Dots don't matter in Gmail addresses
support.google.com
support.google.com
But what mystifies me is how these people keep going for years without ever realising they aren't getting account transaction emails (from their banks), notifications of stock trades, even OTP emails etc. How is it possible for people to use these services for years without ever wondering why they aren't getting the routine emails they're supposed to get or even why they aren't getting the OTP email they had generated?
Also none of the institutions I contacted to ask their clients to update their correct email bothered to do so. On the contrary they sent me back what looked like automated replies asking if their customer service was satisfactory.
At this point I'm sorely tempted to delete my email and start over with another service provider. The nuisance of having to delete almost a dozen emails not meant for you every single day is annoying to say the least. At least with spam you get it sent to spam folder and there it stays. Confidential emails not meant for you is awkward and uncomfortable to have to put up with.
But without a confirmation process to verify correct emails, this will continue as a fact of life, just like wrong phone numbers in the last generation, and wrong postal addresses in the gen before that.
I had a bank account I thought I had closed, but hadn't. Finally noticed and closed it 10+ years later. We moved around a lot.
Why not? Or you could start over without deleting your current email and go into Gmail settings > Forwarding and POP/IMAP > Add a forwarding address, and make it forward all of your emails to your new provider, where it should be easy to sort all emails from your old address to a certain folder or tag that you only check and clean, say, once a week (for any senders that don’t have your new email).
Perhaps they also get paper statements in the mail and text message notifications, and don't even know that they also are being sent redundant emails?
(It can go the other way, too. I think I've got some of my financial institutions configured to only send me email and text. If one was also still sending paper statements and those were going to the wrong address, I'd never notice).
Hope that helps, as someone with a common name I sympathize enormously.
You can also automate this part, perhaps to reply with "You probably have the wrong person, but if it is actually for me I'll get back to you shortly".
E.g. johndoe+mailinglist@gmail.com
Unfortunately some services won’t accept that as a valid address.
The worst example of "we know what are valid email addresses better than anyone" case was when adidas.com decided that they'd redesign their registration flow and in the process disabled logins with "invalid" email addresses when they previously had accepted registrations and logins with email addresses tagged with + for years. That was genius.
I've marked most of them as Spam at this point, so hopefully Gmail's filters are simply learning to automatically send anything in Spanish to my Spam folder.
What I HAVE noticed is that it's usually transcription error. These people that share my name are writing down their email with a pen and paper and a secretary or transcription service is inputting it incorrectly. Lately I reply back to hotel confirmations asking for a complimentary hotel upgrade with lots of extra soap in the room.
If my email is foobar@gmail.com, his is foobar7@gmail.com.
You'd think 10 years would be enough time to learn the difference, but nope.
A group of students included my email address in their project discussion. They ignored my emails asking to remove my address. So I started replying as if I was a part of their project, but requested/suggested slightly stupid things. They figured it out real fast after that.
If you have the person's actual email, CC him on all that. If not, include a note saying your a different John Doe and to please remind the John Doe they want to reach, to use his own email address.
I did this once when someone created a Facebook account using my address. I let it go for a year and then did a password reset and deletion. At the time there was no requirement for email verification so the account was fully functional. Again, this is Facebook's responsibility to verify new accounts. A confirmation email link is last century's technology.
Moreover, what happens if this doppelganger is committing crimes via said account and investigators track you down from the email. It is in your best interest to eliminate these accounts. Kindly explaining the situation to non-existent customer support will get you nowhere.
IANAL but I don't think it works like that. Ownership is not the same as control.
Yeah, no. Peace out dude, I'm done here.
If you took it literally that would imply the actual email address is a single letter @gmail.com and although some ex-SRE people and others at Google have said there were ways to get short addresses for employees, nobody has suggested a single letter would be available even for them. For normal users the minimum was six characters.
But yea your right about the plus I guess Ii didn't read it detailed enough.
Also some senior woman in Oregon, who is a frequenter of "silver singles".
Some industrial supply company in Canada is very confused by the fake Groupon I sent them for the free stuff they are trying to bill me for.
Some guy in Australia has his security deposit box setup with my address, and is way overdue on some payments.
(I've tried multiple times to correct the wrong email address of the people I mess with, and have been ignored)
Lots of US political junk mail, from many localities, both parties. LOTS AND LOTS OF KINKY PORN SITES.
Fortunately none of them have the dot in the address and I have a filter to send them all directly to trash.
