Ironically, the problem of spam has created another weird problem. I'm not sure what's the right kind of thing to describe them, so I'll call them the ambulance chasers of the email world. But that doesn't sound right. Some kind of leech, patent troll, and mafia rolled into one?
Last week, one of my organization's user email accounts was hacked. It started getting used to send out spam. We caught it pretty quickly and updated the password so that the spammers couldn't use it anymore. But it was too late, we got listed on several spam blacklists. As such, all emails from our mail server started going into recipient mailbox spam folders. OK, we just get ourselves off of the spam blacklists, right?
Most of the spam blacklists gave us one of two options. First option was to manually request removal, some of them required sending an email to confirm what had happened and why we're confident the problem didn't exist anymore. Easy. Second option was to wait as their service monitored our email services to confirm if we were still sending out spam. If after a few days they confirmed that the spammy behaviour had stopped, we'd be automatically removed from their blacklist. Annoying wait, but reasonable methodology.
Then the annoying ones. One spam blacklist would not remove us for a week, though we could expedite the process by paying them $106 USD. Otherwise, we have a week of going into people's spam folders. It's a friggin racket. Dare I say even extortion? The other annoying spam blacklist said that we could not get removed from their list because we were on several other spam blacklists, including the blacklists that required us to wait a few days for them to monitor our email behaviour, AND the spam blacklist that wanted us to wait a week if we didn't pay $106 USD. So we're on one spam blacklist for a week due to not willing to pay extortion fees, and on the other spam blacklist for a week because they're too meta to develop their own spam blacklisting mechanisms and just follow what other blacklists are doing. The meta blacklist annoys me more than the extortioner. Why are they checking whether we're on other spam blacklists? They should be depending purely on their own capability to identify spammers, not the capability of other organizations. Why do they even exist? There's no value added by being meta here.
Just like DDoS attacks are forcing websites to hide behind a small number of major services like Cloudflare, spam is forcing email users to consolidate into a small number of well-known platforms like Gmail and Outlook. It's just too much hassle otherwise.
But unlike in the case of a website using Cloudflare's DDoS protection to fend off attacks, someone who gives up running their own mail server and signs up for Gmail isn't doing so in order to get any direct benefit from Gmail's spam filter. (Open-source spam filters have gotten good enough that they often do just as good a job as Gmail, if not better.) It's almost entirely because of the insane hassle of dealing with third-party blacklists as you said. Google and Microsoft should give them a medal or something.
Many of the blacklist operators are highly moralistic, too. You'd think they were on some sort of holy crusade against the ultimate evil. Of course you are partly at fault for e.g. not enforcing strict password policies on your users, but a small percentage of users are going to get hacked no matter what. I wish the blacklists would redirect at least 10% of their moral outrage at the danger of centralization that they're so willingly facilitating.
For many on shared hosting with Cpanel, spamassasin isn’t good enough, I don’t want to even deal with spam, much of it needs to just go to a black hole
That's an issue with shared hosting and cPanel. Most of those servers are configured so terribly that they'll probably mark their own outgoing email as spam if they set up their spam filter any stricter.
I don't like black holes, they're impossible to debug when something goes wrong. All email should be either rejected at the SMTP level or delivered to a mailbox (even if it's the spam folder) so there's a clear indication of what happened to it.
It's all clean, except on http://www.spamrats.com (specifically the RATS-Dyna list, and I am not using a home connection.)
I know my mail server is not ideally configured, so I checked the details there. Turns out not only my IP is listed as spam, the whole C network is. "Worst Offender Alert", they call it. Apparently they want nothing to do with me because my neighbours look crap. As a result, I can't even request being removed. Now what, I quit my provider because he gave me the wrong IP?
Seriously, this is getting closer and closer to not even being allowed to send email yourself.
Meanwhile, I receive plenty of spam from gmail and yahoo accounts. I doubt this affects the rating of Google's and Microsoft's servers. I guess their size an money makes them legitimate, somehow?
> It's all clean, except on http://www.spamrats.com (specifically the RATS-Dyna list, and I am not using a home connection.)
That particular list is very well known for doing this. Essentially no one uses them, but they get a bunch of free traffic by being listed on mxtoolbox.
Their removal requirements are fairly absurd anyway (must provide them with a full customer list of everyone using your IPs)
I think charging people to be removed from spam blacklists is a pretty clever way to combat spam. If you're not a spammer then, sure, it's an annoying fee but it's basically one-time. If you are a spammer then you either have to wait a week and be throttled or you can pay more than you are probably bringing in spamming.
