We all dread the day our Gmail password stops working, but this is what we signed up for.
I know my gmail is safe, because I know that without the password, not even I can get into it.
This is by design.
How can it prevent phishing?
I think it's complete conjecture that it's meant to be some kind of anti-phishing method - the solution there is just removing the ability to create addresses with periods - but I guess this way has some kind of utility for users?
I tried doing a password recovery of the account (to see what I could do to change the address, or contact Playstation) and found that on their end, firstnamelastname@gmail.com and firstname.lastname@gmail.com are treated differently:
Both gave the message that a reset e-mail had been sent. Only firstnamelastname@gmail.com caused me to receive an e-mail.
So Google (and other e-mail providers, like ProtonMail) ignore the dots, but it's possible that other companies don't ignore this.
Resolving the Playstation account required calling their support line for about 30 min, talking with an agent, and then replying to an e-mail generated specifying some information to confirm that I hold the e-mail account. They seem to already have the option for reporting misuse of an e-mail address.
I'm not sure I follow? This isn't an exploit, but a feature of Gmail. It doesn't allow you to receive anyone else's email.
John.Doe@gmail.com, JohnDoe@gmail.com and J.ohnDoe@gmail.com are not 3 different gmail accounts.
It’s one account with multiple dynamic aliases using the dot.
From the link in the other comment in this thread