Authorize.net rejects customer emails containing “+”
community.developer.authorize.net
community.developer.authorize.net
'I've reached our to our developers and engineers, since this is a highly unusual question. They have confirmed that our system does not allow that character, and that this is an intentional decision. They provided the following reason as an explanation of why that decision was made:
"It is a security issue. We do not allow the special characters so that hackers cannot do SQL injection in the field"
Good riddance.
I'm sure we all have different reasons why we use a + for me it's email+list@domain which lets me sort out client emails into folder for me to easily manage.
Not allowing . would be a similar cry from users; if it's a valid email address shouldn't you accept it?
Otherwise you are letting authorize.net pick your customers