BLOG

Author: steve

Apple MPP reporting and geolocation

A while back I wrote about Apple Mail Privacy Protection, what it does and how it works. Since MPP was first announced I’d assumed that it would be built on the same infrastructure as iCloud Private Relay, Apple’s VPN product, but hadn’t seen anything from Apple to explicitly connect the two and didn’t have access […]

2 Comments

Apple MPP

You’ve probably heard about Apple Mail Privacy Protection. Email marketing chat has been all a-twitter about it since it was announced in June. Skipping over all the “Openpocalypse” panic, what is it and what does it do? Image Loads It’s all about images in email and how they’re loaded (particularly invisible one pixel images that […]

3 Comments

Cyber Monday

— @TwistedDoodles

No Comments

The OSI Seven Layer Model

In the 1970s, while the early drafts of the Internet were being developed, a competing model for networking was being put together by the ISO (International Organization for Standardization). The OSI (Open Systems Interconnection) Model broke the work needed to implement a distributed network service into seven separate layers of abstraction, from the physical infrastructure […]

No Comments

Authentication

Some notes on some of the different protocols used for authentication and authentication-adjacent things in email. Some of this is oral history, and some of it may be contradicted by later or more public historical revision. SPF Associates an email with a domain that takes responsibility for it. Originally Sender Permitted From, now Sender Policy […]

1 Comment

Alt-text and phishing warnings

For a long time one of the “best practices” for links in html content has been to avoid having anything that looks like a URL or hostname in the visible content of the link, as ISP phishing filters are very, very suspicious of links that seem to mislead recipients about where the link goes to. […]

No Comments

Link tracking redirectors 2

It’s not too difficult to build your own link redirector, perhaps a few hours work for a basic implementation me, yesterday Yesterday I suggested that link tracking wasn’t too complex, but didn’t really have anything to back the claim up. And nobody trusts developer time estimates. So I cranked DEF CON Radio and wrote a […]

1 Comment

Link tracking redirectors

Almost every bulk mail sent includes some sort of instrumentation to track which users click on which links and when. That’s usually done by the ESP rewriting links in the content so they point at the ESP’s tracking server, and include information about the customer, campaign and recipient. The recipient clicks on the link in […]

No Comments

New laptop, old reminder

I have a new laptop. New OS (maybe this year will be the year of Linux on the Desktop?). New hardware problems. New applications. New keyboard layout. New mail client. It reminded me of another reason why you want to keep the email address in your From: consistent – it’s something some users will use […]

No Comments

CAN-SPAM Again

The US CAN-SPAM act is the primary US legislation covering commercial email. It’s been around since 2003, but I still see a steady stream of questions about it, and the folkloric answers to some of them are all over the place. What does CAN-SPAM require? The important requirements are Don’t use false or misleading header […]

No Comments

Recent Comments

Archives