15 ms·
Show HN: Startup with no website - GuerillaClick@gmail.com
Hey there, there are lot of disposable email services, but as I was thinking I realized 95% of the time, I don't care about my inbox. I just want to "verify my email".
That's why I created a startup with no website, it's called guerillaclick@gmail.com, it's a credible domain (you don't say) and it will click on any "verify" links you send it to it.
You can use aliases to get around of duplicate emails in the target system, so like
guerillaclick+eralp@gmail.com
guerillaclick+sdfaskdma@gmail.com
guerillaclick+111@gmail.com
so choose an alias and start using the service!
I will provide a website to see the inbox of your alias. (maybe for services who send your pw in the email, but then you might be better off using other established servers.)
Gmail API is a bit slow so it might take 30 seconds for email to be received on my end, keep in mind while testing!
Best,
- ClassyJacket 8y agoInteresting idea!
- aogl 8y agoA lot of services don't allow +uniqueSection in email addresses anymore; just bear in mind..
- ixwt 8y agoBecause it's a gmail address, you can put as many . as you want anywhere in the name. Gmail strips them out when determining the email address.
- williamdclt 8y agoNot as useful as `firstnamelastname+twitter@gmail.com` for example :/
- floatingatoll 8y agoNot as readable, but each inter-character spot is a bit, and if you have 11 bits, you can represent 2^11 addresses. EDIT: Assumes Zero or One periods per bit-gap; if you can chain them, the sky’s the limit.
- ixwt 8y agoI just tested it with a bunch of periods. I got rejected with just two periods adjacent, and with quite a few more periods adjacent. So only bits. Looks like it can be used for filtering too.
- dimensi0nal 8y agoDots cannot appear consecutively in the local-part unless quoted.
- macspoofing 8y agoI never understood why that was useful. If you're a spammer that harvests email address or if you're an unscrupulous service that sells your user email address to spammers, wouldn't you simply remove the '+' suffix from any gmail address before commencing your spamming?
- fxfan 8y agoDon't worry about providing website.
- swongel 8y agoYou can use Mailinator to do this already, you can see all of their inboxes on their website and you can use all of their domains to bypass domain restrictions. For example I might use somethingsilly@bobmail.info and it will be redirected to https://www.mailinator.com/v3/index.jsp?zone=public&query=somethingsilly https://www.mailinator.com/v3/index.jsp?zone=public&query=so...
- kodablah 8y ago> You can use Mailinator to do this already While I'm a fan of Mailinator and their approach, I think the feature OP has about auto-clicking verify is unique. But yes, to do this right, you need the multi-domain approach of Mailinator instead of just aliases. Maybe Mailinator has an API or supports POP/IMAP that would make this possible, I haven't checked.
- bionoid 8y agoLast I checked it appeared like Mailinator's POP3 support was completely removed, and API access requires a subscription. It was priced way above what I was willing to pay (I think $150/mo)
- close04 8y agoAlso Mailinator is banned by multiple sites and I feel like that number is increasing (anecdata). Which means it's getting less and less useful for the purpose of "burner" email addresses.
- cenal 8y agoYou can point your own domain to mailinator mx records for free. Don’t have a domain to throw spam at? Pick a sub domain and use that.
- close04 8y agoI used Mailinator as the quick solution to access some one time resources on websites that forced me to register. It was the simplicity of the throwaway email that made it attractive to me. But when it's blocked on a website I usually wouldn't want to bother with c more complicated setup. If the effort is justified then I can probably use a regular email address. Other people might have different use cases.
- bobjordan 8y agoThanks, just spent five minutes modding my webapp to disallow email aliases.
- sourceless 8y agoKind of a slap to anyone who uses email aliases to sort/filter email
- ioulian 8y agoI use aliases to filter my email and also to see who sells my email address to third parties. All the websites I've used allow "+" in the email address so that's good.
- bpicolo 8y agoYou can assume that the companies selling off email data are smart enough to do the entirely trivial "remove + sign to @ sign" transformation for gmail addresses, at least partly because their job tends to be tracking you across a large amount of domains.
