7 ms·
Can't upvote this enough. There simply is no need to check the email addr provided by the user. Send the mail, if it bounces, the user has only himself to blam
by usrbinbash 4y ago
Can't upvote this enough.
There simply is no need to check the email addr provided by the user. Send the mail, if it bounces, the user has only himself to blame. What if I don't want them to go through the hassle of an activation link? Then I don't bother with an email account in the sign-up process in the first place. If they want a passwd reset method, they can later provide an email in their settings page, if that isn't valid, well, tough luck.
- passerby1 4y agoBouncing usually requires money
- akersten 4y agoSo does sending the verification email, so it's a wash. Thinking about implementing email validation + verification is a great opportunity for developers to do two things: 1) Consider if you really even need to verify that email address. Why are you collecting email in the first place, why do you need it? HN is a great example of this - email totally optional, if you forget your password it's on you. Lot of online services going in the wrong direction with requiring a phone number. 2) Trust the user. Okay to give them nice nudges ("you probably meant gmail.com and not gmail.co") but if I really did mean gmail.co, let me through if I insist. Don't throw up a garbled mess of a Regex[0] that only serves to frustrate me when I try to sign up with my vanity email. I'll abandon the sign-up entirely. [0]: https://stackoverflow.com/questions/20771794/mailrfc822address-regex https://stackoverflow.com/questions/20771794/mailrfc822addre...
- caiomassan 4y agoThe most underrated crypto thing that people don't discuss enough, is that i don't need an email account to interact with web3 apps, i just sign in with metamask. if I could do it for every single app around that would be great.
- jeofken 4y agoIf only browsers had a public/private keychain built in to sign and encrypt messages. Authenticating = sign a message with your private key.
- jeroenhd 4y agoBrowsers have mutual TLS auth if you want that type of authentication. The UX is mediocre and MANY tracking websites will ask you to sign in (either out of incompetence or malice) in your regular browsing, but it's definitely possible to use such a system. Nobody is accepting random self-signed certificates, of course, usually they need to be signed by a CA belonging to the party you're authenticating to, but there's no technical reason why you can't use a random certificate to authenticate with a website, or even modify your browser to add a quick and easy button to generate them on the fly. Browser vendors have stopped caring about this type of auth and are focusing more on webauthn, which stores a cryptographic token in your device's secure storage (if available) or on the file system. When browsing from a phone, this means it's essentially "sign in with your fingerprint" for websites, which is really cool! You can't easily back those tokens up, though, so you still need something like a recovery email if you don't want your users to lose their accounts when they drop their phones too hard.
- boondaburrah 4y agoWhat's wrong with a username and password?
- arthurcolle 4y agonot secure enough, prone to easy abuse/workarounds.
- deleted 4y ago[deleted]
- programmarchy 4y agoTo answer this, ask why you use an SSH key to authenticate with all of your servers.
- makeitdouble 4y agoDon’t most emailing services heavily penalize a high bounce rate, including banning of the commercial account if it goes on for too long ? (which as far as I understand is also to protect the emailing service from getting blocked itself)
- samwillis 4y agoI can assure you that this would end up with far more problems than it will solve. I run an online store, people miss entering their email address is one of the largest causes of customers contacting support, and they regularly jump to being angry accusing us of being incompetent or worse. I would take the 0.001% of people who may have an email incompatible with a regex being frustrated (which will happen to them all the time) over the 10% who screw up entering their address. We even have code that looks for common typos and prompt the users to double check them. Somehow they still make those mistakes.
- Avamander 4y agoYou can obviously warn the user, but it shouldn't be a strict validation. That's half of the point. It's probably a mistake if someone typed gamil.com instead of gmail.com, but it's not a mistake if someone typed pm.me (or something punycode).
- kazinator 4y agoWhat's much more important than validating the syntax of the e-mail is not to let your service be turned into a relay for targeting e-mail addresses of third parties with "backscatter". Don't put up a web page where any visitor can put in an e-mail address, to which you send something, without any safeguards: like not sending to the same e-mail address more than just several times in a 24 hour period or something. Have Captches or or something to reduce the bots. Proof of work. Whatever. It may be wise to validate not for valid e-mail address syntax, but for certain invalid e-mail addresses to which you shouldn't send. For instance, would any legitimate user be subscribing with an e-mail address of postmaster@example.com? It seems it would be worth it to have a database of patterns of at least some well known mailing list addresses. Certain domains are almost certainly mailing lists; e.g. anything@vger.kernel.org is probably a list; don't send to it. Process bounces.
- zeeZ 4y agoI got some like that just last week. They were using a public sales quote request contact form, filling it with a bunch of random characters except for a valid email address and the name, which was something like "♥ Martha wants to meet you! Click http:// http://... ♥"
- Avamander 4y agoIt's a massive issue. It's not only spam, it also enables malware distribution and e-mail bombs (flood of mail to cause DoS or to hide some other letters). It is mostly because proper defenses against such abuse aren't built into software allowing such forms (or cost money). Wordpress form plugins are one such widespread bad example.
- robbiemitchell 4y ago> Send the mail, if it bounces, the user has only himself to blame. Some products don’t want to let users fail so easily. Especially if they spent good money to get you to the point of signing up.
- leros 4y agoI would like to agree, but sending an email that bounces will negatively impact your email reputation and thus your deliverability. I work at a large web company. We ran a test around removing email validation and we had about 20% of users typo their emails when signing up. Simple things like not putting the period before com like "john@gmailcom". It resulted in customers basically creating accounts they couldn't get back to which was a bad user experience and loss of revenue for us. Based on our testing, email validation mostly served to prevent these basic typos.
- mekster 4y ago> if it bounces, the user has only himself to blame So your system always makes the least effort and pushes the blame to users. Great. How about just even do a minimal check that is /.@./ so that the basic format is at least there or if you'd take 10 minutes to look around, you'll find the regex browsers are using and just steal it and be done with it, so most of the malformed inputs are warned to the user before the user realizes the confirmation email isn't arriving minutes (or days) later and possibly lose the conversion right there. https://developer.mozilla.org/en-US/docs/Web/HTML/Element/input/email#basic_validation https://developer.mozilla.org/en-US/docs/Web/HTML/Element/in...