"From" address on welcome email is triggering spam filters #2145

Closed
JohnONolan opened this Issue Feb 7, 2014 · 8 comments

Comments

Projects
None yet
5 participants
Owner

JohnONolan commented Feb 7, 2014

Currently the "welcome to your new ghost install" email is sent "from" [user's email address] - this is triggering spam filters heavily, as the user is receiving an email "from" and "to" the same address, but from a different origin IP (classic email spam/spoofing/phishing)

I think it would be advisable to update all system emails to come "from"

ghost@[blog.url]

Update: webmaster@[blog.url] where blog.url is taken from config.js

Member

javorszky commented Feb 7, 2014

It is something I am implementing in #1601

Do you want me to get that part in quickly though?

hillct commented Feb 7, 2014

For what it's worth, I suggest using 'webmaster@[blog.url]' rather than ghost@ because while ghost@ is cute and useful branding, it may present problems for users who neglect to change the address insofar as webmaster@mydomain.com is likely to be a default alias for my email having just purchased and arranged hosting for mydomain.com (at some arbitrary provider) whereas ghost@mydomain.com would require me to setup a separate alias (assuming again the user has neglected to change the from address durring Ghost setup)

Member

javorszky commented Feb 8, 2014

That's actually a good point. @hillct 👍

@ErisDS ErisDS added the beginner label Feb 19, 2014

Owner

ErisDS commented Feb 19, 2014

Although I do want #1601 to land, this is a really good candidate for a beginner issue 👍 So it would be cool to do it separately.

To clarify, the issue is to replace the default from address that Ghost uses to send email with webmaster@mydomain.com where mydomain.com is the blog url as defined in the config.js.

Contributor

jondavidjohn commented Feb 24, 2014

I'll try and get a PR submitted for this tonight.

Owner

ErisDS commented Feb 24, 2014

👍

jondavidjohn added a commit to jondavidjohn/Ghost that referenced this issue Feb 25, 2014

Change fallback from address to webmaster@[blog.url] to prevent spam …
…filtering


Fixes #2145
- added `fromAddress()` to GhostMailer to handle this logic
- added unit tests to `mail_spec.js`

jondavidjohn added a commit to jondavidjohn/Ghost that referenced this issue Feb 25, 2014

Change fallback from address to webmaster@[blog.url]
This change is needed because the previous default of the user's email
address is too often mismatched against the site domain, triggering spam filters.

Fixes #2145
- added `fromAddress()` to GhostMailer to handle this logic
- added unit tests to `mail_spec.js`

@ErisDS ErisDS closed this in #2252 Feb 27, 2014

Owner

JohnONolan commented Mar 6, 2014

Sorry, I totally missed this discussion - my fault.

The webmaster@ concept is very flawed for a number of reasons:

  1. This email does not have the requirement to come from an address which exists, or one that might exist. That is not a thing. It is equivalent to a noreply@ address. There is no requirement to set up any sort of ghost@ alias.
  2. Using "webmaster" implies that it is a real address, which is actually a hinderance, not a help, if someone replies to it and the email goes to a random webmaster somewhere on the domain who has no idea what it's about.
  3. Using "webmaster" does not indicate in any way where the email came from. It could have been generated by anything. The value of branding is not to be "cute" - it's to be clear.
  4. ghost@domain.com is consistent with how other large CMS products brand their automated emails, which is tried/tested/accepted.

For those reasons, I'm reopening this issue to implement what was originally set out in the issue description.

@JohnONolan JohnONolan reopened this Mar 6, 2014

Member

javorszky commented Mar 6, 2014

Right, so... not touching the from address in #1601. :)

@JohnONolan JohnONolan self-assigned this Mar 6, 2014

JohnONolan added a commit to JohnONolan/Ghost that referenced this issue Mar 6, 2014

@ErisDS ErisDS closed this in #2345 Mar 6, 2014

@ErisDS ErisDS modified the milestones: 0.4.2, 0.5 Mar 10, 2014

ErisDS added a commit that referenced this issue Mar 14, 2014

Change fallback from address to webmaster@[blog.url]
This change is needed because the previous default of the user's email
address is too often mismatched against the site domain, triggering spam filters.

Fixes #2145
- added `fromAddress()` to GhostMailer to handle this logic
- added unit tests to `mail_spec.js`

morficus pushed a commit to morficus/Ghost that referenced this issue Sep 4, 2014

Change fallback from address to webmaster@[blog.url]
This change is needed because the previous default of the user's email
address is too often mismatched against the site domain, triggering spam filters.

Fixes #2145
- added `fromAddress()` to GhostMailer to handle this logic
- added unit tests to `mail_spec.js`

morficus pushed a commit to morficus/Ghost that referenced this issue Sep 4, 2014

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment