foo@bar.com is a real email address
bar.com
bar.com
1) There are exactly 3 domains the IANA keeps free for that purpose:
example.com
example.net
example.org
2) In addition, all domains under the following 3 top level domains can be used freely for that purpose: *.test
*.example
*.invalid
3) The domains under the following top level domain have some special meaning (should point to loopback IPs only): *.localhost
Everything else is either registered, or might be registered by somebody in the future. Don't (mis)use those names unless you own them!Unfortunately, this kind of criticism is not always welcome on HN. (for example, http://news.ycombinator.com/item?id=3129459 was scored -1)
[1] RFC 2606, http://tools.ietf.org/html/rfc2606
IPv4: 192.0.2.0/24 - as described in RFC3330, http://www.faqs.org/rfcs/rfc3330.html
IPv6: 2001:db8::/32 - as described in RFC3849, http://www.faqs.org/rfcs/rfc3849.html
I had to rename an entire corporate network once because the previous folks thought .local "looked good". It cause constant issues with clients that had bonjour or avahi running.
That, and mDNS already being used as a psuedo-standard with things like Avahi.
Where does email sent to wildcard@example.com go? If I accidentally sent sensitive information to wildcard@example.com would some evil person (potentially at the IANA) be able to retrieve it someday?
ETA: I am now starting to doubt my memory here, and Google's USENET archive search is broken. Sigh.
It was common advice back in the day to use "example.invalid" and NOT kill some poor guy's server at example.com; I don't think .invalid was explicitly reserved before then, but it was known not to be a ccTLD or gTLD.
http://web.archive.org/web/20040210183242/http://black.wiret...
that server.com server was hilarious. it ended up becoming a mini-BBS with people posting funny messages, file names etc. to it. When I went to check it out to see what was going on, I ran a dir on the c drive, and there were almost 500 funny folder and file names there, with 'X WAS HERE' etc.
someone then put out a URL on IRC which would fire up a reverse shell. and that server.com server ended up running gaming servers, porn ftp sites, warez, the works. the guy emailed me around 2-3 months later asking for help to patch the box because it kept getting owned.
fun fact: I wrote a scanner in C back then that would check for these vulnerabilities. The scanner had two 0day vulnerabilities that weren't in this paper. one night at a friends house we were playing around with NXFR transfers from DNS servers (this is back when you could do them and before people figured out to lock this down). we started downloading lists of all the domain names from various TLD's. for eg we had .net, .org, .com etc. then we started downloading various countries, for eg. .at, .co,
we were talking to each other about what to do with them, and he said 'lets run one of these through your scanner'. so I made a quick change that would check the Server banner returned, and if it was IIS, it would then try these different exploits and run a command. we couldn't work out which command we wanted to run, so I had the idea of just creating a file called 'heh.txt' in C. I set it all up and ran it against all the Austrian domains. within a few seconds it was obvious that it was working too well - because it was churning through 5-10 hosts per second and a lot of them were 'SUCCESS'. I left it running, no idea when it finished, but when I picked it back up again the next day around 40% or servers (may have been more) were running IIS and of those, around 98% had our 'heh' command run successfully.
tl;dr hacked ~40% of all servers in austria. if you ever found a file called 'heh.txt' in the root of your C drive, that was me.
Anyone when educated about the proper use that says that is just spouting BS.
Do it right or don't do it all.
This page is a memorial to Foo at Bar.com
Back in the earliest of early days, I (The Foo at bar.com) got a few emails a week, mostly from sysadmin type people who were invoking The Foo in an effort to debug some kind of system or other.
Of course I, being a gregarious sort, answered the messages. Mostly along the lines of "hello? Foo here. What can I do for you?Ó or "who you? I Foo.Ó
I met a lot of really interesting people in 1994 and 1995 that way.
But soon I had to return to obscurity, as my email volume grew overwhelming.
Y'see people building web sites started putting little "give us your email address and we'll let you see the goodies" challenges in their web sites, and lots of folks entered foo@bar.com.
Soon, I was getting thousands, then tens of thousands of emails a day, mostly from people who didn't care whether I replied or not. Alas, I was overwhelmed and had to return to my solitary life.
For a while, I MX'd email addressed to me to 127.0.0.1 but that made some people cranky (although I still take some quiet pleasure at the thought of what that address did to spammers).
I MX'd the mail over to a friend's spam-detection server for about 4 hours one time, but the volume crashed his server and he asked for relief.
So now I'm content to tell you this small story.
Onward,
The FooGuys, please stop: what makes you think test.com can't be a real destination? :-) Actually, they don't have a mail server for that domain, but still...
http://cl.ly/1L1C0O2A081x000t382z
You might want to edit those.
I wish all our users would read the docs as carefully as you do! :)
* post a public webpage with all email going to @test.com
* post a public webpage with all email addresses harvested from emails to @test.com
Or
* setup an auto responder asking people to stop sending there (bonus points: threaten to post emails of repeat offenders to spammer lists)
http://blog.washingtonpost.com/securityfix/2008/03/they_told...
Whenever I fire up email testing tools, I use president@whitehouse.gov.
HN will never bring you more than a few hits per second at the most..
I dread to think how many emails they get everyday.
As a side note, looks like they copied HN's favicon.
Wasn't aware of the Chrome bug though, thanks.
In recent years, I started using the + notation at gmail -- anything you put after the + and before the @ is ignored by gmail, BUT you still receive it -- the handy part is you can filter it out (e.g. myname+hackernews@gmail.com will go to myname@gmail.com, and I create a filter to archive everything that comes to myname+hackernews@gmail.com)
If your email is mylittlepony@gmail.com
Then your can use as many '.' and filter it out.
You will also receive emails sendt too my.little.pony@gmail.com
M.y.l.i.t.t.l.e.p.o.n.y@gmail.com
Gmail ignores punktum. Thats smart!
I imagine only a few of the big guys (yahoo, microsoft, google) could handle large unexpected volumes without hiccup.
(Also, it wasn't enough to spam them, now we DDoS them)
So if anyone's reading this: Please stop using random gmail accounts and use foo@bar.com instead. Thanks!
* just kidding, test@example.com would be the one to go for ;)
The thing is an overly sensitive, badly configured setup; but still troublesome?
If your excuse is "I didn't know about example.com!"...well, that's a lame non-excuse. Do the rest of the IT world a favor and fix your tutorials and software -- mail server administrators like me already have enough headaches from the gazillions of spam techniques in use today.
Ignorance is a legitimate excuse. I'm getting sick of people spreading this moronic misunderstanding that ignorance is not an excuse. Just recently the police in NYC failed to follow a judge's order out of ignorance. I wonder what excuse they used.
As for why people don't use example.com, if you're signing up for a site that annoyingly makes you put in a password it will check for non-real email addresses so example.com is out.
Thus foo@example.com might be a better address to use, especially in examples.
We recently got this email from Fake.com
Hello
We own the domain fake.com, and from time to time some moron out there in the world-wide-waste-of-time uses our name to try and sign up for something...
Not just that, there’s also a whole slew of dozy IT people who test links by doing the same thing without doing a whois check first!
Whichever it is, could you please delete this account?
Thanks [redacted]
fake landscapes - the artificial plant company http://www.fake.com*
Somehow I don't think this has the desired effect... that's a tough domain name for this sort of thing, feel sorry for the guy but not much we can do.
I assume you have an obvious 1-click subscribe on all of your emails? If not, I'd gladly mark you as spam over, and over, and over...
How do you tell fake from real?
What if someone who works at fake.com wants an account?
Anyway, we already have example.com for this purpose.
Personally, I was familiar with the acronym FUBAR first, so it comes as natural to me as most mainstream, American acronyms.
Thanks!
after DNS was in place, MX records came along in order to route mail destined for a host to a different server, or just supply a list of backup servers. now since most people just use email addresses containing only a domain, MX records are pretty much common place (since the A record of many domains resolves to the web server). now MTAs check for MX records before trying to connect directly to the host.
to demonstrate:
jcs@thalamus:~> host -t mx test.jcs.org
test.jcs.org has no MX record
jcs@thalamus:~> host test.jcs.org
test.jcs.org has address 10.10.10.10
jcs@thalamus:~> echo test | mail test@test.jcs.org
and shortly after, in postfix's mail log: Nov 21 22:59:18 thalamus postfix/smtp[23742]: connect to test.jcs.org[10.10.10.10]:25: Operation timed out