33 ms·
Most of the Amazon SES IP blacklisted by SpamCannibal
- belorn 12y agoBlacklists are general a very effective method in handling spam, but its kind of dangerous to use in a commercial setting. A few weeks ago SpamCop blocked gmail for a few days, causing some "mild" issues for companies that depend on email. There is sadly not much options. Either I can accept more spam, or use blacklist and put the control of the filtering in the hands of a third-party with none of the responsibility attached.
- austerity 12y agoIP blacklists are a waste of everyone's time.
- mike-cardwell 12y agoIP blacklists are the reason Email still works.
- __david__ 12y agoFor lazy sysadmins, maybe. I don't use any blacklists, only spamassassin and the spam for me and my users is perfectly manageable.
- mike-cardwell 12y agoHate to break it to you, but SpamAssassin uses blacklists.
- __david__ 12y agoIt doesn't use them to insta-spam an email, which I think is where blacklists go wrong. It gives spam points to the message if the sender is on the lists, which turns them from "blacklists" into "suspicious lists". If an otherwise normal email happens to come from a blacklisted computer, it'll still have a chance to get through, which is the correct thing to do, in my opinion. I still believe that everyone has the right to run their own SMTP server, and I dislike that so many places blacklist someone just because they are on a cable modem.
- fixermark 12y agoPossibly, but if Amazon isn't doing enough to secure SES against abuse by spammers(1), it's not unfair for entities intended to guard against spam to treat it as a spam source. This is one of the risks of letting third-parties run software on one's systems. (1) keeping in mind that the definitions of "spam" can be quite subjective
- cpncrunch 12y agoAmazon SES definitely does have a spam problem, and the issue is that they don't bother doing anything about abuse reports. I've reported a spammer (who scraped our email address) to them, but the spams kept coming. Other people have reported the same thing. If you're running a bulk mailing server you simply must respond to abuse reports, otherwise your service will get blacklisted and be essentially useless. Other providers such as mailchimp are much more proactive about getting rid of spammers.
- lazyant 12y agoNot my time and my clients'. By appending in the Posfix configuration file line smtpd_recipient_restrictions = ... spamcop and spamhaus , spam decreases in like 95% without even touching your server further (spamassassin I'm looking at you). I you add greylisting you get rid virtually of all of spam.
- deleted 12y ago[deleted]
- giulianob 12y agoYes but if everyone using SES is getting blacklisted then you will also have a lot of legit emails being blocked.
- lazyant 12y agoCorrect, and the onus is on Amazon to tighten up and crack down on abusers.
- dataminded 12y agoOr Amazon might take a closer look at who is using SES and clean up the system. I'm all for cleaning up email.
- eli 12y agoHow much good mail gets mistakenly canned? I'd rather sift through a little spam than lose something I wanted.
- ScottWhigham 12y agoI think we'd all rather "sift through a little spam than lose something I wanted" but my guess is that you've never run an email server. "a little spam" is not what you will get - it will be orders of magnitude more spam than legit emails. This is hard stuff - Gmail, supposedly one of the best, catches between 2 and 10 emails a day in my "Spam" folder that aren't actually spam. If I were to turn off the spam filter (if you could) in Gmail, I'd get 2,000 emails a day - of which 50 would be legit.
- ScottWhigham 12y agoThis sort of vague comment with no substance is just opinion stated as fact. If you have more information - hell, even a more expressed opinion, I'd be interested. As expressed, however, it's a garbage comment that waste's everyone's time. Why bother?
- pconf 12y ago>This sort of vague comment Not sure about "vague comment"s but anyone who has run an email server, used an rbl/rhsbl, and followed the logs <http://www.postconf.com/docs/spamrep/> http://www.postconf.com/docs/spamrep/> would say the same. Having done so for years and run reports on dozens of servers daily it is clear that blacklists are the most effective form of spam blocking, by at least an order of magnitude.
- ScottWhigham 12y agoI can't tell whether you agree with the OP or with my comment. Your first sentence argues that OP is right - "IP blacklists are a waste of everyone's time". Your second sentence though is "it is clear that blacklists are the most effective form of spam blocking, by at least an order of magnitude." Maybe a typo in your reply?
