Mozilla's Firefox Relay to be added to disposable-email-domains blacklist
github.com
github.com
It's further compounded by shoddy security that leads to leaks and exposure of people's personal email addresses to pwned compromised lists.
People don't want to give up their personal email addresses so that they can be spammed or hacked. Until services do better (ie don't sell me out for cheap) I'll keep using the latest disposable email address to sign up for your user-hostile websites.
From the prospective subscriber’s perspective, that’s your problem to worry about — not theirs.
> We don’t sell any data.
How should users know that? It’s also not just a matter of selling data — almost all companies will spam your email address, even if you check the box asking them not to.
exactly...which is why there are blacklists like the one linked in the OP.
- multiple sign ups using different emails and similar name
- same ip address
- same data
etc.
Don't underestimate greed or laziness.
But some obvious candidates are
1) discontinue free trials.
2) provide enough obvious value to convert the current funnel of free trials into paying customers at a high enough rate that you don't care about the "freeloaders"
3) radically differentiate the support available on free trial accounts.
In the long run, and dev effort/time spend integrating email domain blacklists is just time taken away from building features that add value to the service/company. It's only possible that spending that time adding features will turn the conversion rate up, but its guaranteed that fencing off the top of the funnel will reduce the number of conversions.
Mitigation against abusers of a service is a valid strategy.
I find this very hard to believe. "Spam" has a specific definition; the most important bit of which is that it is unsolicited. Mails landing in your inbox that you'd rather not get, but which are not unsolicited (say, by you signing up for an account and confirming your address), are not spam by definition.
"Almost all companies" would find themselves unable to send email in short order if what they were delivering was spam.
Definitions are important. Let's not misuse them.
For 98% percent of services I use I mainly want my email for one thing: a way to reset my password.
Often I need to unsubscribe from each of them individually and then navigate some sort of "notification preferences" interface. Even after that has been done a lot of them seem to default any new newsletter or preference to on instead of deriving the preference from the closest existing option.
It isn't spam because you don't want it. If you actually don't want it, then click 'unsubscribe' - and if they continue to bother you afterwards (which, FWIW, I've seen a reputable company do a grand total of once in years), then and only then, is it spam.
It isn’t not spam because you want to send it.
You’re departing substantially from both the historical and commonly understood, contemporary definition of spam.
» Your Prime Membership: {{first name}} {{last name}}, discover the latest in deals and entertainment included with Prime
Commercial email, differentiated from spam in that you have a commercial relationship with Amazon that you initiated and agreed to (i.e. solicited), and as such, they are allowed to market to you until such time as you ask them to stop.
I can see my opinion on this matter isn't a common one on HN.
Your opinion isn’t common among anyone other than marketers trying to justify sending spam.
I'm disappointed to see that attitude here.
Did I sign up for a mailing list?
Yes - not spam
No - spam.
Creating an account with a company is not signing up for mailing lists unless there's a choice presented. Yeah, you can hide consent in the ToS that nobody reads, but that's not asking for permission.
The "mark as spam" button gives users the ability to keep their inbox clean and you shouldn't be faulting them for using it.
Not to mention, even if we agree for a minute that the report spam button should only be used for emails that conform to the legal definition of spam, which law should we be following? The US' definition of spam is much more liberal than the EU GDPR's one for example.
solicit, v 1. To ask from with earnestness
unsolicited, adj 1. not asked for
Your justifications hinge entirely on a very unusual and rather tortured definition of “solicit”.
It's not a false positive. The filter needs to be tuned to what your users think is spam, that is what spam filters are for. You are not the gatekeeper of what other people are allowed to think is spam.
That's not what that word means. I didn't solicit marketing emails; the only emails I asked for were the bare minimum to open an account and anything needed for orders that I initiated.
Man, oh, man, you're funny. Even more so as it is apparently unintentional and you're being totally serious.
To the rest of the world, i.e. everyone who isn't a spammer, 'email I'd rather not have in my inbox' is and has always been the exact definition of 'spam'.
HTH!
That conflicting definition is why the people receiving your email marketing get so mad at you. They would rather have not given you their email at all, but they have to, and they don't want emails from you, but they get them anyway. They don't click your link to unsubscribe because they don't think it would work, and probably just make things worse. So they mark your email as spam, send it to their junk folder, and the returns on your email continue declining, and eventually the mail services start blacklisting you.
Some EU countries require that you offer a simple and effective option to opt-out when gathering the contact details. Depending on the content, that can be a required to be an opt-in toggle.
It's not enough to offer users a way to unsubscribe once you've already started spamming them, there should be a way to not have the first spammy newsletter/newsletter group.
Also, it is presicely spam because I don’t want it, whether you have a right or even obligation to send it or not.
[1] https://ico.org.uk/for-organisations/guide-to-data-protectio...
