Spam blacklisting is out of control(blog.roastidio.us)
blog.roastidio.us
Spam blacklisting is out of control
https://blog.roastidio.us/posts/spam_blacklists_are_out_of_control/
415 comments
I'm dealing with this right now.
Both my personal domain and rsync.net are on a distinct subnet, but that subnet is smaller than a /24 and someone on a different subnet has, apparently, behaved badly.
Enter "abusix" ...
One of my engineers had an enlightening webchat with one of their engineers where we were shown the "offending" IP and it was explained that they have no ability to distinguish subnets (and no interest in doing so). So if you're not wasting an entire /24 (we only need ~10 IPs at this location) you're in danger of this misclassification.
We were also informed that our normal, business communications with paying customers should have unsubscribe notices appended to them. Which is to say, you're a paying customer of a service and we send you some kind of alert or critical announcement ... and it should have an unsubscribe link.
Unbelievable.
Both my personal domain and rsync.net are on a distinct subnet, but that subnet is smaller than a /24 and someone on a different subnet has, apparently, behaved badly.
Enter "abusix" ...
One of my engineers had an enlightening webchat with one of their engineers where we were shown the "offending" IP and it was explained that they have no ability to distinguish subnets (and no interest in doing so). So if you're not wasting an entire /24 (we only need ~10 IPs at this location) you're in danger of this misclassification.
We were also informed that our normal, business communications with paying customers should have unsubscribe notices appended to them. Which is to say, you're a paying customer of a service and we send you some kind of alert or critical announcement ... and it should have an unsubscribe link.
Unbelievable.
Spam blocklists are run by an unaccountable cowboy cult that somehow has managed to consolidate a ton of power simply for the fact that most people who run email inbox services didn't want to deal with the problem of spam, so they were more than willing to just hand over anti-spam "enforcement" to anyone who was allegedly doing "what was best for the internet." There's no check on these people who run these blacklists, and the system they've built is entirely a black box, antithetical to the principles of the open internet. And if you're not a huge corporation that can afford professional management of your email deliverability, good luck – the individuals and small organizations are just out of luck. It's a miserable racket and for what?
If you want to know why there's a new thread each week on HN about why it's impossible to host your own email service, this is why.
If you want to know why there's a new thread each week on HN about why it's impossible to host your own email service, this is why.
> Or I can leave the current hosting company
Yep, that's the one.
If your hoster doesn't care about spam spreading from their IP space, you should take your mail server elsewhere. There's literally nothing to think about.
And if they do care about this issue, they are likely to be taking steps to remove any of their IP space from the blacklists, without being nudged.
PS.
I've been running a mail server for close to 20 years now and I do blacklist by /24 netblock on the second offense. This doesn't bounce emails though, just tags them as spam. So I had a quick look in the logs and Hetzner, Digital Ocean, OVH and LeaseWeb are all spamming a lot. LayerHost, Colo Crossing, Liquid Web, Host Winds and Servion are also close to the top. Anecdotal data, obviously, so caveat emptor and all that.
Yep, that's the one.
If your hoster doesn't care about spam spreading from their IP space, you should take your mail server elsewhere. There's literally nothing to think about.
And if they do care about this issue, they are likely to be taking steps to remove any of their IP space from the blacklists, without being nudged.
PS.
I've been running a mail server for close to 20 years now and I do blacklist by /24 netblock on the second offense. This doesn't bounce emails though, just tags them as spam. So I had a quick look in the logs and Hetzner, Digital Ocean, OVH and LeaseWeb are all spamming a lot. LayerHost, Colo Crossing, Liquid Web, Host Winds and Servion are also close to the top. Anecdotal data, obviously, so caveat emptor and all that.
