photog.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A place for your photos and banter. Photog first is our motto Please refer to the site rules before posting.

Administered by:

Server stats:

260
active users

Update: domain unsuspended!

Porkbun took a dim view of the outcome apparently; overnight they went into bat for me while I slept and have now sorted it with XYZ! I have updated them with the responses from Spamhaus and are going to follow up on that as well. Honestly I am super impressed with Porkbun after this. Faith in (some of) humanity restored. Especially their staff member Steve.


TLDR: Be wary using XYZ owned domains

What a fucking debacle. I purchased a cheap .quest domain to run my xmpp server on for my family and a few close friends. It was on sale, was cheap and I grabbed it.
It lasted less than 24 hours before being suspended by the regsistrar.

Turns out, it ended up on a spamhaus list, and XYZ suspends domains automatically based on that. I have lodged tickets with each, but can't rectify because:
- Spamhaus issues can't be rectified because the domain is locked
- XYZ won't unsuspend because it is still on the Spamhaus blocklist

Chicken and egg. I have tickets with each, and with Porkbun which is where I started.
I get it. It's a fucking great scam to bleed money from spammers when they snap up cheap domains.

I just wanted one to self-host xmpp for my family though, and am now caught up in the loop sadly.

It is extremely unlikely I will purchase any other XYZ owned domains (there are a lot, and some fun ones sadly).

Spamhaus in itself isn't necessarily a bad thing; it is a great tool. But automatically flagging everything listed by it in your registrar? Yeah nah fuck that. XYZ using external blocklists where everything is automatically opted in with no practical recourse is a terrible idea. The same goes for domains, fedi, whatever. There is always collateral damage and it sours it for everyone. It is just a stupid.

#spamhaus #domains #domain #DNS #XYZ #spam #blocklist #porkbun

@nigel
Wow. Thanks for the warning. I have several .xyz domains that I was planning to use for some projects. I also own readers.quest, which I was going to use for my own Bookwyrm instance (readers.quest is PERFECT for that!).

@Photorat@photog.social I've worked out that the Sydney Linode DC dishes out IPs that were flagged in Spamhaus from April 12 to 14, which is right before I spun up a vps there to use for VPS on the 15th.
So its either that, or Porkbun in general, or the old in general... but they won't be specific because why you let a potential spammer know where they stuffed up, I guess.
The worst part is that XYZ just suspends the domain based on that automatically. It's just so frustrating.
Photorat

@nigel
On the XYZ website they say they have zero tolerance for spam. They're proud that they're hard-asses compared to the rest of the industry.

I have an email deliverability book. It says:
"To stimulate growth, one-year registrations of many of these TLDs, such as .xyz are given away by domain registrars for free or for a nominal fee. This results in them being resold and used by spammers."

I guess it's worth the effort to try to find a .com name that is meaningful but not taken yet.

so they literally are taking peoples money knowing it'll be suspended... and by locking the domain due to suspension they're "upholding their stance on spam" even if others get caught in the crossfire.

Honestly, that’s shady as fuck; let it go for 24 hours, then suspend it and keep the dollar. Anyone legit will just ignore it usually as it is to hard and only a dollar, and so they just keep the funds anyway like they did for me. Thought I just cost 3 organisations more than a dollar of someone's time reponding to the tickets while I worked that out because I had time currently. I guess the "stimulating growth" part works from a dodgy corporate strategy angle.

Man I hate that bullshit, I can see exactly how it would have been pitched too. Le Sigh.

But anyway; I am now set up with Prosody on another of my domains that I have had for a long time, so should be all good now.

@nigel
I think they make their money on people like me who buy domains out of great optimism for projects we never get around to doing.

I think I bought readers.quest four years ago, so I paid them three full-priced renewal fees. I was actually getting ready to set that up and go live. Guess I won’t be doing that after all.