28 ms·
Falsehoods programmers believe about email
- timvisee 4y agoAnother falsehood: Users use the same email address on different services.
- jph 4y agoAn email falsehood surprised me recently: I thought a case-insensitive email address can be compared by using pseudocode `lower(x)`. But that's false. An email system that guarantees case-insensitive email addresses can still fail during comparisons of lowercase-to-lowercase, due to international encodings, locales, I18N, L10N, etc. Pseudocode: string-compare-case-insensitive(x, y) => true // Right way string-compare(lower(x), lower(y)) => false // Wrong way It turns out this issue is called a "case folding non-deterministic" error, and is a broader issue with strings in general. For more about "case folding" with Unicode: http://www.unicode.org/Public/UNIDATA/CaseFolding.txt http://www.unicode.org/Public/UNIDATA/CaseFolding.txt For more about "non-deterministic" comparisons: https://www.postgresql.org/docs/current/collation.html#COLLATION-NONDETERMINISTIC https://www.postgresql.org/docs/current/collation.html#COLLA...
- landofredwater 4y agoWhat would the mechanism behind case-insesitive string compare be? How would you program out all the edge cases?
- connicpu 4y agoPresumably the case-insensitive version is also doing unicode normalization as well, which is what a byte-level comparison of tolower versions would miss
- School-Cotton 4y agoBy implementing the Unicode’s case folding specification in detail, as described in section 5.18 of the Unicode standard. Or, more likely, by using a library like ICU.
- silon42 4y agoit is host specific.
- bmn__ 4y agoUnicode does not depend on a host. You probably meant something else, and the expression came out wrong. Care to explain in more detail?
- PeterisP 4y agoAs Unicode standard describes (e.g. the same 5.18 section mentioned above) case mapping depends on locale, so lowercasing the same string may have different results on different hosts, and so also the truthfulness of lowercase(x)==lowercase(y) is not universal and depends on the host locale. See the standard https://www.unicode.org/versions/Unicode11.0.0/ch05.pdf https://www.unicode.org/versions/Unicode11.0.0/ch05.pdf for the most commonly used example of Turkish i, but there are others.
- Quekid5 4y agoIndeed, a fundamental to the problem is that most unicode text doesn't actually carry the relevant locale information... (Of course, one probably wouldn't want to rely on sender-specified locales for email adresses when deciding address equality -- that would open one up to all sorts of potential weird scenarios, i.e. a nightmare for security).
- Dylan16807 4y agoIf you're setting up proper case folding, part of your job is not leaving locale up to the host.
- kubanczyk 4y agoA primer (taken straight from GP's first link): > the full case foldings are superior: for example, they allow "MASSE" and "Maße" to match.
- skupig 4y agoThis sounds like a fun vulnerability to find in a password reset flow
- thrdbndndn 4y agoYeah but isn't email address in ascii? I still have no idea why it would be different.
- tssva 4y agoAnother falsehood to add to the list.
- School-Cotton 4y ago> isn't email address in ascii? Yes in the basic SMTP RFC, but there are extensions that allow non-ascii local-parts.
- systemvoltage 4y agoThe whole thing is a mess. I remember trying to make a Postgres email address column and wanted to do make sure it can do comparisons either way, then found this stackoverflow post that shattered my expectations of a clean well understood problem: https://dba.stackexchange.com/questions/68266/what-is-the-best-way-to-store-an-email-address-in-postgresql https://dba.stackexchange.com/questions/68266/what-is-the-be...
- jph 4y agoYes you're right, same kind of issue. Thank you for the link with the detail.
- Gigachad 4y agoCase insensitivity was a huge mistake in computing really. Most languages don't have cases and its very non trivial to convert between cases. Should have treated every char as completely unique. Sure. At the user signup side, block emails that are too close in ways like case, but as a sender you should always treat them as unique emails.
- wereHamster 4y agotolower() works mostly well in ASCII and languages which don't have weird rules (=works mostly well in english).
- 3np 4y agoThe context is e-mail addresses, not English.
- stouset 4y agoI think that's GP's point: tolower() looks like it works well to English speakers but it's subtly wrong and will fail unexpectedly for people with other locales.
- gumby 4y agoThose rules are only weird to you, but perfectly reasonable to others, such as Turkish or German speakers…well, readers :-)
- msh 4y agoInternalization is hard. I think its too much to expect software written for a specific market to handle all languages in the world. Fx in danish we have 3 letters (æøå) that is not common in the latin alphabet. I cant go to germany or turkey and expect people to be able to write out those letters when doing input in a local system.
- MandieD 4y agoFun thing I've run into in a Germany-based but increasingly international company: German always spells out umlauts and eszetts when going to lower ASCII for email addresses ("Schäßler" -> "Schaessler"), but Hungarian does not. Not sure how Turkish ö and ü get fully lower-ASCII-ized there, but in Germany, they get spelled out "oe" and "ue" as if they were German ö and ü. This isn't as much of a corner case as one might think - there are a lot of people with Turkish names in Germany.
- heurisko 4y ago> string-compare-case-insensitive(x, y) => true // Right way what is inside that function?
