Then, I gave up, moved all my services to another email account, and after 2 or 3 months tried logging in, and it suddenly allowed me to log in.
Needless to say, I will never again use gmail for critically important things.
Then, I gave up, moved all my services to another email account, and after 2 or 3 months tried logging in, and it suddenly allowed me to log in.
Needless to say, I will never again use gmail for critically important things.
That way at least if you no longer can access your account, or you get banned, or whatever, you don't loose your address (since you can just move to another provider).
Also, use an email client on your PC (such as Thunderbird) and configure it to keep a copy of all your emails locally (and possibly have the PC backed up). That way if you loose access to your account you don't loose access to your mail, that you can even upload again in the new provider server.
Unfortunately... it was Google (so kind of hiring the wolf to care for my sheep, as it turns out).
And now they're cutting off all of us free tier folks. Which I can't fault them for, but still blame them for. Because I'm petty and entitled or whatever.
I'll lose important things like my Google Voice number that I've had for a decade unless I pay for a business account.
It is very frustrating. I did a lot with Google Apps on that domain, and migrating that stuff out to a consumer account is a painful process.
For me ideally I would like to move to something else (even paid) just because someday Google deciding to block me for whatever reason scares me quite a bit after having everything for the last decade attached to this account. I would like to export my emails, switch my domain to the new service, and import everything - but I have no idea how realistic that will be yet.
I'm documenting everything here if you're interested:
I adopted Fastmail for my domain email, and it has been a good experience (I do know that Fastmail is a five-eyes company with all the related issues around privacy, and I researched alternatives for several weeks, but I guess in the end I was willing to trade privacy for ease-of-use, uptime and various other factors).
Now I am looking into getting away from other Cloud-provided backups such as Prime Photos, iCloud, etc., moving to self-hosted NAS storage.
It lets me track who is sharing my email address and gives me control over that (set up simple filter to automatically delete any email received at ticketmaster@mydomain.com when I start getting spam on it).
It’s been really effective - such a part of my day-to-day flow now I can’t go back.
The transition was pretty painless. I setup an email forward from gmail to my proton inbox using gmail@mydomain.com, every email I received at that address I’d go update my contact information with. After a bit, I was able to turn off the forwarding. Basically the classic strangulation pattern for microservice migrations applied to email.
And you can't convert your account to a regular Google account. I really want to untangle all this, but there's no way to (for example) export your Google Photos sharing settings and import them into a new account. I have hundreds of GPhotos albums, with many of them shared with various people, and if I migrate to a new, regular Google account, I'll have to manually set up all those sharing settings again. And this is just one of many difficulties; I'm assuming I'll also lose all my Hangouts/Chat history as well, with no ability to import the old history.
But I'll be doing all this sometime soon, as Google has decided to finally pull the rug out from under those of us who signed up for GSuite when it was free (well, "Google Apps for Your Domain", as it was known back then), and will start charging later this year.
This is all incredibly frustrating, and the level of lock-in is pretty severe after more than a decade of having this account. If I could do it all over again, knowing what I know now, I would have created a Google account without GMail[0], using my email on my custom domain, and hosted my mail somewhere else. Though, admittedly, back when GMail was first a thing, webmail otherwise universally sucked.
My favorite is that I cannot migrate my Nest account to a Google account because it does not support Google Workspaces accounts. I use it with my own domain and it is my private Google account.
If you think this is bad you should check out iCloud. They're all as scummy as each other about locking in users so the friction to leave is sufficiently high.
Do you have a citation for this? I heard last year they were going to start charging for new accounts, but that since I set it up on my domain in 2008 I was grandfathered into the free plan indefinitely.
Well this is horrifying. Of course, not much worse than Google unilaterally and permanently banning a Gmail account.
that way I've got the comfort of gmails features but always have a "real" mailbox to fall back to if anything happens
The first time this happened I completely lost all access to my Google account. I transferred all of my important email correspondence over to a Microsoft account and I have never looked back. Unfortunately I still need to maintain another Google account for my phone (Android) to work properly, so there are times I still get bitten by it. It's absolutely infuriating when you get a new phone and specifically need to log in with your Google account to be able to do anything, that's exactly the time Google blocks you from being able to get into your account, because it's apparently detected the new phone and decided you're a hacker.
This also happens to me regularly with PayPal, almost always when I am traveling overseas, at exactly the moments that I really need PayPal to work so I can pay for something related to my travel. It's so annoying. Tech support never, ever solve the problem. All you can do is wait and try again later until magically it works. Sometimes weeks later.
The only thing I can say for certain is to never try log into your account over open wifi or over a VPN connection, because somehow Google (and PayPal) seem to flag that as a hack attempt no matter how many times you correctly confirm your identity. And once you've been flagged once, your account gets caught in some kind of loop where even after you get back onto an apparently blessed IP address, you're still locked out for some unspecified period.
They won't let me reset my password.
They won't let me reset my password.
The fact that I've had to learn this through trial & error and spend time & money setting up a personal VPN host is crazy.
This is mindblowingly idiotic. Do they have such a bad vacation policy for their employees that not a single ONE of their engineering managers has experienced the above? Do they just sit in front of their desks for 365 days a year and never leave their country borders?
