Not processing '+' is a way for spammers to self identify.
If it was about being able to spam, they'd just silently strip the + part. I think it's just ignorance ... in my own mailserver I have a custom separator that usually doesn't trip validation functions.
I used - in the qmail days and never had any problems. The + causes enough problems that I've basically stopped using it.
People seem to spam me, but gmail is pretty good at filtering all that stuff into the "Promotions" folder, which is nice.
This assumes the “+” is not a trick to see if they are stripping the “+” from the username of the email address; which then is automatically flagged as SPAM. Of course this assumes you’re creating a new email per contact, not just using a feature that was never intended as a anti-spam tool.
Can you go into a little more detail or provide a pseudo example?
I'm confused at how this allows spammers to self-identity.
If they strip it out you know the want to spam you so can block their domain and/or decline to sign up.
And if they don't strip it, you can add a unique identifier to your address for every site you use it on, and know who sold your address.
I have only a handful of addresses on my machine so implemented the letter ‘f’ as the selector (none of the usernames nor various full name aliases have that letter in them). I really doubt any spammer could screen that out :-)
You can deal with this by using subdomain tags on some providers. user@tag.domain.com rather than user+tag@domain.com.
This is intentional. It's because the people who own the site know the gmail <realemail>+thisisspam@gmail.com trick and they prevent people using that trick.
I've fixed this issue at a large company, and it was not intentional, but poorly written regex
Fair enough. I failed to apply Hanlon's razor.
Using regex on email is a horrible idea unless there are very well defined blocks - such as only allowing a given top level domain.