17 ms·
Gmail and Yahoo’s 2024 inbox protections and what they mean for email programs
- gwbas1c 3y agoI can't wait for this to take effect. It seems that every time I buy something or someone gets ahold of my email address, I get added to a SPAM list. I can't wait for all of these to be blocked. For example: I recently elected a benefit, and the company added me to a SPAM list for weekly deals 100% unrelated to the benefit. They even ignored the fact that I unsubscribed.
- zie 3y agoI promise, these changes won't fix that.
- mrWiz 3y agoI've started using this approach to combat spam that ignores unsubscribe attempts: 1. Report each and every offending email to the FTC: https://reportfraud.ftc.gov/#/ https://reportfraud.ftc.gov/#/ 2. Forward the "report received" email that the FTC sends you to support@spamming_domain.com and explain how and why you're reporting them 3. That's it. I've had a 100% success rate with this approach
- d3w4s9 3y agoSlightly off-topic: it seems that Outlook has given up fighting spam and isn't even in such conversations. I have a decades-old hotmail.com email address that is getting spams daily in the inbox, while a similarly old gmail.com almost always filters them out. Well, Gmail occasionally flags false positives but never false negatives. This is getting so bad that I have completely moved off that hotmail.com address.
- rebelde 3y agoMicrosoft, like the old Microsoft, seems to completely reject all these modern methods and use their own instead. So, you get a lot of spam and my legitimate emails are rejected.
- deleted 3y ago[deleted]
- ubermonkey 3y agoMailgun is a spammer, so, like, cry me a river? I have them blocked at the server level because of how much spam they were sending me. They clearly do zero enforcement of opt-in.
- jdhawk 3y agohow are they supposed to enforce it?
- ubermonkey 3y agoNot really my problem. But any bulk mailer that doesn't solve that problem is by definition a spam engine, and should probably be blocked at the ISP level.
- EGreg 3y agoUnsubscribe HAS to require an authenticated session. What do they mean by “single click”? Otherwise anyone who receives a forwarded email can unsubscribe you! Right? At least we can email the peson to say they’ve been unsubscribed, as a transactional email? And give them a chance to resubscribe and prevent such unsubscriptions — or what? Enable easy unsubscription: Senders will need to implement a single-click unsubscribe link within emails if they haven’t already, to allow recipients to easily opt out.
- hedora 3y agoIt certainly does not require authentication. Have you used unsubscribe flows? Normally, you click once, it goes to a web page that displays your email address, and has an "I'm sure" button, and maybe some checkboxes to only partially unsubscribe. If you really care about people being maliciously unsubscribed from marketing materials they forwarded around, then you can be one of the sites that sends a final "you have been unsubscribed" confirmation email.
- EGreg 3y agoThe "I'm sure" button is sensible since the session cookie confirms it's you. But that button requires a second click. That would violate the "single-click". According to the "single click" requirement, merely visiting the page by clicking the link in your email should be enough to unsubscribe you. Meaning, the GET request, which normally shouldn't change server state, should change server state. The major issue with that is, if you forward the email, you are giving the capability to anyone else to act as you. It's a horribly insecure model, it also breaks HTTP semantics, but at least you can limit it to the "unsubscribe" action, I guess. Could be worse. Google could require other "single click" actions that may modify your profile or withdraw money from your bank account. The only mitigation I can see is that the "you've been unsubscribed" email is a transactional email, and can inform the user that "if it wasn't you, then click here to restore your subscription to this newsletter, and don't forward your emails anymore, because Google says someone can unsubscribe you anytime and we can't do anything about it." PS: Ironically, Apple's newest ITP scrubs information from tracking links in emails, so in theory it would make it impossible to even track whose account to unsubscribe from. "It will do this by automatically detecting user-identifiable tracking parameters in URLs and removing them." Apple ITP anti-tracking requires you to explicitly log in before doing stuff as you. Google now requires the opposite. It's impossible to satisfy both. https://www.peelinsights.com/post/ios-17-disrupts-link-tracking-for-marketing-attribution https://www.peelinsights.com/post/ios-17-disrupts-link-track...
- hedora 3y ago> Gmail and Yahoo are getting serious about spam monitoring and senders will need to ensure they’re keeping below a set spam rate threshold. Does anyone know what this sentence means? Is this “the user said this is spam”, or “the gmail spam filter false positives 10% of the time; don’t be part of the 10%, or it’ll permaban you”?
- nulbyte 3y agoIn my experience, it means nothing. Most of the spam I get to my Gmail account comes from other Gmail users using Gmail, and I don't believe Google will do anything to hold themselves accountable.
- cnees 3y agoGmail postmaster tools says, "This dashboard shows the percentage of user-reported spam vs emails that were sent to the inbox for active users. Emails delivered directly to the spam folder are not included in the spam rate calculation. Only emails authenticated by DKIM are eligible for spam-rate calculation." The threshold for the number defined above is 0.3%; that's the point where Gmail starts penalizing the sender by putting their emails in spam folders.
- hedora 3y agoOh, so if 0.3% of people subscribe to a mailing list, then mark it as spam (instead of unsubscribing), then it goes to my spam folder? That explains why I had to immediately disable gmail's spam filter.
- simscitizen 3y agoMandatory DMARC basically breaks all e-mail forwarding services (SPF doesn't survive forwarding due to modification of Return-Path). I think ARC/RFC8617 is supposed to be the fix for that, but it's not even standardized yet. This seems like a rather big issue?
- anticorporate 3y agoI find much of the discourse on these changes to be pretty amusing. It's a lot of sales and marketing teams asking how they can tweak things at a technical level so that they can keep doing the same things they've always been doing. You can't. That's the point. Stop. I mark all commercial email as spam. I never asked for it, I don't want it. I don't really care if you carefully constructed a form in such a way to be compliant with the laws in my country. I don't care how your BDR found me. I don't ever want to hear from you. If I didn't ask for it, it's spam, I'm marking it spam, and I hope people who use Gmail and Yahoo do the same.
- izzydata 3y agoIndeed I do. Any email I didn't explicitly ask for that isn't a unique personal email I mark as spam. Although I also stopped using Gmail in favor of Proton.
- codalan 3y agoSometimes I wonder if their mindset is, "Hey, even if only .05% engage w/ the marketing email, that's still > 0%!". Maybe their mindset should really be, "Hey, we're annoying 99.95% of our users who did not consent to these emails, and > 50% will be turned off to our product and will associate our brand to that of a needy, attention-grabbing parasite". If I wanted these emails, I would have opted in. Instead, not only do they automatically opt you in, but they'll re-opt you in after you've unsubscribed. I've had it happen a year or two later; suddenly, I'm back on their spam list. It's become so bad now that I can't even let a shopping cart sit anymore without getting a nagmail saying "HEY YOU NEED TO FINISH CHECKING OUT NOW1!!!". That email is the reminder to empty my cart and never do business with them again. Seriously, STFU and leave me alone. If your sales and marketing team insist on these tactics, you need to fire them and hire people who get it.
- anticorporate 3y ago> If your sales and marketing team insist on these tactics, you need to fire them and hire people who get it. So, full disclosure, in addition to being kind of an anti-spam zealot, my day job is running marketing operations at a big-ish software company. So I get the fun job of telling everyone from the junior intern to the senior VP that no, my team is not going to send that email for you. That no, in fact, I don't care what the old person in my job let you do, or what you did at your old company, or how many levels above me you are in the org chart. We're only going to email people what they asked for, at the frequency they asked for it, on the topics they asked to hear about. These new Gmail/Yahoo rules have helped immensely in making the case to our CMO to have my back.
- repeek 3y agoHow does the one-click unsubscribe not get triggered by enterprise SPAM tools like Mimecast or Barracuda?
- tgsovlerkhgsel 3y agoI hope the <0.3% spam limit is low enough to force companies to stop with the usual "congratulations, you unsubscribed from newsletter 13 (but will continue to get newsletters 1-12 and 14-39)" bullshit.
- XCSme 3y agoIf anyone is interested, I wrote some sort of tldr blog post for quickly setting up your DMARC/SPF/DKIM: https://www.uxwizz.com/blog/stop-others-use-your-domain-emails https://www.uxwizz.com/blog/stop-others-use-your-domain-emai...
- h0nd 3y agoYahoo cracked down on my wanted emails - they simply deleted my first 10 years of emails.
- pqvst 3y agoFrom Q1 2024, Gmail and Yahoo will require senders to have SPF, DKIM, and DMARC. Also, spam complaints must be kept below 0.3%. I recently added DMARC monitoring to some of my domains through CloudFlare.
- deleted 3y ago[deleted]
- sylware 3y agoAbusive, SPF is plenty enough unless you cannot map the domain with the right IPs due to DNS trickery (rotation, etc), then you would need an IP agnostic way to do some checks, hence the cryptographic DNS based signature. That said, with no-DNS email addresses, SPF comes for free (alice@[x.x.x.x] bob@[ipv6:...]). Namely, if SPF does pass, cryptographic DNS based signature mecanisms are excessive and must not be used to score.
- jabroni_salad 3y agohttps://github.com/CanIPhish/spf-bypass https://github.com/CanIPhish/spf-bypass i wish. If you are using spf-only, you are consenting to being spoofed.
- ericpauley 3y agoIP addresses get reused, private keys don’t. Aside from SPF being around first DKIM makes far more sense.
- chuckadams 3y agoSPF only authenticates the envelope-from, whereas it's DKIM that takes care of the From: header. Without DKIM, one can easily do "EHLO randomspamdomainboughtyesterday.com" and "From: accounts@citibank.com". SPF is about the transport, DKIM is about the content. And to round it out, DMARC tells the receiver what to do when the SPF or DKIM tests fail, namely "report", "quarantine", or "reject". Not sure why they're requiring it when it doesn't affect a spam verdict. Maybe it's so those who run a misconfigured server can't complain if their mail is being dropped silently, google and yahoo can just tell them to switch the policy to "report".
- sylware 3y agoThis is wrong: DKIM would be used only if SPF does not "pass", if there. DNS SPF is inappropriate for those email provider implementing DNS trickery which cannot work with DNS SPF. For DNS SPF to "pass", not only the SMTP prolog and transactions must be evaluated, but also some header fields (from:,reply-to:). For instance, if you are self-hosted and your SPF DNS entry does match the domain in the SMTP prolog/transactions and the header fields, your spam score will be significantly lower. With no-DNS email servers, you don't have the SPF DNS indirection and can directly check the IPs ( bob@[x.x.x.x] alice@[ipv6:... )] for spam scoring. That said, the real worst are those sys admins blocking instead of enabling grey listing.
- bagels 3y agoWhat're the best resources for testing and configuring this stuff?
- XCSme 3y agoI wrote this blog post for myself for whenever I have to configure email again: https://www.uxwizz.com/blog/stop-others-use-your-domain-emails https://www.uxwizz.com/blog/stop-others-use-your-domain-emai...
- YPPH 3y agoFor testing, I find https://www.mail-tester.com/ https://www.mail-tester.com/ helpful.
- 1over137 3y agoFor testing: https://mxtoolbox.com/ https://mxtoolbox.com/ For configuring: https://www.cyber.gc.ca/en/guidance/implementation-guidance-email-domain-protection https://www.cyber.gc.ca/en/guidance/implementation-guidance-...
- cassianoleal 3y ago> These mandates will only affect bulk senders, defined by Google as senders with volumes of 5000 or more messages to Gmail addresses in one day. This is not a requirement for a personal self-hosted email.
- StayTrue 3y agoIf your personal self-hosted email routes outbound messages through a smarthost, it could affect you.
- judge2020 3y agoWouldn't it be based on send volume from your domain, and not send volume via your sending IP / smarthost?
- zinekeller 3y agoUsually when talking about spam filtering it's based on sending IP and not domain names (domains are still important, but IP addresses are usually the first thing that is being evaluated), although admittedly Google is vague on what constitutes "5,000 mails per day".
- judge2020 3y agoThe linked article points to blog.google which points to this support article https://support.google.com/mail/answer/81126 https://support.google.com/mail/answer/81126 which then finally points to this article: https://support.google.com/a/answer/14229414 https://support.google.com/a/answer/14229414 > What is a bulk sender? > A bulk sender is any email sender that sends close to 5,000 or more messages to personal Gmail accounts within a 24-hour period. Messages sent from the same primary domain count toward the 5,000 limit. > Sending domains: When we calculate the 5,000-message limit, we count all messages sent from the same primary domain. For example, every day you send 2,500 messages from solarmora.com and 2,500 messages from promotions.solarmora.com to personal Gmail accounts. You’re considered a bulk sender because all 5,000 messages were sent from the same primary domain: solarmora.com. Learn about domain name basics. > Senders who meet the above criteria at least once are permanently considered bulk senders. IMO this is better since they have to handle all of the personal domains and small communities that send from a SMTP service like Sendgrid or Amazon SES. Relying on IPv4s to not be shared wouldn't work universally.
- ryandrake 3y agoAs a self-hoster for over a decade, setting up SPF, DKIM, and DMARC are pretty much once-and-done and free, so there's pretty much no downside. I'd be shocked if most self-hosters haven't set these up long ago.
- boplicity 3y agoFor those sending in bulk, the more challenging part will be complying with rfc8058 https://datatracker.ietf.org/doc/html/rfc8058 https://datatracker.ietf.org/doc/html/rfc8058
- diggan 3y agoFor sending outgoing emails in a self-hosted environment, the toughest step will absolutely be to find a host willing to accept you as a customer. A lot of places don't accept outgoing SMTP traffic at all, some allow it for personal usage and finding someone who accepts you sending lots of outgoing SMTP traffic is gonna be really hard, except if that host already hosts lots of already spam-marked IPs.
- yencabulator 3y agoIsn't that just a webserver to handle the click and a header in the email List-Unsubscribe-Post: List-Unsubscribe=One-Click That shouldn't be hard for any mailing list manager software to handle.
- illiac786 3y agoI don't know if self hosted but I regularly get emails from companies where this has not been set up. And not "Joe's Car Detailing" but rather "medium size gas provider" ...
- 1over137 3y agoYes, they are quite easy to set up. Yet I know several small ISPs that haven't done it yet. :(
- deleted 3y ago[deleted]
- tikkun 3y agoMy addition to title: “If you send >5000 emails a day.” Posthaven has very helpful (free) tools for setting up this stuff. Also GPT has a good understanding of the dns records needed.
- StayTrue 3y agoIn practice I think people who care about deliverability have already instituted these measures ... because spam blocking measures at Big Email are so opaque you’ve tried everything/anything. And it’s not that difficult.
- LanzVonL 3y agoThat's so weird considering those two domains are the source of ALMOST all the spam I've seen over the last couple decades.
- technion 3y agoA fairly big deal is being made of this, but dmarc has been a signal for a long time and there's a good chance half your mail has been randomly landing in junk folders if you don't have it setup right. This may actually help people by making them realise that.
- TheCycoONE 3y agoDKIM, SPF, and DMARC are old hat and implemented by anyone serious for years. What's buried in this article is the required https://datatracker.ietf.org/doc/html/rfc8058 https://datatracker.ietf.org/doc/html/rfc8058 support for one-click unsubscribe posts. I don't see many messages in my inbox yet with that.
- illiac786 3y agoHow does that interact with crawlers, like what Microsoft does? (They visit every link in every email it seems) does it automatically unsubscribes you by error then?
- pbronez 3y agoUnsubscribe links make me nervous. Such an obvious attack vector.
- gwbas1c 3y ago> required support for one-click unsubscribe posts The article gets it wrong. They imply that emails have to have one-click unsubscribe links, which isn't true. Emails need to include headers (described in your link,) which the mail client can use.
- jasonjayr 3y agoI understand that the request happens in the background by the MUA at the user's express consent, and the unsubscribe is not allowed to send back any ui/html/whatever to present to the user, but the RFC is missing any information about how a response ought to be handled, HTTP Status code wise? Retry if 400/500? Give user any affirmative or negative response that it succeeded or failed?
- zie 3y agoYou can't send back anything? oops. I better re-read the RFC's, that's not how I implemented it...
- chuckadams 3y agoThat's up to the MUA, but I imagine that they would at least show an error dialog. If the backend of that POST is broken, then the spam complaints are going to rack up, which will get the list blocked, List-Unsubscribe header or no (some of the most notorious spammers around were actually quite scrupulous about having said header, which they would actually obey ... temporarily)
- flemhans 3y agoHow are they counting the 5,000/day? Per sender email? IP?
- snowwrestler 3y agoPer sending domain name, it appears.
- darylteo 3y agoHow does this interact with transactional emails / 2FA / password resets? If 5000 people request a 2fa code in a month, I have to give them a unsubscribe header as well? Or magic login links? If I don't provide a list-unsubscribe header: do these emails then get blocked and noone can log in ? If I provide a list-unsubscribe header, what is the expected behaviour if they do click the Unsubscribe button? - tell them they can't unsubscribe to this email because it's needed to accomplish what they want to do in the future? - delete their account? what if it's a bank account or something like that? Would appreciate some clarify from Google at least...