- pconf 12y ago> Maybe a typo Could be a bug in your web browser. The first sentence is a quote as indicated by the ">" character at the beginning of the line.
- ScottWhigham 12y agoCould be a bug in your web browser. I got that part, I'm talking about your first sentence. ... anyone who has run an email server... would say the same. This reads as though you agree that "IP blacklists are a waste of everyone's time" as OP said. And maybe you do (and that's fine) - I'm just unclear given your second sentence.
- kordless 12y ago> The SES team knows about the spam cannibal listings and is in contact with them, they say it's unlikely your open rate drop from 25% to 0.15% is caused by the SC listing. SpamCannibal can cause the originating mail server to get caught in a 'tarpit' by slowing it down. Given the AWS CUSTOMER was sending a significant amount of measurable email to a given destination server (which was running SpamCannibal) it's possible the sending servers are being slowed down. In that particular scenario, that would affect open rate over a short period of time.
- sjwright 12y agoLet people run rampant on your IP range, and this is what happens. I run a fairly large website, and I block all traffic from the likes of Amazon AWS because it's full of dodgy bastards who think they're entitled to run however many HTTP requests they like. Webmasters, look at your web logs. Don't be surprised if the majority of hits are coming from bots pretending to be web browsers.
- guac 12y agoSES uses different IP ranges than those used by EC2.
- sp332 12y agoIt's the same idea though. Web sites might block crawlers in EC2, and mail servers might block emails from SES.
- billyhoffman 12y agoOur company offers a frontend web performance scanning SaaS product. We use EC2 for our scanning boxes. I've found many of our customers's website filter EC2 IPs. Its mainly from websites that offer a high demand product with a large secondary market. (think ticket websites for concerts/musicals/plays, airlines, hotels, etc).
- bowlofpetunias 12y agoI'm surprised you're pointing the finger at AWS. As far as I can tell, 90% of all that crap still comes from the shitty cheap home user ISP networks and el-cheapo web-hosting services. Never seen much bot traffic from AWS. (The bot that is currently pissing me off is Netcraft. The practice of just "guessing" domains and then firing http-requests at them is annoying.)
- _asciiker_ 12y agoI have been managing email servers for over 10 years, and it has gotten to the point that I feel like blocking some of the most common ISPs. Seriously. I am following all the best practises, hell, I even advocate them. It is just that these days it seems not to matter if you have SPF, Sender ID, DomainKey and DKIM, PTR, proper MX and even a normal to good IP reputation. There is still no guarantee what you will be able to reach the inbox of the likes of Gmail, Yahoo, Hotmail, etc. I have been filling out huge forms for each and every major ISP for the past year because one or two users mark a newsletter as SPAM. Conclusion: There is no common standard because every major ISP can set their own standards. This will eventually force everyone to use the same services worldwide. Where's the freedom of choice here?
- dminor 12y agoYeah, we just completed a switch to MailChimp after years of sending out our email ourselves. It's just too much hassle now for a smaller organization.
- kaoD 12y ago> one or two users mark a newsletter as SPAM. I'm one of them. Those newsletters are spam. I would never sign up for a newsletter and somehow I'm getting those too. If my intent was not to get the newsletter, it's unsolicited mail by definition, i.e. spam. Stop spamming me and I'll stop flagging you. Period. How not to be flagged as spam: - There should be a checkbox clearly visible and it shouldn't be pre-checked. - Your "kind" product reminders are obnoxious too and I'll flag them as spam as well. Did I ask you to remind me of your product? Nope. Unsolicited then. - If you ToS say I agree to receive mail, guess what? I don't agree, I just want to try your product. I'll flag you in a breeze. - Social reminders like Twitter's trending around me or people I might know? SPAM! I don't care if I can disable these, I didn't enable them. - You want to offer me discounts but I didn't ask for them? Flagged! - I submitted a paper to a conference and it got published? Dozens of "calls for papers" in my inbox. Flagged, flagged, flagged, flagged! - Calling it a newsletter or adding a tiny "unsubscribe" link won't hide the fact that it's still spam. I didn't click subscribe, I shouldn't have to unsubscribe. -- EDIT: Woah, this seems controversial. Lots of up- and down-votes. Dear product owners, downvoting me here won't change the fact that me (and your fellow users) will still flag the shit out of your unsolicited mail. I guess it pays if you keep doing it, but you should direct your energy far from that downvote button and closer to "ways not to annoy my users".
