home.social

#solutionstospam — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #solutionstospam, aggregated by home.social.

fetched live
  1. @jeffmcneill The email situation's interesting.

    On the one hand, it's TCP/IP networking which routes mail, though it might be possible to apply the peering notion to mail servers rather than network peers.

    (Technically, of course, VOIP also operates over TCP/IP, though that's only a subset of total phone traffic, and ... I'm not entirely clear on how that might operate.)

    The next question is whether or not it would make sense for individual email servers to be bonded. That probably splits sensibly into a few categories:

    • Large email service providers: Gmail, iCloud (Apple), Outlook (Microsoft), Yahoo, Proton, etc.

    • Individuals operating their own servers (families, small groups, generally not business-oriented).

    • Businesses and organisations self-serving email for their own employees.

    • Other online services with an email notification component: FB, Fediverse servers, Reddit, Pagerduty, etc. These serve third party email, rather than just personal or own staff, often notifications though potentially user-generated messages as well.

    • Mailing lists. This is a common sticking point for other anti-spam proposals. (See classically: craphound.com/spamsolutions.txt, and yes this is a somewhat market-based solution.)

    • Mail-campaign services. Generally: sales/marketing emails, such as Mailchimp, ActiveCampaign, etc. Third-party mail, generated by the third parties and generally sent in mass to large numbers of fourth parties.

    • Black-hat "bulletproof" email providers. Spamhauser.

    • Proxy servers. Individual systems hijacked by third parties to send spam.

    Questions:

    1. Does it make sense to bond each of these classes?
    2. How much should that bond be / how should a bond be computed?
    3. What is excessive (say, for individuals), what is insufficient (say, for major email service providers), to permit legit mail, but discourage spam?
    4. What forms of abuse might be triggered through such a system? Spurious claims, joe-jobs, and the like, say? How should those be mitigated or addressed?
    5. Who can file claims, who gets paid?

    I'm not going to answer those, it's for discussion. I think there might be some viability to this. It's not a per message postage concept ("microtransactions"), but instead an aggregated and risk-based skin-in-the-game notion.

    I do think that bulletproof hosters and proxies would be pretty well addressed, while large services and marketing providers would be strongly incentivised to clean up their acts. Smaller servers should be reasonably OK under this schema, and might aggregate to a large pooled bond (small servers already often have to direct outbound through a larger provider already).

    #email #spam #SolutionsToSpam #antispam #bonding