Do you just let it fill up your inbox and essentially make it unusable as it's saturated with marketing spam? Do you read every single incoming email (if so how do you find time and how do you justify spending that time for this instead of other, more productive/fulfilling endeavors)? Do you have some magical, bulletproof AI that can classify and hide these marketing emails with 100% accuracy? Do you outsource the management of your inbox to someone else and if so how do you justify paying for that?
When I get email I don't want from a company I have an account with, I scroll to the bottom and click 'unsubscribe'. I then don't get anymore of those kinds of emails.
What I absolutely do not do is throw a hissy fit and click 'report spam' (which not fucks up my own bayes classifiers and makes false positives more likely, but sends harmful false reports to antispam orgs).
Seems to work quite well. Certainly well enough that I can't comprehend the level of snark and vitriol received here.
> of those kinds of emails [emphasis mine]
Also keep in mind that scummy companies have caught on to that and now have dozens of different categories of marketing emails and unsubscribing merely unsubscribes you from one of them.
Your definition is based on what’s legal under the “established business relationship” exemption in the CAN-SPAM act, not any “commonly-accepted objective standard” of what spam is.
So then it wasn't originally defined as per your preferred legal wording, now was it?
> RBLs came into being in 1997, Spamhaus in 1998.
And did they coin the expression, or was the concept itself around long before that...? (A: AFAIK, at least a decade earlier.)
> You'll note precisely none of these organizations (in any country) blacklisting Amazon, or any other company, because they send marketing emails to their existing customers.
Ah. So it's not actually the legal definition that is important, but the corporate one. OK, gotcha, that is of course so much better. (Blindingly obvious: /s)
[Edit: Added missing quote marker > ]
But, sure, say we go with your wishes and, as someone else suggested, call your spam something else than "spam" -- let's go with their suggestion and call it "trash email". Then the category -- or, now, categories -- of stuff that we want to get rid of from our inboxes become, in stead of just "spam", the more cumbersome "spam and trash email".
I'm sure you see the problem that immediately rears its ugly head: Language is lazy. "Spam and trash email" will in daily speech, inevitably, shortly become... "Spam". You may try to resist that, and as a longtime linguistic prescriptivist I extend you my sympathies... (But, psst, spoiler alert: This quixotic struggle is doomed to fail.)
But, anyway, you are of course perfectly free to keep campaigning for your cause. Only, in the name of all that is decent, be honest about it and call it for what it is: You're not defending spam, "only" trash.
Maybe after a while you'll realise why the rest of the world sees no difference in your distinction.
Maybe if enough scummy companies have to mess about getting de-blacklisted, they might reevaluate whether their emails serve their customers, themselves, or, more likely, neither the company nor the customer but rather someone in between who is using some artificial metric (maybe "clients reached", "tracking pixels delivered", whatever) to angle for a pay rise.
I also don't understand why "marketers" want to put stuff in my email inbox or anything else I use to receive real communications that I just don't want.
I’m just a lowly user. Reporting it as spam is the only recourse I have.
Thanks to years of abuse of my email address by marketers I am all out of fucks to give.
This itself is a redefinition of “spam” to exclude the types of spam businesses want to send.
There’s a two-part test I use to define “spam”, which I think is aligned with both the historic definition, and how most users perceive it:
1) An e-mail is a marketing e-mail if, on the balance, the e-mail primarily benefits the sender, not the recipient.
2) A marketing e-mail is spam if the user did not explicitly opt-in to receiving them.
The legal definition of spam arose as a distortion of the preexisting concept lobbied for by spammers to allow as much spam as politically possible while allowing politicians to be seen as “doing something” about the spam problem.
Merriam-webster (https://www.merriam-webster.com/dictionary/spam)
"e-mail that is not wanted"
Oxford (via google https://www.google.com/search?client=safari&rls=en&q=oxford+...)
"irrelevant or inappropriate messages sent on the internet to a large number of recipients."
Neither is your absurd definition.
And to be clear, entering a business agreement for a product or service you sell, is not me soliciting anything other than that product. Marketing emails, "product updates", etc are not the product or service I am paying for.
I have sympathy for businesses out to make a buck: they are the reason I get to put food on my table. But on the scale of balance between users' rights and business rights over the last twenty years, it's no contest: business rights reign triumphant.
At most you may send reminders, but even then, those may end up in a spambox?
Even once you've verified the email, you have not much of a guarantee it will stay verified/working long. That's more the subscriber's problem, if they want to continue to use your product.
People may exploit paid services by creating many new accounts -
1. Free trials: When trail period ends, create a new account.
2. Services with metered billing: Use the service, then refuse to pay. Then create a new account. Then refuse to pay. Then create a new account...
Of course, (theoretically) if the service provider has enough resources (i.e., money, time, knowledge...), they can always find a better solution than banning all disposable emails.
