, .mil or a standard international domain (like .co.uk for UK .com sites) illegitimate. .win can fuck right off.
- approxim8ion 5y agoI have my personal site on an xyz domain because it's the only thing I could justify spending on. I don't intend to earn from it, it's just a static site, and it's significantly cheaper than anything else. I'll probably stick with it.
- tombert 5y agoI was pretty excited when ICANN opened up a bunch of new domain extensions, but it does sometimes feel like "all these extensions are great if you don't plan on using them". It was pretty cool that I managed to buy a bunch of domains like <my last name>.<new-tld>, but to be honest I really don't see myself using my .blackfriday domain for anything. For that matter, I think that (somewhat ironically) `my-last-name.email` would not be taken very seriously for a primary email address. I use a `.app` domain for my personal email, which has its issues, but if I owned a business, there is no way on earth that I would be using anything but .com.
- hcurtiss 5y agoI had .email for a while. Many shopping sites wouldn't actually let you use the address, presumably given some filter assuming that "email" was a fake address. Because my name ends with "ss", I switched over to .es, which conveniently is a country TLD (Spain). That's worked very well, though occasionally I'll get spam in Spanish, which cracks me up.
- bink 5y agoI wonder how well these new TLDs work for custom email if you use them with Google Workspaces / Google Apps for Domains or another reputable email hosting service. I've been using a custom domain (though a .net) for decades now and since I moved to Google Apps years ago I haven't had an issue being seen as spam.
- vel0city 5y agoI use the free email provided with the domain hosting I got with a domain on one of these gTLDs. The only real issue I get are places that think the gTLD isn't a valid email domain, ensuring I always have to fall back to a more traditional email provider for some places. Otherwise, deliverability-wise I haven't really experienced any issues. My mail is regularly delivered to the big email providers.
- hcurtiss 5y agoI use Fastmail. Delivery has been fine. My only challenge with .email was that some services wouldn't take the address as a valid email address.
- legrande 5y agoWell .COM has had its day. There (was?) even a semi-parody site called Domains For the Rest of Us[0] that generates .COM domains that you can use for side projects (or startups?). [0] https://news.ycombinator.com/item?id=24538758 https://news.ycombinator.com/item?id=24538758 The new gTLDs are a godsend since all the domain hacks have been largely exhausted. E.G: `del.icio.us`. I like the new avalanche of gTLDs since it reduces domain squatting, domain hacks, and stops people snapping up short .COMs as if they were some digital gold to be mined. Not to mention the hassle of having a really obscure ccTLD like .SO and having to battle to get that domain back if it was seized by pirates, yarr
- reidjs 5y agoI read a series of blog posts about a guy who would essentially work backwards from a domain name to start a business. E.g. he would buy things like 'weehawkenjobboard.com' then SEO a job listing service for people/businesses in Weehawken NJ. I thought it was a pretty clever strategy.
- fotta 5y agoWas it this[0] guy? Previously discussed on HN[1][2]. [0] https://www.deepsouthventures.com https://www.deepsouthventures.com [1] https://www.deepsouthventures.com/i-sell-onions-on-the-internet/ https://www.deepsouthventures.com/i-sell-onions-on-the-inter... [2] https://news.ycombinator.com/item?id=19728132 https://news.ycombinator.com/item?id=19728132
- reidjs 5y agoThat’s the one
- egfx 5y agoThat’s what I do too. https://news.ycombinator.com/item?id=26380124 https://news.ycombinator.com/item?id=26380124 building one product at a time.
- 5y ago
- ChrisArchitect 5y agotough story for a company and I know there's a ton of shady TLDs out there now but this will change rapidly I think - it used to be a .com world but as we all know .io etc has changed rapidly in last 5 years. Lately due to lack of .coms I get the feeling a lot of the other TLDs like .shop, .whatever are being used more and more for random sites for startups, projects etc, so I'm sure as they become more accepted in tech systems like SMS (weird about the filtering) and servers etc.
- nickdothutton 5y agoMost of these new TLDs are just the .biz of the present moment. I went to email whitelist a decade ago and haven’t looked back.