If you start a new mail server in 2022 (or migrate from a previous address), you have to apply to be whitelisted by outlook.com and the many domains owned by Microsoft. They no longer accept mail from servers they haven't seen before. Companies such as google, microsoft, and facebook would rather that email died, and are actively working to destroy it through neglect, so that people will shift their messaging to proprietary networks they happen to own. Email has problems - spam being one of them, but it's as potentially important as IP routing itself, and we should work to preserve it.
Fortunately for the author, I haven’t noticed any email servers that use the UCEPROTECTL3 RBLs to reject mail—which is to say, I’ve noticed some servers I administer end up on UCEPROTECTL3 incidentally and it has never caused a delivery problem.
On the other hand, some VPS providers are still allocating multiple customers to the same IPv6 /64 using SLAAC by default, and this will make it impossible to deliver mail on IPv6 since reputable RBLs always blacklist the whole /64.
As far as the argument about spamming being immoral but not illegal, I’ve never seen a reputable ISP that didn’t prohibit unsolicited bulk email in their terms of use, so the grounds for reporting it is that a customer is violating the terms that they agreed to follow when they signed up.
And to answer the question of whether or not RBLs are useful: in my experience, yes, they are quite useful. The biggest problem I’ve noticed with them is not typically false positives on small providers, but false negatives on giant companies like Google who cannot ever end up on an RBL because they process so much mail but don’t do a good enough job of preventing their servers from being used to send spam.
On the other hand, some VPS providers are still allocating multiple customers to the same IPv6 /64 using SLAAC by default, and this will make it impossible to deliver mail on IPv6 since reputable RBLs always blacklist the whole /64.
As far as the argument about spamming being immoral but not illegal, I’ve never seen a reputable ISP that didn’t prohibit unsolicited bulk email in their terms of use, so the grounds for reporting it is that a customer is violating the terms that they agreed to follow when they signed up.
And to answer the question of whether or not RBLs are useful: in my experience, yes, they are quite useful. The biggest problem I’ve noticed with them is not typically false positives on small providers, but false negatives on giant companies like Google who cannot ever end up on an RBL because they process so much mail but don’t do a good enough job of preventing their servers from being used to send spam.
UCEPROTECT is a scam. Blocking innocent people and asking them for money has nothing to do with security.
The good thing is that most email servers do not use it because it's just bad.
The bad thing is that Hotmail uses it (or at least was at until recently). It does mean that, as a Hotmail user, there's legitimate email that you won't receive.
I do wonder if the guy behinf this scam is randomly blocking whole ip ranges to make a living, having enough people agreeing to the racket.
I do wonder if the guy behinf this scam is randomly blocking whole ip ranges to make a living, having enough people agreeing to the racket.
This has literally just recently (re-)become an issue for me because after a good year or so of not being blocked, several emails from my server started getting filtered as spam by both Google and then just being outright blocked by both Google and Microsoft. When I got through Microsoft's steps to unblock, after several days and steps, they send me the message that actually my IP is not blocked.
Google's recent message was more helpful - apparently forwarding emails from the accounts I setup for my kids to my wife's Gmail account triggered some obscure rule that ruined my server's reputation with Google, and I think Google & Microsoft collaborate because the issues cropped up within a week of each other.
The interesting thing was I discovered the Outlook issue by trying to reply to an email sent from an Outlook customer. Yes, my reply to an Outlook customer's email to me was blocked because of my server's reputation.
To be clear, I run no mailing lists nor solicit any business with my email server. I use it for personal use only and my consulting work which involves know contacts. The forwarding I spoke of before is solely to our own personal accounts.
I use Mail-In-A-Box, for what it's worth, on a Linode VPS.
Google's recent message was more helpful - apparently forwarding emails from the accounts I setup for my kids to my wife's Gmail account triggered some obscure rule that ruined my server's reputation with Google, and I think Google & Microsoft collaborate because the issues cropped up within a week of each other.
The interesting thing was I discovered the Outlook issue by trying to reply to an email sent from an Outlook customer. Yes, my reply to an Outlook customer's email to me was blocked because of my server's reputation.
