After a quick check, I found that our IP address is listed on UCEPROTECT Level 3. The listing is based on the reputation of the entire ASN 14061 (DigitalOcean, US) [1]. In other words, even if your IP did nothing wrong, it will still be listed because of its ASN.
If your site is innocent and listed only because it's hosted on DigitalOcean, UCEPROTECT offers to whitelist it for about $30/month or $108/year [2].
I checked the ASNs of several other popular hosting providers, and they're all listed too. So if your site is hosted on DigitalOcean or any other major provider, it's probably blacklisted as well. That can cut you off from customers on mobile networks like Orange, whose "cybersecurity protection" uses blacklists like UCEPROTECT to filter traffic.
Honestly, in my 20-year career, this is the first time I've seen a blacklist misbehave this badly and ask for money when there's clearly been no wrongdoing.
So, yes, if a service provider is known for having a lot of spam coming from it, it makes sense to be on there. They're not saying every IP is bad, they're literally stating the opposite (which seems fair).
So, if Orange are blocking purely based on it, not only are they using a spam filter as a DNS query/web filter (given uceprotect seems to flag based on mail spam traps based detections etc.) and ignoring their documentation (which says it shouldn't be used to block on it's own).
The problem is either with other things raising your scores (very likely) or with Orange dropping traffic based on the wrong list (unlikely)
Hosting providers should be good citizens of the network and immediately terminate spammer accounts. This used to be standard practice until about 2015. When suddenly management decided it’s more profitable host spammers than not.
I think this is a great policy decision by uceprotect.
All that aside, the website and their communication around this over the years is extraordinarily unprofessional and it's astounding to me they wield such power.
UCEPROTECT and other RBLs are just lists of text files. They do not block anything. As the mail administrator, you can choose what you do with a UCEPROTECT listing.
When I ran my mail server, I had UCEPROTECT tied into SpamAssassin, so that a UCEPROTECT listing by itself wouldn't block email; it would just raise the "spam probability rating" up.
UCEPROTECT is not a huge professional thing; it's "some guy" who's been running it, effectively, for free since the very early 2000s. No one is obligated to use it. If someone is being blocked by it, they need to contact the mail admin. UCEPROTECT just lists problematic hosts.
On to WHY DO and no CF/AWS? I don't know.. I'm not the "some guy" running the thing. But if I had to guess, it's that DO doesn't respond to spam complaints[1]. Whereas CF/AWS, while they host spammers, will take action against reported spammers.
[1] https://www.reddit.com/r/sysadmin/comments/1cwilrc/does_digi...
for example: "People with a brain would simply fix their systems after getting listed for abuse. Stupid losers are different." http://www.uceprotect.org/cart00neys/index.html
or
"This time, however, we have a premiere: A Woman. Actually, it reads more like a brat than a woman [...] If we were as emotional as you are and report you to our authorities, the handcuffs might click the next time you move your ass off the British Isles. [...] This means that they have heared that bullshit you spammed to them at times when you still slipped across the floor with your shit diaper. :-) [...]
Grow up and also try to grow a brain before you make a fool out of yourself, again next time.
Claus von Wolfhausen
Technical Director" http://www.uceprotect.org/cart00neys/2021-001.html
their main page has an iamverybadass quote, too: "WARNING: Do not play around here. You have no idea who we really are, and what will happen to you!"
https://news.ycombinator.com/item?id=49966613
Check this...
the Internet used to be almost entirely composed of this guy.
Like in 1996 if you wanted to do something on the Internet you had to deal with some version of him. I worked for the top car electronics installer in Houston in the 90s, who ran a few websites as a hobby and he was 100% like this.
Literally sat and typed out Monty Python dialogue so he could just have it hosted on his page, and would make .WAVs of annoying customers to put on the site
Dear god.
I've had a successful mail sender on that list for almost two decades.
Your problem is most likely something else, and if it's not something else then Orange are being completely ridiculous.
Digital Ocean is not a great neighborhood.
After seeing periodic bursts of login attempts from there, I now block all inbound ssh from AS14061 (among several such bad neighborhoods) as no authorized clients are hosted there and there is a constant level of attempted attacks from there.
https://www.aaroncake.net/misc/showthought.asp?thought=57
I personally found Meteor in Ireland (previously owned by Orange) to be far more liberal with blocks on an unregistered mobile internet connection than other providers.
Also, Orange UK have a much stricter block list to enforce than, for example, Orange FR.
Orange UK disappeared over a decade ago (merged with T-Mobile to become EE in 2010, then they stopped using the Orange brand in the UK in 2015).
The core flaw is depending on email for this. In fact it used to be a real-time API and the agency regressed to this. And their own system doesn't recognize invalid or undeliverable messages so it can get lost easy.
Seriously?
The rest of the list is as credible as that?
Source: managed a high volume (by layperson standards, it's not very high volume) commercial mail server for more than a decade.
However, there is nothing preventing function/scope creep of these blocklists into things they should not be. Political bias, censorship, morality policing will trickle into blocklists. Furthermore these false positives are quite onerous for legit businesses and customers who sincerely want to connect. I've connected again to an ad-blocking DNS service, and many people may subscribe to filtering services, or simply be involuntarily subscribed, in the hopes that their Internet would stay usable, and scam-free.
I suppose this is the price to pay in low-trust society (wild and wooly Internet). I wonder if the Great Firewall of China obviates the need for their citizens to throw up such protective measures.
At one time quite recently, Cloudflare was on Spamhaus's "Don't Route Or Peer" list. Imagine where the world would be if anyone cared about that list.
But if an entire ISP is blocking you based on UCEPROTECT, which is designed for email spam filters - are you sure? An ISP that blocked all of DO would get so many complaints and be open to so much legal liability. Usually these are only used for email filtering.
it was only 2 /23's (only 1024 IPs, ASN14061 is 3,140,680 IPs), and was resolved without a monthly subscription in ~24 hours after being posted to the NANOG mailing list
https://lists.nanog.org/archives/list/nanog@lists.nanog.org/...
the scale of the issue is significantly different and the resolution is significantly different (both in time and in money). that's important when comparing the situations.
highlighting those differences does not mean i think either situation is "good". one of them is "less bad" though.
As I explained, Orange's security filter seems to automatically block requests at the DNS level if your website's domain resolves to an IP listed on UCEPROTECT Level 3. In this case, that appears to be the entire DigitalOcean ASN.
I am not a lawyer, so consult one.
Uce level 3 should never be used alone to block general tcp traffic.
Are you saying that Orange is using uce level 3 to block email sent from your DO vm? Are you really sure that Orange blocks for this list only? Is it possible that your ip is on another RBL?
If Orange is really blocking smtp based only on uce level 3 they are doing wrong: their system may be mis-configured or they have not read correctly hiw level 3 is populated.
Or - probably - they did on pourpose!
Today I checked september smtp traffic: almost 99% of traffic coming from uce level 1 (single ips) was spam. Traffic hitting level 2 but not present in level 1 (subnets, one I checked was /15!!) was also 99% spam.
Of the 5000k messages received, very few arrived into the mailboxes. A lot of messages were blocked by following spam checks and the few remaining were flagged as spam.
I feel your pain. If you host on DO and you send email, you should look for a email provider that will funnel your emails.
Ps: i repeat, email shoild not be bloocked only by uce level 3