- ahoka 3y agoAlso forcing people to click on opaque links in random emails cannot end good.
- mrtesthah 3y agoWell the answer of course is for google to clone the unique features of your service and classify your site and its outgoing emails as spam.
- trawls14 3y agoOur (Postmark's) take is that while these changes are explicitly for marketing/bulk email senders, they are coming for transactional emails as well sooner or later: https://postmarkapp.com/blog/2024-gmail-yahoo-email-requirements https://postmarkapp.com/blog/2024-gmail-yahoo-email-requirem...
- orliesaurus 3y agoYou're talking about Transactional emails? You cant unsubscribe from TRANSACTIONAL emails. That's why they're transactional...not marketing. It's really important to differentiate that.
- darylteo 3y agoI "know" that. I'm asking how does Google differentiate between a transactional and a non transactional email? They also say in their guidelines > *Marketing messages and subscribed messages* must support one-click unsubscribe, and include a clearly visible unsubscribe link in the message body. So how is Google determining what is a Marketing/Subscribed message? If they're not, then am I required to tack on this header to ALL emails regardless of type or risk getting binned?
- kaetemi 3y agoIs there any service that can process DMARC report e-mails? Those mails with zips with indecipherable XMLs inside them are a bit useless. Something that takes the junk, gives a nice human readable dashboard, and informs me if something is wrong, would be nice.
- snowwrestler 3y agoDmarcian, I think.
- rbut 3y agoPostmark have a free DMARC service [1] that emails you a report once a week. I use it for all my domains. Note that they also have a paid offering, but this one is free. [1] https://dmarc.postmarkapp.com https://dmarc.postmarkapp.com
- kaetemi 3y agoThis looks very easy to set up, thanks. I'll try it tomorrow.
- linuxalien 3y agoMailhardener and dmarcdigests are 2 that I've used. Dmarcdigests also has a free version through postmark that sends you a summary email weekly instead of a dashboard. I personally like mailhardener, I felt the dashboard was better and easier to understand.
- wetoastfood 3y agoI’ve been using DMARC Digests for a year and haven’t had any issues. Was quick to set up.
- donmcronald 3y agoThe DMARC industry is nuts. Most services charge a lot for what amounts to retrieving emails and doing a little XML parsing. It’s mostly transient data too, so it’s not like paying for a ton of redundancy is worth it. IMHO, they’ve taken something that should be simple and turned it into a complex system that needs a ton of infrastructure because they all want a SaaS business. Everyone pays for the cost of scaling when simple sharding would do for most users. I’d love to have a simple, self hosted DMARC analyzer running on something like PocketBase.
- deleted 3y ago[deleted]
- Michaelhartnett 3y ago[dead]
- deleted 3y ago[deleted]
- hsbauauvhabzb 3y agoPlease describe ‘easily unsubscribe’ - subjective terms like this don’t work when you’re dealing with the profit focused marking department of scumcorp. I don’t want to log into your service or explain why I want to unsubscribe or chose which mailing lists I want to unsubscribe from (read: All of them) nor do I want to deal with your dark patterns such as colouring the ‘cancel my request to unsubscribe’ button green and ‘yes really unsubscribe me’ red.
- dexwiz 3y agoSenders will need to implement a single-click unsubscribe link within emails if they haven’t already, to allow recipients to easily opt out. It does in the article. The industry has clear definitions for things like one click unsubscribe versus two click confirmation.
- hsbauauvhabzb 3y agoI know it’s not possible to implement a literal double click in web but hear me out - if someone told you they interpreted that as ‘a link which you only have to click once to open the unsubscribe website which may have additional clicking’ - would you think they’re malicious or incompetent?
- dexwiz 3y agoIncompetent. But I think those decisions are often made by neither the people who send nor receive the emails.
- mook 3y agoMy bank sends (non-transactional) email to me with an unsubscribe link, then magically I get sent more even after going through the whole thing (to the screen where they confirm everything has been unsubscribed). It's hard to confirm externally that things worked.
- actualwitch 3y ago
- navigate8310 3y agoHaving DMARC to allow all emails is still stupid. They should have added a mandatory reject policy.
- TheCaptain4815 3y agoI’d say the only real worry for “black hat emailers” is the spam rate monitoring. Everything else is fairly trivial to comply by, but lowering the spam compliance threshold could really put a wrench in a lot of sales outreach campaign. The market(Google and others) was forced to act because how laughably easy the Can-Spam act is to stay compliant while legally mass spamming.
