DKIM, DMARC, SPF, rDNS/PTR, EHLO… all correct and verified in the email “original source,” BY GOOGLE. Still goes to SPAM folder because **** you, apparently. I hate Google.

  • SystemNeo@toast.ooo
    link
    fedilink
    English
    arrow-up
    178
    arrow-down
    6
    ·
    28 days ago

    Tbh, out of all services I’ve seen people self-host, email is the most common one I’ve seen people describe as a bad idea™️.

    I just chose a paid mail service (mailbox) and called it a day.

    • surewhynotlem@lemmy.world
      link
      fedilink
      arrow-up
      81
      ·
      28 days ago

      Same. It’s great for a technical challenge. Don’t do it for your primary email unless you’re ok losing emails and having them rejected a lot.

    • galoisghost@aussie.zone
      link
      fedilink
      arrow-up
      51
      arrow-down
      5
      ·
      28 days ago

      Yeah we should just let them win. Why fight? It’s not like most of the spam and phishing come from Gmail and hotmail accounts. It’s those fucking self hosters

      • WesternInfidels@feddit.online
        link
        fedilink
        English
        arrow-up
        22
        arrow-down
        1
        ·
        28 days ago

        Maybe the way to fight GMail’s outsized power is to stop using GMail. You can do that without going all the way to self-hosting.

        • MousePotatoDoesStuff@lemmy.world
          link
          fedilink
          arrow-up
          5
          arrow-down
          1
          ·
          27 days ago

          Yeah, I figure I did enough of a step by moving to Tutanota. Selfhosting email seems like overkill unless you’re running some large organization or doing self-hosting as a hobby.

        • daveyOsborn@infosec.pub
          link
          fedilink
          arrow-up
          2
          ·
          27 days ago

          Maybe the way to fight GMail’s outsized power is to stop using GMail.

          Stopping your own gmail use is trivially easy. It just scratches the surface. In order to not lick Google’s boots, you also need to stop sending email to gmail users. That means doing an MX lookup before emailing to see if their vanity email address is on a Gmail host. And of course this also means not sharing an email address with gmail users.

          I do that, in fact. I also boycott Microsoft. In the end, this means I am not using email much at all.

    • realitista@lemmus.org
      link
      fedilink
      English
      arrow-up
      17
      ·
      28 days ago

      Even using a reputable hosting provider and personal domain will get you spam black holed these days

      • jaybone@lemmy.zip
        link
        fedilink
        English
        arrow-up
        12
        ·
        28 days ago

        I wonder if there should be some kind of law or regulation around this. It’s an antitrust issue. Though no one in Congress would understand what this is.

      • Tiger@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        3
        ·
        28 days ago

        Many hosting providers won’t even let you try, they don’t want to host potential spammers.

    • Dultas@lemmy.world
      link
      fedilink
      arrow-up
      5
      arrow-down
      1
      ·
      28 days ago

      I use a free outbound smtp relay that lets me do like 5k emails on the free tier. I use it primarily for alerts and Immich updates / new user links. But I don’t do inbound so don’t have to expose any ports. Only time I did was to do validation with the relay so just a few minutes during setup.

    • motruck@lemmy.zip
      link
      fedilink
      arrow-up
      4
      arrow-down
      2
      ·
      27 days ago

      I do not understand all the people who are too afraid to try email hosting on their own that are out here discouraging people cause they want to sound right.

      Email is hard cause people don’t host it enough and the few corps ignore the minority problems.

      If more people shift back to hosting email the balance will tip again.

      It is fine if you don’t want to host email but telling people not too without even trying yourself is anti-selfhost IMHO.

    • Diurnambule@jlai.lu
      link
      fedilink
      arrow-up
      1
      ·
      27 days ago

      Same I use commercial for most of my usages, but I have one properly registered for my selfhosted services.

  • Prontomomo@lemmy.world
    link
    fedilink
    arrow-up
    59
    ·
    27 days ago

    I stopped thinking of any email as “private” regardless of where it’s hosted, when I realized that everyone I email uses Gmail anyways; so all my emails end up going to Google anyways.

    It made me an email nihilist

    • GamingChairModel@lemmy.world
      link
      fedilink
      arrow-up
      7
      ·
      27 days ago

      Microsoft Exchange and the web-based Outlook probably still has a plurality of email volume, because of their dominance in enterprise. Even on the web based consumer space, Apple and Yahoo still have significant market share.

  • Lena@gregtech.eu
    link
    fedilink
    arrow-up
    43
    arrow-down
    1
    ·
    28 days ago

    Self-hosting email is quite the undertaking… I don’t have the energy to deal with it and just pay 10€/year for a hosting service.