- caitlinface 5y agoWhat do you mean "email whitelist"?
- chipgap98 5y agoPresumably a list of TLDs or domains they will receive email from rather than only blocking bad domains as they come up.
- toast0 5y ago.biz was a new TLD, so yeah. It was part of the 2000 round of new TLDs. I don't think I've seen a .museum, but all of the others from that round give me negative vibes, although I guess slightly less than most of the newer new tlds. That said, I've got a 'clever' .pictures I use to share images and a totally appropriate .fun that has no need to have positive domain associations.
- soco 5y agoIt's sometimes difficult to believe how much misguided logic is put into input validation. Addresses which must have a street and a number, middle names not allowed, valid postal codes not recognized or auto-filling the wrong town, arbitrary maximum length for street names, and I could go on. We programmers (or we product managers?) invest way too much time in nonsense.
- ev1 5y agoI really hate this. I've seen separate input fields for street number and street name. Meanwhile you have vendors with street addresses like "Vodafone House, The Connection, Newbury RG14 2FN"
- mtm7 5y agoHas anyone noticed any of this with .dev domains?
- EduardoBautista 5y agoI haven't noticed any issues. An advantage of .dev is that it belongs to Google, so I am sure it that will work smoothly for the most part.
- readflaggedcomm 5y agoAlphabet also owns abc.xyz, but the author observes that Google Voice seems to censor it.
- CydeWeys 5y agoBut .xyz does not belong to Google, and the contamination is coming from all the other bad .xyz domains that Google has no control over.
- type0 5y agoWhy are .net domain names relatively unpopular? New technology sites often use .io and .dev even when there are a lot of available .net names.
- bink 5y ago.net and .org were the original .xyz. Back in the late 90s and early 2000s they were seen as less reputable for businesses. I think they still carry some of that tarnish.
- jer0me 5y ago.org domains actually have some credibility as there's this misconception that you need to be a non-profit to register one, like how you have to be a accredited university to register a .edu domain or a government entity to register a .gov domain. .net domains however have a bad reputation regardless for some reason.
- kureikain 5y agoBefore I get into email business(I run my own email forwarding service[0]), I don't understand why provider block those domains. Then I immediately got it. The amount of spam emails from .xyz .click .faith .top is huge. And with every email comes from them, we have to run spam scanner, which isn't cheap. So we have to score those TLDs more sensitive. https://www.spamhaus.org/statistics/tlds/ https://www.spamhaus.org/statistics/tlds/ can give some insight about spam rate by tld. --- [0] https://mailwip.com https://mailwip.com
- ifreund 5y agoFrom that spamhaus link .xyz has a lower bad percentage (4.4%) than .com (5.1%) and .net (10.5%).
- dredmorbius 5y agoWhat are its positives?
- chmike 5y agoMaybe because .xyz is blacklisted, spamhaus doesn't see them.
- sneak 5y agoSeems like an easy solution is to simply start spamming from .coms like we had to back in my day.
- SilverRed 5y agoThey spam from these weird TLDs because they often have really cheap deals like $1/year for the first registration so you can buy a load of them.
- GuB-42 5y ago> We should have known better from the beginning as we previously founded Outreach.io, the leading sales engagement platform, making us no strangers to email deliverability. In the early days of Outreach, we had utilized some short .xyz domains to use for shortened links in emails sent on behalf of our customers. Translation: We used .xyz for spamming, of course .xyz is associated with spam.
- unethical_ban 5y agoYep - used to work at a bank that very aggressively blocked gTLD because they had a (very stupid in this case) security-first mindset. Despite having multiple first-class URL filter products that can detect reputation and site category without needing to bother an analyst or cause a disruption. SOCs, web filter, email filter teams and vendors all need to catch up to the 2010-era idea that carpet-blocking TLDs is not the first tool to reach for when securing a network, especially when you have a good URL filter in place.
- waiseristy 5y agoThe XYZ TLD is a hotbed for spam due to it's very low fee's for purchase / renewal. The registrar was, at one point, selling massive blocks of xyz domains to foreign squatters and spam artists for quick cash. No wonder it's become blacklisted by email/cell providers. Can anyone try `abc.xyz`? and see if that fails to send? It would be very typical for our corporate overlords to be omitted from our spam censorship filters.