- amenghra 4y agofunc string-compare-case-insensitive(x, y) { return lower(x) == lower(y) ? lower(x) == lower(y) : lower(x) == lower(y); } /s More seriously, if you want to learn about this, one place is to look at OpenJDK's sources. E.g. here: https://github.com/openjdk/jdk/blob/master/src/java.base/share/classes/java/lang/String.java#L1978 https://github.com/openjdk/jdk/blob/master/src/java.base/sha... which calls: https://github.com/openjdk/jdk/blob/17283cfe4c697e2118f19992a6e87dbee268061e/src/java.base/share/classes/java/lang/String.java#L2141 https://github.com/openjdk/jdk/blob/17283cfe4c697e2118f19992... and https://github.com/openjdk/jdk/blob/17283cfe4c697e2118f19992a6e87dbee268061e/src/java.base/share/classes/java/lang/String.java#L2230 https://github.com/openjdk/jdk/blob/17283cfe4c697e2118f19992...
- jph 4y agoWhat's inside that function is Unicode case folding and non-deterministic collation, such as ICU, or its equivalent. See https://icu.unicode.org https://icu.unicode.org
- kuon 4y agoI think the part before the @ is actually case sensitive per RFC, but most mail server will treat it case insensitive. But I am not sure I am reading the RFC correctly, citation: Verbs and argument values (e.g., "TO:" or "to:" in the RCPT command and extension name keywords) are not case sensitive, with the sole exception in this specification of a mailbox local-part.
- a-dub 4y agorfc 822 local-parts (stuff to the left of @) are weirdly permissive. you can include quoted spaces, carriage returns and newlines (!)
- jwilk 4y agoQuoting CR and LF is no longer allowed in RFC 2822.
- jwilk 4y agoCorrection: it's still allowed, only considered obsolete. :-/
- derefr 4y agoWhich is to say, nobody of note is still allowing it; you can allow it if you like, for anyone who is still doing it; but if you don't, and someone sends you a message, and it bounces, then, well, they already know why.
- marcosdumay 4y agoYes, there are very few rules on the standard that could create two binary-different local parts that resolve to the same value (mostly involving parenthesis). But the mail server can add as many rules it wants, including the very common setting of making completely different names resolve to the same mailbox.
- tremon 4y agoI thought a case-insensitive email address can be compared by using pseudocode lower(x) You shouldn't be comparing the mailbox part of email addresses at all other than as literal bytestrings: you cannot know what equivalence rules the mailserver for that domain uses. The domain part can be equivalence-tested using the normal rules for domains though, including case insensitivity, IDN translation and punycode resolution.
- jph 4y ago> you cannot know what equivalence rules the mailserver for that domain uses. You're right in general. In my specific post, I do know the equivalence rules, because I'm administering the mail system and working with its source code, and the documentation guarantees/requires that internally its email addresses are treated entirely as case-insensitive. What I saw was source code comments about not using `lower(x)` nor Postgres module `citext`, and instead using Unicode case folding ICU and Postgres non-deterministic collations. In the end, what surprised me wasn't about email servers in general, it was about human languages with case folding.
- joshdata 4y ago> You shouldn't be comparing the mailbox part of email addresses at all other than as literal bytestrings It's hard to know what to do in practice, but this seems to be wrong according to https://www.rfc-editor.org/rfc/rfc6532#section-3.1 https://www.rfc-editor.org/rfc/rfc6532#section-3.1: "normalization form NFC SHOULD be used".
- tsimionescu 4y agoThis also depends a lot on why you are comparing those addresses. If you want for example to make sure that you don't easily allow the same person to register multiple accounts (say, to take advantage of a free trial period), then they are both wrong, since X@gmail.com, X.@gmail.com, X..@gmail.com etc. are all the same account and cost nothing to make. However, if you just want to make sure this is the same user that signed in earlier, you get to chose what rules you want - it's their problem to some extent to remember what account name they gave you.
- Asraelite 4y agoJust a nitpick: Gmail doesn't allow consecutive periods, so X..@gmail.com doesn't work. You can do a.bc, a.b.c, ab.c etc. instead.
- tsimionescu 4y agoOops, you're right. Did they also support user+somestring@gmail.com to be equal to user@gmail.com as well?
- Asraelite 4y agoYeah, they support +something. Sadly lot of websites don't accept it as a valid email address because of the +.
- imglorp 4y agoI wonder if that's because they know people use + to tag for later spam blocking, or is it just a lazy regex user who needs to read this article?
- skeeter2020 4y agoIME it's the latter, but not because they are lazy, but because email validation is hard. The lazy regex was in the late 90's early 00's when any email that didn't end in .com, .edu or .net failed!
- deleted 4y ago[deleted]
- Lucent 4y agoHere's another: Email addresses must have at least one dot. There are MX records at the apex of .ai, so postmaster@ai probably works.
- Gigachad 4y agoThe domain can also be an ipv6 address with no dot. Really the only thing that can be said is there will be something, an @, and another something.
- buzer 4y agoAre decimal & hexadecimal addresses accepted as email domains? e.g. root@2130706433 & root@0x7f000001
- School-Cotton 4y agoNo. For IPv4 the dotted syntax must be used and for IPv6, the colon syntax preceded by the string “IPv6:”. In either case the whole thing must be enclosed in square brackets.