I’m not at all careful to keep my email address hidden on the internet either.
It never occurred to me that it might be due to being on a custom domain. I figured either I was just lucky, or that there’s less spam these days.
Tip: configure a catch-all to your email address, and use custom email addresses for every website. I love having e.g. news.ycombinator.com@gilani.me and being able to filter out bad email addresses whenever they become tiresome.
I've also configured Mailgun on the domain (not what it was intended for but ¯\_(ツ)_/¯ ) so whenever I need to send an outgoing email from one of my custom addresses, I use their SMTP credentials.
At this point, I've been me@ amin@ heyamin@ and even notamin@gilani.me.
My GMail spam folder has around 10-15 messages in it per day. My inbox is nearly always fine. The nice thing that GMail does is sort promotional emails that it doesn't judge to be outright spam under the "Promotions" category, which I don't see unless I seek it out. That one still isn't that bad, on the order for 10 per day, but it is genuinely stuff I don't care to see.
If I were to move away from GMail (which is on my todo list), I'd have to figure out what to do about those. Likely they mostly have unsubscribe links; after a quick scroll down the list, I think it's nearly all from companies that I do have or had an existing relationship with.
I wish GMail had an "unsubscribe" button so I don't have to hunt through emails for their often-hidden unsubscribe link. Yes, I could click Spam and then "Unsubscribe + Mark Spam", but I really want just "Unsubscribe", but that's not an option.
I do have a fairly uncommon last name, so it's not something that spammers might accidentally put in a word list to use as an email domain, but overall I've just mostly not cared about "protecting" my email address, and it's mostly not been a problem. Is this entirely atypical? If so, I wonder why...
At one point I decided to actually hit the unsubscribe links rather than just archiving these emails. Turns out I was subscribed to nearly 200 different mailing lists. But there were only 1 or 2 that wouldn't let me unsubscribe.
I keep dedicated email addresses for most purposes, and the two that are getting any are a random mailing list, and the kickstarter address. That one has been caught in a vortex of spam, clearly meaning that kickstarter can't keep their mouths shut about customer emails.
Most of it goes to:
* admin@<mydomain>.com - listed in whois publicly for a few years, understandable
* <dropbox's address>@<mydomain.com> - started coming in 2014, the fact they were breached only became properly known in 2016.
* <my first name>@<mydomain.com> - This is the actual email address I give to in person contacts. Not quite sure how it ended up on spam lists, my best guesses are from a recruiter sharing it, git commits (though the fact the address I use way more commonly for git isn't there indicates probably not) or someone just figured it out.
I gave up on Gmail for all the same reasons as the stories in this thread.
> The guy in Zimbabwe works for a college of some sort. I make sure he's signed up for all the educational trips to Europe.
Both made me laugh, you are a wild man!
The weird thing for me is that it seems to be more than just a single person writing down the wrong email or using it for junk mail. I have gotten emails from places all over the US, a couple places in the UK, and in the past year or so from someone in France. And while some of it is junk mail, I've gotten emails about rental agreements, company emails, insurance policies...
I used to try to be nice and email people back and tell them they had the wrong person. Now I just delete them. It's not worth the time and effort. Unless it's a kind old lady sending an email to her grandson, it's getting deleted. Hopefully their insurance company or whoever will call them after not hearing a response. Unlike regular mail, there's no consistent "return to sender" function, so...deleted.
Now I realise I was a chump and should probably have just stuck with sexxiboi69@hotmail.com
If you put that on your resume and they hire you, it's probably a good place to work.
So I get a lot of emails meant for other people whose email is firstname.mylastname@gmail.com where some sender drops the firstname and the dot for some reason.
I received airline reservations (where I can click and change seat assignments!), cancer diagnoses(!), wedding invitations, bank statements, real estate documents to verisign, all sorts of things.
I've been tempted to do things like switch the person's seat to a middle in the back by the bathroom, but while I've clicked through to see if I _could_ do it, I never actually completed it. I did once send my regrets to a wedding invitation.
A week later I got an apology email, and the incorrect emails stopped.
You can set up a filter for the incorrect version of your email address (any email to namenodot@gmail.com) and get those out of your inbox.
Usually I am polite about it and let people know, but sometimes I make a game of it. I was invited to participate in a drum circle with an offer to pay for my flight to which I replied that I would love to join, but they would also have to pay for drum lessons. I got a mother insisting that I come home for the weekend to which I replied that I am home, perhaps she hadn't knocked hard enough.. etc.