The difference between real and disposable is manufactured. A novice could register a domain, sign up for email hosting, and set up a catch all for cheap.
That's a lot of effort to go through to avoid paying for something. And I guess you can't keep your data or configuration, if the app has any.
I argue that maths is negative for your business and a better approachbis to make it easy tonget started, but show them clear benefit of switching plans. Maybe a cheap entry level plan with a small set of convenience features, not available to the test account.
* Reduce the trial period for users with a disposable email.
* Don't allow data import/export so that creating a new account is more work.
* Reduce cookie lifetime so that a login is needed more often.
And yes, it is not a meaningful number of people that do so, but over time this is very ugly and frustrating (as it requires manual intervention) and you block the disposable Email provider they used ...
Missing the forest for the trees and all
This seems like an ego issue honestly. Like you feel like you are being taken advantage of. If only a very small numbers of users are doing this then I don't see it worth the dev time to block the email providers they use possibly hurting valid customers. Just leave it alone. I use Relay for services I genuinely pay for but don't want to give out my email address in case of leaks.
Suggest using the Standard plan but with significant rate limiting. Like 5/day.
If they want to remove that, enter credit card details which you verify.
You can still have the trial expire and the credit card isn't ever charged; but you can track people on trials more easily.
I think that someone who doesn't want to give their real email address to try out a service is even less likely to trust an unknown service with their credit card number. There are just too many "free trials" that promise to not charge your credit card and then make you jump all sorts of hurdles (e.g., having to call) to cancel the free trial.
I think you'd be surprised. Credit cards are easier to dispose of then email addresses, and they offer greater protection with fraud and billing dispute processes. Some banks even offer virtual cards that let you set limits on duration or amount.
And that's OK. The problem as I understand it is that people are signing up with disposable email addresses, using the API key they receive for 7 days, and then signing up again. They are leeches, exploiting the generous free trial.
If they stop signing up, no problem. Other people who sign up with a disposable email address can test within the restrictions, and once they trust the service have a choice to enter card details or not. If they are planning to do business with the service, they're going to have to trust it with card details.
"Would have paid for the service" vs "Are actively working to use the service without paying for it" are two different things.
I worked for a company that had some free tools on the web, with no published API. Those tools were scraped well above the T&C limitations to be mined by other companies.
We had a "free forever" account that you could use to monitor a single domain. Within the user table there were multiple instances of 20 to 300 (worst case) myaccount+<domain>@mycompanydomain.com trying to abuse the single domain rule without paying for it. In one case, the results were being packaged up to be shown in somebody else's product.
I'm certainly not advocating for spam or selling data (the company I mentioned didn't do this either), but abuse it the more common use case that web businesses deal with. To combat abuse, 90% of the battle is to identify where the abuse is coming from first.
So, make it worthwhile to pay for the product.
If it is now mainstream to basically feel you're entitled on setting the terms for other businesses or stealing their software then nobody needs to complain when any email relay service gets just blacklisted. If people now think it's okay to abuse multiple accounts to avoid paying for software that they use and that costs money to build then nobody needs to be surprised that everything gets an identity verification.
It's exactly how it works, if you want to succeed. If you don't offer value that enough people are willing to pay, you still own the product, but it's worthless.
Yes, it really is how it works.
> If you create something and unless you license it permissively that product is yours and you get to set the terms and conditions.
And if you want people to pay for it, you have to offer enough marginal value over not paying for it so that they choose to do so. The concrete, social, and personal moral consequences of violating social norms can provide part of that value by weighing negatively on the “not” side, in the case there is an available but “not permitted” mechanism which gives the benefits without paying. But that doesn't change the basic fact that you have to provide adequate value if you want people to voluntarily pay.
> If people now think it's okay to abuse multiple accounts to avoid paying for software that they use
Then models where you give the full service for free for each account with the limits actually applied that people are exploiting that way probably isn't the right model for that SaaS.
Besides, the whole idea of a "disposable email blacklist" is ridiculous. Are you going to block Gmail? Gmail addresses take like 1 minute to make. If not, you've already lost the battle, so do us all a favor and stop this blacklist nonsense.
Not only do I have zero reason to trust you when you say that (because every person planning on selling my data ways the same thing).
But I also have zero reason to trust you're skilled or resourced enough to adequately secure my data (or have sufficient motivation to do so).
And I also know that one day you'll likely sell your SAAS, and will have no control over what the people you sell it to will do.
If you've got enough traction that people are willing to jump through minor disposable email address hoops to use your product for longer than the free trial, but not enough traction to convince them to pay for it, I reckon you'd be better off building more features that add value and reconsidering your free trial plan - instead of devoting any dev effort into rejecting disposable emails.
That explantion was acceptable to me; if it works for them. I might note that they only send me transactional email (statement of charges for the month) and no marketing.