    Here’s an informative (and funny) talk on why self-hosting email in its current state is probably a bad idea.

  • OR3X@lemmy.world
    link
    fedilink
    arrow-up
    40
    ·
    28 days ago

    I work for state government and even we have trouble with email reputation issues from the big orgs. It’s a pain for everyone.

  • Forester@pawb.social
    link
    fedilink
    English
    arrow-up
    27
    arrow-down
    2
    ·
    28 days ago

    If you want you can PM me your dkim and dmarc and SPF policy. Or just send me your url and I’ll look it up. I used to fix these for a living. It’s likely an issue with your SPF not being properly annotated.

  • x7HlPDq9dSNO6v3A9@lemmy.world
    link
    fedilink
    arrow-up
    19
    ·
    28 days ago

    I run my own mailserver in docker and it’s not so hard! There was some difficulty at the start with mail going to spam, but after a little while “warming up” the IP with usage, it works fine. It’s hardest to build an IP’s reputation in the beginning because if your mail goes to spam, it doesn’t typically lead to healthy conversations that can support it’s history.

    My trick was to forward all my incoming gmail messages from the account I was replacing into the new server - that way I could receive and reply from the new mailserver if people sent mail to the old one. Once it built up a bit of a history it started working fine, and that took maybe a few conversations over a couple of days.

    The thing I have noticed is that you very quickly get destroyed by incoming spam - a more advanced filter is definitely on the list.

    • trxxruraxvr@lemmy.world
      link
      fedilink
      arrow-up
      13
      ·
      28 days ago

      One of the problems with self hosting is that a lot of IP addresses have historically been used for spam and still have a bad reputation. If you get assigned one of those IP addresses there’s very little you can do about your mails going to spam.

      • Dultas@lemmy.world
        link
        fedilink
        arrow-up
        5
        ·
        28 days ago

        Another is most ISPs will put your IP in the PBL so unless you use a relay your outbound email is going nowhere. Google fiber was slow on updating their PBL when they rolled out service in my area so I got to send direct for several months before having to use an external relay.

      • PokerChips@programming.dev
        link
        fedilink
        arrow-up
        1
        ·
        26 days ago

        You can request to be removed from the list by SpamHaus. Worked for me. But for still need to make sure everything is set up currently (which is true is tedious) or you go right back onto the list.

  • Fluffy Kitty Cat@slrpnk.net
    link
    fedilink
    English
    arrow-up
    18
    ·
    27 days ago

    Me and a couple other people have ran into on the internet have thought that we need to invent “email 2”, a clean slate implementation of email that serves it’s asynchronous long form and attachment friendly function while leaving behind Decades of Cruft . We can make it into an encrypted by default and have conveniences that we never had before. It might even be an actual useful thing instead of just being the thing you sign up for accounts with to get to 2fa codes and spam from websites you buy stuff from

    • MonkeMischief@lemmy.today
      link
      fedilink
      arrow-up
      8
      ·
      27 days ago

      Love this idea!

      I feel like Arcane/Delta Chat is a step toward this. It somehow uses an email protocol and it works just like Signal or any other message app! I dunno how the heck it works but it’s super cool.

      That’s something I want too: An open standard my friends and family can be on, where “the market” isn’t.

      Edit: I see, it seems the issue in the main thread is:

      • Gmail blocks custom servers as spam 99% of the time.
      • 99% of normieverse uses Gmail. :(

      But getting people on other email providers to talk to each other… shouldn’t be an issue then?

    • jj4211@lemmy.world
      link
      fedilink
      arrow-up
      4
      ·
      27 days ago

      Frankly, I’m rather shocked it hasn’t happened by now.

      We’ve tried to bandaid over it with various weird things, but fundamentally SMTP is just weird.

      I could easily imagine a domain having some SRV record to advertise “hey, I support NeoSMTP”, and peers switching to that instead, possibly pinning on successful NeoSMTP negotiation.

      Get rid of a lot of the relaying which has not been useful in modern times and only a liability, and perhaps offer an https option to be less likely to be blocked (a TXT record to indicate url, and a node could declare their NeoSMTP entry point as https://mail.server/NeoSMTP/ or whatever works for them).

      • ricecake@sh.itjust.works
        link
        fedilink
        arrow-up
        3
        ·
        27 days ago

        Oh, there have been plenty. The issue though is the classic “make a better standard, and now you have N+1 standards”.
        Everything is wrong with SMTP. It’s still in use because it’s supported everywhere. Anything that wants to replace it either needs to entirely replace it in one fell swoop, or it needs to be backwards compatible.

        The result is that occasionally a new thing comes up, a handful of people try it but there isn’t critical mass to make other features really useful so it fades.