To be clear, I run no mailing lists nor solicit any business with my email server. I use it for personal use only and my consulting work which involves know contacts. The forwarding I spoke of before is solely to our own personal accounts.
I use Mail-In-A-Box, for what it's worth, on a Linode VPS.
RBLs are useful, but there are a few that are not what they appear to be. The particular one in question, UCEPROTECT is
a) not worth paying
b) should never be used by a production mailserver to block messages.
From the beginning there have been enterprising RBLs that are clearly overbroad, and offer to accept money. The money is not for getting off the list, it is always for something else so as to appear legitimate and a side effect is getting your domain off the list. This model is unethical at best, and is right up there with companies that snail mail over-priced domain renewal notices.
a) not worth paying
b) should never be used by a production mailserver to block messages.
From the beginning there have been enterprising RBLs that are clearly overbroad, and offer to accept money. The money is not for getting off the list, it is always for something else so as to appear legitimate and a side effect is getting your domain off the list. This model is unethical at best, and is right up there with companies that snail mail over-priced domain renewal notices.
My personal experience with UCEPROTECT was that they had blacklisted 2 or 3 IPs in my /24 that were not routed to anything, nor had they ever been routed to anything, a fresh new block from RIPE NCC too.
Of course they offered to unblacklist them in exchange for payment, or wait.
Waited 2 weeks and they dropped off. I've yet to hear about anyone using their DNSBL for anything serious in 2020/2021/2022
I only knew about the listings because a monitoring service emailed me about it.
Of course they offered to unblacklist them in exchange for payment, or wait.
Waited 2 weeks and they dropped off. I've yet to hear about anyone using their DNSBL for anything serious in 2020/2021/2022
I only knew about the listings because a monitoring service emailed me about it.
> I can complain to my hosting company and hope they evict the bad user from the network. But then why should my hosting company do so?
The answer to this is the other option, leaving the hosting company. In this manner, every hosting company gets a choice - either they will kick out legal-but-immoral things like spammers, or they will not and rightly lose their above-board customers.
This is essentially how the global e-mail community self-polices by establishing a norm that a host either has to work to exclude bad actors or will get boycotted/excluded for allowing them.
The answer to this is the other option, leaving the hosting company. In this manner, every hosting company gets a choice - either they will kick out legal-but-immoral things like spammers, or they will not and rightly lose their above-board customers.
This is essentially how the global e-mail community self-polices by establishing a norm that a host either has to work to exclude bad actors or will get boycotted/excluded for allowing them.
This is a complaint about "UCEPROTECT Blacklist Policy LEVEL 3" [0]
It's description is not subtle:
> This blacklist has been created for HARDLINERS. It can, and probably will cause collateral damage to innocent users when used to block email.
So if the mailsystem you are trying to reach employs it, is either experiencing spam levels that justify it's use - OR they made a mistake in using it, if this is the sole reason you are being banned.
The first order of business is of course to complain to your hosting provider. Nobody wants spammers on their networks - but if they do: then this is kind of exactly the reason for this list. The policy describes in detail what made it possible for this netblock to end up on the list, that should be enough for them to take action either pre-emptively or by notifying their offending customer, and if neccessary kicking them off the network.
The next thing you can do, instead of paying for whitelisting, ist to contact the mailserver-admin at system you are trying to deliver mail to. This can be a bit of a hassle - seeing that your mailserver just got blocked - but it usually works. The same way systems don't want to receive SPAM they also don't want to overblock, after all they want their users to receive emails as well. If you are the mail admin of a sending system and you're reaching out to the receiving system this is usually a pretty good indicator that you don't want to spam them.
I have had success doing this even at some larger ISPs, where you would expect this to be more difficult.
I very much enjoy these blocklists - simple, transparent. Loads better than the kafkaesk black holes that are the major mail providers who barely care, and who do not give you easy recourse if you are mistakenly blocked.