- Thorrez 5y ago>The text including the .xyz link is notably absent. Until I realized what was happening, I would sometimes have some very strange text exchanges with people whenever I would mention my company or my email address. Once we switched to spotvirtual.com, this issue went away. >Ironically, Google Voice also has the same behavior with abc.xyz.
- dhosek 5y agoWikipedia has a blanket ban on .xyz domains unless specifically whitelisted. I'll likely move finl.xyz to some other tld eventually.
- Twisell 5y agoGot a nice .xyz domain mainly for mail with SPF,DKIM correctly set up and tested against multiple validators. No big issues so far except for the HR department of a potential new gig which can painlessly mail me@mydomain.xyz about job interviews BUT never get my replies back. I don't who to blame more in this mess: - Me for playing smartass instead of using a @gmail.com because they impose the rules so everybody comply to them (maybe my reluctance to encourage this broken system explain my recklessness) - The IT department of this organization that probably didn't what to deal with modern standard and/or reasonable spam filtering and set up a blunt rule for new TLD (I mean come on it was a REPLY to a mail ADRESSED to this specific mailbox) - The broken system that keep on inventing arbitrary new rules that everyone must implement to keep getting accepted by "the big players". (For instance I already had to change hosting two years ago because apparently you are also responsible for bad neighbors) Guess i'll just have to be brave and migrate to a more classical TLD and set up redirects to ease transition. But it's pretty annoying to start over with crap like that because some dudes in "the big players" teams decided to ban a whole TLD just because it's "easier".
- cortesoft 5y ago> (maybe my reluctance to encourage this broken system explain my recklessness) This is a great example of a Collective Action problem. Everyone would be better off if we could break the gmail domination of email policy, but as an individual you will have zero effect on gmail's dominance and only suffer the pain of not being a part of the system.
- Twisell 5y agoAnd I would love to see EFF a little more involved in that matter. If things continues to goes downhill this far how many years left before big players decide to outright reject mail that doesn't come from a curated whitelist of their own? The responsible answer should be IRL legal actions against real spamers because they'll always adapt to new arbitrary protocol rules faster than legitimate users, it's their jobs! Even from an environmental standpoint I get tired of user-shaming articles about why you should delete your email for the planet. Maybe as engineers our duty is somewhat to propose a new version of the mail protocol that doesn't allow this much crap to fly around in the first place. Current solutions seems to revolve around the concept of "everybody should duck and cover if anything is suspicious" thus blocking some legitimate message that no sane human would reject should they be in charge instead of a basic AI. PS: I'm not suggesting by any mean that you should punish any human being with manual moderation. PS:PS: Maybe a NGO whitelist system is a solution, I'm just fearfull about which entity will end up with such power. But actually domain filtering is already kind of an implicit unpredictable non shared whitelist build on top of ICAAN register... So here we are already...
- teddyh 5y agoIf I ever start a super-secret club, I now know what the domain name TLD should be. Nobody would be able to spread the secret!
- hermitdev 5y agoPersonally, I'd go for some non-printable characters. But, maybe I'm just nostalgic for when starting a directory name with ALT+255 rendered the directory inaccessible to Windows 9x...
- mbreese 5y agoNot to be secretive, but I do have an emoji domain name (.ws allows them). You can use it for email, but it's a bit of a pain to use the address in practice. It's easier to send links directly to people, but it is kind of funny to be able to use emojis to email my kids.
- teddyh 5y agoMost, I would guess all, registrars don’t allow those characters in domain names.
- 10GBps 5y agoI run email servers and I get such a massive amount of spam on "vanity" TLD's that I just block them outright. I don't automatically block them all but any that start sending serious levels of spam get blocked. Which is most of them and that block covers the whole TLD. It's just too much work to try anything else. Now this is just for incoming email. I still allow web browsing and links to these domains through various systems and outgoing mail to those domains works. The incoming mail though, I just can't allow it. It's just pure spam at ridiculous levels.