        • jj4211@lemmy.world
          link
          fedilink
          arrow-up
          1
          ·
          27 days ago

          Hence my references to DNS records in addition to MX to determine if an endpoint is SMTP only or better. For compatible interop.

          • ricecake@sh.itjust.works
            link
            fedilink
            arrow-up
            1
            arrow-down
            1
            ·
            26 days ago

            But that’s the thing: now you haven’t made an email replacement, you’ve made email more complicated.

            If you’re backwards compatible you need a very compelling feature to get people to switch, and using the feature is limited until people switch.
            That’s how we added spf, dkim, dmarc and starttls.
            The biggest difficulty is managing the layers of compatibility.

        • Fluffy Kitty Cat@slrpnk.net
          link
          fedilink
          English
          arrow-up
          1
          ·
          26 days ago

          It’s fine if Legacy email Remains the thing that could spend whereas email 2 can be used for actual correspondence between people

          • ricecake@sh.itjust.works
            link
            fedilink
            arrow-up
            1
            arrow-down
            1
            ·
            26 days ago

            You’ll have to walk me through what you mean by that. I’m not sure how what I’m hearing you say would improve anything.

  • Elvith Ma'for@feddit.org
    link
    fedilink
    arrow-up
    16
    ·
    28 days ago

    Google Groups allows spammers to subscribe you to their groups in a workspace account, but doesn’t allow you to unsubscribe since you’re not part of that workspace account… Worse - all autoresponders for the spam will also be forwarded to all members of said group.

    Since I do not participate in Google Groups, the nuclear option is to file all mails from Google Groups as spam with a Sieve script.

    Note the require part may be too large as may sieve script also contains more rules than this one.

    require ["body", "date", "editheader", "envelope", "fileinto", "imap4flags", "mailbox", "regex", "reject", "variables"];
    
    if anyof(
        header :contains "List-Subscribe" "groups.google.com",
        header :matches "X-Google-Group-Id" "*"
       ) {
    	if header :matches "Subject" "*" {
    		set "subject" "${1}";
    	} else {
    		set "subject" "";
    	}
    	deleteheader "Subject";
    	addheader :last "Subject" "[Google-Groups-Spam] ${subject}";
    
    	fileinto "Junk";
    }
    
    • ayyy@sh.itjust.works
      link
      fedilink
      arrow-up
      6
      ·
      28 days ago

      autoresponders for the spam will also be forwarded to all members of said group.

      This sounds like a pretty effective way to get yourself unsubscribed from groups you don’t want to be in.

      • Elvith Ma'for@feddit.org
        link
        fedilink
        arrow-up
        4
        ·
        28 days ago

        They will be drowned in hundreds of „Thanks for your email, but we don’t do support via mail. Please open a ticket at $URL“ and „Thanks for your mail, we will get back to you shortly. Your ticket ID is #123456“. Also everything you add as an auto response will be distributed to all other victims in that group, so I chose to not be a dick.

  • Nester@feddit.uk
    link
    fedilink
    English
    arrow-up
    14
    ·
    28 days ago

    I self-hosted my own email for a few years, everything was set up and reporting correctly, but Google just would never have it. I think the worst is it would be a bit inconsistent.

    Anyway, I switched to an email provider with my own domain and it’s much more reliable. That is until this week, I have noticed that some services are rejecting my domain. I think there is some whitelisting nonsense going on, but in those instances I just use an alias and that seems to work.

    I just want to have control of my data!

  • FLOSSbOxIN@mastodon.fbin.in
    link
    fedilink
    arrow-up
    12
    ·
    28 days ago

    @laurenceOfSuburbia
    This ain’t anything new. They have been doing this for decades and will still do it forever. Just move on with it, since it like trying to figure out something which has no meaning at all.
    Just know for sure that every company has systems designed by some developer based on a whimsical mindset of someone at the very top. So, I can care less for these stupid companies and their useless management.

  • mspencer712@programming.dev
    link
    fedilink
    arrow-up
    9
    ·
    edit-2
    28 days ago

    I also self host email and so far haven’t had any problems. Initial setup was annoying but it’s required zero effort this past few years, and I don’t think my emails land in spam folders. Maybe I can help?

    Shoot me a message at test-message-lawrenceOfSuburbia@mspencer.net (which I’ll delete after it gets a message, for obvious reasons) and I’ll take a look. (I misspelled the name, I apologize, no insult intended)

    Honestly I think I’ve received 10 spam messages in the last four years, and five have been from gmail addresses (Best Buy invoice spam) in the past two months. I submit each one to support.google.com/mail/contact/abuse and hopefully it helps.