- ANTSANTS 12y agoIf you were to remake email from the ground up, how would you solve the spam problem while keeping it as decentralized of a system as it is now?
- dredmorbius 12y agoEngineering in a lot of reputation management and metrics would help. There are some interesting (I'm not sure "compelling" or "strong" is necessarily the case) arguments to be made for enabling open relays and other forms of unauthenticated messaging. John Gilmore of EFF has fought that battle for a long time, and still runs an open relay on toad.com. Signing and authentication measures (particularly on header data) have to be both standard and quick to process. Methods which increase the costs of delivery -- pacing receipt rates from a given IP or block, can help. Being able to specify receipt priorities: high for IPs and ranges with which frequent legitimate business is transacted, very slow for most others, would also be useful. Along with a lot of built-in support for this. Killing :80 and moving to entirely secured ports wouldn't be a bad move either.
- phunehehe0 12y agoMaybe you mean 25 or something else? Port 80 is for HTTP. And what does a secure port mean? If you want people to be able to talk through a port you have to open it. The number doesn't matter.
- dredmorbius 12y agoDoh! Yes. :25. By "secure port", I mean forcing encryption of all over-the-wire traffic. It's happening now in many cases with STARTTLS (modulo utter brokenness of the CA and SSL/TLS systems), but that's still only opportunistic. And of course, encrypting payloads would be vastly preferable. Headers as well other than absolutely required for delivery.
- gabemart 12y agoAny such discussion will be well informed by https://craphound.com/spamsolutions.txt https://craphound.com/spamsolutions.txt
- leccine 12y agoI believe in IP blacklisting. Why should my business be open to countries like North-Korea or Somali if I don't have anything to do with those? Spam comes from everywhere, but you can get rid of at least 50% by simply dropping traffic from certain countries, so the expensive score based spam filtering get cheaper. Unfortunately Amazon SES is the victim of cyber warfare and spammers.
- jzwinck 12y agoThis sort of logic will hurt you with customers who are US persons living overseas. I cannot tell you how annoying it is when as a US citizen and taxpayer I am blocked from using US services because I am not physically in the US. In 2014, where we plug our computers in does not define who we are. Geolocation is not authentication.
- leccine 12y agoIt is a trade off. You can purchase a cheap VPN service from thousands of VPN providers and get routed through a US IP. For you, who wants to fill the tax return it is worth it, for those who want to spam the sh*t out of other companies it is not worth it. I think this system works perfectly...
- MichaelGG 12y agoNot even just that, but where they ignore your Accept-Language and just make up a decision on what language you should be using. Google has no way to fully switch languages - even after going to Google.com and setting English, you'll see images have tooltips in your "local" language. Google's Play app does the same thing for a bit of their content. Certain headers get localized, despite everything else in the app being English. Netflix has the same problem, and then to further add insult, they send you to non-English phone numbers for support. The most annoying thing is that someone probably got a raise for these "features".
- frik 12y agoYou can use http://www.google.com/ncr http://www.google.com/ncr https://support.google.com/websearch/answer/873?hl=en https://support.google.com/websearch/answer/873?hl=en
- adarsh_thampy 12y agoI had had the same issue with amazon SES. While Spamhaus PBL is not necessarily a blocklist, due to the default configuration error, all the emails we send out (from other providers like mailchimp) ended up in spam. Finally, the issue got fixed by configuring reverse PTR.
- mrsaint 12y agobl.spamcannibal.org is notorious for a higher error rate (false positives). It'd be crazy if a popular mail service provider like Yahoo categorized incoming mail based on results from Spam Cannibal. If I added them to my MTA, I'd rank them fairly slow to diminish the effect of their false positives. See here: http://dnsbl.inps.de/analyse.cgi?type=monthly&lang=en http://dnsbl.inps.de/analyse.cgi?type=monthly&lang=en And see here how to add them to your checks (and rank them accordingly) if you're using Postfix: http://www.postfix.org/POSTSCREEN_README.html http://www.postfix.org/POSTSCREEN_README.html
- notacoward 12y agoI know there are legitimate uses for something like SES, but it has always seemed a bit like "Spam as a Service" to me. Ditto for every other service that's designed around mass email, no matter how much YC startups might depend on them to "improve their conversion rate" or whatever the buzzword is this week.
