8 ms·
DKIM, SPF, and DMARC are old hat and implemented by anyone serious for years. What's buried in this article is the required https://datatracker.ietf.org/doc/htm
by TheCycoONE 3y ago
DKIM, SPF, and DMARC are old hat and implemented by anyone serious for years. What's buried in this article is the required https://datatracker.ietf.org/doc/html/rfc8058 https://datatracker.ietf.org/doc/html/rfc8058 support for one-click unsubscribe posts. I don't see many messages in my inbox yet with that.
- illiac786 3y agoHow does that interact with crawlers, like what Microsoft does? (They visit every link in every email it seems) does it automatically unsubscribes you by error then?
- pbronez 3y agoUnsubscribe links make me nervous. Such an obvious attack vector.
- gwbas1c 3y ago> required support for one-click unsubscribe posts The article gets it wrong. They imply that emails have to have one-click unsubscribe links, which isn't true. Emails need to include headers (described in your link,) which the mail client can use.
- jasonjayr 3y agoI understand that the request happens in the background by the MUA at the user's express consent, and the unsubscribe is not allowed to send back any ui/html/whatever to present to the user, but the RFC is missing any information about how a response ought to be handled, HTTP Status code wise? Retry if 400/500? Give user any affirmative or negative response that it succeeded or failed?
- zie 3y agoYou can't send back anything? oops. I better re-read the RFC's, that's not how I implemented it...
- chuckadams 3y agoThat's up to the MUA, but I imagine that they would at least show an error dialog. If the backend of that POST is broken, then the spam complaints are going to rack up, which will get the list blocked, List-Unsubscribe header or no (some of the most notorious spammers around were actually quite scrupulous about having said header, which they would actually obey ... temporarily)
- Analemma_ 3y agoThat's very odd to me. Where are you located? I'm in the United States and virtually all my newsletter/marketing emails have one-click unsubscribe these days. The only ones which don't are from foreign companies, e.g. I bought a day planner from Hobonichi and found they put their unsubscribe behind a login, to my irritation.
- MBCook 3y agoSame. Basically everything that comes from a legitimate mailing list/subscription has it. Even stuff I would personally consider spam like political mailing lists have it. It’s only the worst spam stuff that doesn’t. The obvious scam stuff sent to any email address they can find, containing every language I don’t speak, with lots of bad obfuscation to stop keyword scanners from 2002.
- bediger4000 3y ago> Basically everything that comes from a legitimate mailing There's the fly in the ointment. "Legitimate" shades off very slowly into bottom feeding Sanford Wallace-ass spamming. The temptation to become worse and worse is real, economics favor spamming, as it externalizes advertising costs. Until the torches and pitchforks come out.
- OkGoDoIt 3y agoI’d say somewhere around half of the marking emails I receive in the USA have one-click unsubscribe. It’s still very common to have unsubscribe links that require you to enter your email address and then select that you actually want to unsubscribe from everything, etc. And some of them still require logins, although those are getting rarer. Not sure if it’s actually a loophole, but one of the dark patterns I’m seeing often is one-click unsubscribe generally only unsubscribes you from a very specific type of notification or topic of the mailing list, and you’ll still get other types of emails unless you fully log into your account and go in your email settings and unsubscribe from everything. Not sure exactly how Google and Yahoo treat those, but it feels kind of like marketers found a loophole that seems to work for them.
- kragen 3y agoalso it violates longstanding security measures against malicious prank unsubscribes; it means that if you forward an email list message to someone else, they can unsubscribe you without your consent as a prank
- AlexandrB 3y agoAs far as pranks go, this is one where I'll probably thank the prankster instead of being annoyed. Even stuff I'm subscribed to intentionally, I can live without if it went away.
- callalex 3y agoIs this a real problem in your life?
- rstuart4133 3y ago> it means that if you forward an email list message to someone else, they can unsubscribe you without your consent as a prank Surely that is a bug in the email client that forwarded the email. It should have replaced the headers, including List-Unsubscribe, with its own. That looks to be what's happened in the emails I receive. The one exception would be if someone forwarded an email as an attachment, but in practice almost no one does that.
- kragen 3y agowhat does your user interface for interacting with the list-unsubscribe header look like?
- SpaghettiCthulu 3y agoIdeally a big green "Unsubscribe" button. Make it promise cookies too for good measure.
- rstuart4133 3y agoI haven't unsubscribed from a list in years, perhaps decades, despite being subscribed to a few. So I can only tell you from memory. In Thunderbird, I believe I've see a "List Unsubscribe" button in the list of actions available, alongside "Reply-All", "Edit as New" and so on. In GMail I believe senders that have this implemented now have a big blue UNSUBSCRIBE button next to their email address at the top of the message. Neither appear if the headers aren't there.
- pests 3y agoI've seen a perverse dark pattern on one click unsubscribe. The page you land at has a button that lets you resubscribe! It looks non-obvious you've already unsubscribed and it looks like the regular two-click flow needing to enter your email address to confirm. Very sneaky.
- buttocks 3y agoWorse, the unsubscribe link is behind a tracker url so pi-hole blocks it. Drives me nuts.
- boplicity 3y ago> I've seen a perverse dark pattern on one click unsubscribe. The new requirement specifically sidesteps this, by making it possible for the email client to send a POST request directly. No need to visit the website at all; just click a button in the email client. In Gmail, senders that have this implemented now have a big blue UNSUBSCRIBE button next to their email address at the top of the message.
- classified 3y agoIt could have been that you clicked that tiny, greyed-out, hidden unsubscribe link by accident.
- dotancohen 3y agoOr forwarded the mail to 256 of your closest friends and one of them clicked the unsubscribe link.
- mullingitover 3y agoIf unsubscribing requires even two clicks I always flag it as spam. The rule is one-click to unsubscribe and I ruthlessly enforce it. Make it their problem.
- hospitalJail 3y agoHuh, I am an individual who is a scientist, not a web dev. I paid some company to do my email. I email 3 times per year and get 'spam' warnings from AWS every time despite everyone subscribing through a: "SUBSCRIBE TO OUR NEWSLETTER" No bait, just an email field and submit. I wonder if its your type that makes it so I have to be Amazon for forgiveness. Or at least that is how it used to be, now I sell addicting clicking casino games. No emails needed. I make way more money than back when I was giving away free content via email.
- atesti 3y agoI have seen Outlook and other systems click on every link in our mailings. Using a sandboxed browser. How can one click unsubscribe work here? Mail scanners, virus scanners and even Microsoft's own spam filters would probably click these links!
- zie 3y agoThe unsubscribe links are POST, not GET's. That's basically the entire safety net.
- atesti 3y agoReally? I have not seen a <form> html element in an email in decades! Do you mean a list-unsubscribe header? I mean the hyperlink at the end of an email with "unsubscribe". I think it would be good if that unsubscribe link opens a page where one would need to press one more button to prove that it is not automatically involved by url scanners. But this would not be "one click" unsubscribe anymore. So how can this be solved? Why is not everybody constantly auto-unsubscribed who uses office 365 or hotmail?
- zie 3y agoI was talking about https://datatracker.ietf.org/doc/html/rfc8058 https://datatracker.ietf.org/doc/html/rfc8058. Where the URL is in the headers as List-Unsubscribe: <URL> A 2 page overview is here: https://certified-senders.org/wp-content/uploads/2017/07/CSA_one-click_list-unsubscribe.pdf https://certified-senders.org/wp-content/uploads/2017/07/CSA...