<- Back
Comments (54)
- someonebaggyAll of the spam blocklists are like this.At one time quite recently, Cloudflare was on Spamhaus's "Don't Route Or Peer" list. Imagine where the world would be if anyone cared about that list.But if an entire ISP is blocking you based on UCEPROTECT, which is designed for email spam filters - are you sure? An ISP that blocked all of DO would get so many complaints and be open to so much legal liability. Usually these are only used for email filtering.
- john_strinlaithe more ive looked at this uceprotect site, the more i see how unhinged they are.for example: "People with a brain would simply fix their systems after getting listed for abuse. Stupid losers are different." http://www.uceprotect.org/cart00neys/index.htmlor"This time, however, we have a premiere: A Woman. Actually, it reads more like a brat than a woman [...] If we were as emotional as you are and report you to our authorities, the handcuffs might click the next time you move your ass off the British Isles. [...] This means that they have heared that bullshit you spammed to them at times when you still slipped across the floor with your shit diaper. :-) [...]Grow up and also try to grow a brain before you make a fool out of yourself, again next time.Claus von WolfhausenTechnical Director" http://www.uceprotect.org/cart00neys/2021-001.htmltheir main page has an iamverybadass quote, too: "WARNING: Do not play around here. You have no idea who we really are, and what will happen to you!"
- mrmattyboyThe uceprotect Level 3 page clearly says using the list will cause collateral damage and should only use as an indicator as part of a spam score, not to act purely on it.So, yes, if a service provider is known for having a lot of spam coming from it, it makes sense to be on there. They're not saying every IP is bad, they're literally stating the opposite (which seems fair).So, if Orange are blocking purely based on it, not only are they using a spam filter as a DNS query/web filter (given uceprotect seems to flag based on mail spam traps based detections etc.) and ignoring their documentation (which says it shouldn't be used to block on it's own).
- JohnMakinDigitalOcean has been on their list for a while, they say something like “if you don’t want to be flagged as spam, dont host on a site that hosts spammers” which is pretty ridiculous given every cloud platform does
- 5kyl4bhttps://uceprotect.wtfCheck this...
- ozimSounds like this should go via Orange they have means to slap UCEPROTECT on the wrist. It also looks like it would be in Orange business to have proper spam lists not ones like that.
- tagyroPlaying the devil’s advocate, my domains get constantly scanned from DO ips. I know it’s not feasible but some basic kyc on DO’s side would probably help.
- PolizeiposauneDo you have any direct evidence that the Orange block is due to the listing in UCEPROTECT?Digital Ocean is not a great neighborhood.After seeing periodic bursts of login attempts from there, I now block all inbound ssh from AS14061 (among several such bad neighborhoods) as no authorized clients are hosted there and there is a constant level of attempted attacks from there.
- petecooperUCEPROTECT Extortion Service: All Your Mails Are Belong To Us! (2009)https://www.aaroncake.net/misc/showthought.asp?thought=57
- throwaway67743This is not new, "UCEPROTECT" has been a garbage RBL doing this for decades (even listing blocks preemptively, so that when they're assigned they're unusable), nobody worth emailing actually uses it.
- rithdmcWhich Orange are you blocked on?I personally found Meteor in Ireland (previously owned by Orange) to be far more liberal with blocks on an unregistered mobile internet connection than other providers.Also, Orange UK have a much stricter block list to enforce than, for example, Orange FR.
- pelagicAustralI think what's happening is obviously not fair, and should be corrected, but I also what to say that I've had pretty bad experiences when working with DO. I think maybe what happens is that they take too long to weed out problematic accounts. Not going to mention any other provider so it's not assumed that shilling for someone else, but there are quite a few that are no in the AWS, GCP, or Azure tier and work just fine, so, shouldnt be too hard to find a replacement.
- cendyneUCEPROTECT is why I stopped self hosting my own email :(
- nottorpApparently in this uceprotect thing my home ip (business connection, fixed IP) has a "dns problem" because there's a PTR record at my ISP but not an A record.Seriously?The rest of the list is as credible as that?
- anonundefined
- ButlerianJihadFor a long time, the Internet has been replete with blocklists and reputation scores cultivated by admins who had the means to track such things. And ad-blocking software/DNS often gives users the chance to tap into those bad reputations and protect themselves.However, there is nothing preventing function/scope creep of these blocklists into things they should not be. Political bias, censorship, morality policing will trickle into blocklists. Furthermore these false positives are quite onerous for legit businesses and customers who sincerely want to connect. I've connected again to an ad-blocking DNS service, and many people may subscribe to filtering services, or simply be involuntarily subscribed, in the hopes that their Internet would stay usable, and scam-free.I suppose this is the price to pay in low-trust society (wild and wooly Internet). I wonder if the Great Firewall of China obviates the need for their citizens to throw up such protective measures.
- garaetjjteWhy do you think Orange is using Uceprotect? It seems unlikely that big corp would use some weird unknown list.
- diamondDrillits like we are in the grifted age
- seebeen[dead]
- tcdentForgive the snark, but I find it incredibly surprising that in your 20-year career you haven't arrived at the conclusion that self-hosting your own outbound email is not worth it, especially if you don't own and/or manage the reputation of your IPv4 block.
- mercurialuserI was reviewing uceprotect policies a couple of hours ago and what you say is really strange.Uce level 3 should never be used alone to block general tcp traffic.Are you saying that Orange is using uce level 3 to block email sent from your DO vm? Are you really sure that Orange blocks for this list only? Is it possible that your ip is on another RBL?If Orange is really blocking smtp based only on uce level 3 they are doing wrong: their system may be mis-configured or they have not read correctly hiw level 3 is populated.Or - probably - they did on pourpose!Today I checked september smtp traffic: almost 99% of traffic coming from uce level 1 (single ips) was spam. Traffic hitting level 2 but not present in level 1 (subnets, one I checked was /15!!) was also 99% spam.Of the 5000k messages received, very few arrived into the mailboxes. A lot of messages were blocked by following spam checks and the few remaining were flagged as spam.I feel your pain. If you host on DO and you send email, you should look for a email provider that will funnel your emails.Ps: i repeat, email shoild not be bloocked only by uce level 3