7 ms·
Thanks, just spent five minutes modding my webapp to disallow email aliases.
by bobjordan 8y ago
Thanks, just spent five minutes modding my webapp to disallow email aliases.
- sourceless 8y agoKind of a slap to anyone who uses email aliases to sort/filter email
- ioulian 8y agoI use aliases to filter my email and also to see who sells my email address to third parties. All the websites I've used allow "+" in the email address so that's good.
- bpicolo 8y agoYou can assume that the companies selling off email data are smart enough to do the entirely trivial "remove + sign to @ sign" transformation for gmail addresses, at least partly because their job tends to be tracking you across a large amount of domains.
- TeMPOraL 8y agoI switched to mails under domain I own (and powered by FastMail) some time ago; I now use alias@username.mydomain form. Try to filter for that without breaking non-aliased e-mails!
- DarkWiiPlayer 8y agoBy that point you might as well set a fixed-width length and treat everything after that as an alias, like me@domain.tld would be the base and mespammers@domain.tld would be your alias for spammers.com, etc. Even better, put the alias before the username and keep the + as a separator.
- bpicolo 8y agoCome to think of it, I bet doing this actually gives them better signals than they'd otherwise get, because if they receive emails by word of mouth, then they get additional context as to what sites you're signing up to.
- tobyhinloopen 8y agoI will call support to notify them my e-mail (with a + in it) isn't working, like I have done before. No I don't have another e-mail address. Yes, this is really my e-mail address.
- kodablah 8y agoTo be fair, I would assume/hope the implementation is gmail specific and just truncs the + part only when doing uniqueness validation. Granted its effectiveness is small.
- deleted 8y ago[deleted]
- __ryan__ 8y agoThis would not account for emails which have a custom subdomain but are still hosted by gmail, which will behave the same way as gmail with respect to the "+" sign (I've seen many universities do this).
- leowoo91 8y agoThat is essentially losing 1 customer vs handling thousand spammers.
- TeMPOraL 8y agoExcept people use aliases to protect themselves from spammers - who frequently buy or steal e-mails from companies like the one you're considering.
- leowoo91 8y agoThen better alternative would be to develop a unique mail check functionality ignoring the + part. Maybe that could work for both sides.
- 8y ago
- kodablah 8y agoNot sure of your app, but what do you care if multiple people share the same inbox? They can always with something like Mailinator or other domain-level aliasing.
- ReadyPlayerNone 8y agoI'd reconsider this change. Lots of people use email aliases to track which sites share their contact details with third parties. I see it all the time in signups for one of my sites - don't mind, of course, because I don't share their data. If you stop people doing this it might send the wrong message.
- ixwt 8y agoThis is a poor way to track who is selling your contact details. It's trivial to strip + aliases from a list.
- adhipg 8y agoYou may want to allow email aliases, but ignore the 'alias' part when checking for uniqueness.
- williamdclt 8y agoPlease don't. It's an important feature for a lot of people (me included). Just ignore it when checking uniqueness, if you really must
- DarkWiiPlayer 8y agoThat has to be the worst idea of the year. You are essentially blocking perfectly valid emails on the assumption that one single email provider uses the + character with some special meaning. Congratulations, that's how you break the internet.
- wifistrong 8y agoExcellent work. Now disallow catch-all email addresses. I'll wait.
- Kiro 8y agoGreat marketing for your services since you're putting them in your profile.
- floatingatoll 8y agoWhen a website presumes to normalize my Gmail address, I presume they aren’t interested in my money. You are well within your rights to prohibit duplicate signups from the normalized address, but please don’t presume to replace what the user entered.
- neals 8y agoI use an alias for every website, like me+apple@gmail.com to login to Apple.
- frou_dh 8y agoSounds like busywork without appreciable gain
- neals 8y agoUntil you take a look at your spamfolder to see who's been selling you e-mail address.
- trumped 8y agomost spammers use bcc, no?
- BenjiWiebe 8y agoNot the ones that are in my junk folder currently.
- _eht 8y agoThe problem is that you are no longer compliant with the email spec: https://tools.ietf.org/html/rfc5322#section-3.2.3 https://tools.ietf.org/html/rfc5322#section-3.2.3 Does nobody read RFC’s anymore?
- DarkWiiPlayer 8y ago> Does nobody read RFC’s anymore? I did, before posting my answer, though I admit I was too lazy to look up the email RFC and instead just used the URI RFC and assumed the allowed characters in the user-name would be the same :P
- dcbadacd 8y agoRevert that change. Just like DRM is easily defeated, so is your webapp's alias check, one can simply buy a few cheap domains and your checks fail.
- O_H_E 8y agoWell surprise, I actually use that feature in real life with my real email. It is really helpful if you want multiple profiles for a service (ex. Different mode, different recommendation) or in filtering all emails sent to that specific address (can't filter with the "from" as I don't know who is emailing me) Please don't break standards
- wtmt 8y agoThat's downright silly and a user hostile move, IMO (why at all wouldn't you want someone to test things out without having to give one of their main email address?). Your solution seems to assume that everybody uses only Gmail and Gmail plus addressing. Gmail also considers dots/periods in addresses as not existing. Try blocking those too (no, actually don't try this!). There are so many temporary or disposable email services that you'd be wasting your time trying to disallow all those. Your time could instead be better spent on making your product or service more attractive to paying customers.
- mxuribe 8y agoBut, then you are not complying with standard email, are you? See https://tools.ietf.org/html/rfc3696#section-3 https://tools.ietf.org/html/rfc3696#section-3