[0] https://www.uceprotect.net/en/index.php?m=3&s=5
It's description is not subtle:
> This blacklist has been created for HARDLINERS. It can, and probably will cause collateral damage to innocent users when used to block email.
So if the mailsystem you are trying to reach employs it, is either experiencing spam levels that justify it's use - OR they made a mistake in using it, if this is the sole reason you are being banned.
The first order of business is of course to complain to your hosting provider. Nobody wants spammers on their networks - but if they do: then this is kind of exactly the reason for this list. The policy describes in detail what made it possible for this netblock to end up on the list, that should be enough for them to take action either pre-emptively or by notifying their offending customer, and if neccessary kicking them off the network.
The next thing you can do, instead of paying for whitelisting, ist to contact the mailserver-admin at system you are trying to deliver mail to. This can be a bit of a hassle - seeing that your mailserver just got blocked - but it usually works. The same way systems don't want to receive SPAM they also don't want to overblock, after all they want their users to receive emails as well. If you are the mail admin of a sending system and you're reaching out to the receiving system this is usually a pretty good indicator that you don't want to spam them.
I have had success doing this even at some larger ISPs, where you would expect this to be more difficult.
I very much enjoy these blocklists - simple, transparent. Loads better than the kafkaesk black holes that are the major mail providers who barely care, and who do not give you easy recourse if you are mistakenly blocked.
[0] https://www.uceprotect.net/en/index.php?m=3&s=5
> My hosting company is competitively priced, is fast, and has served me well for many years.
... attributes which they achieve by (1) selling services to anyone and anyone and (2) not dedicating any resources to fighting spam.
So you got what you pay for.
... attributes which they achieve by (1) selling services to anyone and anyone and (2) not dedicating any resources to fighting spam.
So you got what you pay for.
The author has some oversimplifications which would be worth addressing.
First, there actually does exist a strata of spam which is plainly illegal. All the phishing spam and all the messages that claim to be from networks and/or addresses that they are not, for example, are illegal. The problem is that it's not enforceable.
Second, sending unsolicited messages when you do not have the permission of the sender is unambiguously wrong. Large sources of spam get around this by mixing bad messages in with good ones. This is why we get tons and tons of spam from Gmail, from Outlook.com, from Sendgrid, and so on, even though they really should know better.
The point is that your "bad neighborhood" doesn't just have regular spammers - it's almost certain there are illegal and egregious spammers that your ISP is doing nothing about. How do we know this to be the case? Because many of the blocklists also run honeypot email addresses. If email addresses get harvested and someone sends spam to these addresses, you can be 100% certain that no permission was ever given, so the behavior that leads to this is definitely wrong.
ISPs make too much money to punish anyone but the worst of their clients, and that's definitely a factor that contributes to the affordability of the author's ISP.
However, the author left out one big, simple, obvious option: pay significantly less money than the cost of the blocklist extortion to smarthost through an ISP that has good email reputation. You get what you pay for, so when you save on your ISP, don't be surprised if you have to pay a little more to make up for their shortcomings.
First, there actually does exist a strata of spam which is plainly illegal. All the phishing spam and all the messages that claim to be from networks and/or addresses that they are not, for example, are illegal. The problem is that it's not enforceable.
Second, sending unsolicited messages when you do not have the permission of the sender is unambiguously wrong. Large sources of spam get around this by mixing bad messages in with good ones. This is why we get tons and tons of spam from Gmail, from Outlook.com, from Sendgrid, and so on, even though they really should know better.
The point is that your "bad neighborhood" doesn't just have regular spammers - it's almost certain there are illegal and egregious spammers that your ISP is doing nothing about. How do we know this to be the case? Because many of the blocklists also run honeypot email addresses. If email addresses get harvested and someone sends spam to these addresses, you can be 100% certain that no permission was ever given, so the behavior that leads to this is definitely wrong.