Ad companies' customers willingly share the email addresses in hashed form so the ad companies can correlate this against their own lists (by doing the same hashing and checking for a match).
The same happens with phone numbers as well.
---
"Ravenstine, kick your goals into overdrive now"
"Check this feature out!"
"We're the best, but don't take our word for it"
"Your account is waiting for you"
"This will be like money in your pocket"
"Don't miss out on our webinar"
"The gift that keeps on giving"
"It's been a while..."
"So this is goodbye, Ravenstine?"
---
F--- YOU! F--- YOU F--- YOU F--- YOU F--- YOU!!!
https://www.kalzumeus.com/2012/05/31/can-i-get-your-email/
+ anybody else miss reading about the Rust Evangelism Task Force?
You can tell which companies have especially corrupt and greedy corporate cultures by how they treat your email address. Whenever I find myself witnessing behaviors like this I do my best to move off the platform and bad mouth them whenever I can.
I hate to admit this, but we send a lot of email like this at work, and I always get tickets like "all of our email is being marked as spam, can you fix DNS?" Usually it is a DNS issue (people add email senders without setting up Spam Permitted From and DKIM), but nobody will address the elephant in the room that maybe users don't want to read our marketing newsletters. They likely get 100 of the same things from 100 other vendors, and at some point, enough is enough.
(Dunno if this is a public Gmail feature or one that I'm allowlisted into from working at Google in the past, but I have a "tabbed inbox" and everything like this goes in "Promotions". I look in there from time to time and see thousands of messages a day of this type. Everyone sends these and Gmail knows that nobody wants to read them. It's unfortunate, but true.)
It's apparently a public feature, since I remember being annoyed by the tabs and disabling them in Gmail preferences.
They were linking their accounts to use some spammy marketing software to mass send "campaigns ".
Marketing should be forbidden.
Of course I mark them as spam and blacklist them. I often see followups months later in my trash box. It makes me feel good at least having wasted some of their time.
On LinkedIn I blocked my last name to non-contacts (everyone else it just shows my initial) because our work has a simple email address naming scheme (first.last@company.com). But still I get an absolute ton of them. Literally several per day. It's so annoying, though most of them are not as persistant as I mentioned in my post above.
All of them seem to be from the US by the way, and always trying to propose meetings during US timezones so they seem unaware that I'm in Europe. I'm kinda suspecting a data leak in the past or something.
Seems to do the job and fairly priced given what I know about what it costs to acquire a phone number via Twilio.
The downside is limited set of numbers vs. iCloud+ creating a brand new email every time I register on a website.
> My reasoning on including this is that an email with a mozmail domain is never going to be a primary email and is always going to forward to some other address.
This is laughable and sad at the same time. I have a few tens of email addresses that are used for different purposes and with different classes of sites and services. None of them are “primary” and I wouldn’t really give one address used for one purpose to a service that I classify under another. People also use aliases on email services, and those are also “forwarding” emails in a way. This point about forwarding is a poor distinction.
As other comments in the issue have stated, adding Firefox relay domains to this list is a user hostile move with no benefits. I’d love to see them try this with Apple’s email relays (used by Sign In with Apple if a user decides to hide their email address).
[1]: https://github.com/disposable-email-domains/disposable-email...
If you signup for Netflix using the feature, you can't cancel your account and then signup with a new Apple email, it will only allow you to login with your original one.
This negates the primary reason for blacklists like in OP, in that users generate multiple disposable addresses, within the one domain, for their single identity, usually to circumvent account limits, user blocks etc.
This whole thread is going on about spam but most have misunderstood what "spam" the blocklist is trying to tackle. It's there to tackle people signing up with a disposable address, spamming or abusing the platform, getting blocked and then creating a new account to do the same thing again.
You absolutely can. You can generate as many as you want, whenever you want
I have only used the "Sign in with Apple" feature directly in apps, which only ever lets you create one for that app.
However, apparently with an iCloud+ subscription, you can generate arbitrary email addresses from within iCloud itself, and then use those wherever you like.
Typically, online service provider may have empathy towards users with whatever emails, including disposable emails for privacy reasons. Then the online service becomes popular, and spams / scraping activities become out of control - Internet is big and there are a lot of bad people / bots. Try different tactics to fight bad users / bots. Eventually, the service provider joins the dark side and bans the use of all disposable emails. It's not ideal. If you are Google or Amazon, maybe you can trivially allocate 20 full time engineers to develop an elegant solution. For small businesses, you just use very limited resources and do whatever to survive.
[1] I run listennotes.com
From a service user’s point of view, a big portion of “services” that demand their real email address have intention to do bad things, e.g. spamming
Services use emails from well-known providers specifically because they're "good enough" signal in terms of spam/bot avoidance. It's not like the need for those signals go away and "real emails" are one of the most privacy preserving because they're pseudoanonymous. The alternative is Real Name policies.