- teddyh 4y agoTechnically, the address must also be surrounded by brackets.
- School-Cotton 4y agoIsn’t that what I said?
- teddyh 4y agoYou’re right, you did. Sorry, I must have missed it.
- galleywest200 4y ago
- technion 4y agoJudging by the number of times I've had this fight with developers, and seen other people argue it online, I'd suggest the biggest falsehood programmers believe is: Your random VPS can just send email from any address you like and expect it to be delivered.
- nix23 4y agoJust because you cannot setup a mail-server correctly, i have installed 100's of email-server (2022) from AWS to Hetzner to Vultr andandand. Yes your random static ip can deliver reliable email IF you have: -Static IP (4 and 6) -Correct Reverse DNS for IP4 and 6 -Correct Hostname -Site-verification for gmail/microsoft -DMARK -DKIM -SPF for IP4 and 6
- slyall 4y agoSo not: "Your random VPS can just send email from any address you like and expect it to be delivered"
- nix23 4y agoSure it can, if you configure it correctly.
- Denvercoder9 4y agoNote the from any address part. You can send from any address on a domain you own if you set it up correctly, not from any address in general.
- nix23 4y agoWow that's new that you have to configure something correctly so it works.....
- Dylan16807 4y ago
- 29athrowaway 4y agoIf you: 1) are a programmer 2) use e-mail regularly 3) have configured an e-mail client 4) care about how things work 5) have received spam e-mail (including spoofed e-mail) ...It is hard for me to believe that you can believe those falsehoods.
- sanitycheck 4y agoNot sure why you're being downvoted, I was keeping count of the the ones I believed as I went through the list and I ended up with a total of.. 2. If it was renamed "Things About Email Programmers Have To Repeatedly Tell Designers And Managers" that might be more accurate.
- dvh 4y agoIt's not about falsehoods I believe about emails, it is about knowing that emails will be used in million different ways in wide range of often legacy software and I'd rather force user to use normal email like user.name@domain.tld than to debug some early '90s cow milker at 2am on Saturday standing knee deep in cow piss in the middle of Nebraska just because some smart as have backslash or emoji in email address.
- eyelidlessness 4y agoI don’t disagree on principle but I’m genuinely curious how you arrived at your counter-example. My probably not entirely correct mental stereotype would have your Nebraskan farmer using an email address like benjomcfamilyname13464@megacorp.whateverispbranding.weirdlyunfamiliardomain.definitely.com
- happyopossum 4y agoThis one: > An email address like ^_^@example.com or +&#@example.com is invalid Is basically a self fulfilling belief - enough systems will reject such an address that it’s effectively unusable.
- technion 4y agoAs far as Microsoft's concerned it's invalid. I just tried creating such an address in Exchange Online. https://ibb.co/3zCyP9J https://ibb.co/3zCyP9J
- jkaplowitz 4y agoNo provider has to allow its own users to use the full range of legal email addresses. But can you receive an email from someone with such an address and reply to them? That's the real test of whether it's valid (and not too buggy) from the perspective of Exchange Online.
- sorisos 4y agoI have an email like "a@b--c.com" - not that crazy you might think but 1/10 websites reject it as "invalid" due to some stupid regex check.
- horsebridge 4y agoLists like these would be better with some more explanations for the less obvious bullet points. For instance, when/why would an email have multiple From addresses?
- School-Cotton 4y agohttps://serverfault.com/a/554615 https://serverfault.com/a/554615 Tl;dr it’s intended for messages with multiple collaborating authors, but is rarely used in practice.
- jcla1 4y agoI'd deem it useful, though unusable in practise, as GMail for example does not accept messages that contain multiple From addresses.
- jaza 4y agoYeah, that one took me by surprise. I had no idea that multiple from addressees was possible. I wonder how many (popular today) email clients support that (for sending and/or for receiving)?
- raverbashing 4y agoGood writeup > All email comes from a .com, .net, .edu, or .org address Hah. Tell me you're american without telling me you're american > Email is a reliable transport > Email is an instantaneous transport > Emails will be sent within a few minutes of their scheduling > Emails will be sent within a few hours of their scheduling > Emails will be sent within a few days of their scheduling Replace 'email' with SMS and the list also applies
- 3np 4y ago* Blocking sending to domains listed in [0] or similar is a useful way to prevent spam or sybil attacks with minimal impact on authentic users I hate this. Motivated attackers can trivially circumvent it at minimum effort and cost while it further normalizes centralization and strengthens surveillance capitalism as the barrier to use unlinkable e-mail for different service providers for a normal person becomes untenable (curiously equally disposable domains from major providers are absent from most of these lists, supposedly precisely because it is disruptive). I'm ambivalent on even sharing the link for the risk of a dev reading this going "oh, neat!"... [0]: https://github.com/disposable-email-domains/disposable-email-domains https://github.com/disposable-email-domains/disposable-email...