- cperciva 12y agoSpam as a Service I'd call it "Sender Reputation Checking as a Service". Where said service is paid for by the sender, but provided to the email recipient. Anyone can send email directly; but knowing that email has been sent through SES and Amazon hasn't killed the account yet provides a greater degree of trustworthiness. In a sense, it's like a bond rating service.
- notacoward 12y ago...and we all know how well the bond rating services performed their function. Sorry, couldn't resist. On a more serious note, it seems like the "greater degree of trustworthiness" is only very slightly greater. SES might be better than some server in a domain nobody ever heard of, but it's still not as good as a provider with a long history of responsible email use. Many people can and do block SES and its ilk, as is the subject of this story, because the aggregate amount of spam is so great even if the individual spammers are transient (like they care). Amazon could raise the bar, thus raising their own reputation and thus making the service more valuable to those who can still afford/qualify to use it. It's probably just not worth their while to do so. I'm not even criticizing them for that. I'm just observing that online business has a shady side, and Amazon isn't afraid to partake.
- lazylizard 12y agoare people not relaying their newsletters/unsolicited mails/spam thru some antispam outgoing smtp gateway if they're concerned about being blocked? filter it yourself before people filter u?
- mgkimsal 12y agoIt might help the situation more if webmail providers provided actual 'unsubscribe' or 'hide' links in their UI instead of 'spam' being the only feedback mechanism users are offered. "unsubscribe" links vary in position, language and visibility in various clients. Making something beyond "this is spam" part of most mail clients, perhaps with reporting back to the originating sender, would help.
- skymt 12y agoGmail has done this since 2009, though it depends on good behavior from the sender. http://gmailblog.blogspot.com/2009/07/unsubscribing-made-easy.html http://gmailblog.blogspot.com/2009/07/unsubscribing-made-eas...
- cones688 12y agoIt is also part of UK law for Marketing folk
- PythonicAlpha 12y agoProblem here is that particularly such "unsubscribe" links where used in the past (and still are, I guess) to reassure spammers that somebody is there. Because one problem spammers have is the quality of the addresses they have. Many spammers use lists from dubious sources and a big number of addresses are invalid. So, if they get an "unsubscribe", they know which addresses are better and can deliver more spam to it ... So many don't dare to use such links and rather click on spam. The only solution could be some "trusted" functionality that goes via the own mail provider of the receiver. But of course the mail provider can not simply send information to the sender of the eMail .... So the thing gets complicated. As much I learned, for spam clicks there is something like that available ... some kind of trusted feedback chain that gives information to trusted senders, that some mails where labeled as spam. Thus those senders can (indirectly) adopt their eMail campaigns.
- __david__ 12y ago> Many spammers use lists from dubious sources and a big number of addresses are invalid. So, if they get an "unsubscribe", they know which addresses are better and can deliver more spam to it ... That's only true of the dubious "viagra" style spam, where they got your name from a list. I don't think those even bother with "unsubscribe" links any more. I only see unsubscribe links from places where I've had to give my email up to buy something or sign up to a site. Those are generally legit and most of the techy/startup web sites will unsubscribe you immediately. The next tier are the sites that unsubscribe you but take more than a week and will keep spamming their dumb newsletter in the meantime. The final ones are either broken by stupidity (it's amazing how many web developers cannot grasp that "+" is a legit email character), or willfulness and will keep spamming no matter what. I block these at the SMTP level with 503 messages (usually containing some personal insults and swearing) as soon as they "RCPT TO" the unique email address I gave them.
- driverdan 12y agoConsidering Amazon themselves send spam this isn't surprising. They like to send out product spam under the guise of account notifications with no opt-out. The only way to remove yourself is to close your account. At the very least they do this to affiliates and to Student Prime members.