- TeMPOraL 8y agoI switched to mails under domain I own (and powered by FastMail) some time ago; I now use alias@username.mydomain form. Try to filter for that without breaking non-aliased e-mails!
- DarkWiiPlayer 8y agoBy that point you might as well set a fixed-width length and treat everything after that as an alias, like me@domain.tld would be the base and mespammers@domain.tld would be your alias for spammers.com, etc. Even better, put the alias before the username and keep the + as a separator.
- bpicolo 8y ago
- ReadyPlayerNone 8y agoInteresting, I've a few questions as food for thought. - Is it allowed under GMail's TOS? - Have you considered the security implications of having what is presumably a server somewhere in your name clicking on any link that's sent to it? - You say startup - do you have monetization plans? Putting adverts on the associated website perhaps?
- dkoston 8y agoGoogle TOS is pretty broad. However, one of the main factors here is that export controls could quickly come into play. Since Google is US-based, providing this service for those in embargoed countries could get you shut down quickly. They also have a "don't misuse our services" clause and I'm sure this would count as misuse if found.
- spdebbarma 8y agoSomeone who works for GMail or Google has already read this HN post. I don't expect it to work for much longer unless OP has found a loophole.
- imhoguy 8y ago> providing this service for those in embargoed countries could get you shut down quickly. How come Google can figure out who and where the interested end-user is when emails are actually send by web apps and clicking is done upon email retrieval (I bet some cron with POP3). Moreover emails from "bad" countries are rather filtered out as spam/scam. Apart of this thread publicly inviting people it may be also hard to distingush the accout from any busy one. But I guess G may have some pattern matching and rate limits for such sinks.
- simonebrunozzi 8y agoLet me answer this: from what I know, and broadly speaking, this service is both illegal and not allowed by ToS.
- jake_the_third 8y ago
- tnr23 8y agowhat about the gmail receive limit? its 60 emails per minute or about 80k per day if you hit 1 minute over 60 you get blocked 24h
- programbreeding 8y agoThat seems like it would be incredibly easy to DoS someone.
- nine_k 8y agoThis is delightfully crazy. Give some random guys with no website your registration record somewhere, allow them to verify your registration as theirs, and then impersonate you, reset passwords, see any communications, possibly log in as yourself and do anything. All this with no recourse. Nigerian spammers moan from envy for such a brilliant self-propelled gullibility filter.
- sleepychu 8y agoIn that regard though, it's not different to existing throwaway email services. I'd use this sort of thing for registering for annoying things like "free" wifi.
- faissaloo 8y agoMost free wifi hotspots don't verify your email fyi
- basil-rash 8y agoTo some extent, they can't. (How do you verify the email without being on the wifi?)
- gpm 8y agoIt's no crazier than using any other disposable email service... if I'm registering an account at neopets.org or whatever I probably just don't care.
- aboutruby 8y agoSeems like the perfect one to get one's account stolen
- TeMPOraL 8y agoThrowaway/shared e-mail addresses are not for accounts you care about, they're for working around stupid requirements to register "for free" to access a resource you need.
- siruncledrew 8y agoDid you get the idea from GuerrillaMail? https://www.guerrillamail.com/ https://www.guerrillamail.com/
- protomikron 8y agoMore and more services recognize disposable e-mail domains and don't allow such addresses. Obviously they can't block the gmail.com domain. I like the idea, but it probably is against Google's TOS, so there's that ...
- godot 8y agoTheoretically if this guerillaclick@gmail gets popular, I'm sure services can just specifically block guerillaclick+anything@gmail right?
- ArtWomb 8y agoNowadays, most require SMS confirmation that "You are indeed a human". And thus a mobile phone number. Have often considered wiring up something in Twilio so I can create multiple accounts, etc. But am too lazy to put in the effort. Perfectly willing to trade privacy for convenience in most cases ;)
- O_H_E 8y agoJust make sure that account is not associated with any of your real data (even IP). There have been horror stories at /r/TIFU about people getting their personal accounts suspended and the whole enterprise account with them. If Google gets angry about you, your life MIGHT be ruined –partially–
- metahost 8y agoTurns out those r/TIFU stories were fake. A Googler from the GSuite support debunked the claim. [0] [0]: https://amp.reddit.com/r/google/comments/8l231x/google_banned_an_entire_company_gsuite_accounts/ https://amp.reddit.com/r/google/comments/8l231x/google_banne...