- p-e-w 4y agoYet another article that can't tell the difference between a "falsehood" and a heuristic. The end goal of most software is to weed out bogus email addresses, not to weed out email addresses that don't match the standard. "a@a.com" is a valid email address according to RFC 5322. But when a user provides such an address, you can be 99.9999% certain that it is neither the user's address, nor anyone else's. Many programmers are very much aware that "mymail@[123.123.123.123]" is technically a valid email, but allowing such addresses invariably leads to spam and service abuse, for virtually no benefit. Restricting accepted addresses to "normal" ones is common sense, not a falsehood. The same is true for many of the other supposed mistakes pointed out in the article.
- raverbashing 4y agoYou're right. Though there might be an use case where those 'weirder' emails get accepted. Correct, for your average "sign up here" website, no. But for example, where the receiving side is an automated mailbox, you might want to be more careful accepting 'weird' emails
- deleted 4y ago[deleted]
- onion2k 4y agoRestricting accepted addresses to "normal" ones is common sense, not a falsehood. In the case of a@a.com, that's just someone not wanting to give an email address. You can block it with validation rules, but they'll just use some random but not real address like noemailforyou@gmail.com instead. The validation achieves nothing except annoying the user, really annoying anyone whose legitimate address is blocked as a false positive, and makes your email address database harder to clean up if you ever want to send an email to everyone. Blockimg emails because they're "not normal" is validation theatre. It doesn't stop anyone nefarious or who wants privacy, it doesn't stop spammers, and it does stop rare cases of people with weird email accounts.
- MForster 4y agoFacebook used to reject my email address, because the local part was "email", i.e., "email@my-domain.tld". I was not amused.
- oconnor663 4y ago> An email address like ^_^@example.com or +&#@example.com is invalid My current employer autogenerated a company email address for me including the apostrophe in my last name. I couldn't believe that was a legal character, but I looked it up, and sure enough it is. Of course, plenty of other internal systems reacted the same way I did, and I frequently generate errors whenever I try to register myself with random services :p
- technion 4y agoI wrote our onboarding system and had it strip apostrophes from names. Some people object, but they object more when random websites refuse to let them sign up.
- wtmt 4y agoI’ve seen a lot of systems, including corporate systems for internal use, reject apostrophes in email addresses (and sometimes even in other fields). Apparently the developers are too lazy to deal with strings properly and fear SQL injection attacks, and perhaps they don’t trust all the other systems they may interface with. So their escape hatch is to prevent these from being allowed. (“Little Bobby Tables” from xkcd comes to my mind whenever I see these restrictions)
- seanw444 4y agoI wonder if this is a good indicator of a bad product/company to be a user of. If they're so uncertain about their tech stack that they have to prevent certain characters from being used in passwords/emails/etc, maybe it's not something you should trust?
- marcosdumay 4y agoIt is a very good indicator that it's a large company with centralized IT, where ops personal works in a different department from devs. If you are buying software from them, it's probably bad. But I don't think it's a reliable indicator for companies in general.
- 4y ago
- msh 4y agoIt seems like it mixes up things people believe and things that people do for ease of use/ease of life, like: >Anyone with a .edu address is a student >Anyone with a .edu address is a student or faculty I dont think most people believe that, but its a easy filter if you want to give rebates to students and they dont cost you too much, like dropbox giving increased free quota to people who sign up with a .edu
- rlayton2 4y agoWhich I've had failed as a student in Australia, as we use .edu.au (not for Dropbox, but other services). As you said though, its a simple test, and if you don't think about it too much, its too easy to just test the email ends in .edu and move onto the next task.
- msh 4y agoSure, if you go for international markets you have a lot more work to do. But in most countries you cant use extension to verify anything. I had a .edu as a university student in denmark, but I think my dapartment was the only danish education instituion who had that, the rest just used normal .dk domains.
- gwd 4y agoMy university has lifetime email forwarding; so I use my .edu address as my main personal email address. (I tell people, "In 30 years, it you email that address, it should still get to me.") I once signed up for a SaaS team workflow thing with my personal email address, thinking about trying to use it w/ my family to try to work together on a project; and within a day or two got a call from someone from that company obviously hoping I was actually a decision-maker at that university. Sorry...
- thrdbndndn 4y agoYeah like "everyone has an email address", of course not everyone has one, but if you don't, you're simply not going to be our client. And I'm not even sure what this "everyone has exactly one email address" is about.
- Zobat 4y agoEvery programmer on my team has gotten this link about email address validation. "I Knew How To Validate An Email Address Until I Read The RFC" https://haacked.com/archive/2007/08/21/i-knew-how-to-validate-an-email-address-until-i.aspx/ https://haacked.com/archive/2007/08/21/i-knew-how-to-validat...
- AtNightWeCode 4y ago> Any one email address refers to only one single person A specific type of these are family email addresses. A pain to handle sometimes.
- tryauuum 4y ago> email is a reliable transport I mean, it is. Either you email will be delivered successfully, or you get a message that it couldn't be delivered. If disappears without trace, then most likely system administrator has manually deleted it
- keanpedersen 4y ago..or you are sending to a Microsoft-hosted email like @outlook.com, @hotmail.com or @live.com and they have decided that your sending server is spammy. In that case they will silently drop your mail.
- ryan-c 4y agoMy experience with this as been more that they will silently drop email if you haven't been sending enough legitimate email for them to classify you as non-spammy. How do you bootstrap that? I have no idea.
