16 ms·
Major European payment processor can't send email to Google Workspace users
- Deukhoofd 7mo agoMight want to consider Adyen, which should support IRIS, the Greek instant payment system.
- thatha7777 7mo agoThank you for the recommendation! That I couldn't sign up using a form and I had to "talk to their team" was a turn-off for my (extremely extroverted) self.
- nottorp 7mo agoThat usually means you can't afford it unless you have people working for you that do the 'talk to the team' thing.
- cl0ckt0wer 7mo agoDo you want to enable receiving email for viva.com? sign up for VibeCodedSAAS for E49.99/month
- EGreg 7mo agoJust did! My mac mini got pwned though and I wish I didnt give it SMTP accesss… sigh I just hope my OpenClaw skills registry doesnt have malware anymore. I sure trust my supply chain of vibecoded software!
- that_guy_iain 7mo ago[flagged]
- iso1631 7mo agoIt does seem unlikely that there are no customers on google workspace who have tried to use viva. I don't do payment processing, and my email is via zoho, so I've no idea how large either of those groups are. I wonder what google workspace support said.
- thatha7777 7mo agoI suspect that Google going out of their way to make this required had a very reasonable and thought-out process, while the sender's omission was on oversight, so I haven't contacted Google Workspace support. What's truly iffy is that GMail doesn't have the same strict requirements, and there's no way (at least that I found) to turn it off for my Google Workspace domain.
- iso1631 7mo agoWikipedia says Viva.com is a multi-billion dollar startup It seems unlikely you're the first company using viva.com and using google workspace. Clearly the problem here is that viva.com emails aren't arriving on your google workspace, despite what their support process says. viva.com emails do arrive on other email providers, so seems unlikely to be problem with your viva.com account It seems unlikely workplace blocks all viva.com emails otherwise more than you would have complained. Whether that's viva's problem or google's problem is a separate problem.
- flerchin 7mo agoInteresting, your take away is that Google is the one with the bug here?
- that_guy_iain 7mo agoMy takeaway is there is no bug. My takeaway is that his test email bounced because he didn't have the reputation Viva does. Emails are handled on a reputation basis, this is why we use email service providers like Sendgrid, Mailgun, Postmark, etc.
- flerchin 7mo agoI think that's a misunderstanding of the tale. Viva sent a "click here to verify your email" to OP. That email never arrived because Google rejected it for missing a header. OP tried to tell viva, but they don't wanna hear it because OP worked around it.
- yatac42 7mo ago> My takeaway is that his test email bounced What test email? I see no mention of a test email in the blog post. The mail that bounced was the one with the verification link from Viva.
- that_guy_iain 7mo agoSo you think he had access to Viva's email servers to see the response? No, he clearly tested it himself and used his credentials to send it.
- bn-usd-mistake 7mo agoThe log line is from Google Workspace which exposes it to its customers for incoming mail
- thatha7777 7mo agoThank you! I added a screenshot of the Google Workspace Admin log screen... just becuase.
- basilikum 7mo agoIf you read two paragraphs further than the Tl;Dr: > To unblock myself, I switched to a personal @gmail.com address for the account. Gmail's own receiving infrastructure is apparently more lenient with messages, or perhaps routes them differently. The verification email came through.
- renewiltord 7mo ago1. Email didn’t arrive in his inbox of his Google workspace 2. He checked workspace email logs (with admin you can do this on gsuite) 3. It showed the intentional non-accept 4. Comprehending the problem, he switched to personal Gmail 5. The email arrived 6. He informed the sender of the original problem which he worked around 7. Sender is tech-illiterate and did not realize what the problem is. This is common with first line customer support so that happens. The question to ask is whether you are literate in English or you skimmed too fast. Because I did a 30 s read of the article and got that.
- that_guy_iain 7mo ago> 1. Email didn’t arrive in his inbox of his Google workspace > 2. He checked workspace email logs (with admin you can do this on gsuite) But it didn't arrive, so how was it in his email logs!?!?!?! Are you tech literate? Isn't this the second time you've been asked or was I rate limited at that point?
- johnnyfaehell 7mo ago[flagged]
- Dylan16807 7mo agoEU doesn't require edits, what the hell? And nobody "decided to stop you" if you just hit the end of the 2 hour edit window. But go on, what's your tagline.
- that_guy_iain 7mo ago[flagged]
- Dylan16807 7mo ago[flagged]
- that_guy_iain 7mo ago> You don't have the right to complain to random websites without punishment. And nobody punished you. And "ability to redress" is something you still have. And there are no damages. Well, you see Dang aka Daniel edited the settings on my account to stop me replying, or that's what I've heard, and pointing out the absolute lie that the blog post is. And that did hamper my ability to redress and people have been lying about me so there are damages. But even if it's just rate limiting that hampers my ability especially since it's been optimised heavily for high traffic so there is no technical reason for it since it's a file-based datastore. > You brought it up. Though it's pretty obvious you're a liar. I said someone there should know. I didn't say everyone should know. I clearly made it quite clear it was insider knowledge. This is what is known as a flex. I want to tell you my tagline because it's awesome but you can just call me a keyboard warrior.
- Dylan16807 7mo agoI thought the problem was inability to edit, now it's inability to reply? Also you're wrong about the post and you don't know what damages are and your flex failed real bad. Good luck in life. And nobody ever has to let you post on their private website. Right to redress is unrelated. If you take away anything from this conversation, please let it be that.
- iso1631 7mo ago> Their support team's response to my detailed bug report: "your account has a verified email, so there's no problem." Sadly I doubt their system is xkcd806 compatible ether. This isn't an engineering problem, it's an ITIL problem. To be fair 99% of these complaints will be dealt with by the flow chart. Sadly people on the front line are either not knowledgable enough or not empowered enough to bust out of that straightjacket.