Simple, we create a blacklist for spam blacklists, any spam blacklists that misbehave are added to the spam blacklist blacklist and require a $100 fee to be removed from the blacklist blacklist.
I can already guess what your next question will be "But what monitors the spam blacklist blacklist?"
But don't bother asking - it's blacklists all the way down.
Do I think this could be abused in a number of ways? Yes.
But as long as they only add you if you have actually sent spam this should be ok.
And if I did this I guess I'd try to come up with an free (but annoying so it would still be a punishment) way to get off tell list. Something like: go to this web address that is only reachable for 5 minutes at some random time. It will then give you instructions to actually send the removal request. ;-)
> But as long as they only add you if you have actually sent spam this should be ok.
What's this mean though? How are they judging? I've worked for a company that soley sent transactional email from the domain and IP address in question (basically just receipts and password reset. Not even our (fully-opt in, optted-out-by-default) newsletters was ever sent from this domain and IP. Every few weeks we'd have to contend with some blacklist because a user had (mistakenly?) marked one of our emails as spam.
From my experience, it's an extremely inexact and sensitive, but neither precise nor accurate, process.
(Not to mention the time one of the major providers just began blackholeing the same server despite SPF and DKIM. No rejection message in the logs, just many, many, many customer support calls about missing receipts.)
Yes, because I should be unable to communicate (potentially loosing opportunities such as jobs) with anyone because of a bad automatic judgment I can't appeal.
If spammers are as intelligent as the article indicates, they are also monitoring blacklists and will code this into their bots. It would be fairly simple to pause spamming for a week, then resume when the blacklist entries are removed.
Well, on the other hand, forcing spammers to pay money (in your case it's $106, even if it sounds like a racket) is the most effective way to battle spam. That's the price you pay for neglecting your information security.
I would even make the price higher, so people would pay more attention to their information security practices. Like, sorry dude, if you're hacked -- it's your problem, not problem of all the innocent people who received the spam from your hacked accounts.
Once the fees become higher, there will be insurance plans for it, and insurance companies will require some basic level of security controls. There are already talks about it in IoT community.
It really annoys me when people think it's someone else to blame when they neglect their own information security and get hacked.
I see that it's still really easy for people to make judgment on what happens to others without knowing all the details.
It really annoys me when random stranger know-it-alls proclaim all the answers that are already obvious and tried, acting as if others are incompetent.
Never mind that I clearly stated that I was most annoyed with the blacklist that was a meta list riding the coattails of other blacklists, more than the blacklist that wanted payment anyway.
> It really annoys me when people think it's someone else to blame when they neglect their own information security and get hacked.
Seriously, when did I ever say it's someone else to blame? It also really annoys me when people put words in other people's mouths.
Finally, if you knew anything about maintaining live systems, you'd know that technical issues are the smallest and easiest concern to handle when protecting infrastructure.
People have been doing this for at least a decade and a half. There's one particularly notorious one that always used to refuse to tell you how you got on their blacklist, and refused to remove you from their list without you paying them money. They used to be popular enough that being on their list was a pain in the neck.
Last week, one of my organization's user email accounts was hacked. It started getting used to send out spam. We caught it pretty quickly and updated the password so that the spammers couldn't use it anymore. But it was too late, we got listed on several spam blacklists. As such, all emails from our mail server started going into recipient mailbox spam folders. OK, we just get ourselves off of the spam blacklists, right?
Most of the spam blacklists gave us one of two options. First option was to manually request removal, some of them required sending an email to confirm what had happened and why we're confident the problem didn't exist anymore. Easy. Second option was to wait as their service monitored our email services to confirm if we were still sending out spam. If after a few days they confirmed that the spammy behaviour had stopped, we'd be automatically removed from their blacklist. Annoying wait, but reasonable methodology.
Then the annoying ones. One spam blacklist would not remove us for a week, though we could expedite the process by paying them $106 USD. Otherwise, we have a week of going into people's spam folders. It's a friggin racket. Dare I say even extortion? The other annoying spam blacklist said that we could not get removed from their list because we were on several other spam blacklists, including the blacklists that required us to wait a few days for them to monitor our email behaviour, AND the spam blacklist that wanted us to wait a week if we didn't pay $106 USD. So we're on one spam blacklist for a week due to not willing to pay extortion fees, and on the other spam blacklist for a week because they're too meta to develop their own spam blacklisting mechanisms and just follow what other blacklists are doing. The meta blacklist annoys me more than the extortioner. Why are they checking whether we're on other spam blacklists? They should be depending purely on their own capability to identify spammers, not the capability of other organizations. Why do they even exist? There's no value added by being meta here.
It really annoys me.