ISPs make too much money to punish anyone but the worst of their clients, and that's definitely a factor that contributes to the affordability of the author's ISP.
However, the author left out one big, simple, obvious option: pay significantly less money than the cost of the blocklist extortion to smarthost through an ISP that has good email reputation. You get what you pay for, so when you save on your ISP, don't be surprised if you have to pay a little more to make up for their shortcomings.
There is a typo in their title. If intentional please instead consider words like block reject and deny for the people that do not speak English as a first language.
I've dealt with real time blocklists as long as they have existed. They are not going away any time soon. I agree that the paid exception lists are a bit shady but I also see the validity of their methods of temporarily punishing everyone on a hosts network to put pressure on the ISP/platform provider to police it's own network and remove spammers. The best one can do today aside from securing ones own server is to research an ISP's IP space ahead of time to see how dirty they are. There are plenty of providers that cleaned up their act some time ago. Linode is a great example of change. New accounts can't even send email unless they open a ticket and prove they made some effort to comply with can-spam. More providers need to follow that example so that we don't run into this problem of dirty networks that real time block-lists like UceProtect have listed. It's an imperfect solution to an old ugly problem.
I've dealt with real time blocklists as long as they have existed. They are not going away any time soon. I agree that the paid exception lists are a bit shady but I also see the validity of their methods of temporarily punishing everyone on a hosts network to put pressure on the ISP/platform provider to police it's own network and remove spammers. The best one can do today aside from securing ones own server is to research an ISP's IP space ahead of time to see how dirty they are. There are plenty of providers that cleaned up their act some time ago. Linode is a great example of change. New accounts can't even send email unless they open a ticket and prove they made some effort to comply with can-spam. More providers need to follow that example so that we don't run into this problem of dirty networks that real time block-lists like UceProtect have listed. It's an imperfect solution to an old ugly problem.
I guess another option is to sue the blacklist operator for inappropriately including him. Or sending some legal sounding letter threatening suit.
I found some old lawsuits [0] that got injunctions and even damages awarded from being included in black lists.
I hate how the big tech customer nonsupport is bleeding into small firms attitude. “Sorry, you did nothing wrong but might one day so get fucked.” is really not something that should happen very much.
[0] https://www.techdirt.com/articles/20051228/1349229.shtml
I found some old lawsuits [0] that got injunctions and even damages awarded from being included in black lists.
I hate how the big tech customer nonsupport is bleeding into small firms attitude. “Sorry, you did nothing wrong but might one day so get fucked.” is really not something that should happen very much.
[0] https://www.techdirt.com/articles/20051228/1349229.shtml
What would be nice is if there could be whitelists as well, or a blacklist that additionally keeps count of positive interactions.
I've had an IP for about a decade that never once sent spam, but has ended up on blacklists from time to time (hosting EICAR on a web server apparently gets your mail server banned, 15-year-old me found out). SPF nicely says that this IP is supposed to be sending email for this domain. I don't think I'm on blacklists anymore, but email still ends up in spam folders nine out of ten times. People are giving off signals that my messages aren't spam all the time (it's my personal email server).
Years of non-spam emails count for nothing whereas a single spam mail from an adjacent IP can get you on such a list. Somehow it's a bit imbalanced.
I've had an IP for about a decade that never once sent spam, but has ended up on blacklists from time to time (hosting EICAR on a web server apparently gets your mail server banned, 15-year-old me found out). SPF nicely says that this IP is supposed to be sending email for this domain. I don't think I'm on blacklists anymore, but email still ends up in spam folders nine out of ten times. People are giving off signals that my messages aren't spam all the time (it's my personal email server).
Years of non-spam emails count for nothing whereas a single spam mail from an adjacent IP can get you on such a list. Somehow it's a bit imbalanced.