- thatha7777 7mo agoSHIBBOLEET. I was seriously thinking of this when I contacted them :)
- tracker1 7mo agoI usually reply with snark dialed up about 50% asking if anyone had actually read the original message. And include detail about how it is not, in fact, "ok" The other day, I literally had trouble signing into a website... then I tried filling the contact us form, about the bug... only to have that fail... call in, have the person on the other end schedule my appointment, then almost drop the call without actually logging my bug report/complaint about the whole issue that had me calling in the first place.
- flerchin 7mo agoThe specific bug is annoying, but that there's no way to report such a thing is an exact hallmark of our current corposphere.
- deleted 7mo ago[deleted]
- newsoftheday 7mo agoGoogle's Postmaster Tools site has a "Report deliverabilty issue" link at the bottom left navigation column. https://postmaster.google.com/v2/sender_compliance https://postmaster.google.com/v2/sender_compliance
- stonogo 7mo agoWhich is, of course, hidden behind a login wall
- dathinab 7mo agoit isn't a google bug Message-Id being required for automated mails is a de-facto industry standard while the consequences differ between mail provider, it missing will also make it much more likely for mail to be reject or put into the spam folder It's also well known. Pretty much viva engineers fucked up doing proper research. Now to be fair: - it sucks that you can't just implement the RFC(s) - the standards suck, docent of different RFCs overlapping and replacing each other and referencing often older versions of other RFCs, with docents of ways to do the same things of which only some can be used reliable in practice and a common gaps in the standards about edge cases or about the "higher level semantics" of constructs. - so overall mail seems very simple at first but if you want to automated send mails reliable internationally it's a total pain and Message-Id is just the head of the iceberg.
- st_goliath 7mo ago> Viva.com's outgoing verification emails lack a Message-ID header, a requirement that has been part of the Internet Message Format specification (RFC 5322) since 2008 > ... > `Message-ID` is one of the most basic required headers in email. Section 3.6. of the RFC in question (https://www.rfc-editor.org/rfc/rfc5322.html https://www.rfc-editor.org/rfc/rfc5322.html) says: +----------------+--------+------------+----------------------------+ | Field | Min | Max number | Notes | | | number | | | +----------------+--------+------------+----------------------------+ | | | | | |/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/ ... bla bla bla ... /\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/| | message-id | 0* | 1 | SHOULD be present - see | | | | | 3.6.4 | |/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/ ... more bla bla ... /\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/\/| | optional-field | 0 | unlimited | | +----------------+--------+------------+----------------------------+ and in section 3.6.4: ... every message SHOULD have a "Message-ID:" field. That says SHOULD, not MUST, so how is it a requirement?
- ale42 7mo agoThe official definition of SHOULD per RFC2119: 3. SHOULD This word, or the adjective "RECOMMENDED", mean that there may exist valid reasons in particular circumstances to ignore a particular item, but the full implications must be understood and carefully weighed before choosing a different course. Not sure how the people at Google interpreted this about the message-id
- Juliate 7mo agoFor producers, ignoring a SHOULD is riskier because it shifts the burden to every consumer. For consumers, ignoring a SHOULD mostly affects their own robustness. But here Google seems to understand it as a MUST... maybe the scale of spam is enough to justify it. Users are stuck between two parties that expect the other to behave.
- basilikum 7mo agoWith fintech that surprises me not the slightest bit. Financial institutions are filled to the brim with unbelievably incompetent people. A large part of it is probably willful ignorance, too. It's often truly staggering that a financial company I interact with in day to day live is even able to exist. That's until I remember that all the others are just as incompetent. "Major European Payment Processor" really just translates to "Major European Incompetence Center".
- oasisbob 7mo agoWith a broad statement like this, I would usually just suggest this is inflammatory and surely overstated. However, I've also worked at a financial institution which used core systems by Harland Financial Systems. Their "encryption" for data in transit from teller workstations to the core system was just a two byte XOR, and they sent the key at the beginning of the connection! Was so unbelievable to be able to crack this in under a half-hour after noticing patterns in a PCAP. Wouldn't have believed it if I hadn't seen it with my own eyes. That fraud was good enough for our regulators and theirs, so I have no doubt the industry is filled with rotten incompetence through and through.
- ryandrake 7mo agoThe biggest disappointment in my 30 years of adulting has been how much absolute, shameless incompetence is out there in the workforce. When I was a kid, I naively thought that adults were smart and knew what they are doing. Then I got into industry and saw so many people just outright bluffing for 8 hours a day before going home, day in and day out. It's amazing that society even functions at all.
- zos_kia 7mo agoI think that's actually an interesting feature of society as a macro system. It is very fault tolerant, which is frustrating for any power user but without which the system as a whole would not function at all.
- saurik 7mo agoMy pet peeve are services that go out of their way to include a text/plain alternative message part but send something useless, such as the message without the key link. One time I seriously ran into a service just send a short one-sentence note along the lines of "this is a plain text email" as the plain text part. If you don't want to support plain text, maybe just don't send the alternative part?
- Marsymars 7mo agoSo I'm wondering a bit here - I've seen an implementation where emails to send only have html versions, but as part of the sending process the html is run through a Lynx browser process with the -dump command to get the plain text, which is included as the text/plain part of the email. Is there actual value to this? e.g. Is the output of Lynx's text dump better for plain-text email clients than whatever they'd display for html emails?