If that's really what you need, the relevant jurisdiction is likely to have some adopted e-identity system.
If not, go back and question how you can solve your issues with as little PIIs as strictly necessary.
If you don't like "accounts of well-known service providers" -- email or login-with-whoever then sources of identity that "everyone" has that are hard to get many of are government ids, phone numbers and credit cards.
Like what else is there? For super technical people we could do something like "proof of bitcoin address" where we verify control of a wallet with some minimum long-standing balance. We could make you submit a recording of yourself saying some random phrase and then do some facial recognition to detect duplicates. IP banning hasn't worked since the 90's.
Seems to me that 1) Gmail accounts aren't that hard to farm 2) most spam comes from free webmail providers not disposable email and 3) a captcha will solve most of your problems and if it doesn't, it means your site is being specifically targeted by someone with cash to burn, so you can assume that they'll have emails that aren't on the blacklist. At that point, invest in detection and moderation.
This is 100% not true. Yes, the main site will require it, but there are legacy "portals" that allow signup without a phone number. No, I won't link to said portal.
As of gmail -- one of the guidelines for the list addition is whether you need to go through some sort of a registration. If you do then it is usually not treated as disposable by us.
If accounts or services are paid, spamming becomes unprofitable (the ROI of spam would become negative as they'd need to keep paying for new accounts all the time).
Scraping? If you're selling content you should be selling content and not mode of consumption, and for misbehaving scrapers your DoS defense strategy (you have one, right?) would also work there - an easy solution is to rate-limit the amount of requests by account to a reasonable level (that a human user won't exceed) and then let them choose whether they want to consume the content manually or through scraping.
Free trials are a common method to battle the barrier people have in spending money before understanding if a product or service fits their needs.
I'm not sure what the point of that list would be other than to drive users away from your service, but hey, if you want to be a dick, you're perfectly allowed to do so.
Edit: as written here: https://github.com/disposable-email-domains/disposable-email... the list is not intended for websites where one needs to sign up for an account first, like free mail services. I suppose that means neither Firefox Relay, nor any other such service should be on the list.
GMail does antispasm. It’s easy to create a disposable gmail, but it is much harder (I supposed) to use that address for outgoing spam/fraud/etc.
One’s individual right to remain anonymous does not necessarily take precedence over the societal right to hold one accountable. The pendulum of that tension swung all the way to fully anonymous over the past decades, and we now have the most unsafe Internet that has ever existed.
It will, guaranteed, swing back from full anonymity, as already began with many things one could previously access anonymously (such as email verification only) online or in person: Cellular service (ID required), FedEx shipping (ID required), many Discord chats (verified phone number required to defend against sock puppet attacks), and LinkedIn name changes (birth certificate and photo ID required). Whether it swings back to “no right to pseudonyms” or instead cones to rest on lesser outcomes such as “identity protected by law” and “a warrant is required” is up to politicians to decide.
Politicians do not accept and consider anonymous letters, so adhering to the outgoing belief in perfect anonymity may severely construct your ability to influence the outcome of the pendulum’s backswing away from it. I hope that when you write your politicians about this issue, you are doing so in handwriting from your registered voter name and address, so that they are considering your input at all.
But we're not talking about fighting crime here, but companies tracking what people do and as far as I know there is no societal right for Discord and LinkedIn to track people.
If that pendulum ever swings back too far, and you're right, it likely will, I'll be sure to let "my politicians" know using regular old no-government-id-required email as I already did on occasion with no issue.
Email should work in a similar fashion but as we know it doesn't, and there are various systems in place such that it's a game of roulette if your email reaches its intended target, and worse of all to me it's opaque, there's no way to know how likely it is or the various processes that may prevent my email being received by the other party.
And for systems that are critical for communication we should not allow them to be put in any type of "allow"/"deny" boxes and no domain should be either trusted or untrusted, after all Gmail can be a huge source of spam, but it seems those who provide users control and privacy are considered an adversary which is really sad.
https://www.fastmail.help/hc/en-us/articles/4406536368911-Ma...
Fastmail does have undisclosed limits, however:
> If you're having trouble creating new Masked Email addresses, please note that we have limits on how many new Masked Email addresses can be created within a certain amount of time to prevent abuse.
It would be good to see other email services offer a similar feature.
The problem is that even though "+" is a perfectly valid character, a lot of services don't accept it.
did you know that the `.` character is also ignored? So you can actually devise a scheme where you put in dots into your email address (unfortunately, it has to be your email address, not any additional suffixes), and bypass these checks and filters.
E.g., youremailaddress@gmail.com is the same as your.email.address@gmail.com
and for some extra fun, you can do both - add a unique set of dots to your email, and also add a `+` suffix, and if the service emails you without the `+` suffix, you know they deliberately filtered it out to spam you.
