*@gmail.com
xkcd.com
xkcd.com
-latest reply all on every reply-all storm.
In my early days at Amazon, around 2012-2015, this would happen frequently enough [0]. I pretty quickly learned the best thing to do was to ignore the conversation and never think about it again rather than try to 'help'.
[0] - too many new products and orgs set up new mailing lists with 5000+ people on it, most of whom had no idea what it was. Growing pains.
If someone is bothered by such a thread, it's really easy to avoid.
It was a very expensive email for sure.
I admit have been tempted to respond to some reply-all maelstrom mailstorms to herald the mute key…
The management had to chime in and sometimes threatened people with punishment if they continued participating to the reply-all storm.
If you ignored the conversation you may not have seen it, but most reply-all storm ended up with someone saying something the line of "we don't care about your wallet".
Anyway, asking people to stop hitting the reply-all button is far from being the latest reply-all on these kind of things...
Not quite. It started with a meeting invite that was accidentally sent to everyone. The meeting was for the Amazon Wallet team (I think they did something with payments, etc.) for whatever work they were doing at the time.
Most people ignored the meeting invite and just deleted it, but someone hit "Reply All" and said something to the effect of "I know this meeting invite was not for me, but I wanted to make sure that whoever was supposed to get it did not miss the meeting."
From there, it turned into a "Reply All" storm with lots of people replying all with "Please do not reply all".
Others thought it was funny and sent memes. One guy was so bold to promote his indie rock band that was taking off.
The incident is famous and became known as "Wallet", but the name comes from the Amazon Wallet team.
I arrived a few months after that, so someone tried to explain to me but either my memory is wrong or the explanation was flawed.
It really simplified things.
Address not found
Your message wasn't delivered to \*@gmail.com because the address couldn't be found, or is unable to receive mail.
LEARN MORE
The response was:
550 5.1.1 The email account that you tried to reach does not exist. Please try double-checking the recipient's email address for typos or unnecessary spaces.
Learn more at https://support.google.com/mail/?p=NoSuchUser f15-20020a05651201cf00b00500994b137asor390839lfp.19 - gsmtpThe “+” tagging was a great idea, but the fact that incorrect address matching has become a “feature” (and not fixed over decades) plus constant spates of spam has made me believe there’s nobody left at the helm who actually understands e-mail.
I’ve kept my Gmail addresses for some mailing-lists, but moved everything of consequence to better providers.
So I mean at my Gmail I have all manner of different Facebook accounts with various misspelling of my email address notifying me of stuff, none of them are mine. I'm sure they entered my email address (with dots) by accident, not on purpose.
I appreciate that sites not allowing you to register the same email address twice hardly solves everything, as I absolutely get email to my actual correct Gmail address from random sites I've never signed up for. But at least it would help in certain cases like Facebook where I do have an account.
I never get any of these problems.
I had to do this once when someone signed up to FB with my email address. It actually was an eye opening experience as to how much data FB collects from everyone.
Now keep in mind that: 1) I don't have a FB account myself 2) This person signed up with my email address (which is <something-generic>@gmail.com), but their name is completely different from mine 3) They didn't even speak the same language, when I logged in to the new account the whole thing was in Swedish or something like it.
So nothing at all linking the account to me, except a misspelled e-mail address. When I logged in, FB was happy to suggest I friend a whole bunch of people I know IRL. Including people that do not know the e-mail address used. Absolutely crazy. How were they able to link me to these people when I was signed in to a complete stranger's account?
Of course it backfired, after he stopped using his account facebook and a couple of weeks facebook started sending begging emails to my email account again (don't believe them when they say they delete anything), I still get the occasional "what you've missed on FB" emails and about once a year the guy tries to recover his account and I get an email, I'd drop him a note, but the only email address I have for him is mine
[1] now pretty much abandonned but I mostly keep it to avoid anyone obtaining it and impersonating me. I still need to do some housekeeping and make sure I am not registered anywhere with that address anymore.
I've had a number of accounts opened in my address but with different dots (eBay, Spotify, Shutterstock) that didn't require confirmation.
I usually reset the password, inform customer service (who generally don't care, or don't want to do anything because it's not my account), and then I close the account.
I tried to login to Discord. It detected a novel browser or location. Sure, this stuff can happen. It wanted to confirm that I was still me and asked me for my e-mail address. I gave it and it said "This e-mail address is already registered". What. Of course it is. It's me. Mine. The one I have registered with you.
Since I have a few useful things tied to Discord, I felt my pulse go up. I googled for answers, found a Reddit thread with this specific problem. They said "Hey, if you use Gmail you can use the dots-are-ignored-feature to give Discord a "new" mail that will still go to you, allowing you to verify it!" (https://www.reddit.com/r/discordapp/comments/12makhd/verify_...)
Sounded clever so I gave it a fore.name.sur.name@gmail.com variant.
Sure enough, I got the mail.