- kodablah 8y agoIf something like this becomes popular, one might expect sites concerned about non-human verification to add a captcha to their verification page before the account is considered verified.
- deleted 8y ago[deleted]
- herogreen 8y agoOr: ask the user to use the same browser and check that cookies match / "sanitize" gmail adresses
- dimensi0nal 8y agoWhen Google inevitably shuts this down can you opensource the link clicking program?
- justin_oaks 8y agoThe "link-clicking" can be done using a Google App Script. I've used it before to auto-accept AWS opt-in notifications for Elastic Beanstalk environments. My code was tied to a Google Sheet that would hourly pull matching emails, use a regex to extract the link, send an HTTP request to the URL, and record the URL and response in the spreadsheet. Having a high level description of the code isn't as useful as the code itself. Alas, my code was part of my Google account at a previous employer.
- eralpb 8y agoI will open source whenever I have time, I just did it last night and decided to share.
- asimjalis 8y agoBeautiful.
- eXorus84 8y agoGood luck for your startup with no website. It's very simple and clever. I started my startup with a website to do a disposable emails service: mailcare.io It's also available in open source.
- alpb 8y agoWhy do you call this a "startup"? It's a nice hack for sure but I'm not sure if it's has a prospect of being a business.
- bdcravens 8y agoBecause overwhelmingly the HN crowd thinks building an app is building a startup.
- judge2020 8y agoThe product is a big part of a business, so if you have one, all you need is a business partner and VC's to create a multi-million dollar company.
- jressey 8y agoYes those are trivial things that are simply an afterthought. The app ain't shit, it's how well the business can execute.
- ravenstine 8y agoNot enough people realize how true that is. I've worked for companies that made pretty awful products, but they sure knew how to sell 'em.
- deleted 8y ago[deleted]
- crb002 8y agoThe monetization is having a curated up to date list of email verification handshakes. This has value.
- p49k 8y agoIf the Yo app can raise 1.5 million...
- rcfox 8y agoI've always wanted sort of the opposite. I'd sign up to a website, and they wouldn't ask for a password. To login, they would email a link to click and I'd be logged in for however long that cookie lasted. Why don't sites do that? (Is email still considered slow? I remember having wait times in the hours back in the 90s, but I'm not sure I've ever waited anywhere near a minute in the past decade.)
- overcast 8y agoPasswordless authentication exists, Medium has it, I've implemented it before, and I prefer it myself. The biggest issue being it adds an additional step, that most don't want to deal with. What if they don't have access to their email on that machine? Blasphemy, but it happens.
- Brozilean 8y ago> I've always wanted sort of the opposite. I'd sign up to a website, and they wouldn't ask for a password. To login, they would email a link to click and I'd be logged in for however long that cookie lasted. Why don't sites do that? > (Is email still considered slow? I remember having wait times in the hours back in the 90s, but I'm not sure I've ever waited anywhere near a minute in the past decade.) Tumblr does this at the moment. It asks for either email click or a traditional username/password setup.
- nijynot 8y agoMedium actually does this.
- jonathankoren 8y agoTumblr does that now. I’ve never used the feature. I have an integrated password manager.
- gpm 8y agoThis is basically how steam works these days. Sure, there is a "password" - but they won't let you log in without also verifying you have access to your email account - and you can reset that "password" only knowing the username and having access to the email account.
- rajeshmr 8y agoDoesn't mailinator (mailinator.com) already do this ?