At one point I got like 15 emails deriding me and my choice to "not support firefighters". Turns out that a member of a city council had listed his email as councilman.<me>@gmail.com and most people just ignored everything before that period. I took it as a challenge to see what the most outlandish thing I could say was that would be believed. Some of the better attempts: "My wife had an affair with a firefighter once!" and "My house has never burned down, why do we even need these guys?".. etc.
With most of the financial emails you can unsubscribe at least. =/
My e-doppelgängers have priced cars across the state of Ohio, been active in the PTA, pursued higher education in Germany, and seems to always be interested in commercial real estate in the outer boroughs of NYC.
Though once -- I received an email asking me to please just apologize to my sister already.
I replied, "I think you have the wrong email address; I don't have a sister."
I saw a response -- "HOW COULD YOU SAY THAT? Your mother is crying." I thought it best to just walk away at that point.
It's the same guy, who works in a Eastern European country, where I emigrated from.
The first instance, he was asking his supervisor to use his vacation time so he and family could make a trip to Mecca for Hajj. I chuckled and ignored it.
Second time random picture of some massive metal parts from what looked like some factory he works at.
Third time was this year, very recently and I received a pretty unnecessarily detailed email about how he had to turn back home because he had soiled himself while driving to work... That one made me worry he had gotten Covid.
I guess I'm this guy's boss now.
But yea, 5 characters. I was an early gmail SRE so I was able to circumvent the restrictions. =)
Were you a Google employee? Or did you mean something other than how I read this, that your first and last name combined are 5 characters? Because I believe 5-character usernames are not permitted for gmail addresses.
I tried to confirm this and provide a link, but all of support.google.com appears to be non-responsive right now. When it stars working again, this may support my assertion: https://support.google.com/mail/answer/9211434?hl=en
But yes your right, 6 characters is the minimum of "open" gmail accounts. I know of at least a dozen 2 character accounts created by insiders though.
At the time, I thought about pestering my Google-employee friends, but decided to just suck it up.
I have nothing to add, except that you made me smile on a Friday afternoon.
Anyway, I designed a badge called "I broke Gmail" that would get applied to anybody that did exactly that. I intended a hint of shame but I got a wall of emails asking to get it with explanations of how each had broken the service at some point.
Some dude 2,000 miles away from me has bought a Lexus and now I get regular emails about the status of his vehicle, receipts for all work done to it, and reminders of all maintenance not done to it. For a year and counting.
Each email helpfully includes instructions for unsubscribing: First, you log into the Lexus app...
I finally got fed up with it and reported them to abuse@.
99.9% chance no one would care. But people do freak out over this stuff.
Knew one guy that saw that a Bank got hacked on the news. Did an nslookup or similar to check the banks site.
He was arrested the next day and expelled from college for hacking the bank.
Eventually all got cleared up, but screwed up a year of his life
Do you mean nmap?
MIn the old days, when I ran my own mail server, I used to enjoy rejecting them with custom SMTP 550 messages.
Now I can't do that so I hard to resort to bothering the poor folks at abuse@.
In my defense, they have emailed me from 3 or so different domains/services, so I've had to set up a filter more than once.
I have a boilerplate "you have the wrong address" email in multiple languages that I use to reply to the first email from real people. If they persist they then get added to my auto-reply "you have the wrong address" and delete rule.
For automated emails, I don't even bother trying to unsubscribe. They all get added to the delete blacklist rule.
Some of the more fun mistakes I have gotten have been multiple years worth of tax documents from New South Wales, Wine Tastings in South Africa, Church Choir concerts in Germany, and resumes for a receptionist in Colorado at a Gym.
My personal favorite was a contract offer to play for a minor league baseball team in the Midwest a few summers back.
I also once got hired by the National Park Service for what sounded like a nice gig as a park ranger.
I can't believe this person is missing so many emails that are presumably quite important to them. I can only assume they have the same first name as me but spelt differently and that other people are typing their address in wrong to various systems.
These days I just ignore every email like that, mostly for fear that one day I'll end up stuck with someone trying to hold me responsible for something.
I put the blame squarely on those vendors. "well, we made them type it twice, what more do you want?" Please, please, just pretend it's a communications channel and close the loop!
Notes from BankCorp Ticket BUG-14333: "CIO saw some post on HN so we need to change the email validation. Make them type it three times."
Because they never received the first one, so it's not abnormal to miss the n emails after that.
