4 ms·
Real Email Validation
- healthenclave 14y agoVery helpful thanks !!
- martinp 14y agoMaking your app connect to random SMTP servers every time it needs to validate an email address doesn't seem like a good idea. Shared domains (gmail.com etc.) might even get you blacklisted if you flood the same SMTP servers over and over again.
- healthenclave 14y agoIs there a work around ? How about using proxy but I guess that adds another layer of complexity
- SudoAlex 14y agoUse a queue processor - but that's probably going too far for simple email validation. The simple work around - don't do it. This code is susceptible to Denial of Service problems similar to the URLField verify_exists option https://www.djangoproject.com/weblog/2011/sep/09/security-releases-issued/ https://www.djangoproject.com/weblog/2011/sep/09/security-re... - a malicious SMTP server could tarpit all your SMTP connections from Django leaving your site with no workers to process other requests. The email validation from an EmailField is designed to ensure that it could be a valid email address, not that it's a valid mailbox. Live with the limitation instead of trying to be too smart.
- jpadilla_ 14y agoThis is pretty awesome! Wonder how much time would it take to validate. Last thing I would want is to make that signup process even slower. I guess you could still let the user pass and then run an async task to check "if the domain name exists, ask for MX server list from DNS, and verify that SMPT server will receive a message to that address" and then maybe set a flag somewhere.
- makethetick 14y agoCould be easily modified to verify email lists too, very handy if you haven't sent for a while and want to avoid bounces.
- jodrellblank 14y agoAnd I'll still give you fakeaddress@mailinator.com, it will pass every check you can throw at it, including sending an email and getting me to click a link, and it still won't be a real email address. Still your move, e-mail harvesters. Checking that I haven't mistyped it or put the wrong thing in the wrong field is a basic sanity check. Beyond that, the only way to actually get a real email address that I read is to be a service I care about.
- Swizec 14y agoFor me the trick isn't to get my real email address, I give that to anyone. But kudos to you if you can make it into my "Important and unread" inbox and remain there. It's the only part of my email that I actually check. Some services are so great I let their daily reminder emails go there and enjoy reading them. That's right, there are services out there (I only know of one) whose daily "You should use us" email is so awesome I enjoy reading it every day.
- roc 14y agoThe only E-Mail validation involves sending an actual email with a response link. Because even if people happen to give you a functional email address, it isn't necessarily their email address. And I say that as someone who has come to regret registering a first-initial-last-name gmail address. And it's not even a particularly common last name.
- addlepate 14y ago> Because even if people happen to give you a functional email address, it isn't necessarily their email address. True, but also true of Mailinator. Ultimatley, we can only receive what people are willing to give in the first place.
- vincentkriek 14y agoI think the purpose of this validation is to help people who mistype their emailadress, not to check if it is their emailaddress.
- cincinnatus 14y agoRight but on a large system it is possible to mistype it to a valid address that isn't yours.
- papsosouid 14y ago>And I say that as someone who has come to regret registering a first-initial-last-name gmail address. And it's not even a particularly common last name. It is amazing how common this problem is. I assumed it was incredibly rare, but I have 23 different people who have given my email address to someone thinking it was theirs somehow. Not like "I am just signing up for some forum" kind of stuff, logins to government websites, banks, car dealerships sending me stuff about someone else's financing, etc, etc. It is crazy how many places don't verify the owner of an email address before sending it sensitive info.
- mikeash 14y agoI used to get a lot of pictures of children related to a guy with my name. That was pretty creepy.
- bambax 14y ago('SMPT' is used throughtout instead of 'SMTP'.) What does django.core.validators.EmailValidator actually do? Validating an email address with a regex is surprisingly hard: see http://www.ex-parrot.com/~pdw/Mail-RFC822-Address.html http://www.ex-parrot.com/~pdw/Mail-RFC822-Address.html I wonder if EmailValidator does this, or something simpler?
- baudehlo 14y agoThat validates RFC822 addresses, which is the full syntax of the From/To/CC headers. You don't want that for validating an email address on a web form.
- alexkus 14y agoWill also fail to allow addresses that purposely soft bounce (4xx) the first attempt (or attempts within a certain time limit) to deliver to them.
- bambax 14y agoAs an aside, would there be some value in providing an email validator API? Something exactly like this: http://mythic-beasts.com/~pdw/cgi-bin/emailvalidate http://mythic-beasts.com/~pdw/cgi-bin/emailvalidate but which would respond in an easy-to-parse way (JSON|XML). It could be enriched by detecting common spelling errors ('gmial' or 'g-a53'* instead of 'gmail' for example). *: gmail when typed on a European laptop with numlock on.
- mmmooo 14y agoGreylisting is pretty common, and this would obviously fail: http://en.wikipedia.org/wiki/Greylisting http://en.wikipedia.org/wiki/Greylisting
- fein 14y agoHere's a secret: regex: /^(.+)\@(.+)\.(.+)$/ maxlen: 254, minlen:5 Aside from sending your verification email, that's all you need.
- ceejayoz 14y agohttp://www.ex-parrot.com/pdw/Mail-RFC822-Address.html http://www.ex-parrot.com/pdw/Mail-RFC822-Address.html
- saurik 14y agohttps://news.ycombinator.com/item?id=4794368 https://news.ycombinator.com/item?id=4794368
- pythonist 14y agoI believe that this part is using the Django's pattern matching: super(EmailValidator, self).__call__(value) Just tried it. It works!
- micampe 14y agoAre single letter domain and tlds allowed?