See https://gmail.googleblog.com/2008/03/2-hidden-ways-to-get-mo... for details on it
The discontent comes when companies rely on that as fact, and someone comes along and via masking or disposable or lots of other ways (even just signing up for a new email at yahoo or hotmail or proton or tutanota or..) , shows them it isn't true.
For emails that I don't want an ongoing obligation to read... I used to have a custom alias for mailinator (nospam.jrock.us MX <them>). At some point I guess I got rid of it, perhaps because mailinator stopped offering that service. Unsurprisingly, nobody ever looks up the MX record to implement the denylist. Worked perfectly every time.
That is untrue. Mailinator definitely still supports pointing any domain to it's MX records and will allow all incoming email (modulo DoS protection, abuse, etc). Such email will arrive in the respective Mailinator inbox (i.e. bob@yourdomain.com goes to the "bob" inbox)
Edit: icloud.com seems to be another domain used in Hide My Email but is also not present (although I guess this one is actually primarily used for permanent addresses): https://github.com/disposable-email-domains/disposable-email...
Blocking `privaterelay.appleid.com` would be kinda pointless since you'd be breaking your "Sign-in with Apple" feature, but if you don't support that feature you could block it (theoretically, one could create a login for SiteA and use the private-relay address for SiteB). Blocking `icloud.com` would mean blocking lots of legitimate email addresses along with the hidden ones.
I deeply regret using the @icloud.com address for anything serious, because you would be unable to receive or send emails as soon as your iCloud storage subscription expires, provided that you use a larger quantity of data than is allowed in the free-tier iCloud. This is what actually happened to me a few weeks ago. I forgot updating my credit card number on the Apple account, thereby making it impossible to renew the iCloud storage subscription, resulting in the inbox full of emails "Your iCloud storage is full" -- these are what replaced the emails that have been sent to the @icloud.com address after the subscription expired. In addition, I did not receive these emails even after I renewed the subscription. To this day I do not know what these emails were about.
Yep! one of my primary email accounts is an iCloud domain. It only gets used for services I know I’ll be using for a long time, or it’s particularly important.
Any useful disposable email service will only allow *receiving* emails. As a user this protects me against possible bad actors that for some reason need me to give out my email to them.
Any service allowing *sending out* mail from their mailservers will quickly find their mailservers blocked - this is also list based. A common one being spamhaus.org . The way firefox relay solves this is by only allowing to *reply* to mails you have received, and I assume they have some rate-limiting in place as well.
This is really just about making life harder, and forcing people into using an emailaddress as their identity token, which seems all sort of wrong.
Next someone will block mailservices that allow + adressing or other kinds of alias systems ?
it is. The idea is to prevent users from being able to sign up anonymously, and try a service risk-free. It ensures that a user has something to lose by trying a service (aka, their real email address), in the hopes that said user would not abuse the free-trial, and also to allow the service to send marketing reminders on paying.
I have made it my policy to not sign up to any service that require an email address, if that service does not accept a disposable email address, nor will i pay for such a service.
Such as WHOIS info (if not cloaked), or an algorithm may assume I'm a business and charge me higher prices, etc. I used to get marketing spam from Dropbox saying that many of my coworkers enjoy using it and to upgrade -- but I was the only user on that domain name.
I wouldn’t consider this a legitimate concern. Whois privacy is common and often free for nearly all registrars (barring TLDs which disallow this)
> May assume I’m a business
I really doubt this happens frequently, at least far more infrequently than a business using your permanent email for spam. Besides, if the algorithm decides that any non-gmail/outlook/yahoo/etc mail is “business”, then they’re going to assume that about any disposable email.
Personally, I find the $4/year I spend on a domain name to be incredibly worth it and the downsides are far fewer than the upsides.
(Obviously anything at a domain I own is directly associable to me, and for many trashwalls I still prefer to use mailinator etc)
Surprisingly, the game Eve Online was super-strict in refusing these types of addresses. Most other services were fine though.
With EVE, fraud comes in many ways and most would presume credit card fraud but because you can earn ISK in-game, which can be converted/sold for PLEX (their game-time subscription currency, worth real $) many items (Capital Ships, High Experience Characters, Corporations) are bought and sold for real money outside of the platform - which in some cases, is revenue that EVE would/could benefit from if PLEX was purchased from them directly and used legitimately instead.
So aside from basic things like blocking utility email addresses, they have sophisticated algorithms that monitor user accounts for unusual activity. The definition of unusual is constantly growing/changing and it is monitored and managed by a dedicated "security" team.
Source: Friend of friend works in that security team.
You (martenson) are one of them. The other member (di), who is a "core maintainer" of the project according to the README changelog,[2] is also a member of the Google organization on GitHub.[3] di describes himself as part of the "@google open source security team"[3] and the website linked from his profile says that he is "a Developer Advocate at Google".[4]
[1] https://github.com/orgs/disposable-email-domains/people
[2] https://github.com/disposable-email-domains/disposable-email...
For instance, for starters, go search through all of your email for any email sent from Google servers where the "Reply to:" doesn't match the "Mail from:", and tell me if there are any legitimate instances. We could all benefit by starting to reject all Google sourced email with a different "Reply to:".
What we really need is a blocklist / allowlist system which tracks the millions of Gmail email addresses. Has it never been seen before? Reject it with a message telling them to go sign up for the allowlist. Has it been around for a while? Allow it.
Google can't be asked to keep their own spam in check. We have to force it on them.
This is not outside of the realm of possible. Google does nothing to stop spammers, makes up their own non-public rules and doesn't communicate with the Internet community, so Gmail addresses are already on shaky grounds. For instance, for starters, go search through all of your email for any email sent from Google servers where the "Reply to:" doesn't match the "Mail from:", and tell me if there are any legitimate instances.
Why is this scenario a red flag in all instances? Mailing lists, including Google Groups, may have settings that set the Reply To to be different from the Mail From.
Lesser evil criminals such as spammers already have a supply chain of phone numbers, residential IP addresses, etc that can be used to work around the restrictions.
Of course if you do it constantly or from third-world IP addresses, I understand they refuse your attempts.
Yes. Very common. Sorry but you have a very limited view of realistic mail traffic.
While Gmail might be a major source of SPAM, they're also the email service most people legitimately use. If you block dummy-address@my-email-relay.tld, someone might be annoyed, but can sign up with their non-proxied address. If you block Gmail, the person can't just use their "real" address. You're forcing them to create a different email address to use your service - and there's no reason to think that new email address will be from a service that better validates their users.
That was once true of Yahoo, Myspace, and even AOL.
Also, what a big surprise that one of the two creators of this repo works in Google's "open source security" team.
Fine use a disposable email but the account will be wiped soon when you never log back in again.
At least I can turn it "off" when I don't expect a phone call or text message.
One solution is a traditional webmail provider being willing to reuse that primary user domain for forwarding addresses. There are two that I know of doing this, Fastmail with @fastmail.com and Apple with @icloud.com. These domains probably won’t ever be blacklisted, because you’d also blacklist a ton of primary email addresses. (Aliases, which most providers have, tend to be too inconvenient and quantity limited.)
Another solution is to use different addresses at your own domain, which trades anonymity against the company you sign up with for freedom to change providers.
I think all three of these, including announced proxies like MPR, can be the best solution depending on whether you just want to be able to cut contact or you want privacy, and from whom.
I've got my own domain, for example: mydomain.com. So my fastmail email address is depingus@mydomain.com. But with subdomain addressing, I can sign up for services with unique email addresses that look like:
social.hackernews@depingus.mydomain.com
Fastmail will automatically route incoming messages arriving to this email address to my "social" folder. If I start getting junk to that address I can easily blacklist it.
It wasn't easy switching out my email address EVERYWHERE. And there are places that won't even let me change it. But in the end, it was so worth it. I don't even miss Google Inbox anymore!
A lot of the logic I see in replies here is that people use services like mailinator to abuse free trials. I think this is also the logic for blocking or stripping RFC 2822 email addresses (something+somethingelse@gmail.com). On the RFC 2822 stripping / blocking, you are just breaking the internet. Disposable emails seem like a problem, but I suspect the trend is towards more "private" email forwarders like Mozilla's relay, Indeed's private emails and iCloud's hide my email.
If you are having problems with free tier abuse, one small thought... This isn't universally applicable advice... but it may be helpful. If having an account on your service does not accrete value for the user, the user will be ok with abandoning the account and starting from scratch to get free service. If it is not possible to accrete value, you may have a product that is not a good fit for the freemium model. Try alternative models. You may find you are leaving money on the table.
This repo helps dividing the internet into monitored or not. Just like recaptcha. No wonder someone from google came up with it.
If you're using "equals" - it won't catch it.
[1] Tech Evolution of Mailinator - https://youtu.be/BqNfHsZ3QUc?t=3866
[0] - anonaddy.com
If I give my email *@<fixedCustomDomain>.mozmail.com to a spammer, now they know the custom domain I own and can spam me on infinitely generated aliases on this domain e.g. by sending emails at <infiniteAliases>@<fixedCustomDomain>.mozmail.com?
This is such a simple exploit.
And frankly, there's no sense in getting upset about a directory of services that allow the creation of unlimited disposable identities. If it wasn't this github repo, it would be another. As long as there's demand for lists of these services, the lists will exist.