- max_ 3y agoI use cloudflare's email remailer. i.e emails are mailed from from & to my Gmail via cloudflare. Using a custom email domain. Does this mean that my emails will no longer be sent?
- corney91 3y agoDMARC only requires SPF or DKIM to pass, so the mail will pass of it's DKIM signed.
- deleted 3y ago[deleted]
- darylteo 3y agoI think you can set a ARC header for forwarders.
- modernerd 3y agoI think they set it automatically, at least based on https://blog.cloudflare.com/email-routing-subdomains https://blog.cloudflare.com/email-routing-subdomains
- deleted 3y ago[deleted]
- freddieleeman 3y agoFor those interested in testing their email for SPF, DKIM, and DMARC compliance or eager to learn about these mechanisms that enhance email security and prevent spoofing, check out https://learnDMARC.com https://learnDMARC.com. This is a site I developed to promote adoption and share knowledge. It includes a challenging quiz, tough even for professionals. I'd be keen to know your scores on the first attempt – honesty counts!
- w3ll_w3ll_w3ll 3y agoAmazing site!
- Kirce 3y agoIf I scroll the DMARC Results on mobile Firefox, the right column doesn't scroll, while the rest of the table does. The results where all green, as expected :)
- flumpcakes 3y agoThis is great! I scored 60% because I didn't realise 5321 HELO was also checked. That's news to me, I've never seen that before. I got 90% on my 2nd attempt :) Also I think there was one question that was a mistake, it had a policy along the lines of: v=DMARC1; p=reject; <stuff...>; pct=0; <stuff...> I answered that a failing message would have an effect of p=none, but the right answer was apparently p=quarantine. Is that right, considering pct=0? (Unless I was blind and the pct wasn't set to 0 in the question...)
- freddieleeman 3y agohttps://datatracker.ietf.org/doc/html/rfc7489#section-6.6.4 https://datatracker.ietf.org/doc/html/rfc7489#section-6.6.4 "If email is subject to the DMARC policy of "reject", the Mail Receiver SHOULD reject the message (see Section 10.3). If the email is not subject to the "reject" policy (due to the "pct" tag), the Mail Receiver SHOULD treat the email as though the "quarantine" policy applies. This behavior allows Domain Owners to experiment with progressively stronger policies without relaxing existing policy."
- 3y ago
- jwr 3y agoI get plenty of spam through Gmail, and there is no easy way to report it, it also doesn't seem like they are the least bit interested in tackling the problem. I wish they took a closer look at themselves and also applied these kinds of rules to themselves.
- wakeupcall 3y agoI get >50% of my spam from legitimate hosts such as gmail and yahoo, which tick all the spf/dkim/dmark boxes. spf/dkim/dmark helps with phishing/forgery, it does little to nothing for spam, even though this policy change makes it look like it's connected. If I send spam through gmail, the spam is "authenticated". spammers were among the first to implement these in an attempt to get higher score in spam filters. For quite a while dkim was positively correlated with spammyness for me. Meanwhile.. does google even respond postmaster@ or abuse@ requests?
- forgotpwd16 3y ago>there is no easy way to report it If you mean coming to Gmail, three-dots > report spam. If you mean coming from Gmail, https://support.google.com/mail/contact/abuse?hl=en https://support.google.com/mail/contact/abuse?hl=en.
- unsupp0rted 3y agoI thought this button isn’t hooked up to anything
- HelenePhisher 3y agoA contact form is too complicated for this. I think an abuse header with an address to forward the entire mail with headers should be standard.
- red_admiral 3y agoI hope this also applies to T&C spam - the thing where a company reminds you that they exist once a month by e-mailing you about a minor change to the wording of their terms and conditions, and because it's "important legal information" it overrides your opt-out preferences. If I think someone is taking the piss, I flag these as spam, and if more than 0.3% of the population did this then companies would think twice about this tactic.
- tempestn 3y agoI wonder if this will force Borrowell to finally allow unsubscription from their regular emails without deleting your account. https://helpcentre.borrowell.com/hc/en-us/articles/10014508919060-How-do-I-unsubscribe-from-Borrowell-s-marketing-emails- https://helpcentre.borrowell.com/hc/en-us/articles/100145089...