- fein 14y agoyep, thats why we do a check for a min of 5 chars: a@a.a edit: the regex should pick this up by default anyway, given its looking for .+ and not .*, but my validation libs have the min and max length built in as well.
- micampe 14y agoI meant to ask if they are valid in the IETF sense, not in your regex. Turns out that single letter second level domains are allowed but they are reserved in some TLDs http://en.wikipedia.org/wiki/Single-letter_second-level_domain http://en.wikipedia.org/wiki/Single-letter_second-level_doma... On the other hand, no single letter TLD exists http://data.iana.org/TLD/tlds-alpha-by-domain.txt http://data.iana.org/TLD/tlds-alpha-by-domain.txt And I also just found out in that list that there are IDN TLDs (see punycode toward the end of the list), I didn’t know that. Full decoded list: http://mct.verisign-grs.com/convertServlet?input=XN--0ZWM56D%0D%0AXN--11B5BS3A9AJ6G%0D%0AXN--3E0B707E%0D%0AXN--45BRJ9C%0D%0AXN--80AKHBYKNJ4F%0D%0AXN--80AO21A%0D%0AXN--90A3AC%0D%0AXN--9T4B11YI5A%0D%0AXN--CLCHC0EA0B2G2A9GCD%0D%0AXN--DEBA0AD%0D%0AXN--FIQS8S%0D%0AXN--FIQZ9S%0D%0AXN--FPCRJ9C3D%0D%0AXN--FZC2C9E2C%0D%0AXN--G6W251D%0D%0AXN--GECRJ9C%0D%0AXN--H2BRJ9C%0D%0AXN--HGBK6AJ7F53BBA%0D%0AXN--HLCJ6AYA9ESC7A%0D%0AXN--J6W193G%0D%0AXN--JXALPDLP%0D%0AXN--KGBECHTV%0D%0AXN--KPRW13D%0D%0AXN--KPRY57D%0D%0AXN--LGBBAT1AD8J%0D%0AXN--MGB9AWBF%0D%0AXN--MGBAAM7A8H%0D%0AXN--MGBAYH7GPA%0D%0AXN--MGBBH1A71E%0D%0AXN--MGBC0A9AZCG%0D%0AXN--MGBERP4A5D4AR%0D%0AXN--MGBX4CD0AB%0D%0AXN--O3CW4H%0D%0AXN--OGBPF8FL%0D%0AXN--P1AI%0D%0AXN--PGBS0DH%0D%0AXN--S9BRJ9C%0D%0AXN--WGBH1C%0D%0AXN--WGBL6A%0D%0AXN--XKC2AL3HYE2A%0D%0AXN--XKC2DL3A5EE0H%0D%0AXN--YFRO4I67O%0D%0AXN--YGBI2AMMX%0D%0AXN--ZCKZAH http://mct.verisign-grs.com/convertServlet?input=XN--0ZWM56D... I wonder how many validators fail on these.
- baudehlo 14y agoThis is just awful. A quick scan of the code brings up the following problems: * It fails to deal with the case where there is no MX record for the domain (fall back to A record) * It fails to sort the MX records, potentially falling foul to tarpits * It fails to connect to each A record lookup of the MX host on failures * It fails to deal with transient failures (such as 4xx responses) That was just from a quick scan. Connecting to MX servers in a web environment (especially one using blocking I/O like Django) is generally a really bad idea. Many MX servers use delays and slow responses to combat spammers, and you're passing those slow responses on to your users. Just check it looks vaguely like an email (the regexp fein posted is good enough most of the time) and send a confirmation email - it's the right thing to do.
- andrewaylett 14y agoFailing to deal with transient failures is especially bad when trying to deliver to a system that uses greylisting.
- deleted 14y ago[deleted]
- greyboy 14y agoAdditionally, doesn't it rely on the truthfulness of the SMTP server? That's not a good assumption - it's common to accept anything and null-routes bad addresses.
- baudehlo 14y agoIndeed it does - the only way to truly validate is to get that confirmation email through. On the flip side I do think there's some value in a service which provides a check on the domain - that way you can prevent someone typing in username@gmail.con by accident. But you'd have to actually implement it correctly. Would people be interested in something like this as service?
- tomwalsham 14y agoThe best way to improve email delivery is to understand that email addresses represent humans. Address validation and long-term deliverability is primarily a problem of social engineering, not technical. Ordinarily I'm in favour of things that can improve data quality with minimal user friction, but in this case while it looks like an attractive solution, it's both dangerous _and_ broken. It's dangerous because if you repeatedly open empty SMTP sessions with major ISPs (and some neckbeard boxen) to validate addresses, you will rapidly fall onto blacklists. Furthermore existence of an address says nothing of the end user's ownership of that address. It's broken because of the myriad crazy responses that mailservers return -: 5XX errors for soft-bounces, 4XX errors for permanent failures, deliberately dead primary MX server... The web's email infrastructure is so massively fragmented and quirkily non-RFC-compliant you just cannot rely on technical solutions to these problems except at scale of an ESP (disclaimer: I work at PostageApp.com, a transactional ESP, and we tackle this problem on a large scale) Finally, it fails my 'Spammer Sniff Test': If you think of a clever trick to improve email delivery/opens/responses etc, it's been thought up 10 years ago by spammers and long since added to blocked behaviours in email protection infrastructure. Check for '@', and craft your email verification process to incentivize following through. For long term delivery (to bypass the mailinator issue) provide value, pure and simple.