And why do folks want lists of these services? Because they're a massive nuisance: folks avoid paying for services and abuse free services with spam (or worse). This isn't to say that businesses shouldn't support their users in being privacy-conscious, but the unfortunate fact of the matter is that Sybil-esque attacks are costly to businesses (time, resources, reputation), sometimes to the point of being existential threats. Many businesses have no choice but to make _some_ tradeoff between user-friendliness and revenue/operations cost.
My own business was absolutely _flooded_ with spam until I started blocking most popular disposable email services. I built tools to help detect and mitigate the spam, but it was purely reactive. I was spending more than half of my time fighting spam instead of working on the product.
The reason these services work for privacy-conscious folks is because they're convenient. But that's the same reason they're useful for malicious actors: nobody wants to spend the time to set up a new gmail account. The (time) cost of establishing the identity is what makes it hard to use for abuse.
There are obvious potential solutions. The first is for services like Firefox Relay to allow abuse reports. If I see spam from a Firefox Relay user, I should be able to report it and have it count against them. Any legitimate service should hold its customers to some responsible use guidelines, and if they break those rules, there should be consequences.
Another is that identities should not be "free". I disagree with Mozilla's pricing: $1 for unlimited identities is practically begging for bad actors to use the service. Setting limits or scaling the cost of the service (more identities per unit of time costs more, or throttling identity creation) makes it harder to abuse services with those identities. Almost no legitimate users actually need truly unlimited email addresses, and the ones who do can very much afford to pay more than a single dollar. Even generous limits would help to avoid many problems.
I'm generally bearish about crypto and blockchain technology, but I can also see how using it for identity would be super beneficial. There's some cost to establishing the identity, and you separately can use a (~worthless) disposable email for communication. The identity is worthless to "leak" and isn't useful for marketers.
If you charge for the service, a lot of attacks suddenly become pointless or unprofitable, implicitly mitigating the problem.
I don't think you could produce data that shows what you're suggesting, and in fact I think the reality is that the opposite is quite true. Any business that offers trials or free options is vulnerable to abuse, and any amount of abuse will eventually begin to eat into business resources. And business who do charge for their products don't have the "growth and engagement" money to burn on bad actors.
Note that Relay already rate-limits customers:
> we limit our free users to 5 total aliases, and we rate-limit our premium customers so they cannot create large-scale throw-away aliases for abusive sign-ups and behaviors.
I'd be happy to work on building that for my service if someone is interested in using it.
I think your point about mozilla's pricing being too cheap is an interesting one. I don't think of the pricing as $1 - I think it as $1/month, so it builds over time. But clearly it would be a bigger deterrent if it cost more.
I think blocking these email masking services and treating them exactly like throwaway email services is the wrong way to go since I think a lot of users want to use something like this. (discloure: I'm working on https://www.thxnothx.com which is also an email masking service combined with some other features)
> @disposable-email-domains disposable-email-domains locked as too heated and limited conversation to collaborators Jan 16, 2022
https://blog.cloudflare.com/introducing-email-routing/
However, disposable email addresses on a domain that you personally own can still be profiled by the domain name. Services like Firefox Relay try to preserve anonymity by sharing the domain name(s) among all users, the same way VPNs share IP addresses among their users.
Jokes aside, they're awful to Tor users (Infinite captchas), and break sites on anything not running JS.
That's a good point
> and if a link to a site counts as trademark infringement the internet is dead.
It's not a “link to a site” though, it's a public blacklist of domains involved in spam and abuse. I have no idea about how the US trademark laws work,but in my country at least (France), doing so is a great way to get sued by the company. (And yes, this also applies to product reviews posted on say Amazon or Tripadvisor[1])
[1]: https://www.votre-reputation.com/2021/01/20/denigrement-sur-...
Either way, there are few parallels between moderating a users potentially false comments and correctly labeling a site as a disposable email domain.
[1]: journalists are exempted indeed, I'm talking about entertainment here.
I commented on the article you linked. I don't know about French law, but I do know your source didn't back up your claim. I find it hard to believe a URL can be trademarked, things like search engines just couldn't function that way.
And why would you comment about the DMCA, a part of a legal system you seemingly don't know at all?
You realized that I asked a question about it right?
> I commented on the article you linked. I don't know about French law, but I do know your source didn't back up your claim.
The source was about the (only tangentially related) issue of product reviews, since I was talking about it in a side note parenthesis. Not about the main topic.
> I find it hard to believe a URL can be trademarked
It's not an URL, it's a domain name. (a URL is a string “<protocol>://<domain/[<http route>]”) and domain names are clearly subject to trademarks in France[1]. But it's seems to be different in the US[2].
[1]: https://fr.wikipedia.org/wiki/Milka_contre_Kraft_Foods
[2]: otherwise Facebook wouldn't have needed to pay $200,000 for its domain name I guess?