- dredmorbius 5y agoThe reality of Internet filtering and firewalls, and a rule generalisable to any attempt at control and autonomy, is that the effect-to-effort ratio matters. The principle of a small effort with a large result is behind the architecture of every switch, gate, door, valve, or dam. New generic TLDs have the disadvantage of being recently unleashed. There are no venerable sites on XYZ, or its siblings. Much of what's registered there, and that word was "much" and not "all", is absolutely unworthy crap. And for those who are faced with defending either their own or their customers, clients, users, employees, or other stakeholder's security and time, wholesale blocking of the entire TLD solves a lot of problems with very little downside cost. The obvious response is "but there's a lot of crap on legacy TLDs as well". Yes, there is, but there are also valued, venerable, and essential domains, and blocking all of them is not a viable option. (Though the prospect of whitelisting is becoming increasingly attractive.) I've known people who are, on the one hand, Internet freedom advocates of decades-long standing --- before most people reading this were born. Who wholesale block access by all China ASNs to their webservers --- because all they see from such networks is malicious traffic. Again: effect-to-effort ratio here is high. No, it's not "fair". Yes, there's collateral damage. But you're absolutely fighting not merely human nature but all of control theory in trying to combat this. Register on XYZ and you'll be increasingly fighting a common practice of default-deny, whitelist-by-request. For every user you're trying to reach. And you should ask yourself if it's really worth it. XYZ, meantime, are mining and arbiraging short-term cashflow for long-term reputation at the specific expense of its legitimate customers. Those with the least bit of sense will abandon the registrar, leading to an ever-accelerating reputational death spiral.
- deleted 5y ago[deleted]
- imwillofficial 5y agoEmail is such a steaming pile of shit these days. I can’t wait till everyone moves off of it.
- gspr 5y agoMaybe, but there's no other asynchronous, federated, widely deployed, open-standards competitor. Not by a million km.
- qecez 5y agoJust get the dotcom. [0,1] [0] http://www.paulgraham.com/name.html http://www.paulgraham.com/name.html [1] https://zlipa.com https://zlipa.com
- NackerHughes 5y agoOh, if only it were that easy! Just get the dotcom that's already registered or otherwise costs £3,995/year bro!
- jagger27 5y agoGee, I wonder who made zlipa? > Bootstrapped with <3 by @qecez. > Our goal is to help makers find an awesome home for their project and not to help you flip. We reserve the right to refuse, or cancel membership to anyone without explanation. Nice, so only you're allowed to flip your parked domains.
- slavik81 5y agoIt is rather disappointing. I run my personal blog and email on .xyz because it's great for graphics puns. Hotmail and gmail will accept my messages, but corporate email servers often seem to blackhole me.
- smalley 5y agoDoes anybody know if there's a consolidated list of domains and their various blacklist/deliverability issues compiled someplace? I for one would love to know how broad this problem is across the various TLDs for network filtering/email/sms/messaging etc. Seems like it would be a pain to maintain even as a snapshot but I would definitely be interested.
- lgats 5y agomost popular ".xyz" domains (ranked by # of DNS queries) all appear to be spam, https://domain.glass/whois/xyz https://domain.glass/whois/xyz
- bwship 5y agoWe thought we were being smart when we bought a .io domain. Can't tell you how many times we told people the site was foo.io, and they would say, ok got it. "foo.io.com".
- fegu 5y agoI wonder about how the .wtf TLD compares.
- deleted 5y ago[deleted]
- ISL 5y agoWhoa. I use an xyz domain daily. This thread is eye-opening. Here's the reply from a SpamAssassin validator. My domain is almost marked as spam solely on TLD grounds. What's the point of a TLD if it isn't a first-party domain on the internet? SpamAssassin Score: -0.599 Message is NOT marked as spam Points breakdown: -5.0 RCVD_IN_DNSWL_HI RBL: Sender listed at https://www.dnswl.org/, high trust [***.***.***.*** listed in list.dnswl.org] 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [URIs: ***.xyz] -0.0 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2) [***.***.***.*** listed in wl.mailspike.net] 0.0 SPF_HELO_NONE SPF: HELO does not publish an SPF Record 2.0 PDS_OTHER_BAD_TLD Untrustworthy TLDs [URI: ***.xyz (xyz)] 0.0 HTML_MESSAGE BODY: HTML included in message 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature 2.0 FROM_SUSPICIOUS_NTLD_FP From abused NTLD 0.5 FROM_SUSPICIOUS_NTLD From abused NTLD 0.0 TVD_SPACE_RATIO No description available.
