4 ms·
In the end it is Microsoft's problem, since they are the ones that are losing valid SMTP traffic. If a sufficient amount of users are experiencing a loss of e-m
by JacobSeated 4y ago
In the end it is Microsoft's problem, since they are the ones that are losing valid SMTP traffic. If a sufficient amount of users are experiencing a loss of e-mail as a result, then they will be forced to fix it.
There is almost never any valid reason to block an entire ip address. Single user accounts (e-mail addresses), maybe, if compromised.
E-mail, as a standard, is still pretty straight forward. Ideally you should be able to send e-mail directly from your laptop IP, if approved to send e-mail on behalf of your e-mail account / host name. Decentralization is important.
- Avamander 4y ago> There is almost never any valid reason to block an entire ip address. Single user accounts (e-mail addresses), maybe, if compromised. I'm sorry but that's just very naive.
- InCityDreams 4y ago>I'm sorry but that's just very naive. It would be fair(er) to explain why.
- Avamander 4y agoThe statement is just really quite absolute. The most trivial example would be an IP address being used by an abuser behind bulletproof hosting. Someone trying to deliver 200 000 spam letters in a minute and you rejecting each one is a significant amount of load - best case it still reduces your logs' SNR.
- int0x2e 4y agoThe issue is that domains are cheap and plentiful, and a spammer can easily claim to be sending mailflow on behalf of let's say, 1000 users, each sending 5-10 emails a day, and thus, a single IP "forwarding" (sending) mailflow "on behalf" of 10k domains, with 1k users each, with each user sending just 10 emails a day - would result in a pretty nice batch of spam making it through. As things currently stand, the only "expensive" resource that is hard to acquire or fake somehow is source IPs with good reputation. Fair? I'm not saying it is. It's just effective.
- marcosdumay 4y agoThe cost of a domain looks conveniently close to the cost of keeping track of some entity's reputation to me. A domain is relatively cheap. Accepting some 20 messages before you are sure it's spammy is also cheap. You will have to filter out the malicious domain registers, but that's a quite immutable set, as becoming a register is a bureaucratic process with a non-trivial cost.
- Kankuro 4y agoI stopped using my own domain (managed by an association) for sending to outlook.com and yahoo because I know it's a fight that will be a net loss for me. Senders will change provider (because it's critical) before these major actor starts planning a fix. And in an organisation, if a business person asks the IT to fix the issue, the only way to do it in a timely manner is to changer provider. The requester will not care if it's Microsoft fault, sending mail works at home and in other companies, not here, do something, business comes first, bla bla bla.
- Cu3PO42 4y agoI don't think that's how it plays out. Microsoft has a lot of users on their mail services. If you -- as a business -- cannot reach these users, most of them aren't going to blame Microsoft. They're going to blame you and probably choose not to use your website/shop/... unless there is a previously established relation. Thus your deliverability troubles are now a "you" problem. Because you're going to lose customers over it.
- cge 4y ago>In the end it is Microsoft's problem, since they are the ones that are losing valid SMTP traffic. If a sufficient amount of users are experiencing a loss of e-mail as a result, then they will be forced to fix it. One might think that would be the case eventually, but at least in the case of universities insisting on using Office365, it really doesn't seem to be. In academia, where emails to and from university domains are the norm, Office365 seems to frequently treat with extreme skepticism odd domains, like those with .edu or .org TLDs, or prominent universities on ccTLDs in Europe, assuming that most legitimate mail will come from inside an organization. I've seen it send directly to spam emails about papers, peer review, talks, emails from easychair.org, emails from major journals. I know of a case where it has sent emails from Nature's submission system to spam. I've seen it send emails from frequent collaborators to spam. Classifying emails as not spam seems to do little to nothing. Meanwhile, emails from major providers' email services, like gmail and outlook, often seem to get through, despite mostly being spam, and in some cases, rather obvious spam. It seems likely that people have lost publications and talks as a result: the emails being rejected and spam-filtered are important emails. Yet as much as everyone seems to complain—and these are complaints I have heard from many people, at many universities—Microsoft seems to have continued success in selling Office365 to university IT services, and pushing everyone to use it.
- vedranm 4y ago> It seems likely that people have lost publications and talks as a result: the emails being rejected and spam-filtered are important emails. There are likely some silently discarded e-mails as well, but you can't know for sure because they weren't even delivered.
- CatWChainsaw 4y ago>If a sufficient amount of users are experiencing a loss of e-mail as a result, then they will be forced to fix it. The trouble is, how many users are sufficient? Patch Tuesdays have their reputation for a reason, and if your issue isn't one shared by millions of people, it's unlikely a fix will come from Microsoft. Meanwhile email continues to get lost, and Microsoft ignores the issue.