- cube00 7mo agoI find the ones that try to be cute the most frustrating because these appear on the new message notifications so I can't just delete them straight from the notification. We'd love to share this exciting announcement but you'll a different email app. Although I guess the argument will be that email clients should use AI to summarise the HTML into a plain text summary.
- ninjin 7mo ago
- egorfine 7mo agoThis bug will not be fixed before the Environmental Impact Study is concluded on it.
- amelius 7mo agoGripe only related to email in general: what annoys me to no end is that if my boss forwards me an email and asks me to reply to it (to everybody in the original email) then I have to type in or copy+paste all the addresses from the Fwd attachment (using Fastmail, but this problem exists everywhere). Instead, there should be a button to make that easy.
- fy20 7mo agoThere's actually nothing that prevents that, if you craft the right headers you can reply to a thread you were not included in, and have it show up as a reply in the thread of common clients (tested Gmail and Outlook). We added this feature at my $dayjob and I was quite surprised there is no authentication. But thinking about it, this is how mailing lists work (you aren't explicitly specified in "To:") so it makes sense you can do this.
- kotaKat 7mo agoSudden realization that one of my American banks must be having email problems with this too because I use a Google custom email and recently got an in-app notification from my bank saying "we're unable to email you" (and a letter) yet my email works perfectly fine... switching to consumer gmail worked.
- deleted 7mo ago[deleted]
- OkayPhysicist 7mo agoDo you actually not receive their emails? Fidelity uses tracker dots to check email receipt, which drives me nuts, because like any sane person I don't allow emails to load images without damn good reason. My brokerage should not be sending me cute dog photos, thus I have no need of their images. So they send me an email, send me another email saying they can't reach me by email, then mail me a letter with the same content as the original letter, and mail me an additional letter saying they can't reach me by email.
- kotaKat 7mo agoFor some reason the announcement they sent me didn't show up in my email, which was odd. I've had other bank notifications come through unopened before, even after that announcement.
- reeddev42 7mo agoEmail deliverability is the reason I gave up on email entirely for my side project and built on Telegram instead. Setting up SPF, DKIM, DMARC, warming up a domain, monitoring reputation, dealing with bounces and complaints... all of that just to maybe land in someone's inbox. With Telegram you send a message via the Bot API and it arrives. 100% deliverability. No spam filters. No authentication chain. The message just shows up with a notification on their phone. Obviously Telegram has its own limitations (smaller user base in the US, less formal). But for anything where you need reliable message delivery to people who opted in, messaging platforms have a massive advantage over email in 2026.
- newsoftheday 7mo agoSome of us selfhost email, like me for 30+ years, and have 100% deliverability.
- manuelabeledo 7mo agoUnless your email daily volume is close to zero, this is unlikely. I have had random emails from Google Workspaces to Microsoft 365 be rejected because of a rule that blocked whole IP blocks.
- jmuguy 7mo agoMost of that can be mitigated, or at least centrally managed, using an ESP like Mailgun or Sendgrid. It is a pain in the ass though, coming from someone that had to dig their domain out of "low" reputation with Google Postmaster.
- bossyTeacher 7mo agoUntil the platform owner bans for whatever reason and if communication by way of the platform was your only means of communication with your customer base, that's the platform owner having the power to destroy your business. No different that businesses that rely on the neverending goodwill of the mobile app store owners. One misstep and your business is gone with no recourse whatsoever. Protocols > Platforms. Always.
- 7mo ago
- camgunz 7mo agoThe most damning thing about this is they didn't test their email infra w/ Google Workspaces. Imagine what else they didn't test.
- ejpir 7mo agoyeah, because the whole world uses Google workspaces, right /s
- hn_go_brrrrr 7mo agoThat and MS Office are pretty darn popular. Not the whole world, but a very decent percentage of your users.
- AJ007 7mo agoMaybe the whole thing was intentional, right at the footer of viva "Cloud services by Microsoft Azure" ; #1 I've never heard of viva before #2 I've never seen an azure logo at the footer of a website.
- looperhacks 7mo agoIf I were to test an email delivery system, I would test Gmail. I probably wouldn't test Google Workspaces, because I'd (wrongly) assume that they work the same.
- shadowgovt 7mo agoNo, just over 6 million paying business customers. But hey, if you're in a business domain where categorically leaving 6 million potential clients-who-are-demonstrated-to-spend-on-things isn't an issue? One fewer thing to worry about, right? ;)
- tick_tock_tick 7mo agoCertainly enough where this is embarrassing incompetence by them.
- vimda 7mo ago
- mogoh 7mo agoThe problem is always e-mail itself. It is terrible standardised and hard to get "right".
- shevy-java 7mo agoThe bigger issue here is that Europe depends way too much on the USA in so many areas. This is not good - you can be constantly blackmailed when you have people such as Trump in charge. I don't think the EU can be fixed, but at the same time I also think the less Europeans depend on outside factors (in particular the USA) the better. Canada kind of showed how to do it. Granted, Canada is also dependent on the USA in numerous ways and most of this is hard to fix (most Canadians live in the south aka close to the USA and trade is primarily done via the USA; security has also been largely outsourced onto the USA and so forth). The sooner people in Canada and Europe get moving away towards more independence from the USA, the better. And more cooperation would not harm either.
- thatha7777 7mo agoAs a European (who spent 15 years in the US), I coudln't agree more. And while I agree, at the end of the day, I just want the better product for me.