I used to get periodic emails from an elderly German couple giving me their train itinerary for their upcoming visit. I politely reply that I'm not their cousin, and consequently their cousin probably won't be there at the train station when they arrive. And then six months later it all starts again.
I have what I assume is a distant cousin on the east coast and I get an email with an invoice every time the pest control folks come out to his house to spray. No option to unsubscribe, and I've given up calling the company to let them know they have the wrong address.
There is a fellow in Quebec whose <first_inital><last_name> == <my_last_name>, and for a while I got monthly emails because someone was trying to wire him money. Again, no option to unsubscribe.
Lately I've started getting emails from universities interested in admitting another distant cousin in Oregon. I'm guessing some college lead-generation service crossed her name with my email (her/our last name). I haven't figured how to handle that one yet, I'm contemplating printing a few out and (snail) mailing them along with a note.
But I've had the address long enough that I don't want to let it go, so I guess this is all a necessary burden......
The inverse happens too! Sallie Mae regularly snail mails me to tell me that the (snail mail) address they have on file for me — the same one they send this notice to — is undeliverable! I get all the normal mail (like account statements), too…
More recently I forgot to check the front before opening. I realised when the contents were about a mortgage account, I don't like debt so I certainly wouldn't have a mortgage.
Apparently the previous owner still has a mortgage on this place, which would worry me if not for the fact I have monitoring set up so I know the Land Registry says it's mine, which means even if the idiot bank thinks they've got security for a loan they are wrong and the government will cheerfully tell a court of law that if asked. Hopefully they just didn't update the name of the mortgage and actually security is now in the form of some other property bought with the proceeds of the sale to me, but who knows, these idiots didn't understand "Not at this address" for five years.
I decided to call the bank about this mistakenly opened letter, but because of COVID they weren't usefully taking calls. I could remain in a queue for fifteen minutes and then get automatically dumped out with "We're sorry" if I wanted. So I just chucked the letter in the recycling.
If you need a recommendation for a Bank never to do business with in the UK (certainly not to trust with regards to where their customers live) it would be Halifax.
Like they're signing up for something and put in "santosh83@gmail.com" and think "My name is Santosh and I was born in '83. Google obviously knows this and will send me this email!" ????????
This GP from New Zealand signs up for EVERYTHING under my gmail account. A handful of it spam, but mostly important stuff - notifications for financial transactions make up most of the mails I receive.
I have called his offices repeatedly to try to discuss it with him, and even have a reasonable rapport with his secretary, but he never wants to take my calls.
I really cannot figure out why he does it.
Had first.last@comcast.net, but migrated to gmail and had to use something else. Then they misremember and hand out first.last@gmail.com.
Still waiting for them to contact me at the email _they_ used, to ask for their money back. I have no way of contacting them as the sender info is hidden.
So here's where it gets weird/dumb: the kid replies to my friend and his parents and says, "hey mom, you put the wrong email address on my application, there's no dot in mine."
So my coworker, being the only tech savvy person on the thread replies. "Well, actually, [...]" and explains how dots are(n't) handled in Gmail address. Then the parents then reply and write, "but that's your old Gmail address, we had to get you a new one when we moved to Florida."
At this point my coworker gave up and the kid presumably lost his scholarship because his family didn't know you could keep your Gmail address when you moved houses.
(If you're reading this, hi Jake H.!)
Didn't your colleague forward the information ?
I remember seeing @cox in the email though.
I get so much misdirected mail that I don’t even try to help these people.
I hope John gets to his zoom interview for Deputy Chief of Police later today, because I’m not going to tell him about it.
For the first few years I tried to be kind and alert the sender, but it just became impractical to do so.
It breaks my heart when I see my name twin receiving state benefit notifications or HR notices at the wrong address. He's currently applying for quite a few electrician openings. Good luck, my man.
I know this because I'm frequently getting mail from automated systems for something they filled out.
I mean, I know there's an xkcd about this, but seriously? How do you mistype your own email address so often? In both cases, their real addresses are [first-name][last-name].
e.g. My personal is [firstname].[lastname] and work is [firstinitial][lastname]
If I didn’t use macros I’m sure I’d eventually mix them up too.
In understanding what went wrong here, it's worth noting that historically it was more common to have your email service provided by your ISP. If you moved to a house that wasn't served by the same ISP, your new ISP provided email bundled with the rest of the service at no extra charge, and you didn't want to keep paying to retain your old email, there were circumstances under which a move of house might have motivated a change of email.
