Monday, 6 February 2006

I'm going to be on TV today

In case you care, and if you're anywhere near CNBC today at 4.15-ish (EST), I'm going to be interviewed live from London. Topic is the ongoing AOL/Yahoo/Goodmail thing.

Hopefully it'll be more contentful than my soundbite on NPR's Marketplace show
this morning.

GoodMail Systems and AOL -- What's Going On?

Goodmail Systems has announced that AOL will be using its "postage stamp for email" approach to replace or augment AOL's current "enhanced whitelist" functionality. What's going on?.

In essence, AOL has outsourced some of its whitelist to Goodmail. Goodmail will impose a "tax" on commercial senders, if they wish to have first class delivery to AOL users' inboxes. First class in this context means bypassing spam filters and having images and links function correctly without the user being warned of their potential danger. A portion of the tax revenue is returned to AOL (the amount is undisclosed, but we believe it to be at least half) and the rest is retained by Goodmail.

This is an interesting service provided to senders by Goodmail -- the value provided in return for the fees is that senders get better delivery rates and more accurate feedback about whether messages got delivered and/or opened. However, there are also negative implications.

Some senders will object to being "held to ransom." The danger to Goodmail and AOL is that one of the big senders will be big enough to encourage AOL users to use a different email service. Alternatively, they may simply put more emphasis on their own portal messaging systems, like eBay is beginning to. Then they just have to send short text-only mails to AOL users to ask them to check the eBay site.

And what of the poor AOL customer? As I've said before, Goodmail adds no practical value from the user's perspective. Goodmail (and Iconix) deliberately miss the opportunity to protect them from phishing -- there's no big red flashing warning icon when a phishing email is received.


Tags:.

Sunday, 5 February 2006

Need a place to stay in SF?

If you need an comfy alternative to a hotel for a few nights in San Francisco, check out The 23rd & Castro Retreat... "Located in desirable Noe Valley minutes from the The Castro district, surrounded by eclectic shopping and fabulous restaurants. The 23rd & Castro Retreat offers the best of San Francisco with all the comforts of home."



brrreeeport

Correction to Saturday's NY Times story

Saturday's New York Times contained a story quoting my opinion on the Goodmail debacle. (I was wearing my Ferris Research hat, natch.) It also had a pie chart, attributed to Ferris Research, illustrating the proportions of legitimate email that are sent to businesses, sent to consumers, and sent by spammers. The caption of the chart implied that 20% of email gets accidentally deleted or quarantined by spam filters. Ouch. While "false positives" are still a significant problem, this figure is of course far too high. Unfortunately, the sense of the original statistic seems to have been lost in the editing process.

Typical false positive rates experienced by spam filter users are closer to 0.1%. State-of-the-art filters can achieve 0.001% -- equivalent to about one legitimate message per month.

The figure that I gave the NYT was the "lost" proportion of legitimate, bulk email -- e.g. legitimate direct marketing and transactional messages. This is roughly 20%, but dropping fast as better spam filters are implemented. While the Times' caption wasn't wrong, it was apparently misleading without the original context, as illustrated by the requests for clarification I've since received!


Tags: .

Monday, 30 January 2006

Fewer spammers forging the From header

It's a truism that the "From" or "Sender" of a spam email message is almost always forged -- it's hardly ever the actual sender. That could be changing. I've noticed an increasing volume of spam hitting my spamtraps that appears to have a valid return address.

Why would this be? I can think of at least four reasons:

  • It's illegal in some countries -- but many other actions related to spamming are also illegal
  • Increasing use of sender authorization technologies such as SPF, Sender ID, and DKIM by spam filters -- spammers think that a valid return address makes it more likely that their spam will get delivered
  • Increasing use of "call to action" filtering -- spam that invites the user to reply by email is harder to filter than spam that quotes a web site or phone number
  • Lower likelihood of being cut off -- people are unused to sending complaints about the owner of the sender domain; overworked abuse desks are less likely to notice that the spam implicates the sender domain

Tags: .