3 ms·
"trying to validate emails with regex will never work in practice" Of course it does. It just depends on how you define 'validate emails'. Your statement is am
by roel_v 5y ago
"trying to validate emails with regex will never work in practice"
Of course it does. It just depends on how you define 'validate emails'. Your statement is ambiguous. The Friedl has an entire appendix on a single regex that validates an email address to the format described in RFC 5322, although of course maybe a proper parser would be better, from a technical perspective. However, an email address being in the right format does not ensure that the user that email address is 'associated' with (for whatever definition of 'associated' that is appropriate to the application we're talking about) can/will actually receive emails send to that address.
You should do both. Do a first 'pass' validation to check the user didn't make a type. This is more for user convenience, as this can give immediate feedback. And then send an actual email to see if email is deliverable there.
The problem here is not that they checked the format. The problem is that they check the wrong way. Although it's not entirely unthinkable that it's sometimes appropriate to add additional constraints to which addresses you want to accept, e.g. banning certain tld's, or even only accepting whitelisted ones. If your fraud stats say that doing that reduces loss, it's not unreasonable to add such a third filter layer.