You’re fighting the wrong battle.
https://github.com/martenson/disposable-email-domains/blob/m...
A lot of sites I've come across lately are going back to the old-school way of only whitelisting email addresses from .edu domains or ISP accounts ("@comcast.net").
Gmail itself is allowed, but the addresses are normalized. I'm well aware of its potential for abuse.
I personally own over 100 from a couple years back when recapta was easily automateable and the phone-number requirement wasn't there.
I have an email address for every site I sign up for.
Helps you figure out who sells your email.
How do you handle this? Or do you not?
I guess you could do a DNS lookup of the mail exchange records and see if it points back to gmail and compile a list of domains to allow one account from... but then that would break many companies emails. That’s no fun.
Services need a better way to figure out fraudulent or abusive behaviour than guessing based on the email account's domain name.
I haven't seen ISPs give out emails addresses like that in years (I now my last couple of ISPs have no such thing).
So you're basically limiting yourself to people from universities, or who've had an old-school ISP for a while.
Mobile carriers even still seem to, though they are optional and require an additional setup step.
Obviously it never works, as I get the "I see you're trying to create a new account" email, but one of these days he's going to figure out a way to take over one of those accounts and then I'll really be fked.
(1.) What are you imagining is the attack vector exactly?
(2.) Are you asserting that all website owners should build to Google’s (non-standard) behavior?
Can me and my wife both sign up to HN and use my email but hers be josh+swife@joshmanders.com and mine be josh@joshmanders.com?
That's a strange usecase, isn't it?
Having said that, in development, it's super nice to be able to create addresses with +'s in them.
On top of that, it's just as easy to set up a catchall email address -- an email box that accepts all mail for a domain, literally anything@mydomain.com. So a malicious actor could sidestep this security attempt with minimal effort, but it still inconveniences legitimate users despite being worthless from a security perspective.
It's just as easy to write a script to use ephemeral hosts that you don't need to sign up for. Things like Mailinator.
All it does is irritate people like me who use +words as prefilters for email (and to see which companies are selling my email/user data).
It's all too much for me to keep track of, but for some people it's no big deal to create new e-mail addresses every month.