The regulation is already there, mandating the telco routes 000 calls.
They failed and as a result people died.
What the parent poster probably means by rolling heads is, this should not just be a fine to the telco but literally people going to jail for the criminal negligence.
How else is there going to be change?
A money fine is just an operational expense that can be offset and "part of business if someone dies because of bad testing".
> It's currently our policy to not shut down free sites during traffic spikes that doesn't match attack patterns, but instead forgiving any bills from legitimate mistakes after the fact.
Well, giving the option to users to plan ahead would be best, no? Like a setting to choose whether they want a potentially unlimited bill versus downtime.
Instead of that, you are choosing to stress and make people scared/anxious/homeless even (if they don't think of raising the issue on HN).
Seriously, this is not rocket science. This must have been discussed before in your company, and someone actually made this decision to stress people about such bills.
Regarding spam I recently found out this: https://heluna.com/ but haven't tried it yet.
Basically you set your MX to heluna and tell them which server to send the clean email to (and charge your for it....)