HN user

jrodom

85 karma

CTO @ Mailgun, josh at mailgun dot com

Posts6
Comments30
View on HN

Josh CTO of Mailgun here - In this example, there is no actual sharing of domain reputation with other customers. Most inbox providers base reputation on the DKIM domain, which in this case is "sandbox.mgsend.net" not the header from address.

Each message is uniquely signed by the sending domain belonging to the account owner, meaning that the domain reputation cannot be borrowed/shared between customers.

Josh/CTO of Mailgun here - I took a look at this case and these messages were being sent from the sandbox feature of our service. The sandbox only allows messages to be sent to "authorized recipients" through an opt-in mechanism, which makes it impractical for spamming and phishing. The purpose of this feature is to allow customers to get comfortable with the interfaces and test the product in a safe way without having to add DKIM/SPF records. I reviewed these messages and confirmed there is no illicit behavior, likely just a misconfiguration from a user of radiotoolbox.

If this is a recent occurrence, I'd be happy to have our application security team take a look. To be clear, there hasn't been any kind of breach, but our customers are often targeted in phishing schemes that results in the disclosure of account credentials. We're continually adapting our defenses, but this is responsible for the majority of credential leaks.

Thoma Bravo has been a great partner for us. Our management team has maintained a high level of autonomy in driving the vision and strategy of the company including the decision to pursue this acquisition. There is a tremendous network current/past companies with a wealth of experience that we've been able to draw from that already has proven to be incredibly valuable as we continue to scale the company.

We're really excited about MJML. Creating messages that render properly on all email clients is challenging and MJML solves the problem in a very developer friendly way. You should expect MJML and the Passport editor to be integrated into Mailgun in the near future!

Can you email your ticket number to josh@mailgun.com and I'll take a look? This definitely isn't typical and I'll get this resolved immediately for you.

It depends. Most hosting providers will either discourage you or prevent you from relaying messages from your servers, so that is something you need to check for. Also, you'll want to make sure that your dedicated IP is persistent and won't be lost across reboots. Once you establish a good sending reputation, that's valuable in making sure your messages reach the Inbox.

In the case of Mailgun, you should be assigned an IP with a neutral reputation. For example, before dedicated IPs are reassigned we leave them dormant for at least a month, usually much longer, before assigning to a new customer.

This is an area that we're actively working to improve. The system is designed so that customers who are sending high quality messages get moved into better IP addresses. We look at metrics like complaint, bounce, and engagement rates to help make these decisions. This works much of the time, but is imperfect, especially when you start using Mailgun for the first time. We're developing and iteratively rolling out several machine learning classification systems that look at various features when you signup for Mailgun and place your account into better IP pools based on our internal risk calculation.

If you are seeing continuous problems, I'd love to take a look! My email address is on my profile.

We are working on SSL support now. While this has drawbacks, you can terminate on a service like Cloudflare and we can enable HTTPS link writing for your sending domain. Otherwise, hangtight for a more integrated solution.

This is (and probably always will be) a work in progress for us. Our systems promote you into higher quality IP ranges as you send better e-mail. The downside is that this is a reactive process. We have some experiments that we're starting to run to help improve onboarding and IP assignment for legitimate users. In the meantime, support is always happy to review your account and expedite this process for you.

I'm not sure why there was a disconnect with our sales team, but I'm happy to help. Could you e-mail me with more details? josh [at] mailgun [dot] com

The model clause process is not trivial and often requires work between the legal teams from Mailgun and the respective EU company. We've gone through the process and can definitely help any of our existing or prospective customers get through it, though. Every business is a little different, so we'd need to talk through the specifics.

On issue #1, we're going to update the language around this in our control panel and put together better documentation. In reality, having MX records are important to allow for sender address verification [1], which many SMTP servers require.

On issue #2, Thanks and apologies for the slow response, This ticket slipped under our radar.

To give you a quick answer: we'll look into the approach you described in your blog post as well as RFC 6376. It seems legit but we'll need to do some more testing to ensure that deliverability does not suffer due to changing how we sign messages. If deliverability does suffer, we can always make this something that is an optional security setting that can be toggled, like how you can enable and disable TLS certificate validation now.

Our security engineer will take a look and reach out to you with more details in the ticket.

[1] https://en.wikipedia.org/wiki/Callback_verification

We (Mailgun) have a process to support EU model clauses that has allowed us to continue supporting most of our EU customers. There are a lot of nuances to all of this, so it's best to talk to someone on our team who has expertise and access to our legal team to come up with a plan for you.

Additionally, the landscape will change on this once Privacy Shield, the successor to Safe Harbor, is enacted. It will offer stronger protections and guarantees to EU customers without the need to have model clauses signed between entities.

Our sales team sales [at] mailgun [dot] com can talk to you about your specific situation.

We are working on this based on what we have discovered so far, there appears to be a content issue that's impacting deliverability. We have ruled out any issues with the IP address these messages are being sent from. Our lead reputation engineer going through this and we've not been successful in reaching out to the inboxtrail team yet.

Disclosure: I lead product development for Mailgun.

Great feedback. Our UI is definitely something that could use some attention and is a big priority for us this year. We've made some big hires that are 100% focused on making it a great experience.

If you'd like to talk about more specifics, please reach out at anytime josh [at] mailgun [dot] com.

We're looking into how that test is being run, but it's not at all reflective of what actual users experience on the platform. There are many factors that could impact what is being sent to spam that aren't disclosed in these kind of tests.

It's true we offer a premium product, but we do so at a competitive price. At scale, our pricing model compares favorably with Sendgrid. Our pricing strategy is all about simplicity and providing lower prices as you grow with us. We don't have any kind of feature gating pushing you into higher tiers nor do we have punitive overages.

There are many factors that impact deliverability that aren't reflected in the type of simple test InboxTrail conducts. Like most ESPs, your reputation builds on Mailgun as you send with us. If for whatever reason you are experiencing a deliverability problem, you can always reach out to us and we'll help you with any issues you have. We support many large and fast growing customers who are all seeing a >99% delivery rate.

Our support team is here to help 24/7. We have a great team here that is proud of the work we do for our customers.

Disclosure: I lead product development at Mailgun.

Mailgun | Full Stack Developer | San Francisco, CA / Austin, TX | Full Time | On Site or Remote

Mailgun is the e-mail service for developers. We support companies you know and love including Lyft, Slack, and Pagerduty. We're hiring a full stack developer to work on our control panel team. As a member of this team, you will be responsible for helping build a great customer experience for each and every customer who uses our product.

Interested? Learn more about the position @ https://github.com/mailgun/hiring/blob/master/fullstack.md

On site candidates are preferable, but we are willing (and have hired) remote candidates who are exceptional and have a strong track record as a high performer on a remote team.