- joewrong 8y agosome sites prevent mailinator accounts on signup
- Liquix 8y agoTruth. All ephemeral/temporary/one-time mailboxes suffer from the same issue - once enough people start using it, the website owners take notice and it's blacklisted. It'd be nice if you could create temporary <insert reputable domain here> accounts on the fly. User provides a captcha solve, your service uses this to create a random account & log in, user can view inbox or click 'open all links'. This wouldn't work with gmail because of SMS verification but would probably work on other domains and circumvents the above problem.
- bdcravens 8y agoAnd not all sites honor the "+". Too easy to filter that out.
- reaperducer 8y agoguerillaclick+eralp@gmail.com guerillaclick+sdfaskdma@gmail.com guerillaclick+111@gmail.com Unfortunately, more and more services are rejecting + e-mail addresses. Either ignoring them, or flagging them as an error. While it's perfectly within the RFC, companies are catching on to the trick. (3M, I'm looking at you!)
- judge2020 8y agoIt's within RFC, but they all lead to one email inbox so you end up being able to manage multiple third-party accounts from a single email account. It's recommended to not reject these, but strip them: https://gist.github.com/judge2020/af8fb9cd2ac165462d44de4e58d9a509 https://gist.github.com/judge2020/af8fb9cd2ac165462d44de4e58... https://gmail.googleblog.com/2008/03/2-hidden-ways-to-get-more-from-your.html https://gmail.googleblog.com/2008/03/2-hidden-ways-to-get-mo...
- reaperducer 8y agoYes, I know that. And as I mentioned, companies are still rejecting these addresses anyway because they know people are using them to identify and filter spam.
- abryzak 8y agoThis is why I use a catch-all on my own domain with a blacklist for companies found sharing or leaking the email address I gave to them. Fastmail makes this really easy to set up and their web interface also lets you set the From address to anything on the domain.
- josteink 8y agoRecommended. By google, who just played loosely with the email-spec. How rich.
- megous 8y ago? You can store e-mail messages based on the local part of the address however you want. It's basically just an alias.
- mandeepj 8y agoGood thought. At the same time, it's a feature; not a startup. Sorry.
- sodafountan 8y agoA feature of what? If this guy can convince people to send him their registration codes and somehow monetize it he's in business.
- hernantz 8y agothere are alternatives like http://10minutemail.com http://10minutemail.com
- eralpb 8y agoFor future awesomeness please follow @eralpbayraktar on Twitter :) Thanks!
- desireco42 8y agoIf you are not making money off of it, why would you call it a startup. It really is a project of yours. Thank you for making this though.
- deleted 8y ago[deleted]
- megaman8 8y agoWhat's awesome here, is that he/she's created a solution to a problem that almost everyone has. It might need a little work, as shown by other comments. but the core idea is a good workaround for sites that force you to give a bad email address to get at the content.
- giarc 8y agoIs it a problem though for legit sign ups? I find the problem is that when you click the link in your email, you now have 2 tabs open. One with a verified login and one without.
- rkagerer 8y agoHow well will this scale? I know GSuite Gmail accounts are limited to 3600 emails per hour, among other limits.
- anant90 8y agoRequest for feature: Chrome extension: a shortcut fills in guerillaclick+<random_hash>@gmail.com
- eralpb 8y agogreat idea, which also warns about the websites it won't work on. some require session authentication, so bot needs to login and THEN verify.
- timmit 8y agoit is a geek idea! i like it. you still get a website? ``` I will provide a website to see the inbox of your alias. (maybe for services who send your pw in the email, but then you might be better off using other established servers.) Gmail API is a bit slow so it might take 30 seconds for email to be received on my end, keep in mind while testing! ``` just wondering does it break gmail's terms?
- lifeformed 8y agoIsn't it spelled with two R's? "Guerrilla"? I didn't even notice at first, and was going to say that it's a hard to spell word for something you have to manually type in. Now I notice even the service itself is misspelled! Or is it just this announcement of it that's misspelled?
- apexalpha 8y agoA bit weird to call it a startup but a clever idea! Maybe Mailinator could implement this autoclicking.
- iazid 8y agoCan something similar be done with phone number verification ?
- ReedJessen 8y agoWow. This is a sneaky idea. I love it.