- pembrook 7mo agoTypically I'm a DIY type who loves tinkering and building... HOWEVER, I have learned the hard way to never apply that spirit to email. In Europe you see this stuff all the time with old school "IT" (what old industrial companies call tech) people balking at the prices of commercial API-based senders and email marketing ESPs. "Money to send emails in the cloud? HAH! Back at Siemens in 90s we were running millions of emails out of our servers just fine!" Nobody understands that deliverability has gotten immensely harder these days, and trying to DIY it if its not your core business is just plain stupid. I would never in a million years try to roll my own email, it's nightmarish legacy cruft and footguns all the way down, in everything from IP/Domain Rep to something as simple as the HTML in the email templates themselves. Microsoft Outlook and Gmail have the last word on everything in email, and their defacto duopoly (over B2B and consumer email respectively) means you play by the rules they set in 2008 and are too lazy to change or you don't get delivered. The protocol of email exists separately from the world of the actual inbox providers, which are locked down to insane degree given the security/spam concerns with email.
- chanux 7mo agoI recently had the misfortune of looking into email delivery to help a small business. I came out tired.
- jmuguy 7mo agoGoogle is at least less arbitrary than Microsoft. Microsoft will decide an email is spam today, and tomorrow the exact same email is perfectly fine. I think Google relies more and more on sending IP and domain reputation rather than content.
- Marsymars 7mo agoGoogle regularly sends legitimate email to my spam folder. Microsoft regularly sends legitimate emails from Microsoft to my spam folder.
- oasisbob 7mo agoDeliverability to Microsoft famously took a dive a bit over a year ago due to random arbitrary failures within their infrastructure causing DMARC/DKIM problems which they clearly were having problems diagnosing. Even with a six-figure email spend and weeks of troubleshooting the best response we could get from our mail provider was that they were having problems getting traction with Microsoft on the issue.
- afavour 7mo agoI have some level of sympathy with Google here, which isn’t something I often say. I recently switched from Gmail to Fastmail and by and large I’m happy with it. But I’ve been surprised by the amount of spam and (particularly) phishing emails I get in a regular basis. Google might be too strict in its filtering but it does serve a legitimate purpose.
- tietjens 7mo agoI've considered this switch. You're saying that previously gmail was dropping the emails, or they were landing in spam?
- afavour 7mo agoPresumably they were in spam. But I rarely ever checked my spam folder to know with certainty.
- havaloc 7mo agoI switched from Fastmail to Gmail/Workspace a year ago. I think but cannot conclusively prove that Gmail drops Apple transaction emails on occasion ( like receipts ). But I also think Fastmail dropped other emails too.
- jmuguy 7mo agoFastmail seems to go through periods where they're a little slower to adjust to new spam techniques, and they do rely on users filtering somewhat. About twice a year a few will slip through, but if I report them as spam they soon stop. I've been a happy customer otherwise for years, for what its worth.
- lowdude 7mo agoInteresting that you mention this, as I also switched to Fastmail recently and got more spam than before, but after marking it as spam for some time it now died down I think. This may also be a symptom of changing providers, where the previous provider knew the kind of spam I tended to get from past years, while Fastmail needed some time to get up to speed. Fingers crossed that the experience will be the same for you.
- _el1s7 7mo ago> For viva.com's engineering team, in case this reaches you: add a Message-ID header to your outgoing transactional emails. Don't know what they're using for sending emails, but that's something that should be handled by their email service provider, unless they're hosting their own email servers.
- basilikum 7mo agoInterestingly the MX record of via.com points to Google, but their verification emails could come from anywhere of course. The IP address in the log is also a Google IP, although that could also be the receiving IP.
- dathinab 7mo agomessage-id is (or at least was ~5-10 years ago) only required for automated mails, i.e. if you send a mail which looks mostly the same to a lot of users so if you (ab-)use protocols for mail clients to send automated mails they might very well not add Message-Id. In general many mail providers have both a way to send a mail where "they do some clever parts" (like adding Message-Id) and interfaces where they mostly just send what you give them. It's possible that they migrated from one solution which did automatically add Message-Id to one using interfaces where it doesn't happen without realizing that there is a mismatch in this solutions do implicitly add.
- nashashmi 7mo ago10 percent of the effort in building software compatibility with open source file specifications is dealing with knowing the specifications. 90 percent of the effort is dealing with errors in generated files by less worthy software programs. The RSS spec is one way. RSS readers do a fine job of interpreting files done the right way. Publishers don’t always do a good job with publishing error free RSS files. So RSS readers devs have to anticipate all sorts of errors and conduct error handling to ensure RSS items are properly handled. This is why companies want to keep their file format proprietary. Other devs can really do damage to the ecosystem and ruin the experience
- tracker1 7mo agoOne that always irks me to no end, is every time I see someone ham fisting csv handling by hand instead of using an established, well-sourced library. They almost always fail at commas or newlines in quoted text... It's one of the more annoying things. Currently working on replacing a couple decades old system, and my csv output is using a library that isn't quoting all the strings that don't require quotes... so I'm forced to do it (for compatibility) with the other system this csv is going to. (sigh).
- EvanAnderson 7mo agoMy personal fork of ttrss, from 2005, is a dodgy patchwork of fixes for badly formatted RSS. I can't imagine trying to host a service that deals with RSS feeds from random sites at scale.
- fosron 7mo agoWorked on an ESP. We had a couple of server software we used on low-level for sending. None of them would accept the message without a Message-ID. But even if you have a super-custom, SMTP-injecting service built, how can you ignore all of these bounces from a provider thats likeliest to be the major one you are sending to? Unthinkable. I would not like to have business with such a payment provider.
- idopmstuff 7mo agoThis is the one that gets me - sometimes you're forced to work with systems that do annoying things that you have to accommodate. It's annoying, but it's more important to do the thing that prevents your users from having issues than it is to be theoretically right about whether something's required by a standard. I've dealt with many worse cases than this, where the systems I was integrating with were doing things that weren't even close to reasonable, but they had the market power so I sucked it up and dealt with it for the sake of my users. Maybe Google's wrong here, but how do you not just implement the solution anyway?