- SilverRed 5y agoI think the problem is that xyz was and maybe still is the cheapest TLD so it naturally attracts all the spammers.
- tim333 5y agoThere are free ones like .gq . They are probably worse!
- psutor 5y agoI host my own email, and I got nothing but huge amounts of spam from .xyz domains, so I manually increased the SpamAssassin score for just .xyz to +4.0, as KAM was only adding 0.75 for it. It's the only TLD I've had to do that for. Unfortunately for the people with legitimate uses, for email admins it's just a really easy (and arguably necessary) shortcut to block a ton of spam.
- js4ever 5y agoYes this TLD is cursed because of it's low price it has been used by all spammers and hackers on earth
- donatj 5y agoI have had similar experiences with corporate firewalls blocking my .app domain. I got in a painfully stupid argument with a middle-age IT admin “we don’t want to our employees installing apps” It’s not an app, you don’t install it, it’s a “WebApp”, it’s just a freaking fancy website who’s domain ends in .app - lol, this was like three years ago and just thinking about it is getting me heated
- dmuth 5y ago> I got in a painfully stupid argument with a middle-age IT admin “we don’t want to our employees installing apps” If they think that any domain that ends in .app is for installing apps, their mind is gonna be blown about some of the sites on .net and .org domains...
- Aulig 5y ago.net is going to install the entire internet! We cant allow that!
- peter_l_downs 5y agoThis is a total shame because .xyz is extremely catchy and, in my mind, could be the new .com in a few years. All the other TLDs are hard to remember -- in my experience, people will ask "was it my.website or mywebsite.com?" but if you tell someone "it's mywebsite.xyz" they always get it right.
- Godel_unicode 5y agoThis has not been my experience at at; people assume saying .xyz is a joke and then act surprised when the URL doesn't work and you say "no really, it ends in .xyz". Roll your eyes all you want, but get the dotcom.
- bisby 5y agoI have a .xyz domain for my personal stuff. The biggest issue I've had with it is that steam refused to acknowledge that it was a valid email domain. So they just wouldn't let me switch off gmail to me@mydomain.xyz because it didnt get past their filters. That was the biggest roadbump I had for switching off gmail.
- woggy 5y agoKind of related: I have a 'firstname@lastname.email' email address. I had booked movers online as I am moving apartments. I thought it was confirmed because I got an automated email back confirming the booking. I gave them a call about a week later to double check everything was OK and it turned out they never booked me in because they thought it was a fake address ("Wow, this is really weird, I've never seen an email address like this"). Luckily, they could still book me in but at a different time slot...
- eruci 5y agoI run a couple of businesses with .xyz domain (geocode.xyz , poidata.xyz ) Never had any issues with email.
- jccalhoun 5y agoI teach college and I can tell you that most people don't type urls. Many don't even know how. I will tell them to go to an address like kahoot.it to play a review game and most of them just type kahoot and search. if they do actually type in a url they will type kahoot.com instead of what I told them to type which takes them to the site for creating kahoots not directly to playing them. (you can get there from .com but it isn't the quickest way)
- bhartzer 5y agoWe did a bunch of testing of crawling, indexing, and checking of rankings of the 15 top tlds. The .xyz actually was crawled and indexed by google within a few hours, many others took days to get crawled. Google prefers to crawl and index .xyz sites over others domain endings. But they won’t rank them well in the index.
- SURA 5y agoI don’t mind the message being marked as `spam`, and I don’t mind looking up the spam list, but I feel scared when I can’t see it at all (has useful message been blocked by mistake?)