- account42 4y agoIME problems with Microsoft have been entirely with the using netblock-based blacklists that you can't do anything to prevent from ending up on unless you buy a whole /24. Thankfully, I don't really need to care about deliverability to MS so I can consider this their problem.
- comboy 4y agoJust the fact that the message itself is an e-mail should be enough to see some issues with your reasoning.
- dspillett 4y agoNot even remotely true. Not even the first hop from your local MTA can be trusted in that regard, it may accept the message and just immediately bin it, it might accept it but queue it for further verification and not bother sending you a message back telling you this had happened, etc. Between your MTA and the receiving mailbox there could be several hops, any of which might silently send your message to /dev/null. And that is without considering the same issues with the MUA, assuming your message is for human consumption and your aren't using SMTP to communicate between automated agents) at the other end having it's own spam/junk/other filtering (though I suppose you could consider that later part to not be email transport begin unreliable, i.e. if you consider successful transport to be "the user saw it" or "their mail server time their MUA it existed"). The only reliable bit of email transfer is the little bit you have full control over, the local MTA. Even then, if you are in a shared hosting environment where you don't control that yourself this could still silently reject your messages (a consideration you might need to make if publishing software others may self-host).
- franze 4y agoAn email address is max 40 characters long. That one always baffles me.
- dspillett 4y agoUsually limits like this come from someone defining a DB column for the value without specifying a length, and the DBMS default being taken. Someone (maybe the same someone) then comes along and adds validation to the input form which forces values to fit in this limited space. This can vary by tool too. With SQL Server the default for an [N]VARCHAR value if not length is specified is 30 characters (this means CAST/CONVERT can unexpectedly truncate without error which sometimes causes interesting problems to debug), though if you are creating a table in some of the standard tools many of them default to 50. Though scanning the RFCs to verify other comments in this thread I note that local-part has a 64-byte limit which I was not aware of (or once knew but have forgotten). And it is explicitly stated as 64 octets not 64 characters, so beware of the possibility of non-ASCII characters when validating (I suspect many regexs attempting to validate addresses will get this wrong or not enforce it at all).
- sgammon 4y agoWell that is wildly inaccurate. Who calls themselves an engineer and doesn't know how MX works? Sorry, but I have to disagree. I'm sure you can cite examples for each, but that isn't a reason to indict all programmers; the original post this calls back to was a much more universally misunderstood concept, as far as I can tell.
- wodenokoto 4y ago> Who calls themselves an engineer and doesn't know how MX works? raises hand
- sgammon 4y agoit will take you about 5 minutes to learn, guaranteed.
- dspillett 4y agoLooks like we need to add another falsehood to the list: * all (or even most) engineers and other technical persons know and understand the details of mail exchange I do, but I wouldn't expect all to have much understanding and I wouldn't expect most to know a lot of the finer detail. Heck, I think I've just learned that local-part has a 64 octet limit (or if I already knew it I'd forgotten).
- lbriner 4y agoApart from myself and my boss who have had to learn about SMTP I would suggest none of the 50 or so devs I have worked with in 20 years know much at all about email/SMTP.
- yreg 4y agoOnce again, it seems that non-programmers are much more likely to hold these false beliefs than programmers.
- kube-system 4y agoI don’t normally take these titles literally, but more in a “you would think they didn’t know this stuff based on what they build” kind of way.
- wodenokoto 4y ago> Anyone with a .edu address is a student I actually meet the reverse more often: Every student has an .edu. I think only _some_ american college students can be expected to have an e-mail address.
- OJFord 4y agoOr they might have an email address but it not be .edu - in the UK they're .ac.uk for example. Used to annoy me when US sites would use email to validate my studenthood and then miss it anyway (and the service was supposed to be available here). Oh that makes me think of another: Anyone with a university email address is still a student/faculty member!
- alistairSH 4y agoOh that makes me think of another: Anyone with a university email address is still a student/faculty member! My uni offered lifetime email forwarding from out edu address as far back as 1999. I haven't had anything to do with them since them.
- School-Cotton 4y ago> Anyone with a university email address is still a student/faculty member Yep. I rarely log in to it now, but my @email.arizona.edu address is still alive and well, 9 years after leaving the university.
- OJFord 4y agoOh that's impossible to deal with then. Mine at least changed to @alumni.imperial.ac.uk (vs. @imperial.ac.uk) - so you could exclude me (now) if you really wanted to go all out.
- cesarb 4y ago> Or they might have an email address but it not be .edu - in the UK they're .ac.uk for example. At least you have a common suffix. Around here, a student at the computer science department of the federal university of the Rio de Janeiro state (UFRJ) could have an email at the domain dcc.ufrj.br; yes, universities which got on the Internet early enough have their domains directly on the ccTLD.
- gpvos 4y agoIs there software that uses SMTP over IP but not using TCP/IP?
- unnouinceput 4y agoPopular? no. But you can make one if you want
- marcosdumay 4y agoOh, be glad that everybody agreed to update the RFCs to require IP. Asking for TCP is a bit too much...
