Spamhaus unsubscribe requirement

Spamhaus have added me to their CSS list and I'm trying to find out why. It might be a technical issue or it could possibly be something else. (I think it is defamatory to tell the world someone has a bad reputation without giving them evidence of a reason, but I'll leave that for now.)

Their current requirement is that I must add unsubscribe headers to my mail, but that worries me. The bulk of my mail is personal to friends or other ordinary contacts. The rest is related to my involvement in Church or similar institutions. I do not send bulk mail and I have no subscribers, so how can I provide an unsubscription mechanism? At best, it would have to be a dummy mechanism that did nothing, but how would that work as spammers could do the same. I cannot provide a genuine mechanism because there is nothing to unsubscribe.

Also, I worry that friends might get the impression I have subscribed them to some company's bulk lists without their knowledge or permission and I could lose their friendship very quickly if I complied.

The Internet, once we have paid for our access, needs to be available to all to use ethically and lawfully. We can't let it become the property of big companies to use to milk us all or spy on us all.

In the meantime I have a test e-mail bouncing around between my incoming and outgoing servers. The incoming server won't accept my outgoing server's bounce messages because they're both on Spamhaus's list!
 
The Troubleshoot section in the checker outlines the issues with the current configuration. Please follow the recommendations in the checker and ensure you pass all three checks before opening a ticket.https://check.spamhaus.org/results?query=84.92.47.176Regards,
(Emphasis mine.) I have corrected the HELO issue but that's not good enough until I set the unsubscribe link and header and enable IPv6 which my router and so far as I know my ISP does not provide. These are the other two recommendations.

I have replied explaining why this would be "technically possible but socially difficult" but have no great expectations they will move.

Pity, Spamhaus was a very useful tool until they did this.
 
This is generic advice about running a mail server. CSS is a snowshoe spam list; snowshoe spam is sent from addresses that have not previously sent spam, either fresh address block allocations, or compromised servers. The first thing to do is check your mail logs, to see if you are spamming; you might have an infected client behind the server, another risk factor is a vulnerable web server that can access the MTA. Note that snowshoe spam is often low volume. The other possibility is that you are in a block of addresses that has been inferred to be spammer controlled. Either way the listing should age out in a few day if the underlying problem goes away.

If you aren't the spammer, the onus is on the service provider to deal with it.
 
Unfortunately no, the quote was from the specific reply to my ticket, so not generic advice but a requirement for delisting in my specific case.
 
Unfortunately no, the quote was from the specific reply to my ticket, so not generic advice but a requirement for delisting in my specific case.
It still sounds generic to me; how could they know whether you have added unsubscribe headers to the bulk mail you don't send. The only possible way is if your email is going into their spam traps, and that would rule-out delisting anyway.
 
They are taking the information from their test procedure to which I have sent test messages, so they know exactly what my mail does and doesn't provide. The first test result had three failures:

1. Does not comply with Google/Yahoo requirements (unsubscribe requirements for bulk e-mail). I do comply with the requirements for personal mail as published by Yahoo, but that's evidently not good enough for Spamhaus. They want me to comply with bulk requirements even though I'm not a bulk sender. I'm not sure how anyone can tell whether any individual mail is part of a bulk list or not, anyway. Most bulk senders send each one individually to reduce the risk of data breaches. However, if they distinguish in their requirements they must have a way (and I think we can all guess what that is - after all, if they're spending a lot of money providing a free messaging service they must be getting something worthwhile out of it). Spamhaus cannot tell, of course. They have probably put me on the list because my year's delisting has expired, but I have to pass their test before I can come off.

2. Not IPv6 ready. My ISP doesn't provide IPv6 yet so this isn't really a reflection on me and shouldn't be used as a basis for assessing my trustworthiness, but it apparently is. This is not under my control.

3. HELO did not comply with rDNS. This seems to be a new requirement as it never has and I was successfully delisted last year. I have now changed this to match though Spamhaus seem confused by that and have asked me which one is correct.

I gather List-unsubscribe headers can have a text part as well as a link so I suppose I'll just have to make that an explanation they're not actually on a list to start with and set up a page which claims (falsely) they have been unsubscribed, since it's impossible to unsubscribe someone from a list which doesn't exist - but how does that help with spam? Spammers could just add a bogus List-unsubscribe process which does nothing too.
 
I've been down that road. With email configured for all the current "gotta haves", Spamhaus still blacklist my site. In the North Carolina county I'm in, 3/4 of the count ISPs do not support IPv6. The server is headless, so the Spamhaus "how to get unblocked" process of sending an email to the server with a URL that replies to SpamHaus could not easily be done (it's at a local firehouse since they use it for mapping data and notifications). As such, I could not bring up a web page from the URL they supplied.
The only recourse I had was to have the service provider contact Spamhaus and verify that even though the IPv4 address was in their block of IP addresses that I was a vetted provider. It took a few weeks to get that to happen. Once that was done, I was good.
My take on the situation is twofold. SpamHaus has a default "If you're in a IP address block with a fixed IP you must be a spammer" view of the world, a sort of "you are guilty until proven innocent" and large ISP providers of service with a fixed IP address that have near zero support after the sale, and do not wish to complicate the sales parcel by dealing with this proactively when setting up new fixed IP service.
With the advent of CGNAT, existing ISP infrastructure can justify not upgrading their system to IPv6 which is bad for everyone in the long run. As such, the "One IPv4 address associated with hundreds of users" challenges identifying spammers by IP address. In the world of security, everything is a moving target.
So make sure you have all the latest and greatest pieces of security in your email setup done correctly, and work with you ISP to pass the good word on the Sp;amhaus. I see no impetus for these large organizations (Spamhaus, ISPs, cloud hosting) to change.
 
They are taking the information from their test procedure to which I have sent test messages, so they know exactly what my mail does and doesn't provide.
Clearly this procedure is not really aimed at you. The people that pay for Spamhaus, and most that use it for free, regard mail servers like yours as a risk. Without lists like CSS a lot more spam would get through to resource intensive content filtering.

They have probably put me on the list because my year's delisting has expired, but I have to pass their test before I can come off.

The protection may have expired, but it's unlikely that you were listed just because of that.
 
My take on the situation is twofold. SpamHaus has a default "If you're in a IP address block with a fixed IP you must be a spammer" view of the world, a sort of "you are guilty until proven innocent"

What's your evidence for that?

With the advent of CGNAT, existing ISP infrastructure can justify not upgrading their system to IPv6 which is bad for everyone in the long run. As such, the "One IPv4 address associated with hundreds of users" challenges identifying spammers by IP address. In the world of security, everything is a moving target.
It doesn't matter, a listing implies one of two thing: either there is a spam source at that address or a dynamic address is attempting to deliver directly to MX - both are equally damning.
 
Back
Top