The scenario you present is a really obvious risk as phone thieves often compromise those devices.
One of these days someone will not be able to get their heart medications or a flight home because of this damn Gmail policy.
I have been quite impressed with the improvement they've made in the last year or so regarding these locks. It's probably a sudden change when you've been more predictable before that gets flagged.
Only trouble I sometimes run into is Google Search (or Books?) locking me out with increasingly difficult captchas if you keep running searches for 18 hours straight.
One of my personal favorites -- a bank automatically associated phone numbers you called them from to the account, and later they forced SMS 2FA onto the account regardless of any other security you had in place (and of course made the common mistake of allowing account takeovers with JUST that 2FA and a username). Those automatically registered numbers weren't exempted.
1. Forwarding everything to my free tier google apps for business on my domain
2. Annually logging into my throwaways. it seems if i login to them once a year from home, they dont pull this.
3. do NOT attempt to login to my throwaways from a proxies connection (SSH/SOCKS on a VPS or something like that, which i frequently use at work)
your habits are going to have to change soon...
Currently I may just pay the cost. Or move to a more privacy focused service like ProtonMail and at least give my money to a place I support.
That's a hot take. If it was critically important, you'd have 2FA and a recovery phone number associated with it - which would have prevented you from getting stuck in a trust-fail situation to begin with.
Use whatever service you want, but your takeaway from this situation is a bit absurd.
Edit to add: I'm not saying Google's algorithm is perfect here, but relying on heuristic voodoo ("I use the same IP, so I should be fine") for "critically important things" instead of using well-established means of securing access to critically important things (e.g. 2FA, backup mobile number) is a bit insane.
See: Apple ID, where failed password attempts (by anyone) causes Apple to force users to change their known password.
Contrast that to my bank where I can go to the branch, show ID, and get problems logging in resolved.
However, google customer service is definitely erratic since loads of other people have had bad experiences. The best thing to do if you're using Gmail is to enable 2fa and backup the recovery codes offline and somewhere safe. This could probably get you into your account without needing to talk to support.
Quite. If you play the game then all is well but if you don't then you are given very short shrift and no recourse to a higher power or anything at all.
There is very little oversight. If you fall afoul of the "algorithm" or whatever bollocks is running the show, then you have to fall back on calling them out on the socials. Get enough traction on that and lo: "soz, lol, we failed here but your <whatevs> is important to us ... in this case ... etc ..."
Email is too important to rely on a free service which has a history of shutting people out, at any time, for any reason.
I'm a satisfied Fastmail paying user for years
Fastmail was blown offline by a couple of DDoS attacks recently. Both of them impacted my ability to access Fastmail, but I suppose you didn't happen to try to access your account during those attacks.
Life on a crowded planet depends on third parties; choosing vendors well is a critical life skill.
Fastmail have a long-standing reputation for treating customers right; certainly not a reputation google shares.
What's needed is enough of these cases to bring a class action against Google.
It's over a decade since I've used a Google account and I was similarly ignored even back then.
This happens to me from time to time, and the only way I can get back in is through Android. I keep an Android phone on hand at all times for this very reason.
Don’t blame the human for inadequate preparation; I assure you, no amount of preparation will save you from Google’s AI.
When it gets in this state, nothing will work besides going to g.co/sc on Android--it can't be any other platform, regardless of how long I've had the device--and approving the code request there. If I approve it from any other device, even with a YubiKey, it'll give me a code on g.co/sc, but I'll be told it's invalid and I'll get one of those emails telling me the code was correct but declined due to suspicious activity.
I appreciate the attention to security, but c'mon, it's a YubiKey, and I'm logging in from my usual residential location.
That perhaps this deals with a very real threat? Google has no incentive to make it difficult for you to log in, it's the exact opposite.
What a lot of the grumpy posters here probably aren’t mentioning is that many ate probably doing high risk signal stuff like running through public VPNs. Google and Microsoft know a lot about what you are doing and what scammers do. They score risk accordingly.
Usually it happens when I’m using multiple devices simultaneously—for example, Android and iOS. It’s understandable that Google considers that to be suspicious, but if Google isn’t going to learn on its own, there needs to be some way for me to confirm that nothing is amiss. It’ll ignore everything from TOTP codes to YubiKeys.
Not saying it's not true (I believe you), just that it's not designed to be a suspicious case, at least.
Account lockouts are bad enough, but more serious things driven by AI are bound to reveal their fallibility. I sincerely hope tech workers have the integrity to take responsibility, judging by the current political climate and its participants' willingness to venture into thinking (surrounding the value of human life, among other things) that was considered taboo not long ago.
The moral and practical capacities of AI will reflect the limits of those designing them, at best.
That they sometimes get it wrong sucks, but calling their attempts to do so "actual stupidity" is pretty rude.
Seriously! What! The! Hell!
I too have thought before that having 2FA (and linking a phone number, which I hate to do) would avoid tripping in such situations and that the systems would consider a different situation (like a different IP address/location, a different browser) as reliable enough with 2FA. But this irks me a lot.
I don’t really use Gmail much and have other paid alternatives, but I have some old stuff that may be mildly inconvenient if I were to lose them. Need to download the data and dump these accounts.