@thibaultmol@en.osm.town
Exactly. As usual, the lawmakers worsen it. While trying to keep children safe, they are forcing them to use shady VPN services, which expose them to worse harm. Never changes.
But keeping children safe is not really their goal. It's a lie that the gullible will accept and support.
@Rinakochi@hear-me.social Frankly, I think Google has learned that people rattle their sabers and ultimately do nothing about it.
I don't think it's going to matter to them that a tiny fraction of people will stop using YouTube any more than it bothers Meta that some people use Pixelfed.
OMG. It gets worse. The link in the email doesn't go back to their own domain, or even one they control. It points to a 3rd party domain owned by Tucows called name-services.com.
They are training customers to let down their guard when using the link from an email they supposedly send. A scammer can get a similar domain name to easily fool people to click the link since customers have been taught there's a 3rd party link.
They've done everything wrong relating to email security, and they are a web hosting company that should do everything right.
@ExperimentalGuy@programming.dev This doesn't involve security. This is just about a protocol that says a server must let you know, via one email for each rejection, that an email with your from address couldn't be delivered, regardless of whether you sent it.
It's a procedural problem.
If a spammer sends 5 million emails with your email address in the FROM: then you can expect hundreds of thousands of messages from your email provider telling you that it couldn't deliver an email, for whatever reason.
@ikidd@lemmy.world People are not reading. You are not reading.
SPF, DKIM and DMARC are not relevant. Those are instructions to the receiving servers which are not the ones sending the bounces. The receiving server is telling the sending server, based on these DNS records, that it will not accept the message. It refuses them. Period. No bounce message.
The sending server then, as a courtesy, lets the sender know, solely based on the FROM: address, that the email could not be delivered, as one by one messages.
There are no DNS records or configurations that control this. The SMTP server follows the protocol which is to inform the FROM: address, as a courtesy, that the email was not accepted. It is the sender. It does not look at SPF, DMARC, and DKIM rules. That is only what the destination server uses.
@lautreg SPF and DKIM are only used by the destination IMAP or POP3 servers to see what to do when they receive the email. In this case they reject it.
The delivery failure message is coming from the sending server as a courtesy message to the sender to let them know their email was not delivered. The protocol is to tell the FROM: address that the email could not be delivered. The SMTP, sending server, doesn't look at SPF, DKIM or DMARC or any DNS records or any other configuration related to it. It simply tells you the millions of emails sent with your FROM: address could not be delivered, one by one.
People keep bringing up SPF, DKIM, and DMARC, but it's not relevant to this problem.
Depending on the ISP, after making the changes, it usually takes up to 15 minutes for the changes to get distributed to all the DNS servers worldwide. It's pretty quick.
@idoubtit@mstdn.social
Mailpoet is a Wordpress plugin? You should still have appropriate SPF, DKIM, and DMARC records.
If you gave Mailpoet the right to use your email's SMTP server (is this how it works?) then you're fine because it's using your credentials and SPF will pass as the SMTP server is authorized to send email for your credentials.
@rimu I got it in my Mastodon account
@thibaultmol@en.osm.town
Exactly. As usual, the lawmakers worsen it. While trying to keep children safe, they are forcing them to use shady VPN services, which expose them to worse harm. Never changes.
But keeping children safe is not really their goal. It's a lie that the gullible will accept and support.
@Rinakochi@hear-me.social Frankly, I think Google has learned that people rattle their sabers and ultimately do nothing about it.
I don't think it's going to matter to them that a tiny fraction of people will stop using YouTube any more than it bothers Meta that some people use Pixelfed.
@TheOneCurly @rimu Any stock market tips to share? :)
How long were you on lemm.ee?
@rimu feddit.online also has it enabled. Fun day for #Piefed
OMG. It gets worse. The link in the email doesn't go back to their own domain, or even one they control. It points to a 3rd party domain owned by Tucows called name-services.com.
They are training customers to let down their guard when using the link from an email they supposedly send. A scammer can get a similar domain name to easily fool people to click the link since customers have been taught there's a 3rd party link.
They've done everything wrong relating to email security, and they are a web hosting company that should do everything right.
@ExperimentalGuy@programming.dev This doesn't involve security. This is just about a protocol that says a server must let you know, via one email for each rejection, that an email with your from address couldn't be delivered, regardless of whether you sent it.
It's a procedural problem.
If a spammer sends 5 million emails with your email address in the FROM: then you can expect hundreds of thousands of messages from your email provider telling you that it couldn't deliver an email, for whatever reason.
Here. Let Google explain it: https://support.google.com/mail/thread/209018675/my-sent-email-box-is-filling-up-with-bounce-emails-and-emails-i-did-not-send-my-inbox-is-fine?hl=en
@kalpol@lemm.ee No idea what you are saying here. But, you can argue with Google: https://support.google.com/mail/thread/209018675/my-sent-email-box-is-filling-up-with-bounce-emails-and-emails-i-did-not-send-my-inbox-is-fine?hl=en
@ikidd@lemmy.world People are not reading. You are not reading.
SPF, DKIM and DMARC are not relevant. Those are instructions to the receiving servers which are not the ones sending the bounces. The receiving server is telling the sending server, based on these DNS records, that it will not accept the message. It refuses them. Period. No bounce message.
The sending server then, as a courtesy, lets the sender know, solely based on the FROM: address, that the email could not be delivered, as one by one messages.
There are no DNS records or configurations that control this. The SMTP server follows the protocol which is to inform the FROM: address, as a courtesy, that the email was not accepted. It is the sender. It does not look at SPF, DMARC, and DKIM rules. That is only what the destination server uses.
@lautreg SPF and DKIM are only used by the destination IMAP or POP3 servers to see what to do when they receive the email. In this case they reject it.
The delivery failure message is coming from the sending server as a courtesy message to the sender to let them know their email was not delivered. The protocol is to tell the FROM: address that the email could not be delivered. The SMTP, sending server, doesn't look at SPF, DKIM or DMARC or any DNS records or any other configuration related to it. It simply tells you the millions of emails sent with your FROM: address could not be delivered, one by one.
People keep bringing up SPF, DKIM, and DMARC, but it's not relevant to this problem.
@Onurtag@lemmy.world
I didn't remove them. They were removed and in the manage extension screen it listed 6 extensions that were removed
@MajorHavoc@programming.dev
I like how you think!
@william_1844 @admin @my_place_social
I answered in Piefed, but don't see the reply here, so I'll answer it again in case the reply never made it.
It's actually a very good question. Yes, absolutely. Go to settings and select "Join Matrix Room"
@aliceif @admin Thank you. Yeah, it was pretty bad....
@daniel@masto.doserver.top
I've never had issues making changes, so I think it wouldn't be an issue. The caches should recognize they need updating.
@nimi@norrebro.space
Hi,
Depending on the ISP, after making the changes, it usually takes up to 15 minutes for the changes to get distributed to all the DNS servers worldwide. It's pretty quick.
@daniel@masto.doserver.top
Should be able to.
@Ruaphoc@mstdn.games
Thanks for this! This is on my list to look at this weekend. Thank you!
@idoubtit@mstdn.social
Mailpoet is a Wordpress plugin? You should still have appropriate SPF, DKIM, and DMARC records.
If you gave Mailpoet the right to use your email's SMTP server (is this how it works?) then you're fine because it's using your credentials and SPF will pass as the SMTP server is authorized to send email for your credentials.