I agree the email situation isn’t great but it is also more complicated: lots of legitimate companies send emails via third parties or otherwise want to put a name quite different from the email (e.g. mail chimp but also google docs comments appear to come from the commenter rather than some big id email address), so it isn‘t as simple as showing the full address only and users may learn to ignore the full address if it is fully of random-looking letters/digits. And email protocols complicate it further because there are ways in which the from field may not even match the actual sender, though that isn’t such a problem with gmail. I definitely do hope things will improve, however.
"com.google" is what you need to see since it tells you who's really in charge of the content.
Particularly on mobile where I'm writing this I currently can see at most "news.ycombinator.co..." in the address bar. Could be a lot after that, how would I know at a glance?
Google and Mozilla could make substantial progress on this today by just showing an extra bit with the start of a domain name in right-to-left reading order.
If I add more subdomains, it still displays the label and the extension in priority, the additional subdomains are faded and hidden on the left.
This seems sane to me.
What we really should be doing is automating what I do when I get an email from a new domain that might be legit. Look up the DNS info so I can confirm it's the company they say they are.
In this case, the top priority should be display name, (verified) source address and time of reception. The To and BCC line is not that important, thus can be folded under description such as "To you and another...".
I hear that product design in Google is data driven, I'm not really sure what UX data Gmail team has been consuming.
bcc in inbound mails?
(It's actually quite the opposite of what is going on with URLs, where everything is suppressed but the core domain name. Here, the originating domain and user is suppressed. It's more like showing the document title in the location field.)
(Oh my, has it really been that long?)
I think the whole principle of "anyone who knows your email address / phone number can contact you" was already obsolete over 20 years ago. Access to my inbox and ringer should be by revocable invitation only.
But this is what I hate most about Slack specifically and Electron in general. It’s so obviously a web app shoved into what kinda looks like a native window. But all the behavior is webpagey, except not in my browser, which I already know how to use.
Here’s a fun one:
Click in the conversation history panel. Use your “select all” shortcut. Despair.
Arguably, email addresses are (much) simpler to parse than postal addresses (including thing's like c/o, post boxes, etc.)
Both are equally easy to fake. The difference is sending fake bulk postal mail is much more expensive than email.
Detecting scams like this is a skill and some people - like elderly or disabled people - just aren't good at it. It doesn't help that some legit businesses are officially using gmail/hotmail/whatever addresses.
Email campaigns from companies are a mess. Even the company I work for sends official emails out from addresses at numerous 3rd party domains each using different mail servers. They often go out with verbiage nearly identical to what I see in phishing emails. They've contained links that point to URL shorteners or some other random 3rd party site that we don't own with URLs full of unintelligible tracking info.
I deal with phishing issues almost every day. Most of the time phishing emails are pretty obvious, but I've had customers ask me if an email claiming to come from the company I work for was legitimate and even after looking over the message and the headers I couldn't give a clear answer. I've had several talks with marketing about it, and I've managed to catch a few horrific communications before they went out, but they aren't willing to stop sending from or linking to third parties.
Developer: Does anyone know why helpdesk@company.com is being flagged as a spam address? All of our customers are saying our support emails are ending up in their spam folder.
Marketing guy: Yeah does anyone know why our support and advertising emails are being marked as spam?
Developer: …never mind.
It still doesn't justify companymarketing.com and companyhelpdesk.com though.
In many cases, no. They simply see that it has Venmo (or whatever) in it and assume it must be legit.
I've tried to explain this exact thing a few times. Not even sure I managed to get them to understand that a big company wouldn't use Gmail, but rather their own domain.
Yes. They're obfuscating the mechanisms that can be used to assess trustworthiness so they can sell it back to us as some kind of reputation or verification product.
Email is a perfect example. If the from address wasn't moved around, hidden, and obfuscated, it would be easy to tell people "make sure Venmo emails are from @venmo.com" and that's the thing everyone would look for. Instead, there's an entire generation of people that don't know how to identify a from address and it opens the door to a paid verification platform instead.
I mean, you don't. You stop using their company, and you let them and everyone else know why. Vote with your dollars or with your feet.