- fortyseven 5y agoAs a guy who's blog and email consists of .xyz domains, I can only say two or three times in ad many years has it ever been a problem (that I'm aware of, at least), and then it was a website not letting me create an account using it for email. I suspect I'm either lucky, or something.
- Uberphallus 5y agoSame here. My DKIM headers are signed by a well known and respected email provider. I assume if you self host the results are gonna be wildly different. Sometimes I send reminders from my xyz domain to my corporate email accounts (which tend to have a rather aggressive filtering) and everything seems to work fine.
- Diesel555 5y ago> we would occasionally get feedback from users and prospects that the .xyz domain felt unprofessional I had a .xyz domain. I thought it was easier, the domain was short to type. I was completely wrong. I asked a few non-technical friends. They said they would never use my site because of the .xyz, it felt like a spam site. I redid the site on .net with a longer domain name - much better results.
- deleted 5y ago[deleted]
- userbinator 5y agowe would occasionally get feedback from users and prospects that the .xyz domain felt unprofessional and that they would prefer to use an app with a different URL. This was surprising feedback, as we did not believe that, beyond the initial discoverability of our product, the domain itself would create this type of impact. Not surprising at all to me, who has used the Internet for over two decades --- to be honest, all these new and unusual TLDs, whenever they show up in search results, are almost entirely sites filled with SEO spam and similarly useless content. It's nearly an instinct to ignore them at this point. (As for the company, it's too bad virtualspot.com and virtual-spot.com were already taken; spotvirtual.com looks weird, but at least doesn't have the negative connotations of an even weirder TLD.)
- cookiengineer 5y ago- uses googlemail as TXT entries but privateemail.com MX entries for spot.xyz domain - no DKIM/DMARC verification headers that make sense, just a default ~all - wonders why emails are classified as spam Well, yeah. Maybe use an email spam rating tool next time, like mail tester [1]? [1] https://www.mail-tester.com https://www.mail-tester.com
- rsync 5y agomail-tester.com is great and I use it frequently to check (and recheck) the mail servers that I run. However, your (correct) evaluation of their weird DKIM/DMARC/MX values notwithstanding, I currently have 10/10 totally perfect score from mail-tester.com and gmail marks my email to my wife as spam. As in, a 15 year history of my email address having multi conversations per day to her email address and some of my emails (which are responses to her emails) get marked as spam by gmail. I think I am going to sue google.
- qalmakka 5y agoUnpopular opinion (maybe): given the current situation, we should probably consider phasing out TLDs somehow. It's becoming more and more clear than no TLD outside those established before the '90s are actually viable for anything outside of "my small personal blog". It would also avoid people having to remember if the TLD is .net or .com, for instance (even though in my experience .net is slowly disappearing too).
- dkdbejwi383 5y agoI have my name .xyz and I’ve mostly given up using it for email, because I am sick of: * “Do you mean ‘biz’” on web forms * other forms just refusing to validate unless I disable the client-side validation * other systems ostensibly accepting it and just never sending me anything, because it fails to validate silently in their backend * having to put whatever I am trying to get done on hold for a few minutes when I need to read it to a human, because they’ve “never heard that one before”
- chmike 5y agoThe reason .xyz domains are banned is because of the amount of spam sent from that domain. In my case 100% was spam. So blacklisting it was an easy fix. If I was owner of the .xyz TLD domain, I would be very concerned to kick out spammers because it kills the value of the .xyz TLD.
- justshowpost 5y agoStill need to update the footer to the new domain.
- SteveGerencser 5y agoThis isn't much different than when Google de-indexed millions of .co.cc domains. They determined that there were so many spammers on those domains that it was better to just remove them all and stop worrying about it. It did get a very few legit sites in the process, but not enough to care. I get that the people here want more control over their devices, but to be fair, anyone posting here is at the extreme end of the tech spectrum when compared to your average phone user. Those phone users want someone else to help them. It's why I have spam assassin crancked super tight on the mail server that my parents use. They would rather miss a few legit emails and texts than get flooded with spam. The .co.cc discussion was here on HN https://news.ycombinator.com/item?id=2733352 https://news.ycombinator.com/item?id=2733352