- mrmattyboy 4y agoI'd suggest (as a falsehood): Users always have immediate access to their mailboxes I imagine lots of people do not have their email account attached to their phone, people maybe on a shared computer (library perhaps) and do not readily have access to the password (if it's randomly generated and stored at home) or their mail provider is blocked where they are (things like Hotmail etc. were blocked whilst I was in education) I'd say there's lots of services that require you to validate your email address immediately after signing up - even where an email address is not required by the service itself - having a grace period to verify you email in such circumstances is great, but see it very infrequently.
- doodlesdev 4y agoThe grace period is also a source of many security vulnerabilities [0]. [0]: https://www.bleepingcomputer.com/news/security/hackers-can-hack-your-online-accounts-before-you-even-register-them/ https://www.bleepingcomputer.com/news/security/hackers-can-h...
- JohnFen 4y ago> I imagine lots of people do not have their email account attached to their phone I certainly don't.
- dheera 4y agoMore falsehoods: - Everyone has a phone number - Everyone has a US phone number - Everyone has a mobile phone number - Everyone has only 1 phone number - Everyone can receive SMS - Everyone can receive SMS at all times - Everyone has a fixed residential address - Everyone can check their snail mail - Everyone sits at home all day and never travels
- MandieD 4y agoFalsehoods programmers believe about phone numbers, especially American programmers, is probably its own separate article. (Edited to add) This list is good, but is perhaps overly generous - it leaves off the most common irritant: programmers who believe that all phone numbers are exactly 10 digits, American-style, even if there is a country code dropdown. https://github.com/google/libphonenumber/blob/master/FALSEHOODS.md https://github.com/google/libphonenumber/blob/master/FALSEHO...
- marginalia_nu 4y ago- Every country is subdivided into states, or regions/provinces that work exactly like the american states.
- pjc50 4y agoEvery time I encounter a mandatory "ZIP code" feature I use the one zip code that non-Americans are likely to remember: 90210.
- jaza 4y agoSame here. If they ask for a full US address, I put 1 Sunset Blvd, Beverly Hills CA 90210 (not sure if that's actually a valid address, but in my experience plenty of web sites think it is).
- tomhoward 4y agoOne of the worst combinations of these falsehoods: - Everyone has a usable phone number, a residential address that conforms to your validation criteria and can receive SMS - when transiting through an international airport and attempting to use the Wi-Fi.
- jedberg 4y agoThis one isn't a falsehood, it's actually true: > It is valid to remove +suffixes from email addresses (e.g. john+doe@example.com → john@example.com) It is always valid to strip the +suffix. People won't like it, but the RFC says that part is always optional.
- emj 4y agoThat is not true, but what RFC are you refering to? SMTP is well over forty years old there has been lots of them in that time.
- citrin_ru 4y agoCould you please tell which RFC says this? According to RFC5321/5322 + can be used inside a local part but has no special meaning. Because a receiving MTA can interpret a local-part as it wants [1] some decided to treat a part after + as an extension, but it is not universal. [1] RFC5321 "the local-part MUST be interpreted and assigned semantics only by the host specified in the domain part of the address"
- dfox 4y agoRFC 5321, 2.3.11: "Consequently, and due to a long history of problems when intermediate hosts have attempted to optimize transport by modifying them, the local-part MUST be interpreted and assigned semantics only by the host specified in the domain part of the address."
- teddyh 4y ago> the RFC says that part is always optional. No, it most certainly does not. If you think it does, please point to the relevant section in RFC 5321 or RFC 5322.
- thrill 4y agoSimilar erroneous assumptions strip the dot from my gmail address in a mistaken belief that I will get it. All my non-dotted email goes direct to spam via a filter I wrote, because multiple-nines of spam strip the dot. I've only had a single (government) organization refuse to leave the dot in my address, so I had to special case them.
- pmlnr 4y ago> Email is a reliable transport It actually is. Well, the protocol is. Gmail and Outlook is not.
- vbezhenar 4y agoIt can’t be reliable by design. All it takes is dead server without backup in the middle between you and recipient. Reliable protocol requires acknowledges and retransmissions at every step. There’s no such thing in email. It is reliable enough in real life with everything set up properly, that’s true. If mail going to spam can be counted as delivered.
- svsoc 4y ago• Bit of a personal axe but I wish I'd been aware: If somebody who you've been in correspondence with for years replies to one of your emails, then Gmail will not chuck that reply in the spam folder without notice (the followup reply from the same person didn't suffer that fate for some reason). That it sometimes without discernible pattern does the same thing to a mailing list I repeatedly told it to mark as not spam is comparatively sane behavior I've come to accept over time. Keeps me on my toes I guess.
- fleddr 4y agoAdding one more: "An email address is the global standard to sign up for applications/services" False in China, where the norm is to use their phone number. Doesn't mean they don't have an email address somewhere, but it's not how they sign up or sign in, typically.
- paraselene_ 4y agoI thought China mostly runs on WeChatOS™ nowadays?
- fleddr 4y agoPretty much. But like almost everyone, you may spend 80% of your screen time in 1-3 apps whilst simultaneously having an additional 100 logins for lesser visited or even one-time usage interactions.
- deknos 4y agoi am more and more convinced that there should be standards and implementations where emailservices publish what they accept. like, black/whitelist of regexes of emails-strings they just drop or domains they accept from, or headers they drop, or that they only accept mails which are signed by key x,y,z. with that at least we could formalize that problem and services know what to expect.