Of course this was never relevant to gmail, but it might have been a part of the reason for the confusion. Or it might very well not have.
The law here is that once you have it, you can keep it when changing providers at no cost, they have to make it available to you.
I always found it weird, especially when you have so much choice of provider-free ones (less in France than in other countries but still)
^^^ this is the reality of the world , with people for whom edge = internet.
Of course you can get your domain and self-host your MTA (I am sure that this is what you are doing because who would ever want to be dependent on some provider, seriously). You are in the 10^-(whatever)% of the population that understand these words - and that's the reason people have firstnamelastname7656@isp.com as the address.
I personally find this Gmail feature (as well as the ability to append +anything to your email address) extremely useful.
Websites are pretty good at verifying email addresses these days. The real world, not so much. The super funny part is when you try to ask the bank/doctor/etc. to stop sending someone else's personal info to your email address, and they tell you they can't make that change since you aren't the account owner.
When John Smith signs up for an account using JohnSmith@gmail.com (or John.Smith@gmail.com), and the company trusts John Smith to have provided the email address accurately, three parties are affected: Both John Smiths and the company itself. Yes, verifying email address creates a bit more signup friction, but the consequences of getting it wrong way outweigh that friction for the privacy risk and confusion it causes (unless all the company cares about is a meaningless sign-up metric).
1. They send this information (order details, name, address, tracking numbers, receipt) without requiring a confirmation email. In fact, in their system the email on the other guy's account is labeled "unverified".
2. The emails contain no way to stop future emails. There's no "unsubscribe", "this is not me", "contact us", etc. Every link is to an Amazon page which expects the user to be logged in to the correct account.
3. The system does not sufficiently lock old accounts when the account email is reused. One suggestion from Amazon was to create a new account using my email, which should lock the other account. This did not happen, so now there are two accounts able to send Amazon emails to me with no way to tell them apart.
4. The Amazon website doesn't verify the user's account before displaying order details. If I click on a link from the other person's order return (or other types of links), Amazon opens up to my account but displays information from their order. It's confusing to see someone else's "refund status" alongside my account name on the official Amazon.com site.
5. Getting this fixed is a pain in the ass. I call, they say they'll fix it. I call, they suggest something else. I call, they escalate, try something else again. I chat, can't be handled over chat, they call me, try another thing. I'm not sure why they won't remove the email from his account or contact him and ask him to remove it.
I'm still getting credit card statements from an Indian bank. I can confirm the PDF password is easily cracked :)
https://jameshfisher.com/2018/04/07/the-dots-do-matter-how-t...
I do not know if this has been mitigated.
It's a screencast tool- but instead of putting a video of your face in the corner, it overlays/ghosts your face on top of the full screen you're sharing.
Now sure how well it would work in practice. Maybe it's too distracting.
But it looks like a neat thing to try.
Netflix could make this mistake with postal addresses even, if for some reason they used postal addresses. You get a letter from Netflix, you don't notice it's addressed to Eve, who had stupidly written your address instead of hers, you pay for her Netflix.
This is a data protection violation, data processors have a duty to take reasonable care that the personal information they have about data subjects is correct. If you need it, make sure it's accurate. If you don't need it, don't collect it.
Netflix has zero idea how any particular email operator mangles or maps inboxes to actual users. Apple's private email service maps all sorts of inboxes to the same actual person. Mailinator maps every address to everyone.
But in addition Netflix is right to allow the creation of two accounts where the difference is only dots.
Also in the email name part of the email address, anything after + (plug sign) and before the @ (at sign) don't matter either. [1] This is the same behavior for personal Gmail and GSuite email (Gmail for enterprises)
[1]: https://gizmodo.com/how-to-use-the-infinite-number-of-email-...
You can do this for a wide variety of things and combine it with filters to get a lot of extra value from your email.
Ever since I got a basic Gsuite plan and set up a catch-all email address, I can just use websitename@mydomain and then use filters which is oh so practical!
This is supported by icloud and fastmail too.
No, this is neither supported nor not supported by any email provider - it is part of the email specification. It works that way with all email systems, unless they are non-RFC compliant.
It is not a part of RFC5322, RFC2822 or RFC822 - nothing in those RFCs establish any particular semantics of local-part (the part before "@"), and in terms of syntax IIRC those RFCs only defines the escaping rules (backslashes, quotes, etc).
