Happy 20th birthday Gmail, you're mostly grown up – now fix the spam
- Reference: 1712050026
- News link: https://www.theregister.co.uk/2024/04/02/gmail_turns_20/
- Source link:
Sure, it may have seemed like an [1]April Fool's joke in 2004 , but [2]nearly two billion users later, Gmail is arguably Google's most successful venture other than Search and Android.
However, while Gmail's ability to filter out spam is better than some of its email rivals, the feature isn't foolproof. So last year [3]it announced measures targeting those who send over 5,000 messages to Gmail addresses in a single day. Now, anyone violating those provisions will be facing a crackdown.
[4]
"Many bulk senders don't appropriately secure and configure their systems, allowing attackers to easily hide in their midst," Google warned last year.
[5]
[6]
"We started requiring that emails sent to a Gmail address must have some form of authentication. And we've seen the number of unauthenticated messages Gmail users receive plummet by 75 percent," it added. "That's great progress, but there's much more we need to do."
Beginning a couple months ago, all bulk senders had to begin authenticating their emails to close exploit loopholes, add one-click unsubscribe options to all messages, and conform to new spam rate [7]thresholds (determined daily by the number of users who say a message is spam) of just 0.3 percent before being ineligible for bounced email mitigation requests.
[8]
"Most senders already meet these requirements, and for those who are still working on it, we're sharing clear [9]guidance to help," Gmail security and trust group product manager Neil Kumaran told The Register . "Doing so is crucial to close loopholes we know attackers are targeting, and will help make email safer for everyone."
Many of the requirements are being phased in gradually, but Gmail's 20th birthday [10]marks the date when Google will begin rejecting noncompliant traffic.
"Bulk senders who don't meet our sender requirements will start getting temporary errors with error codes on a small portion of messages that don't meet the requirements," Google wrote. "These temporary errors help senders identify email that doesn't meet our guidelines so senders can resolve issues that prevent compliance … We strongly recommend senders use the temporary failure enforcement period to make any changes required to become compliant."
[11]Google killing Basic HTML version of Gmail In January 2024
[12]Google changes email authentication after spoof shows a bad delivery for UPS
[13]That's it, we're all really OLD: Google's Gmail is 10 ALREADY
[14]Google gets the green light to flood US Gmail inboxes with political spam
Mass senders may see one of [15]five error codes for not complying with specific requirements for bulk senders: alignment with either an SPF or DKIM domain, no header spoofing, proper header alignment, valid forward and reverse DNS records, message formatting compliant with [16]RFC 5322 , and sending all messages using TLS.
Google told us it's heard positive feedback from across the email ecosystem after announcing the changes last year, and it's been encouraged by how rapidly senders are moving to comply with the requirements.
[17]
Of course, with any good announcement there's always a drawback. In this case it's that the rules [18]only apply to personal Gmail accounts – not accounts run under Google's Workspaces business productivity suite.
Oh well – happy 20th birthday either way, Gmail. ®
Get our [19]Tech Resources
[1] https://www.theregister.com/2004/04/01/google_launches_email_takes/
[2] https://www.demandsage.com/gmail-statistics/
[3] https://blog.google/products/gmail/gmail-security-authentication-spam-protection/
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZgvXOgXw1G5RinFS8PwCWgAAAJA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZgvXOgXw1G5RinFS8PwCWgAAAJA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZgvXOgXw1G5RinFS8PwCWgAAAJA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://support.google.com/mail/answer/81126?sjid=12562313198915067397-NC#spam-rate
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZgvXOgXw1G5RinFS8PwCWgAAAJA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://support.google.com/a/answer/81126?visit_id=638475964314258524-1391420867&rd=1
[10] https://support.google.com/a/answer/14229414?fl=1&sjid=17254209415122994892-NC
[11] https://www.theregister.com/2023/09/25/gmail_basic_html_discontinued/
[12] https://www.theregister.com/2023/06/09/google_bimi_email_authentication/
[13] https://www.theregister.com/2014/04/01/gmail_tenth_anniversary/
[14] https://www.theregister.com/2022/08/11/google_political_spam/
[15] https://support.google.com/a/answer/14229414#bulk-sender-def&expiration&bulk-sender-comply&email-to-ws&ws-senders&timeline&timeline-new&from-header&reqs-not-met&alerts&error-codes&spam-rate&spam-exceeds&one-click-all-msgs&promotional&why-one-click&one-click-rfc8058&no-one-click&unsub-msg-body&no-unsub-spam&more-unsubscribe-links&howlong-unsubscribe&prevent-unsubscribe-all&unsub-unavailable&mailto&landing-page&dmarc-align&dmarc-fail&mitigation&mitigation-eligible&&zippy=%2Cwhat-is-the-timeline-for-enforcement-of-sender-guidelines%2Cwhat-error-codes-will-you-send:~:text=Temporary%20failure%20messages
[16] https://datatracker.ietf.org/doc/html/rfc5322
[17] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/personaltech&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZgvXOgXw1G5RinFS8PwCWgAAAJA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[18] https://support.google.com/a/answer/14229414#bulk-sender-def&expiration&bulk-sender-comply&email-to-ws&ws-senders&timeline&timeline-new&from-header&reqs-not-met&alerts&error-codes&spam-rate&spam-exceeds&one-click-all-msgs&promotional&why-one-click&one-click-rfc8058&no-one-click&unsub-msg-body&no-unsub-spam&more-unsubscribe-links&howlong-unsubscribe&prevent-unsubscribe-all&unsub-unavailable&mailto&landing-page&dmarc-align&dmarc-fail&mitigation&mitigation-eligible&&zippy=%2Cwhat-is-the-timeline-for-enforcement-of-sender-guidelines%2Cwhat-error-codes-will-you-send:~:text=Google%27s%20requirements%20for%20sending%20email%20to%20personal%20Gmail%20accounts
[19] https://whitepapers.theregister.com/
Gmail is the worst thing that could happen to email
Gmail is not email. Gmail is something similar to email, but different. Its "labels" system is non standard and IMAP clients do "more or less" work.
Also, their antispam rules are obscure and if you are "bad" in their eyes, like my domain is, there is NO WAY you can actually ask them what's wrong. You are just fucked.
My domain is a business one, used by one person (me). My mail server has never sent spam or even legit bulk mail. I have DMARC DKIM SPF and all of that is needed. I have no issues with every other email service IN THE WORLD. But gmail (the free version) files my emails in spam. At least the business version does not.
I hate Gmail.
I have a Gmail account
I got a fairly early one. Never use it except for testing.
The inbox is rammed full of spam ... from other Gmail accounts.
I still use my Gmail...
...But I don't really use it use it, you know?
There is no real way to stop all all of the spam. I am not going to take the time to make all spam as spam and it's been weeks since I deleted all the unwanted messages so I'll have to set aside an hour soon or it will turn into an all day project before I know it.