4 ms·
They say "Both email servers have PTR records set up, and SPF [...] DKIM, and DMARC records[...]". Yes. Great. Thing is that this is such a trivial barrier to
by jfindley 4y ago
They say "Both email servers have PTR records set up, and SPF [...] DKIM, and DMARC records[...]".
Yes. Great. Thing is that this is such a trivial barrier to entry that guess what? Spammers do it too! Email has become so utterly corrupted with spam that the reality is that an independent provider who has no existing reputation is, 99% of the time, going to be a spammer.
It would be wonderful if we could fix this - but so far noone's come up with a workable solution.
- midoridensha 4y agoI agree. It really sucks that a handful of big corps control email now, and we can't all just have our own email servers like in the old days, but the spammers really ruined it. And I don't see how any technical solution could change this: anything that's free and open-source can be easily used by the spammers just like anyone else, and then subverted. The solution to spam isn't technical, it's legislative and judicial, but that's just not possible because they operate across national borders and no one's going to start a shooting war over spam.
- ggm 4y agoIt's not that the solutions are unworkable: The problem is that they are unpalatable. There are outlier Mail-wonks who maintain pay-to-send wouldn't "work" but they are somewhat in a minority: If you forced senders to pay even tokenistic per-mail sums, the attractiveness of mail would disappear. People don't want to monetize Mail for complex reasons. The "won't work" aspect in spam pushback has always been debatable. (there's a well known checkbox list of "your proposed anti-spam mechanism won't work because.. which is a huge antipattern to having a rational debate about it) The problems are regulatory: who sets the price, who collects the price, whats done with the money, and what it does to the ecology of email internationally. But, it would within some definitions of the term "work"
- yipbub 4y agoSpammers are the most willing to pay negligible amounts. Way more than regular users. They pay for tools, servers, services, etc. because they have some expected return on email.
- Analemma_ 4y agoAny pay-to-send model destroys mailing lists and the ability for large sites to use email to send notifications (e.g. Amazon package shipments). It's a complete non-starter. I get that you're frustrated with the famous checkbox list but it exists for a reason beyond intellectual laziness - the "won't works" really are won't works.
- gaganyaan 4y agoIt does actually seem rather lazy. "Whitelists suck" is not informative or helpful.
- ggm 4y agoIt's a matter of opinion. It doesn't destroy them, it demands something like patreon. It's a complete non starter because the community does not want to explore it. I don't expect to convince you any more than I expect to be listened to really: I've held this view since the eighties, earlier list paradigms I used in the 70s met cost, and were policed by list administrators accordingly. This topic has been dominated by a very few loud voices who basically prevent rational discourse.
- EVa5I7bHFq9mnYK 4y agoHow about user-side whitelists + pay-per-send for anything unsolicited?
- tomjen3 4y agoThey pay to send model, at something like 0.1 penny an email does not destory amazon package shipments, but would properly force mailinglists to require payment to be on them. But more importantly: the list didn't give technical answers, it gave political tradeofs that we never debated. Meanwhile the Gmail team went ahead and did what they did, and now we are stuck with one particular system that people then complain about.
- brightball 4y agoThe domain ownership needs to be followed to track them down. The server is one thing, but the domain ownership should leave a trail for real enforcement.
- cge 4y agoIt doesn't seem to matter. Actually getting domain ownership information is generally quite difficult now, because anyone with real DNS contact information will get spammed (even spammed physically). Domain registrars have no requirement to care about spam from domains registered with them, and so generally don't care. Server owners will actually sometimes care, but it seems easy enough for spammers to find companies that don't. To add to this, if the spammers are in the US, unsolicited spam is essentially legally protected there. I've tracked down the actual US offices of some companies sending me clearly unsolicited spam with database-harvested information (usually sketchy loan offers to email addresses they could have only gotten through inappropriate means), but they can say they have an unsubscribe link and thus comply with CAN SPAM, and even if they don't, the act doesn't actually provide any recourse to individuals or small companies being spammed.
- armchairhacker 4y agoA global nonprofit with a curated “whitelist” which takes vetting to get into (and maybe an application fee like $10). And once you’re in, monitoring or some other system to ensure that your emails aren’t spam (and maybe a monthly fee to pay for that too). That isn’t “true decentralization”, but close enough: a global nonprofit organization with strict policies is hard for companies buy and governments to influence. And it’s not truly free either, but those who can’t afford $10/mo sadly have bigger issues than hosting a private e-mail server.
- teddyh 4y agohttps://craphound.com/spamsolutions.txt https://craphound.com/spamsolutions.txt
- Dylan16807 4y agoIt doesn't work if you don't tick the boxes and it's not obvious which boxes should be ticked. I could see a couple that would apply but wouldn't be dealbreakers. Also this is not a proposed solution to spam. It is a proposed solution to aggressive anti-spam.
- tambourine_man 4y agoThat is one sad link.
- tsujamin 4y agoKind of like a Certificate Authority, with all the incentives and fraud issues that follow
- teddyh 4y ago> an independent provider who has no existing reputation is, 99% of the time, going to be a spammer. I suspect that this is the actual reason; “School Interviews” seems to be a new thing, and anything new is viewed with suspicion by large e-mail providers.
- ivan_gammel 4y agoClosed platforms have an advantage of being policed by an owner, open platforms can survive only when there’s a governing body and some entity with the function of enforcement. People problems are solved with people solutions, not with technical ones. As soon as spammers become liable for every message in the cross-border platform jurisdiction, i.e. the email police can seize their collateral or block their servers by invalidating their certificates, the problem is gone.
- 404mm 4y agoAt this point if I had to allow-list all source domains (with choice of unblocking whole domain or just the sender) in exchange for no delivery issue as well as no spam.. I’d probably say yes to that. :-|