- renato_shira 7mo ago[dead]
- nightpool 7mo agoWell, apparently it's not even an issue for gmail users: To unblock myself, I switched to a personal @gmail.com address for the account. Gmail's own receiving infrastructure is apparently more lenient with messages, or perhaps routes them differently. The verification email came through. So it's only an issue for people paying for Google's hosted email—a much smaller set!
- atmosx 7mo ago> Maybe Google's wrong here, but how do you not just implement the solution anyway? But they just did (make it work). The logical assumption is that most ppl did the same, just used another email provider. Why would viva care? (same as google, why would google care?).
- DaOne256 7mo agoMaybe that's something to report to the "European System of Financial Supervision" or some other EU government agency. They even have a Whistleblowing link at the bottom of their website: https://www.bankingsupervision.europa.eu/about/esfs/html/index.en.html https://www.bankingsupervision.europa.eu/about/esfs/html/ind...
- dathinab 7mo agono, please read the article they forgot to include a message-id something the RFC standard recommend but doesn't require but it being required is a de-facto industry standard for sending automated mails and is clearly documented by support sides of large mail providers (like Google) the mail standards only defines what parts you can put together, but widely fail to define how this parts can be interpreted, what are sensible combinations, etc. and they don't cover spam/suspicious mail detection at all so you can't just go by RFC, you need to read up on what all larger mail providers have as additional requirements (which mostly are the same, and Message-Id being the most common dominator) and then hope that another provider you didn't read up one doesn't have some other surprising rule (which doesn't tent to be the case if you don't do anything surprising, but it sucks anyway).
- juancn 7mo agoIf that's how they handle email, I wouldn't want to see what they do with payment data.
- warkdarrior 7mo ago"For simplicity, we support recipient account IDs in the range 1-10. Anything else gets silently ignored."
- sceptic123 7mo ago> Why this matters Hello AI (Claude?)
- hughw 7mo agoPostel’s Law would put the onus on Google to be forgiving in what it receives. Unsure how you could safely use a sender-created Message-Id for anything anyway.
- lokar 7mo agoThat “law” if from a different time, before protocols like SMTP became adversarial. It assumed everyone was acting in good faith.
- bell-cot 7mo agoYep. And even a world of perfect good faith, "forgiving in what you receive" has both costs and scaling problems - from researching what "spec" you'll need to design to, to customer service when the added complexity and permissiveness cause interesting stuff to happen.
- joshuaissac 7mo agoFollowing Postel's law results in the normalisation and proliferation of defective implementations. The actual standard becomes irrelevant, and new implementations have to be coded against the defective ones. My opinion is that Postel's law should be approached in the same way that Linus Torvalds did CVS when designing Git. If in doubt about an implementation decision, consider what Postel's law would recommend, and then do the exact opposite.
- herczegzsolt 7mo agoI vaguely remember hitting this message id issue in Google Workspace, and being able to work around it in mail routing configuration. Saidly I don't remember the specifics, it was something along the lines of not all, but only specific routing features requiring it. Workspace settings are a moving target anyway, so the behavior probably changed more than once since. I'm not saying it's a good idea to send emails without message id, but i'd also double-check that workspace configuration.
- deleted 7mo ago[deleted]
- davsti4 7mo ago"Email is tough", software development is tough, IT is tough, walking and talking at the same time is tough, mailing a letter is tough. When orgs frame problems like this, it erodes trust in the message they try to convey. Email isn't a tough problem, but its a problem nobody wants to really deal with. Email is simple - its a text based protocol, that started out open, but now you need to add security to ensure your email is delivered.
- gethly 7mo agoGoogle NOT following the spec is not surprising. SHOULD does not mean MUST and they are completely in the wrong here.
- thatha7777 7mo agoThe definition of SHOULD is "This word, or the adjective "RECOMMENDED", mean that there may exist valid reasons in particular circumstances to ignore a particular item, but the full implications must be understood and carefully weighed before choosing a different course." I suspect viva.com didn't consider the full implications, and I suspect Google did some hard math on hours saved for their customers
- thayne 7mo ago> Who's in the right I don't think either are. The payment processor should be sending it, but, at least according to the RFC, it is incorrect to reject an email that doesn't have it. I suspect the reason it is SHOULD, and not MUST is for backwards compatibility with software that predates the RFC that adds the message-id header. Maybe there is a correlation between missing that header and being spam, but then it should go to the spam folder, not be outright rejected. ---------------------------- The experience with support is also similar to experiences I've had with support at many companies. I provide enough details that an engineer could probably easily fix the problem, but the support representative just dismisses it, and it is doubtful an engineer even hears about it.
- ajross 7mo agoExactly. This minutiae is all so weird. Email as a formal specification does not work, and the industry as a whole has accepted that for decades now. It's not possible to filter spam from valid traffic without applying a truckload of heuristics and leveraging an ever growing set of auxiliary signals (SPF, DKIM, yada yada). To wit: basically everything in this world is a "SHOULD", at best. The rules are a conversation.
- jonathanstrange 7mo agoThen why does my email program reliably distinguish spam from ham without any server-side filtering involved?
- shadowgovt 7mo agoI'm just speculating, but probably because you're on an email provider that isn't a big enough target to worry about the persistent threat-actor model. Google is a big enough target to justify spending the resources on dedicated attacks against their infra. Other providers may simply get less spam because their email domain shows up less often in the sources attackers use to pick targets.
- ajross 7mo agoIf you have a client app that you think is reliably filtering spam, then to be blunt: you aren't receiving any spam, at least to first approximation. My stack of stuff on my three decade old personal account has a 95%+ hit rate (something I might naively be tempted to label as "reliably filtering spam"), and I see see more spam than signal in the inbox. GMail, on the other hand, is damn close to 100%. And it does it through excruciating application of heuristics like "don't trust agents that don't set SHOULD headers".
- pelorat 7mo agoI've never heard of them. Looks to be a company from Greece. That would explain their reply. Not exactly known for their tech.
- deleted 7mo ago[deleted]
- youknownothing 7mo agoIt used to be said that the reason the Internet evolved so well was because of the basic principle of "be strict when you send, but tolerant when you receive". Clearly Google has forgotten this.
- warkdarrior 7mo agoThat worked when the Internet participants were mostly benign. Nowadays you have to account for abusive participants (spammers, malware writers, etc., etc.).
- robocat 7mo agoThat is unstable if defectors are rewarded - which is a common issue on the internet. If you are too tolerant then bad or lazy actors will cost you too much. You end up with the tragedy of the commons called "quirks mode".
- wolvoleo 7mo agoHuh I've lived in Europe for most of my life and I've never heard of viva except as a poor name choice for Microsoft's corporate Facebook (yammer) Most companies here use stripe on their website.
- amarcheschi 7mo agoit's a greek company, if you buy from greek websites i guess you'll deal with it i'm not greek but a greek ecommerce i buy from uses viva
- rsynnott 7mo agoYeah, they're defining 'major' fairly generously, here, I think. Difficult to find figures, but seems to be transaction volumes of tens of billions a year. So not actually particularly big.
- mrighele 7mo agoThe first thing that comes to my mind is: how come viva.com is unable to send emails to google workspaces and nobody at viva.com noticed before ? For how long has this going on ? The second thing is, what email software are they using ? If it was any relatively used software I would not expect this problem to arise (maybe it is some commond software but misconfigured). Third, while the header is not mandatory, I usually read SHOULD as a "if you don't implement it prepare for possible problems". SHOULD is not MAY. Fourth, they should be thankful that Google bounced the messages with some appropriate error explaining how to solve it. I have plenty of issues in the past with both Google and Microsoft where they accept the message for then sending to /dev/null
- lasgawe 7mo agoliterally everything is tough when comes to emails
- miki123211 7mo ago> This experience fits a pattern I keep running into with European business-facing APIs and services. Something is always a little bit broken. I feel like this isn't just business services though. American engineers are used to working for either big tech or "Silicon Valley inc." European engineers are used to working for Volkswagen, Ikea or Ryanair. Very different kinds of businesses who treat tech very differently. Over here, competing on user experience and attracting users with a slick interface that people love to use isn't really something most companies think about (and so they get their lunch eaten by the Americans). Nowhere is the European mentality more evident than in cybersecurity, where outdated beliefs still dominate. In this mentality, everybody is out to get you (and that notably incudes your vendors, your business partners and your customers), so all infrastructure has to be on prem, open source is free and hence suspicious by definition, obscurity is the best kind of security, encryption doesn't work so data should go over custom fiber, and if you have to expose an API on the public internet, an Authorization header isn't enough, it should also require MTLS behind a layer of IpSec.
- pteraspidomorph 7mo agoAnd we're still getting passwords changed periodically or requiring a number, upper case letter, symbol... I'm an European engineer and I can confirm that our tech is often broken and customer-reachable people are usually obtuse and hostile about it. We don't even seem to properly implement our own legal requirements. Sometimes, Americans implement the RGPD better than we do.
- peter_retief 7mo agoI offered to host a friends business email on my DO instance. Works 99% of the time but every now and then emails just disappear only to find out that MS and Apple block DO IP addresses, sometimes. Silently. There is a war on small email providers it seems.
- Avamander 7mo agoThe biggest war on small providers is waged by other small providers. They can be ancient and outdated or simply extremely picky. Which makes everything Google or others require a piece of cake, which it actually kinda is.
- pmontra 7mo agoIf a business like that doesn't get its emails delivered, it will slowly go out of business. Merchants will find another processor that is able to deliver emails to every inbox. That is, Google could be less picky, but the company with a problem at hand is Viva.
- qualitylearing 7mo ago[dead]
- j1elo 7mo ago> For viva.com's engineering team, in case this reaches you: [...] That's too kind of you, but on the other hand it really doesn't solve the issue of bad priorities and lack of overall Quality. Some engineer might log a couple hours fixing a Level 3 severity bug, emails will start working better, but the poor (or at the least, dubious) backwards technical stewardship (or lack of it) will keep going on inside the company, unnoticed from outside (until something bad eventually happens to some client)
- looperhacks 7mo ago> This experience fits a pattern I keep running into with European business-facing APIs and services. Something is always a little bit broken. Documentation is incomplete, or packaged as a nasty PDF, edge cases are unhandled, error messages are misleading, and when you report issues, the support team doesn't have the technical depth to understand what you're telling them. I can definitely confirm that this is a common thing. But I think this is a "small org"-problem more than a "European business"-problem. Apparently, the company has somewhere between 500 and 1000 employees (I couldn't find good data, sadly). With a size like this, the "support" is probably outsourced (meaning they don't know anything), there are maybe 100 engineers (probably less) and the mailing is either done via a third-party or set up by an Admin that left three years ago. Without any basis, I will speculate that you will notice this more in Europe because there is simply no company at the size of Stripe or similar.
- bojan 7mo agoWhile there is some truth in while you saying, I have to say that from my European perspective all the big American companies feel enormously bloated. For example, I've recently learned thats Atlassian has 13000 employees, and I have to ask myself, what do all those people do?