  • Not_Raccoon_Rick@altgag.net
    link
    fedilink
    arrow-up
    7
    ·
    28 days ago

    Self hosting an email server to send mails that don’t get flagged as spam is a nightmare, I’d rather not attempt doing it again. My Lemmy instance is using SMTP2Go and the free tier is more than enough for my current sending capacity needs

  • mlg@lemmy.world
    link
    fedilink
    English
    arrow-up
    7
    ·
    27 days ago

    They claim its for spam prevention which is why most ISPs actually also block outgoing SMTP port 25.

    The dumb thing is, all it really does is push spammers onto using botted/stolen accounts which work way more effectively, and everyone else is forced to set up their email with Google or Microsoft.

    If your domain isn’t big enough to be recognized, all that SPF and DMARC won’t mean crap to them.

    • daveyOsborn@infosec.pub
      link
      fedilink
      arrow-up
      1
      ·
      27 days ago

      They claim its for spam prevention which is why most ISPs actually also block outgoing SMTP port 25.

      European ISPs block egress port 25, not American ones, generally. Not sure about the rest of the world.

      In Europe, one refuge is to send using the GSM networks, which tend not to block egress 25 for some reason.

        • daveyOsborn@infosec.pub
          link
          fedilink
          arrow-up
          2
          ·
          27 days ago

          AT&T is the worst of the worst. And I boycott them for countless reasons like snooping on their own customers voluntarily without a warrant. It’s really a hard-right corp. In any case, never tried them so I didn’t know they blocked egress 25.

          One trick that works if truth-in-advertising laws are in force: ask the sales people before subscribing if the block port 25. They always say “no, we block nothing” (in my experience). So you subscribe and sign the contract. Then when you see they actually block 25, you have a false advertising situation and also a contract violation (if either verbal contracts are enforcable or if you can get it in writing that nothing is blocked). So you complain. In my experience, they give a gratis upgrade to an enterprise level of service that generally has a static IP and no blocks – for the price of the residential plan you signed up for.

  • artifex@piefed.zip
    link
    fedilink
    English
    arrow-up
    5
    ·
    28 days ago

    I might be out of the loop on how email works, but doesn’t it hop between several other email servers on its way from Alice to Bob (and at least some of it must still be unencrypted)? If so and given google’s scale you could probably just assume that even if they’re not your inbox they’re going to be at least handling many if not most emails along the way.

    • Björn@swg-empire.de
      link
      fedilink
      arrow-up
      5
      ·
      28 days ago

      Depends. Usually not. It hops from your computer to your email provider which then looks up the server of the recipient and sends it there. The recipient’s server might send it on internally and in big installations probably does so.

      It is theoretically possible that one of the involved parties has a third party authorised to accept mails on their behalf in case of outages. I don’t believe that is very common nowadays. It’s much more likely that your provider will keep the mail for a few hours to days when it can’t reach the recipient.

      But ideally only your provider and the recipient’s provider can read the mail with all connections in between being encrypted. There’s just no guarantee that all paths are encrypted. But I think nowadays that is much more likely than it used to be, thanks to Let’s Encrypt.

      Now, if you don’t want any of the servers to be able to read the mail you have to encrypt it with something like GPG. But for that to work you need the recipient’s key. But hardly anyone uses that. And it only encrypts the content of the mail. Not the metadata.

    • trxxruraxvr@lemmy.world
      link
      fedilink
      arrow-up
      4
      ·
      28 days ago

      That was the theory, nowadays moest email goes from google or microsoft to google or microsoft. At least 99% of the rest goes directly from the senders provider to the recipients provider. Afaik none of the larger providers still accept non-TLS connections.

      • artifex@piefed.zip
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        1
        ·
        28 days ago

        Yeah that’s what I’m saying. Even if you’re not using one of the big providers there’s a good chance they’re going to be at least handing it on its way to your self-hosted inbox, and its contents are unencrypted while they’re handling it (unless you encrypt the contents yourself). So there’s not much benefit to self hosting email if your goal is to keep your data out of big tech’s hands (and if that is your goal, don’t send anything important with email)

        • trxxruraxvr@lemmy.world
          link
          fedilink
          arrow-up
          4
          ·
          28 days ago

          If neither the sender nor the recipient is hosted by google the email is never going to reach googles servers. It will go directly from the sender provider to the recipients provider.

  • Impractical_Island@lemmy.world
    link
    fedilink
    arrow-up
    5
    arrow-down
    1
    ·
    27 days ago

    I put dog shit in my ass and Google knew five minutes before it happened, filmed it, and sold it back to me as a custom highlight of my home alone shenanigans. I find this a bit egregious, personally.