RFC5233 mentions the established practice of using a separator character that splits local-part into "user" and "detail" pieces, but does not standardize any particular syntax for the separator (it cites "+" and "#" as possible examples). Moreover, this RFC is about Sieve language, and it is out of its scope to define such standard for email addresses.
RFC3696 mentions "user+mailbox@example.com" but does not define any semantics, merely citing this as an example of a valid email address, then going to how it must be escaped in a mailto: URL.
It is completely up to a particular provider to implement (or not) any subaddressing syntax and any logic related to it. No email specification I'm aware of makes this a requirement. (It's not like I've read every email RFC thoroughly, though, so I could be missing something.)
The dots are probably more reliable, but are not as flexible. The best you could do is a secret code for yourself.
Been getting his bank statements, his amazon orders, class emails, share purchases/sales.
Its a joke.
Edit: been happening for around 5 years.
Its also entertaining at the same time to see what he's doing on another continent. I'm torn, dammit Google!
My address is [first initial][last name]@gmail so anyone with a first name that starts with the same letter as mine and the same last name (which, there are SO MANY).
I get;
job offers family photos (I typically respond letting these people know they're not getting through to whoever they're intending) verizon bills (I'm also a verizon customer and they absolutely refuse to take my email off of the other two accounts - I've also texted both accounts since they're numbers have come through various times in the correspondences and they don't even acknowledge my communication let alone update their accounts - they're always late on their payments, but have the newest iPhone's all the time :D) purchase receipts from so many retailers I don't keep track (some of these people have real silly amounts of money) auto purchase receipts bank emails lease offers (just today I had to respond to a leasing agent who was trying to let someone know they got a place they were trying to rent in NYC for crazy money)
It's mind blowing to me how many people get their email address wrong and miss so many important emails, seemingly without ever realizing it.
johnsmith@gmail.com
john.smith@gmail.com
johnsm.ith+foobar@gmail.com
j.oh.nsmith@googlemail.com
all are pointing to the same logical email address.For selfhosting, there's `recipient_delimiter = +-.` in postfix' config. [0]
The most infuriating ones are those where you can subscribe with the '+', but the unsubscribe function errors on it.
I had an account on some site and didn't use it for years. When I go back and try to login they demand I reset my password and verify my email. Sure, no problem. Thing is I used a foo+bar@ email and they had a little sanitizing script running that removed it when submitting the form. Rewriting their spaghetti and getting the form to submit successfully was fun. I was very surprised it worked. Guess they weren't sanitizing on the backend.
I guess the risk would be potentially not remembering that was done or exactly what was used. Also, could keep you locked into Fastmail or limited to providers who have this same feature.
That left me in a slight bind as I had used well over 50 different e-mail addresses. I had switched to Gmail as my primary e-mail address, but hadn't bothered changing my accounts. Luckily, they allowed a very easy way to create forwarding addresses and basically set it up to forward 50+ addresses to one.
Yes, it's definitely convenient that you can have "multiple" email addresses that all point to the same inbox, but the issue is that identity providers don't treat them as all the same logical email address which creates opportunities for scams like these or worse.
Part of the reason is that Facebook verifies you're the owner of the email if you say "someone else has my email" by sending you an email which you have to reply to. But Google will reply to all of them with the canonical sign-up so mine has my.name@gmail.com that the reply goes out with, which doesn't match so I'm stuck marking all Facebook notifications as spam.
EDIT: Interesting, they no longer send me that email. Probably got flagged.
And this is where it gets weird... I was.
Just not because of the dot. My gmail handle is pretty short, 6 chars. First name last initial, pretty cool. I got it during the early in the first beta year, (gmail was beta for like 10 years.) However 10 years later I'm now receiving emails in german, parking tickets from cities I've never been, paid subscriptions, access to gmail and facebook accounts because people set my gmail handle as their recovery address. I can even unlock a guys car from the manufacturers web UI whom I've never met. The best/worst by far is the time the FBI reached out to me, which I thought was some bad phishing attempt and replied mildly taunting them. However, it was in fact a real FBI agent who wrote back noticeably annoyed at my flippant response. There was a vailed threat that if I don't take this seriously things would happen. A lump formed in my throat. I called them and for 5 minutes it was kind of scary. I found out a doctor had been using my email handle for oxytocin prescriptions and they were investigating this doctor... I explained that I had received other messages for this doctor and approximated his age and name, explained my short desirable email address, at which point the agent broke their stern professional tone and we shared a little chuckle.