- TheAceOfHearts 7mo agoA minor correction, but Atlassian was founded in Australia, and their global headquarters is still in Australia.
- warkdarrior 7mo agoI bet Atlassian's email notifications never bounced.
- hermanzegerman 7mo agoThey're busy hardcoding passwords into their source code https://www.bleepingcomputer.com/news/security/atlassian-confluence-hardcoded-password-was-leaked-patch-now/ https://www.bleepingcomputer.com/news/security/atlassian-con...
- chrisjj 7mo ago> Their support team's response to my detailed bug report As you said, its not a bug. A feature request might fare better.
- 1970-01-01 7mo ago>"We can see your account now has a verified email address, so there doesn't appear to be an issue." There are still too many edge cases like this one that can't get fixed because of ignorant support not doing it's job. In my life, every company that escalates to an engineer instead of punting the ticket with some asinine 'but it works right now, goodbye' message gets rewarded via keeping my business. The ones that don't are immediately cancelled. Sometimes I even do a chargeback as extra punishment. Maybe I'm just old, but I have near zero tolerance for immature support playing games with my time.
- fweimer 7mo agoThe Gmail requirement is actually slightly different: the header must be present and unique. Gmail only keeps one copy of a message per user and message ID. Combined with a mail source that uses predictable message IDs (such as Github), you can abuse this to suppress delivery of certain messages to Gmail users.
- realusername 7mo agoInteresting, but what do you gain to send an email which you know will not land?
- fweimer 7mo agoIf I send it first, the real message won't get delivered. The real message could be be a newly reported security issue.
- ZoneZealot 7mo agoThey mean to send an email in advance, with a message ID that would later be used in the target email. First email gets ignored, moved to spam, or not read yet. Then the target email gets sent with the predicable message ID, and gets bounced. Comments on issues use the format <[OrgName]/[RepoName]/issues/[IssueNumber]/[CommentID]@github.com> A mitigation to this would be to take the combination of message ID and the sending domain and use that as the unique value, because message ID is not guaranteed to actually contain a domain label that's owned by the sender. For example SendGrid's message IDs are <[RandomValue]@geopod-ismtpd-[Integer]>.
- fweimer 7mo agoMinor correction: The message doesn't get bounced, it gets de-duplicated against the first message. Effectively, it's deleted.
- jms703 7mo agoTo author: The phrase: “sends verification emails without a Message-ID header — a recommendation of RFC 5322 since 2008” can be misread as though RFC 5322 recommends not including a Message-ID.
- eduction 7mo agoI’m sorry but in the context of a 50 year old technology like email, 2008 was yesterday. Gmail is in the wrong, you don’t get to just update the standard for email like it’s TikTok content or a Roblox update or whatever. Email was here long before Gmail and will be here long after Google abandons it. This is why I don’t use Gmail. Also, get off my lawn.
- wiredpancake 7mo ago[dead]
- mamiride 7mo agoMamiride dot com email verifications are not delivered to Gmail from a self-hosted mail server and I wonder if this is the reason. We got around this by making email verification an optional step instead of mandatory.
- golem14 7mo agoHilarious - German users lecturing Google on how to interpret the English RFC? I say this lovingly, having significant German ancestry:) But taking a step back : did viva previously send message ids and pushed a change to prod to strip it? Was it on purpose or an accident? And other email providers like proton or Hotmail - do they accept messages without message ids? Have other clients of Google workspace complained about this issue?
- amelius 7mo agoThat will teach those pesky Europeans not to start their own payment processors.
- dboreham 7mo agoShouldn't this be "doesn't want to send..."?
- nonfamous 7mo agoVeeery interesting. I have a personal domain that forwards to a @gmail.com account. There are several companies I interact with, from banks to retail to just about anything, that send mail to my personal domain that never arrives in my Gmail account, but I can see on the hosted mailserver. For those companies I have to use my @gmail.com address instead for the mail to get through. Maybe there are more companies than we think that send malformed emails?
- dathinab 7mo ago> This experience fits a pattern I keep running into with European business-facing APIs and services honestly, it's a pattern I have been running into with many start ups, fintech, banks and some other places _no matter where_. It also often makes sense. For many large orgs (e.g. Banks) this APIs are often a side business, sometimes one they don't want but have to have for compliance (or market pressure). But for strip it's their live blood. And many startups (like actual start ups, not 200 man companies running by investor money) often simply don't have the resources to prioritize a "very nice to use API". Lastly API design which is both nice to use and stable for existing integrations is surprisingly hard to get right (if you don't have some senior engine prioritizing it very highly and forcing it being kept prioritized; Or a surprisingly "clean"/"clear" use case.).
- ebiederm 7mo agoMessage-ID is a requirement for Usenet where it came from. It is a requirement for being able to reply to messages and in general for email threading. Message-ID is a requirement to archive email. Practically every email client has included Message-ID since dial-up internet was fast and fashionable. Given all of the above I am amazed more places don't drop email without a Message-ID. Not including a Message-ID seems to be saying you don't want replies and you don't want your message to be archived. That seems very shady to me.
- gib444 7mo agoIt's amazing how long this has been on the front page. Are people upvoting as a "hit" against the EU wanting out of Visa/MasterCard? It's certainly interesting timing edit: It seems Viva primarily is a neobank, not a payment processor. I'd never even heard of it until today. It's tiny compared to Revolut, Monzo etc. And tiny compared to an actual payment processor eg Worldline (French, 18,000 employees)
- LandenLove 7mo agoEmail seems like such a silly protocol but it's importance cannot be overstated.
