Unsubscribe is a potential attack vector

For not getting e-mail notification at all, there is a workaround such as to change the e-mail address in the account. The different e-mail address is not known to the spammer by default.

2 Likes

@MikeMcQ correctly noted that renewal reminder e-mails are best-effort only; we don't recommend you rely on them to the point where a DoS of them would have any significant impact.

We want to improve a number of things about our e-mail handling, and haven't forgotten peoples' great suggestions about it. Unfortunately, we can't commit to a timeframe for this work.

4 Likes

A bit off topic, sorry. What does activating the unsubscribe link do? Does the e-mail address get unsubscribed from the notifications, or the account, or the account - e-mail address pair?

3 Likes

Unsubscribing suppresses the email address from all our automated mailings for one year, across all accounts.

5 Likes

@bruncsak Just adding to what James wrote - the issue is that it is impossible for a user to re-subscribe to any mailings, due to an implementation detail of their Email Service Provider's (ESP) platform. It's a well-known behavior of that platform. (A user with access/permissions to the ESP's management panel can manually change this, but it's not an usable solution as it is manual and not scalable - it incurs a fixed cost of at least 10 minutes employee time to sign-in and perform the various operations, and additional incremental costs per address)

The only workaround available to users is to use an ACME API endpoint to change the email address, however this has created issues for large-scale end-users who utilize multiple accounts. A few folks on this forum have written scripts to help automate this, but it's still a pain for everyone involved.

3 Likes

With the exact same email address (for 1 year from requested unsubscribe)
But can be done with any non-previously unsubscribed email address.
Which is the entire argument against this being an unavoidable abuse vector - it is NOT.
OPT-IN or even Double OPT-IN would fix this carp in no time flat.
Until then, we just need to stay one step ahead of the abuse.

4 Likes

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.