john.doe@gmail.com
j.ohndoe@gmail.com
jo.hndoe@gmail.com
joh.ndoe@gmail.com
johnd.oe@gmail.com
johndo.e@gmail.com
And now you have six accounts, with the bonus of receiving mail in the same inbox for each account! john...doe@googlemail.com
To see if it passes as a valid address. Don't use this for evil, okay?Two dots in the email instead of one:
j.o.hndoe@gmail.com
j.oh.ndoe@gmail.com
j.ohn.doe@gmail.com
j.ohnd.oe@gmail.com
j.ohndo.e@gmail.com
jo.h.ndoe@gmail.com
...
johnd.o.e@gmail.comjohn.doe+beta@gmail.com john.doe+delta@gmail.com
they all go to the same address
john.doe+uniquestring@gmail.com
j.ohndoe+uniquestring@gmail.com
jo.hndoe+uniquestring@gmail.com
joh.ndoe+uniquestring@gmail.com
johnd.oe+uniquestring@gmail.com
johndo.e+uniquestring@gmail.com
john.doe+uniquestring@@googlemail.com
j.ohndoe+uniquestring@@googlemail.com
jo.hndoe+uniquestring@@googlemail.com
joh.ndoe+uniquestring@@googlemail.com
johnd.oe+uniquestring@@googlemail.com
johndo.e+uniquestring@@googlemail.comOf course some services don't like this so they special case gmail.com addresses to try to block this but it is perfectly legal for a mail server to route these to different mailboxes (such as GSuite accounts do).
I couldn't anticipate the density of misplaced email (allowing me to link multiple parties to the same idiot), the personal insistence of some people (come on, it's me! Your friend —! What do you mean by "I don't know you"?), the ready-made drama (in varied roles: vanished boyfriend, investor in shady businesses, councilman, delinquent debtor...), the quality of delicate misplaced information (with medical records and resumes topping the more obvious invoices, home addresses and bank letters) and the variety of accounts (including e.g. Spotify and a couple of dating sites).
Over the years, I've noticed a slight decrease in incorrect addresses entered by human beings matched by an increase of automated emails to incorrectly registered accounts.
Later I joined as software engineer in a company, I came to know that good email is firstname.lastname@company.bla format, so I wanted to have my gmail id as firstname.lastname@gmail.com But it wasn't available. I was so desperate to have it that I decided to email the person who owns it, so I emailed on the id (having dot in it).
Guess What! I received my own email, requesting myself to handover the id. Then I did some tests to know if dot is making any sense or not. so tested like first.name.last.name etc.
Found this link way back then. Great to know that someone else found it after so long :)
If there is a Googler reading this with the power to remove the dot from my username, please email me (with or without the dot) :)
If you just want a different number of dots in your outbound mails, go to the gmail settings and add a new presentation under "Send mail as ..." and set it as the default.
That's what I needed -- thanks! The dot still shows in my Gmail profile, and it's not possible to remove the "Send mail as..." address with the dot; which is odd. But yes I'm also able to log in without the dot.
I registered an obvious joke email address from a free service. I'm not going to type it here, but imagine something similar to "fakeaddress@example.com". (I could have used a gmail address for the same purpose.)
Occasionally someone will fill out an online form that asks for an email address, and decide to use an obvious fake, assuming that any emails will go into the proverbial bit bucket. That's why I sometimes get emails about someone's health insurance or airline tickets.
It can get a bit frustrating when online support forms insist on asking for account information when the whole point is that I don't have an account.
(Yes, I know I set myself up for this.)
Now odds are, someone is going to respond with the one service where the + becomes significant..
Why? I'm not sure it has ever been a standard and it's certainly not a default implementation for most providers?
Adoption is a mixed bag.
But at the end of the day doing this kind of comparison probably raises more questions than it solves.
It seems to only talk about the receiving server and gives no way for the sending server to do anything useful as it doesn't specify the character to use if the receiver implements it at all.
I think this is good, I would like to not have senders try to guess anything about the structure of my email, but it makes me wonder what the point of having the RFC at all is.
The + trick arose later, as a feature of certain mail recipient programs like Sendmail and Postfix, and most of these programs allow you to change from + to any character you like.
All RFC5233 does is specify how sieve (a protocol for specifying server-side email filters) can describe filtering on subaddresses. It does not confer any actual interpretation on email addresses, especially since many email providers don't actually use sieve for their email filters.