- joecool1029 7mo agoI went through this hell last year when trying to tell my customers I had to change payment processors. In my case it turns out I was victim of Google having a beef with afraid.org years ago (the DNS authoritative record for my domain). 100% of my emails to gmail were going to spam, as soon as I switched NS record to fastmail (with same zone file) I hit the inbox. I never would have caught it without using this site: https://www.gmass.co/inbox https://www.gmass.co/inbox I did not show up on any of the major blacklists with mxtoolbox, this took months to figure out and I felt like I was going insane with hardly anyone responding to my emails.
- tempestn 7mo agoI've often found when receiving a clueless support response like this, it can be effective to just follow up with a polite request to forward the ticket to an engineer or developer. Usually the front-line csr simply hasn't understood the issue. In this case I would say something like, "Yes, I managed to work around the issue by switching to my personal email address, but this bug is still preventing me from using my work email domain. If you could please forward the error log I included to a developer, it should help them resolve the issue. Thank you."
- RobertoG 7mo agoBut imagine that you do that, and they solve the problem. What would you write in your blog about?
- andmarios 7mo agoA quick search for their developer support revealed they accept submissions via GitHub issues for their API. Perhaps try there? https://developer.viva.com/get-support/ https://developer.viva.com/get-support/ Sometimes you have to get creative to reach out to a company's engineering department...
- fergie 7mo ago> The reason Message-ID is SHOULD rather than MUST? Mail clients > sometimes send messages without one to their submission server, which > adds it on their behalf. As for why Google enforces it anyway: > spam. Messages with minor RFC violations are far more likely to be > spam, so rejecting them is a reasonable heuristic. In practice, Google > and Microsoft have become the de-facto standards bodies for email — > what the RFCs say matters less than what their servers accept. Surely the problem is on Google's end? And a metaproblem is that we are allowing corporations to change or ignore standards for critical infrastructure?
- that_guy_iain 7mo agoThe email landed in the spam folder. A bounced email means it didn't find the inbox. If it didn't find an inbox there would be no log for him to check. Technical knowledge of emails and what the terms mean out him instantly as a liar. The fact this is still up on the front page is an embarrassment for the tech community in my opinion.
- DangitBobby 7mo ago[flagged]
- dang 7mo agoPlease don't cross into attacking another user, no matter how wrong they are or you feel they are. We're trying for something different here. https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- that_guy_iain 7mo agoDude, you keep on just believing a blog post even though it makes no technical sense. That's why none of the hardcore nerds are even approaching this and why Viva are going to sue. An email bouncing means it was rejected because it did not find an inbox or a recipient. You AI to question if that is true. So if the email service provider says we don't know who that belongs to, why would they provide logs. And what email service provider is rejecting an email over a RFC thing when millions of emails a day because most devs don't care about the RFCs and only an idiot would have two different mail infrastructure and code versions running for gmail and workspaces. Especially on the sending and receiving part. So are you going to apologies for being confidently wrong? Because I'm technically and confidently right. Again, which is why the hardcore nerds are leaving this the fuck alone because they saw me wreck the post in minutes of it being posted.
- deleted 7mo ago[deleted]
- ergl 7mo agoI hope OP took more effort in making Viva understand the problem than the obvious zero effort it took writing this post, given it is completely AI generated.
- cientifico 7mo agoThis feels jumping on the train of complain about Europe and fully bias. If I apply my own bias I will call it: American companies abuse their dominance my enforcing non documented requirements, making other companies not able to reach their users.
- IAmLiterallyAB 7mo agoAmusing because gmail doesn't even follow spec. I had to workaround gmail quirks when I worked at an email company. Better than outlook though. What a nightmare.
- gsck 7mo agoI dont think people fully realise how novel Stripe actually is. The idea of capturing payments via an API itself isn't unique, but the fact that as a company Stripe is actually on average pretty competent. I've never had an issue with stripe on the integration side because that just works. I work with a massive variety of payment gateways, I'd imagine more than most people on this site ever will, 90% of them suck. The big ones all suck, Stripe's "competitors" suck. They all have effectively the same API but the issues are organisational. Stripe is a technology company, its technology is good, its approach to the end user (Technical people implementing it) is good. The rest are finance companies and you get all the slow to move, impossible to get through to bureaucracy that comes with it. Of course they didn't respond to the actually issue and said "You've already solved it" and then ignored the actual problem. These payment providers sell their services to business not developers or anyone with technical chops. They wont care about these issues because your boss has already been sold on the product, the issues are very very unlikely to change their mind and it is now your problem to solve.
- disgruntledphd2 7mo ago> The rest are finance companies and you get all the slow to move, impossible to get through to bureaucracy that comes with it. Look, I 100% get what you're saying here, but it's not (entirely) the other companies fault. The financial sector is incredibly regulated, and they're required to have policies and procedures for everything which leads to a terrible, no good, sub par user experience. Stripe has (so far) managed to avoid this, but if (when) they end up in the regulators cross-hairs they too will become like many other financial companies. I mean, I want to be wrong on this but I don't think I am.
- mothballed 7mo agoThis is why a sane e-commerce platform should have routing through a bunch of different payment processors so they're not vulnerable to the regulator or regulatory officer anomalous behavior at any particular one.
- disgruntledphd2 7mo ago
- st3fan 7mo agoThe RFC MUST SHOULD discussion is funny ... Considering that Google Workspace is a major player and a place where your customer are, do you want your customers to succesfully use your product? If the answer is no then yes go ahead and debate the RFC. If you care about your customers and your product working broadly with a diverse set of mail services then please spend 15 minutes to write a patch to add a Message-ID header?