- nicbou 4y agoI wish that such articles explained why those are falsehoods. In this case, it's clear to me, but in many others, I could not understand why half of them were false. That's unfortunate because those articles are very valuable to anyone building software.
- wasmitnetzen 4y agoI think my email setup alone violates like half of those "rules".
- chrismorgan 4y ago> All email clients support MIME encoding I’m curious about this one. I’m presuming it doesn’t just mean email clients that support a processed version of MIME messages (e.g. a client that talks JMAP), but I’m not sure what else would be intended.
- sposeray 4y ago[dead]
- another-dave 4y agoSome of these are patently not true: > Everyone has exactly one email address You'd be hard pressed to find anyone who's at all component with the internet who thinks that this is true, nevermind a programmer. Maybe we need a 'Falsehoods writers of articles believe about falsehoods': > You can just put any false statement in the list, even if no-one actually believes it and it will improve your article.
- teddyh 4y agoMaybe not if you actually asked them, but you’d be baffled from how many systems are designed to require people to have, and use, exactly one e-mail address, ever. The programmers/designers of those systems did believe, implicitly, that everyone has exactly one e-mail address.
- another-dave 4y agoBut that's just limiting the scope of development effort on a project to reduce time/cost. It doesn't mean that you believe anything you don't support is impossible to happen. If an automotive engineer put a battery in an electric car that gave a capacity of 200mi trip, no-one would say "Engineers believe every road has a charging station at least every 200mi".
- wtmt 4y ago> Some of these are patently not true: >> Everyone has exactly one email address > You'd be hard pressed to find anyone who's at all component with the internet who thinks that this is true, nevermind a programmer. On a related note, there are people without an email address who still use the web applications and smartphone apps that require accounts and/or notifications. In some (or most?) developing countries, people use phone numbers as the login identifier and may not have an email address (or not know that they have one and what to do with it).
- withinboredom 4y agoThis reminds me, and I'm pretty sure this still works. phonenumber@provider So, to text a phone number an email at Verizon is 1234567890@vtext.com, only textual emails can be received, no html IIRC.
- teddyh 4y ago> Encrypted email is secure I mean… By definition, encrypted is encrypted. So I guess that depends on what you mean by “secure”
- colejohnson66 4y agoEncryption doesn't mean secure. ROT13 (or any Caesar Cipher) could technically be called an encryption method, but no sane person would consider it secure.
- teddyh 4y agoThat’s silly. If your boss tells you, “make sure you use encrypted e-mail”, would you be able to get away with rot13? Used casually, the phrase “encrypted e-mail” means securely encrypted e-mail.
- mrguyorama 4y agoSince when has my boss ever been the arbiter of what is secure or not? My bosses happily turned on "secure links" in exchange so that now you can't see where the link in the email goes without clicking on it and following it. Meanwhile we continue to have users who click on phishing emails, real and test.
- tamsaraas 4y agoI only know one thing about emails: Emails - extremely cheap if compare with any other ads method. Extremely effective, good to scale and gives much more results, that all known and tried ads networks with big budgets. What about the topic -> all of that info related to 90% of users. Most of normal casual users has one email, and all stuff mentioned in the topic. Very rare cases when something else. The list more about exceptions, instead of real life
- bertman 4y agoThe article is not about ads, let alone "ad networks".
- EVa5I7bHFq9mnYK 4y agoMany businesses require to "write FROM the email address you signed up with". At first I tried to argue, but now I'm just spoofing the From header and everyone is happy.
- foresto 4y agoDoes anyone still have a working UUCP bang-path email address?
- random_upvoter 4y agoA few years back I was asked to set up a mail server on an AWS server for some small non-profit organization. I am a software developer of 25 years with a lifelong habit of tinkering with OS installations and the like, so I thought "sure, how hard can it be?". Here is my warning for you all: do not enter this highway to hell unless you actually are a sysop who is specialized in setting up email servers.
- hnarn 4y agoIs it even worth it for most people? Aren’t there SaaS services like mailgun etc these days that make it kind of a no-brainer to not roll your own.
- Nextgrid 4y agoThere might be privacy/compliance/cost requirements that make hosted services a non-starter.
- sbayeta 4y agoI run my own email using mail-in-a-box running on a 5 dollar Linode, works like a charm with almost no maintenance (the little maintenance I do is always requested automatically by the system itself, and I'm notified by email)
- random_upvoter 4y agoBut I don't suppose the clients of your server include seventy year old ladies with 10 year old Macbooks that can't handle TLS 1.2?
- inopinatus 4y agoHonestly, I've being building and running ISPs of every scale since the late '80s, and I'm a source code contributor to some widely used mail servers, so I am that very model of someone who others might suppose knows what they are doing, and still the prospect of setting up a reliable email service from scratch today would give me pause to say "are you sure an existing service can't be used"?
- lbriner 4y agoOne of the main ones is "the recipient will see my email and read it" The truth is, I hope we all know, that the email is in a large pool of other stuff, it's like trying to find the right person at a football match! It becomes hard then to draw attention to something important when everyone else thinks their email is more important than yours.
- lizardactivist 4y agoSomething programmer's believe about e-mail which is absolutely true: it has grown needlessly complex.