I logged in. I gasped as I realized Discord had now created a new, empty user for me! It somehow thought I was a brand new user despite this was only a user account _verification_ due to changed IP or whatever to begin with.
I tried logging in to my original account once more and now I somehow got in! The verification on my new account had somehow triggered (cookie? I have no idea) that I was trustworthy again. Phew! I promptly deleted the new-account-going-to-same-mail and breathed normally again...
I think at that point I would just have been too scared that this would cascade-delete the old account as well ^^
https://engineering.atspotify.com/2013/06/creative-usernames...
The parent poster then did not realize they had created a new account and, even when it told them their email address was registered to a different account, somehow didn't realize they should go click login instead.
I think the easiest way for discord to make this a not-confusing experience for people who aren't tech savvy enough to click "login" to login, is to make it so the signup flow is a normal explicit "Enter email, enter display name, enter username" prompt, not a flow where they silently create a username if you _just_ enter a displayname.
The reason this would help is because forcing the user to enter a username early on lets you display a "Would you like to login instead?" message if the username conflicts.
Having the user enter a non-unique displayname, and silently creating a random unique username, means the signup flow no longer has the ability to say "Are you sure you don't want to login?"
Of course, discord mostly targets relatively tech-savvy users, not the average hacker-news-user, so it probably isn't that big a deal for their main demographic.
But if you do this you better do it everywhere you use email. Otherwise you can get some pretty nasty bugs where two emails aren't considered the same sometimes, are are considered the same other times.
It's really annoying that on some websites you have to open up multiple dropdowns to reach the login page, also passing five sign up buttons on the way there. It's even filled with dark patterns, with the sign up button blinking and screaming at you to click it every single time, while the login button is made smaller and grayed out. I remember GitHub pulling this shit some time ago. Once I truly couldn't find the login button and gave up, opting to guess the URL/find it in history.
What is even the purpose of that? Is it truly a scheme to get users to sign up multiple times for the same service so that the user number goes higher? That seems too dumb.
Instead of clicking the "login" button on discord's home page, you clicked the "Open discord in your browser" button.
This, by default if you're not logged in, takes you to a create account flow. The prompt you entered your _username_ into was the "Pick a display name" prompt. If you enter, say, "user" it silently adds numbers to your displayname to make a new username ("user1234"), rather than redirecting you to the login page or prompting you about it (like most other sites do).
At the end of the flow is a "Finish signing up", "claim your account" prompt (which really is the end of the "create a new account" flow, the ephemeral account without an email you're using there is in a partially signed up state).
This is the box where you were entering your email, getting a conflict, and ended up using a new email to create a totally new account.
I know people who use hacker news are on-average much less tech savvy than the average discord user, so I can get why you missed the login button on the home page and instead went through the "create account flow", but everything that happened is "working as intended" rather than a "bug".
I do agree the flow there is pretty confusing. They've managed to make the new user signup flow so optimized you didn't even realize you were doing it.
Still, by the time it was telling you your email was already registered, you really should have slowed down and noticed it was telling you you were creating a new account rather than using a new email address for some reason.
Sarcasm? Serious question. I used Discord exactly once, many years ago, and it appeared to be mostly children playing video games. I hear things have changed, but it’s hard to imagine a more tech savvy group than HN.
I'd assume kids are better at navigating modern dark patterns, having grown up with them.
Okay.
> Instead of clicking the "login" button on discord's home page, you clicked the "Open discord in your browser" button.
Sure.
> This, by default if you're not logged in, takes you to a create account flow.
That is a UX bug! Why does opening discord in my browser automatically imply I need to create a new account?
> I know people who use hacker news are on-average much less tech savvy than the average discord user
And yet, somehow, much more tech savvy than the average Discord UX designer.
You're right that if Facebook required the email to be verified (by sending an email to it) before it could be used with Facebook then two different people wouldn't be able to have two separate Facebook accounts with one of them having an email address controlled by someone else. However, Facebook, in order to "reduce friction" and "reduce time to first value" is happy for you to use an unverified email address and they're happy to send a variety of emails to that address (including lots of emails telling you to finally verify that address).
I've just gone to facebook
clicked register new account
Entered Name, DOB, Email
Now I'm stuck, can't proceed past "Enter the code from your email" and going to https://facebook.com in a new browser tab takes be back to the "enter code from email page".I doubt they will send any chaser emails but I will report back in some time
That said, clicking the "report spam" button should allow you to unsubscribe from such emails without dealing with logins or whatnot. Gmail supports certain unsubscribe headers that'll automate the process, which should make getting rid of Facebook's spam a lot easier.
experts.exchang@gmail.com
expert.sexchange@gmail.com
Those addresses would be identical by Gmail's parsing conventions.Alternatively: will third-party systems consolidate such addresses under a single account, or treat them as different?
(Examples include both Gmail and other systems.)
<https://news.ycombinator.com/item?id=12025091>
<https://news.ycombinator.com/item?id=12027598>
For a while it redirected, I guess they let it expire at some point.
