Skip to content
Presence & ProtocolAn independent guide to Jabber and XMPP

Standards

When a blocklist bans a name, not a behaviour

Every blocking tool in the protocol answers one question: are you refusing what this address did, or what this address is?

A printed list of blocked domains beside a notebook of dated incident notes on a desk.

XMPP gives its users and its operators the same primitive: a list of entities whose traffic is refused. A user runs it through XEP-0191, the blocking command, which refuses stanzas from a JID or a whole domain without notifying the blocked side. An operator runs it through server configuration, refusing to federate with a named domain at all. Both mechanisms are blunt, and both raise the question a blunt instrument always raises: is the list describing behaviour, or is it describing a category?

The distinction is older than messaging. A public argument about it runs, in a completely different field, through the site legislation that bans a breed, which documents laws that prohibit dogs by appearance rather than by conduct, and tracks the alternatives that judge the individual animal instead. The reason that literature transfers is that its core finding is measurable: bans aimed at a category misidentify the dangerous individuals and miss the badly behaved members of every permitted class. A blocklist written against a domain name has the same shape of error.

What does a category ban actually refuse?

Everyone under a name, including those who did nothing. When an operator blocks a domain, the mechanism does not distinguish the account that sent ten thousand unsolicited messages from the account that sent none; both are unreachable, and both are unreachable for the same reason, the domainpart in their JID. That is precisely the definition of a category rule: the class is the offence.

The justification operators give is real, and it is worth stating fairly. Blocking individual accounts on a hostile domain is whack-a-mole, because registration there is cheap or uncontrolled; refusing the domain ends the incident class rather than the incident. The cost is also real: the same stroke cuts off every legitimate user of that domain, and it quietly assumes the operator of that domain is unwilling or unable to act, an assumption that is sometimes true and sometimes simply unexamined.

Why do behaviour-based rules scale worse?

Because evidence has to be gathered per entity, and gathering evidence is exactly the work a category rule exists to avoid. Judging behaviour means reporting channels, abuse contacts, rate limits that punish the pattern rather than the origin, and someone at the far end who reads complaints. On a well-run domain all of that works: the blocking command handles the user’s side of it cleanly, and an abuse desk on the server handles the rest. On a domain run by nobody, or by somebody who benefits from the traffic, per-entity enforcement is a treadmill the other side controls.

Group chat puts the same question in miniature. A room that bans a participant bans an occupant; a room that bans a server bans everyone who lives there. The group chat essay shows how much of MUC’s moderation vocabulary is about the individual occupant, nick and JID alike, and the blocklist debates in operator communities are mostly about where the individual runs out and the domain begins.

The middle position the specifications left open

Neither the RFCs nor the blocking extensions prescribe policy. XEP-0191 defines a mechanism and deliberately says nothing about when to use it; an operator’s host-list rules are configuration, not standard. The judgement therefore sits where it always sits in a federated system: with each operator, applied locally, and visible to nobody else. Two servers can apply opposite rules to the same domain and both remain perfectly conformant, which is why the question never gets a final answer and why the quality of an operator’s list is a real criterion when choosing where an account lives.

A list that says what it is

The honest version of a category ban admits the trade: it names the criterion, dates it and carries a way back in, because a domain under new management or under a newly responsive abuse desk is a different fact than the day it was listed. The dishonest version pretends the list is a behaviour record when it is a name record.

The hygiene that separates the two is written down and unglamorous. Each entry gets a date, a reason and a review, because a list without a date is a claim that the past is still true. Each entry names the observed traffic, not the reputation, because a block written from second-hand outrage punishes a story rather than an act. And each entry carries a path to removal, because a refusal that can never be lifted is not a moderation tool but a feud recorded in configuration.

Anyone who has watched the breed-legislation debate will recognise the shape instantly: a policy that punishes a class claims certainty it has not earned, and the corrections arrive slowly if they arrive at all. Moderation is necessary; mistaking a name for an act is a choice, and it deserves to be made with its eyes open.