Blacklisting an ISP's ASN or entire network range because the blacklist creator set an arbitrary threshold of acceptable number of spam activity from 1 or more IPs. I'm really not sure about the legal aspects here, but there are so many practices that blatantly approach extortion. And it's skillfully done in the name of "online etiquette" or a "safe internet".
Obviously, legitimate use-cases exist for such services, provided that they are operated faithfully by people/entities with some level of credibility.
Whether or not Spam is legal, many (or most) service providers list it as prohibited in their SLA (Service-Level Agreement). Depending on the type of setup they run--the clientele; company focus/prioritization of ROI--they forward complaints to the account owners, with the understanding that the activity must be stopped. Again, this depends on the service provider, especially as you start thinking on a more granular level. E.g. they can have automated systems handling much of this, or they may have employees handle the communications and provide help to their clients in thwarting such activity. Generally, though, the account owners need to balance the security with compatibility--or the uptime and short-term performance of their services.
Ultimately, however, some of these spam block-lists--UCEPROTECTL3 in particular--are blatantly using a sledge-hammer approach for little benefit to any of their users, in the hopes of spurring controversy; or fear that leads to customers; or outrage from customers toward the service providers. In the end, the intention is purely to get paid, either by clients who sign up for their service or by the internet service providers that can't wait multiple days or weeks until their network gets de-listed. Their accusatory and aggressive language conveys to people that they must be associated with either some amateur company or one that uses, and knowingly profits from, nefarious practices and shady characters if they somehow ended up on their list.
Depending on where you stand, it can be seen as deplorable or underhanded behavior maybe even rising to the level extortion, or it can be considered a shrewd business tactic.
Obviously, legitimate use-cases exist for such services, provided that they are operated faithfully by people/entities with some level of credibility.
Whether or not Spam is legal, many (or most) service providers list it as prohibited in their SLA (Service-Level Agreement). Depending on the type of setup they run--the clientele; company focus/prioritization of ROI--they forward complaints to the account owners, with the understanding that the activity must be stopped. Again, this depends on the service provider, especially as you start thinking on a more granular level. E.g. they can have automated systems handling much of this, or they may have employees handle the communications and provide help to their clients in thwarting such activity. Generally, though, the account owners need to balance the security with compatibility--or the uptime and short-term performance of their services.
Ultimately, however, some of these spam block-lists--UCEPROTECTL3 in particular--are blatantly using a sledge-hammer approach for little benefit to any of their users, in the hopes of spurring controversy; or fear that leads to customers; or outrage from customers toward the service providers. In the end, the intention is purely to get paid, either by clients who sign up for their service or by the internet service providers that can't wait multiple days or weeks until their network gets de-listed. Their accusatory and aggressive language conveys to people that they must be associated with either some amateur company or one that uses, and knowingly profits from, nefarious practices and shady characters if they somehow ended up on their list.
Depending on where you stand, it can be seen as deplorable or underhanded behavior maybe even rising to the level extortion, or it can be considered a shrewd business tactic.
I agree with your plea, and view the current blacklists as Mafia style "protection" (that also conveniently helps the big players maintain their monopoly).
Practically though, if you want to get your mail delivered, you should use Amazon SES or the like to send it - setup is really simple, and they have the clout to not be blacklisted EVEN THOUGH they are definitely being used to send spam. At $1 per 1,000 mails, it is unlikely you will even feel the cost.
(I commented on this a few weeks ago at https://news.ycombinator.com/item?id=29713030.)
Practically though, if you want to get your mail delivered, you should use Amazon SES or the like to send it - setup is really simple, and they have the clout to not be blacklisted EVEN THOUGH they are definitely being used to send spam. At $1 per 1,000 mails, it is unlikely you will even feel the cost.
(I commented on this a few weeks ago at https://news.ycombinator.com/item?id=29713030.)
I think many RBLs started out with good intentions. But it does feel like like many of them have shifted to pure grift. Pay for "priority" review definitely has negatively impacted this. UCEPROTECTL3 especially feels like an extortion attempt similar to the threatening domain renewal scams. But I've never notice any outgoing email from my services being blocked by it. So it just goes in the crank file.
Really we probably need some sort of anti-RBL system. To keep good actors honest and force bad actors out of business.
Really we probably need some sort of anti-RBL system. To keep good actors honest and force bad actors out of business.
If I were to design a replacement messanging system to replace email, I would design it with deny by default, where messages that aren't signed by someone on your contact list are rejected. Maybe with a system to request that someone add you to their contact list (though with a limit on how much text can be in that request).
Maybe something like that could be done with email, but without a culture around it, figuring out what addresses you need to add to your contact list when you add new services could be a pain.
Maybe something like that could be done with email, but without a culture around it, figuring out what addresses you need to add to your contact list when you add new services could be a pain.
F*k UCEPROTECT!
I got listed as well (layer 3 only), because there were more than 32 cases of spam in an ISP that maintains more than 4 /16 networks across the whole country. With the whole AS blocklisted, I fail to see the point of UCEPROTECT and agree with the OP that they are mere thieves.
On topic of protecting people, they have a trivial XSS right on the input field where one checks if their IP address is listed - yes, a GET variable is printed directly to HTML.
</rant>
I got listed as well (layer 3 only), because there were more than 32 cases of spam in an ISP that maintains more than 4 /16 networks across the whole country. With the whole AS blocklisted, I fail to see the point of UCEPROTECT and agree with the OP that they are mere thieves.
On topic of protecting people, they have a trivial XSS right on the input field where one checks if their IP address is listed - yes, a GET variable is printed directly to HTML.
</rant>
Email has basically been taken over by Microsoft and Google. They set the rules and decides who can is blacklisted. Although to me, email has become increasingly less relevant, to a point where I only check it once a week or so.
> If my understanding of the law is correct, spamming is legal, albeit immoral. If I were the hosting company, and I had a paying customer that is conducting legal business on my network, on what grounds can I evict them?
Hosting companies can kick customers off for basically any reason they want to. High-end hosting companies will absolutely kick a customer off if the customer’s activities result in spam blacklisting.
When I first signed with Rackspace, it took almost a week to negotiate their AUP (acceptable use policy). They were basically unwilling to give us any solid assurances about account suspension. They gave themselves enormous room to determine what was acceptable behavior on our part.
If you haven’t carefully read your host’s AUP, it might be enlightening. If your host doesn’t have an AUP, or doesn’t enforce it, then yeah maybe that is not the best neighborhood.
Hosting companies can kick customers off for basically any reason they want to. High-end hosting companies will absolutely kick a customer off if the customer’s activities result in spam blacklisting.
When I first signed with Rackspace, it took almost a week to negotiate their AUP (acceptable use policy). They were basically unwilling to give us any solid assurances about account suspension. They gave themselves enormous room to determine what was acceptable behavior on our part.
If you haven’t carefully read your host’s AUP, it might be enlightening. If your host doesn’t have an AUP, or doesn’t enforce it, then yeah maybe that is not the best neighborhood.
No one sane is using UCEPROTECT.. I would not even care. If someone is using them as blacklist(s) they have more problems than my mail not reaching them. Spamhaus/Spamcop/truncate.gbudb.net/Barracuda with some "premiums" like Abusix is all anyone should need
That UCEPROTECT racket is extortion, frankly. What a mess.
Any shared hosting provider is extremely susceptible to this type of issue and this type of list just doesn't work. It's a scam. There are lots of good blocklists, but there are also lots of bad ones like this.
When I worked with a company who ran email systems like this we'd always steer customers away from lists like this, in cases where we couldn't deliver mail because of it we blamed the other provider. This actually worked a lot of the time and the customer would wind up contacting the sender another way to let them know they had a problem, and fairly often they'd change lists.
