At one time quite recently, Cloudflare was on Spamhaus's "Don't Route Or Peer" list. Imagine where the world would be if anyone gave a shit about that list.
But if an entire ISP is blocking you based on UCEPROTECT, which is designed for email spam filters - are you sure? An ISP that blocked all of DO would get so many complaints and be open to so much legal liability. Usually these are only used for email filtering.
I disagree. Normally you can reach out to request delisting, and it's free.
As I explained, Orange's security filter seems to automatically block requests at the DNS level if your website's domain resolves to an IP listed on UCEPROTECT Level 3. In this case, that appears to be the entire DigitalOcean ASN.
The uceprotect Level 3 page clearly says using the list will cause collateral damage and should only use as an indicator as part of a spam score, not to act purely on it.
So, yes, if a service provider is known for having a lot of spam coming from it, it makes sense to be on there. They're not saying every IP is bad, they're literally stating the opposite (which seems fair).
So, if Orange are blocking purely based on it, not only are they using a spam filter as a DNS query/web filter (given uceprotect seems to flag based on mail spam traps based detections etc.) and ignoring their documentation (which says it shouldn't be used to block on it's own).
DigitalOcean has been on their list for a while, they say something like “if you don’t want to be flagged as spam, dont host on a site that hosts spammers” which is pretty ridiculous given every cloud platform does
Hosting providers should be good citizens of the network and immediately terminate spammer accounts. This used to be standard practice until about 2015. When suddenly management decided it’s more profitable host spammers than not.
I think this is a great policy decision by uceprotect.
Sounds like this should go via Orange they have means to slap UCEPROTECT on the wrist. It also looks like it would be in Orange business to have proper spam lists not ones like that.
I personally found Meteor in Ireland (previously owned by Orange) to be far more liberal with blocks on an unregistered mobile internet connection than other providers.
Also, Orange UK have a much stricter block list to enforce than, for example, Orange FR.
I think what's happening is obviously not fair, and should be corrected, but I also what to say that I've had pretty bad experiences when working with DO. I think maybe what happens is that they take too long to weed out problematic accounts. Not going to mention any other provider so it's not assumed that shilling for someone else, but there are quite a few that are no in the AWS, GCP, or Azure tier and work just fine, so, shouldnt be too hard to find a replacement.
For a long time, the Internet has been replete with blocklists and reputation scores cultivated by admins who had the means to track such things. And ad-blocking software/DNS often gives users the chance to tap into those bad reputations and protect themselves.
However, there is nothing preventing function/scope creep of these blocklists into things they should not be. Political bias, censorship, morality policing will trickle into blocklists. Furthermore these false positives are quite onerous for legit businesses and customers who sincerely want to connect. I've connected again to an ad-blocking DNS service, and many people may subscribe to filtering services, or simply be involuntarily subscribed, in the hopes that their Internet would stay usable, and scam-free.
I suppose this is the price to pay in low-trust society (wild and wooly Internet). I wonder if the Great Firewall of China obviates the need for their citizens to throw up such protective measures.
Why do you think Orange is using Uceprotect? It seems unlikely that big corp would use some weird unknown list.
All of the spam blocklists are like this.
At one time quite recently, Cloudflare was on Spamhaus's "Don't Route Or Peer" list. Imagine where the world would be if anyone gave a shit about that list.
But if an entire ISP is blocking you based on UCEPROTECT, which is designed for email spam filters - are you sure? An ISP that blocked all of DO would get so many complaints and be open to so much legal liability. Usually these are only used for email filtering.
I disagree. Normally you can reach out to request delisting, and it's free.
As I explained, Orange's security filter seems to automatically block requests at the DNS level if your website's domain resolves to an IP listed on UCEPROTECT Level 3. In this case, that appears to be the entire DigitalOcean ASN.
You probably have standing to sue Orange for damages if they're blocking your customers from you based on bullshit criteria.
I am not a lawyer, so consult one.
The uceprotect Level 3 page clearly says using the list will cause collateral damage and should only use as an indicator as part of a spam score, not to act purely on it.
So, yes, if a service provider is known for having a lot of spam coming from it, it makes sense to be on there. They're not saying every IP is bad, they're literally stating the opposite (which seems fair).
So, if Orange are blocking purely based on it, not only are they using a spam filter as a DNS query/web filter (given uceprotect seems to flag based on mail spam traps based detections etc.) and ignoring their documentation (which says it shouldn't be used to block on it's own).
Well, if it's just an indicator, why not delist automatically on request, as other blocklists do? It seems inappropriate to charge for this.
Theoretically speaking, a person could get themselves blocked, request an unblocking, and keep on spamming, hoping they won't get blocked again.
And not just charge. You need to get a subscription even!
UCEPROTECT is why I stopped self hosting my own email :(
DigitalOcean has been on their list for a while, they say something like “if you don’t want to be flagged as spam, dont host on a site that hosts spammers” which is pretty ridiculous given every cloud platform does
It’s not ridiculous.
Hosting providers should be good citizens of the network and immediately terminate spammer accounts. This used to be standard practice until about 2015. When suddenly management decided it’s more profitable host spammers than not.
I think this is a great policy decision by uceprotect.
Following your logic, we'd need to block the entire US, since that's where DigitalOcean's ASN is registered.
Sounds like this should go via Orange they have means to slap UCEPROTECT on the wrist. It also looks like it would be in Orange business to have proper spam lists not ones like that.
While I absolutely agree that Orange is acting irresponsibly here, I also understand that they're not the only ones who rely on UCEPROTECT.
Which Orange are you blocked on?
I personally found Meteor in Ireland (previously owned by Orange) to be far more liberal with blocks on an unregistered mobile internet connection than other providers.
Also, Orange UK have a much stricter block list to enforce than, for example, Orange FR.
Orange FR.
I think what's happening is obviously not fair, and should be corrected, but I also what to say that I've had pretty bad experiences when working with DO. I think maybe what happens is that they take too long to weed out problematic accounts. Not going to mention any other provider so it's not assumed that shilling for someone else, but there are quite a few that are no in the AWS, GCP, or Azure tier and work just fine, so, shouldnt be too hard to find a replacement.
For a long time, the Internet has been replete with blocklists and reputation scores cultivated by admins who had the means to track such things. And ad-blocking software/DNS often gives users the chance to tap into those bad reputations and protect themselves.
However, there is nothing preventing function/scope creep of these blocklists into things they should not be. Political bias, censorship, morality policing will trickle into blocklists. Furthermore these false positives are quite onerous for legit businesses and customers who sincerely want to connect. I've connected again to an ad-blocking DNS service, and many people may subscribe to filtering services, or simply be involuntarily subscribed, in the hopes that their Internet would stay usable, and scam-free.
I suppose this is the price to pay in low-trust society (wild and wooly Internet). I wonder if the Great Firewall of China obviates the need for their citizens to throw up such protective measures.