First establish that they're speaking to the wrong person.
Then suggest the nature of their mistake is a simple omission of a letter or number.
never offer a 'no big deal' or de-escalation until they've acknowledged the problem, otherwise the real recipient will never get the email!
This message was created automatically by mail delivery software. A message that you sent has not yet been delivered to one or more of its recipients after more than 24 hours on the queue on mail.example.com.
The message identifier is: 1JYIJ1-0008Ew-JK
The date of the message is: <date>
The address to which the message has not yet been delivered is: <your email>.
validemail+ignored@gmail.com
You can sign up for sites like:
validemail+facebook@gmail.com
and it will still reach your inbox fine but be very obvious if your info is sold or stolen.
Humanity is guilty of not actually verifying ownership/control of the inbox before letting the person attach it to their account but they were absolutely right to treat it as a separate address.
As a result, I often have problems when communicating by email with companies, as they can't match origin of the email (firstname.lastname@gmail.com) to my account email (firstnamelastname@gmail.com).
first.name@company.com is a different address than firstname@company.com.
I learned that one the hard way.
And I can't trust Gmail anymore because of this.
I feel like most, majorish, online services do email verification, but when you are giving your email address to a someone over the phone, that's where most of the problems start.
Well then I'd like to know how someone keeps signing up for services with my address, even though I never click any confirmation links. The email used for signing up specifically differs from mine by a dot.
(Though I don't think I'll complain to Google, seeing as it's just a dedicated address for shady sites, it's free, and Google aren't known for answering complaints anyway.)
Don't. Google has nothing to do with it. Complain to the services/companies sending e-mails to unconfirmed addresses. It is unfortunately fairly common.
from:<some email>@gmail.com and from:<some>.<email>@gmail.com return different results.
What does often happen is that people FORGET what their actual email address is when they hand it out to other people or write it down on forms. Or their friends or family mis-remember it. Your doppleganger may have actually been issued the address johnny.smith, or smith.johnny, but just forgets.
But when I was younger and more foolish, I opened a mail account with a flippant phrase as the handle, and apparently somebody used that phrase as a "fake" e-mail address when signing up for the Trump campaign mailing list.
One thing I'm learning from that deluge of e-mails is that, no matter how little I think of GOP voters, I cannot manage to treat them with the utter contempt that the presidential family is treating them with.
All because they have the same last name as me and opted to use a period in their email address.
This is happening across multiple countries as well. Sadly, none of these people ever receive their important messages because I gave up trying ages ago.
How they continue to explain this away as a feature is beyond me. Google is constantly pushing forward with various, and perhaps superficial, security/privacy oriented initiatives yet here's one of their core products offering up the most private details of others without zero care to fix it. SMH
> Adding dots doesn't change your address, so dots aren't why you got someone else's mail. Instead, the sender probably mistyped or forgot the correct address.
> For example, if someone meant to email john.43.smith@gmail.com but typed john.smith@gmail.com, the message went to you because you own johnsmith@gmail.com.
I can’t for the love of god make clear to these people that there must be a dozen laws this violates. I see insurance application, invoices, disputes, everything on at least a weekly basis.
I have no idea what my legal position in this is. I tried reaching out to the senders, but I am afraid of reaching out to the C-levels directly because who knows how they respond.
Bottom line, people make typos all the time, and it’s not just dots that cause this. People are just terrible at email and email is terrible for sensitive documents.
Which seems to contradict what the article says, since the article suggests anyone who registered my `firstnamelastname@gmail.com` would own mine.
Or is the article suggesting actually nobody ever registered `firstnamelastname@gmail.com` and some idiots just think "oh i need to write to firstname lastname" (one of many who share my firstname/lastname in French) and they just compose that email address? I don't get it.
edit: but moral of the story I think it's really a bad idea to register based on a real firstname/lastname -- I'm tired of getting junk ... and worse, getting invoices for other people for a service I also use. I got confused once and actually made a payment which was not meant for me >_>
I keep getting email without dots because I too have common name someone mistakenly sends to.
It doesn't. firstnamelastname@gmail.com is also your address. Nobody could have registred it.
> Or is the article suggesting actually nobody ever registered `firstnamelastname@gmail.com` and some idiots just think "oh i need to write to firstname lastname" (one of many who share my firstname/lastname in French) and they just compose that email address? I don't get it.
Yes, that's what is happening. If you get unintended emails, their intended destination is yet another address.