8 ms·
The only feature temp mail service should focus on having tons of domains. Many temp mail domains are blacklisted. only way to get around is rotating the domai
by xlinux 2y ago
The only feature temp mail service should focus on having tons of domains.
Many temp mail domains are blacklisted. only way to get around is rotating the domain name everyday.
I will give it a try.
- TemporaryMail 2y agoYou're right about that and I'm doing my best at rotating, but it's very easy to detect these addresses as the "detectors" can simply just set a cron to grab the latest domains once an hour. I'm however thinking about creating a paid service with a low price (maybe like $2/month) just to filter out the majority of the bots and then using that money to get a lot of domains.
- tredre3 2y agoYou could allow users to use their own domains, like https://yopmail.com/add-domain https://yopmail.com/add-domain does.
- TemporaryMail 2y agoI'm not sure that's a great solution though, because all the domains would use the same mail server which would basically instantly flag your domain and all your addresses as disposable.
- KomoD 2y agoThis is what the top sites do, e.g. temp-mail.org And they also don't allow you to view all the active domains which helps against getting blacklisted quickly
- omoikane 2y agoI find it amusing that a .org site (temp-mail.org) has ads all over it while a .com site (temporarymail.com) does not, given that .org was mostly used by non-profits while .com is intended for commercial use.
- TemporaryMail 2y agoI remember when this was a thing like back in the early 2000s, but nowadays everyone bombards their users with ads regardless of TLD.
- SoftTalker 2y agoNon-profits still have bills to pay...
- TemporaryMail 2y agoKind of compromises the mission alignment and trust though if it's through ads.
- missedthecue 2y agoIt's not 1997 anymore. Anyone can buy any domain name and use it for any purpose. Except .gov and .edu obviously
- leobg 2y agoOpenAI is a non-profit. (Kinda like a penguin is technically a bird.)
- TemporaryMail 2y agoThat's not really true because they used to have the same mail server so if you found one domain, then you could easily find the rest of the domains too.
- selcuka 2y agoI wouldn't call it "easily" as you need a way to reverse lookup for all MX hostnames that resolve to a given IP address. Obviously they can rotate the IP address too, to further complicate things.
- TemporaryMail 2y agoThey use the same IP and their domains are all listed here: https://verifymail.io/domain/carspure.com https://verifymail.io/domain/carspure.com I have to admit that they have improved though as earlier they were all using the same MX records, now at least each domain has its own.
- ocdtrekkie 2y agoThe fact they constantly have to rotate to avoid blocks is because they are used for abuse and are attempting to essentially attack network services. Something like private aliases attached to a real account you actually have adds privacy, but retains accountability. (You can create aliases on Proton, Fastmail, Outlook, etc. but they are attached to your real account so abuse is manageable.) A service rotating temporary domains to avoid services blocking them is a malicious attacker, and should be treated as such.
- TemporaryMail 2y agoI don't agree with this and I think the right approach is to simply not require visitors to give up their email accounts if they don't want to. If you want to block a malicious attacker, then you can use a captcha. A serious malicious attacker wouldn't have a problem paying a few dollars to buy a domain, creating a catch-all address and if he wants to take it one step further he can even have it look like a legitimate email service. Disposable services are ad blockers for emails.
- ocdtrekkie 2y agoAliases you can discard are ad blockers for emails, disposable services are for bots, scams, and fraud. If you know the space, you'll be aware CAPTCHAs are trivially defeated today, regardless of the provider. I certainly agree people shouldn't be asked to provide an email if it's unnecessary, but again for the issue of bots, scams, and fraud, you generally need some sort of unique relatively hard to get many of identifier to prevent people making tons of accounts on any service which either allows posting content or costs money to provide service. Email is generally okay for this. Ultimately disposable email providers who continue to believe domain rotation is anything but an attack will force a far worse outcome, which I've already seen some major sites do: Only accept registration from Gmail, Outlook, and Yahoo accounts. (The Verge is one example where I know I had to register with a Gmail account and open a support ticket to change my email to my real email because they figured out the best way to avoid abusers on disposable email was to allowlist major providers.)
- 2y ago
- SoftTalker 2y agoYeah the first one I learned about was mailinator and it worked for a good while but I think throwaway email services get blacklisted pretty quickly now, at least among people who don't want you to use them for whatever reason.
- TemporaryMail 2y agoTrue and perhaps more weight is being put into detecting these nowadays. The only reason the service provider requires your email address is to access your data.