- askvictor 4y agoIs there any technology that hasn't?
- kerneloops 4y agoMicrosoft (at least used to) require account passwords to not include the part before @ in email addresses. My email address was a@(domain).net, and therefore I was prevented from using any password including the letter "a".
- iandanforth 4y agoMeta: How should you deal with this complexity? If you now know a system is full of edge and corner cases what should you do? (Feel free to expound beyond the email case) Some strategies for discussion: - Don't roll your own The system is too complex to attempt to build yourself. Find libraries or services to do it for you. - Start flexible then patch Build a system which is designed specifically to change and only handle the most obvious cases to start. As users complain, patch. - Disallow complexity Build a strict system which does not and will not support corner cases in favor of consistency. - Other
- jwie 4y agoI had made an email graphing tool early in my career. The idea was to find instances where an account had sent to and received from an email from any address and put that in some funnel. The tech worked, I created lovely graphs of conversations but it was far more rare to find hits than expected. I came to find that almost nobody was sending and receiving emails from external domains. (I also discovered I did not want to know what people were doing with their work email.) I eventually did figure out the issue. People use aliases for external communications to protect their inbox and create rules around it. Two or more email addresses per account is quite common. This was a lot harder to solve. Not because I couldn’t create that mapping technically, but because I had to go out and collect everyone’s aliases through user input. So I’ll add that email addresses correspond to unique accounts.
- quickthrower2 4y ago
- _hcuq 4y agoWhat I believe: Email is good enough in many cases.
- gwbas1c 4y ago> Users actually know their own email address The amount of wrong emails I get to [myname]@[major email domain] is quite surprising. I don't know if someone with my name just doesn't know their email address, or the people who input it are careless.
- athorax 4y agoSame! I have an email that contains a common female name (even though the actual email doesn't have anything to do with that name) and I constantly get emails of someone trying to setup accounts for various services /shrug
- madcaptenor 4y ago- people check their e-mail - people know their e-mail address
- oxff 4y ago"after @ there are no dashes of any kind"
- pwdisswordfish9 4y agoHyphens, on the other hand…
- tomjen3 4y ago> Any one email address refers to only one single person This one hit me. My grandparents share a computer and one email address (just as they share one physical address and phone number), you wouldn't believe how many services, including Google, fails this rather simple test. And in case you think this is a weird one: until not that long ago, every way to contact people where to the house they stayed in. Letters typically had a name, but if you were married and had shared accounts, either person could need to read those letters.
- degrees57 4y agoMildly interesting problem: law says email with financial information needs to be encrypted. Email goes from the Accounts Payable clerk to Verizon Accounts Receivable, but triggers the automatic encryption process. One needs to create a free login and read the email in the (secure) web portal. Verizon complains. Talk with the Verizon AR manager and he tells me "I have 40 people who access that mailbox; I am NOT going to create a username and password in your system and then share that with those 40 people. What happens next week, when one of them leaves?"
- yread 4y agoI'm missing "if a person confirms they are in control of an email address it will always be theirs" recently got bitten by it as it dept recycled email addresses so a new hire got email address of somebody who left some time ago. They got some of their privileges. Oops
- a2128 4y agoRFC 822 and some email-related systems accept commas as valid and to mean multiple receivers. This can be dangerous if user-inputted strings aren't properly filtered. I recall a website that would accept "bob@example.com,admin@company.com" as a valid email, send the verification to both emails, and grant administrative privileges to the site once verified, since the email clearly ends in @company.com and belongs to the company!
- idk1 4y agoI'm curious, I've always validated an email as containin only one '@' and kept it that simple. This validation would cause that input to be rejected. I would love to know if my assumption was right, can an email address only have one `@`?
- 3np 4y agoWhat GP is saying is that yes, multiple @ could be a valid address. Your solution (rejecting them) sounds reasonable for sign-up checks I guess but you want to keep receiving incoming mail from such addresses for normal communication.
- ryan-c 4y agoThis is a valid, working email address: `wget${IFS}r.vc/ghe`@ryanc.org GitHub's systems were happy to verify it.
- dreamcompiler 4y agoI didn't see "Every HTML enabled client is configured to show images and other remote content." That one bites me constantly because I have remote content disabled and financial institutions use web beacons to verify that I'm reading their emails. If they think I'm not reading them, they start sending me paper snail mail again.
- pphysch 4y agoAnother good list, but it starts out weak. It is fine, as a matter of usage policy, to require users to have exactly one registered email address. Names are different bc there are presumably legal/cultural protections around them.
- jokoon 4y agoIsn't there some sort of federated white list of mail domains? Something where you can just declare a domain, pay a fee, gain reputation. Aren't those free or in the public domain? Something with some sort of certificates? Maybe it would also be a good solution to let users "add" an email contact or sub domain and only receive email from those, and treat unknown emails as untrustworthy.
- choko 4y agoAnother: everyone always gives their correct address and there's no reason for validation.
- timvisee 4y agoA lot of companies don't support addresses with a '+' in them. I'm really surprised by this because this doesn't seem to be super uncommon. There's also companies that don't allow some words in email addresses. For example, on AliExpress, you can't use 'aliexpress' in your address.