Our standard messaging was something like, "Google and Microsoft are receiving our emails just fine, something is wrong with the receiving service"
When I worked with a company who ran email systems like this we'd always steer customers away from lists like this, in cases where we couldn't deliver mail because of it we blamed the other provider. This actually worked a lot of the time and the customer would wind up contacting the sender another way to let them know they had a problem, and fairly often they'd change lists.
Our standard messaging was something like, "Google and Microsoft are receiving our emails just fine, something is wrong with the receiving service"
Blame your ISP, or hosting provider. As an email admin, I deal every-single-day with phishing and malware that comes through email. There is not a single hosting company that does anything more than pass complaints onto the spammer - thus verifying that I'm a good target and causing even more of a problem.
While I do not use any blacklists, I do make my own. I've found that blocking individual IPs is useless, there is always another one. However, if I block the entire IP range I have much more success.
This is your hosting company's fault for allowing spamming and doing nothing about it.
While I do not use any blacklists, I do make my own. I've found that blocking individual IPs is useless, there is always another one. However, if I block the entire IP range I have much more success.
This is your hosting company's fault for allowing spamming and doing nothing about it.
The US federal government should tackle huge email account providers that effectively (by accident or design) use anti-spam as a pretext to sabotage self-hosted email.
I have been running my own mail server for two years on my private ISP and have less problems than expected - even with the dynamic IP address (in practice, it changes once in 6-12 months) and no PTR. I also switched the ISP once. I have SPF, DKIM, DMARC.
Edit: The nice thing about running the mail server personally and without a relay (like mailgun) is that mail is to-my-end encrypted. If the other party is running its own mail server, it could even be E2E encrypted. Considering the vast amount of personal information that going through email, this makes me feel good in terms of privacy.
I have never heard of UCEPROTECT and fortunately, I never had to deal with it. The language on the webpage somehow reminds me of Kryptochef...
A small inconvenience is that I had to unblock the IP on Spamhaus PBL every month. By now, it feels as if they know me, because I now only have to do this once if I get a new IP...
Many mail servers are nice and provide the reason for the block even with hints how to unblock it. I successfully unblocked it on Abusix and Microsoft. Never had an issue with Google.
GMX on the other hand will never accept my email because they require a proper PTR record. They are the only company I have come across and I find that scandalous.
Edit: The nice thing about running the mail server personally and without a relay (like mailgun) is that mail is to-my-end encrypted. If the other party is running its own mail server, it could even be E2E encrypted. Considering the vast amount of personal information that going through email, this makes me feel good in terms of privacy.
I have never heard of UCEPROTECT and fortunately, I never had to deal with it. The language on the webpage somehow reminds me of Kryptochef...
A small inconvenience is that I had to unblock the IP on Spamhaus PBL every month. By now, it feels as if they know me, because I now only have to do this once if I get a new IP...
Many mail servers are nice and provide the reason for the block even with hints how to unblock it. I successfully unblocked it on Abusix and Microsoft. Never had an issue with Google.
GMX on the other hand will never accept my email because they require a proper PTR record. They are the only company I have come across and I find that scandalous.
You can do everything possible, have a perfectly clean IP, have a good amount of outbound email traffic, only send transactional email, etc. Still, there will be edge cases where email does not go through. AT&T email servers would constantly blacklist me and not respond to requests to remove me, gmail/yahoo/outlook would silently put emails in the spam folder, and companies using email firewall products would blacklist me, with an IT Dept too inept to fix it.
The solution was to pay a small fee and proxy all outbound email through a transactional SMTP sender, like Postmark or Mailgun. It's easy to do, with one line of code in Postfix. You can be selective, and only proxy emails sent to certain troublesome domains. If you try an email provider and it's not working out, it's one line of code to change to another provider.
This allows me to still manage nearly all aspects of hosting my email server and control my email data, while not dealing with deliverability issues. I use Postmark and I have not dealt with a deliverability issue in two years.