It's spelling errors, not the dots, that are usually the source of misdirected emails (and also, wrong domains).
Kind of ironic that you proved the opposite point of what you intended.
experts.exchange@gmail.com
expert.sexchange@gmail.comI made (and corrected) three further typos writing my correction.
But the point remains that what I'd originally intended to show was that local-part email addresses which read differently, and in cases quite differently, but are identical save for the location of the dot, are treated identically by Gmail.
And that in different contexts this might not be clear and/or lead to confusion.
My email: name.alias@gmail, because already exists namealias@gmail. Ok the email Work fine for 4y before this feature exists, after if email send exacly works but the problem i am started reciving email for the other user and this is e-mail is not cool.
After 10y i give up of gmail and moved to my domain
imagine that someone else has an address namesurname@gmail.com
this is very similar case to my mom's one. she constantly gets emails meant for someone else - including PII - because she has no dot in email, but the other party has a dot.
I know for sure that her's account is quite old one.
> imagine that someone else has an address namesurname@gmail.com
If gmail ignores dots, it shouldn't be possible to have name.surname and namesurname as two separate gmail accounts.
My own mail server is configured to use a different character besides the `+` for tags and its notion of "same account" is defined by a mysql query. There's no way to know the interpretation of the local part in advance: you can apply various heuristics if you don't mind annoying people; or you can accept the email and verify it by sending an email.
if you register namesurname@gmail.com, then you also every combination of it with a dot.
n.amesurname@gmail.com
na.mesurname@gmail.com
nam.esurname@gmail.com etc..
And that's exactly the issue Gmail solves by ignoring dots. There cannot be two different accounts differing by dot(s).
But sometimes handy to fool sign ups and use it twice (or more depending on length). I wonder if you can use multiple dots?
You can also use foo+extra@gmail.com and the +extra will be ignored, so you can give each service a separate email address like foo+hn@gmail.com.
Beware, as I found out the hard way, this makes account recovery more difficult. To reset your password you need to enter your email address usually. But if you used +foo stuff then you might not be able to remember what email address you used.
I’ve sometimes resorted to finding a piece of email from them and looking at the “To” header.
That's exactly what password managers are for.
That wouldn't be a valid email address. (unless it's quoted. "f..oo"@gmail.com is valid, but so obscure nobody will accept it).
"Fixing" that would break a documented feature millions of people depend on.
Somewhat surprisingly to me, "anecdatum" has apparently never yet appeared in print [0], and I'm happy for the two of us to share credit in coining it.
I’d pay to block the “full stop ignore” feature.
How dose ignoring dots cause you to receive other peoples mail?
If you have John.Doe registered, no one can register johndoe or any with or without dots version.
Gmail (rightly or wrongly, whatever) ignore the dots when creating your account and deliver any with or without dots combination to you.
You’re not receiving anyone else’s mail and no one could have registered another account with/without dots to conflict with it.
If you don't want to use the feature, you don't have to. Lots of people find it extremely useful.
https://support.google.com/mail/answer/7436150?hl=en#zippy=%...
> if your email is johnsmith@gmail.com, you own all dotted versions of your address
> If anyone tries to create a Gmail account with a dotted version of your username, they'll get an error saying the username is already taken.
> Your account is still private and secure. Emails sent to any dotted version of your address will only go to you.
Note: my bit of research into this taught me that the googlemail.com domain is used by Gmail users in Germany, Russia, and Poland where the Gmail trademark was already taken 1. In each case, Google was forced to use “googlemail” and therefore googlemail.com instead. As of 2012, the situation with Germany was straightened out and new users to Gmail there get assigned a gmail.com domain.
One person is x.yz@gmail. Tens of times I’ve had people or systems strip the x, I am y.z and get their mail. Invites to funerals. Business mail. Admittedly reduced lately, he probably uses it less.
One professor has a “t” in his name, so “ytz”. People miss the t and send to yz. Dot gets ignored so I get those. I get assignments, or people pleading for extensions. That’s stopped over time.
The stuff is important so I tried hard to get it to the right person. But a bounce to the sender would have been better. It’s a bit wearying to be a post forwarder.
Most of the spam I get is to yz. Some makes it through. I’ve never used that version, ever. I just checked spam now. First 4 messages were to “yz”.
So many mistakes get sent to that version. After many years I tried setting a rule to block that version because it’s definitely not for me, but no go (although maybe that’s why I get less now of the above two examples. I’ll check my rules in the morning). I’ve had the address since the earliest intro-only days so it’s had time to add crud.
That is not how it works, you own every combination of your email address with dots left of @ automatically.
if you own foo@gmail.com, then nobody else can own f.oo@gmail.com because you own it, it's an alias of your email address esentially.
Meaning they can just strip out the dots when matching email addresses: either on login/signup or mail routing.
But the cause of that appears to be user error -- people thinking they own email addresses that are not actually theirs.
Please, please give an example..
Also, read this..
https://support.google.com/mail/answer/7436150?hl=en#zippy=%...
> if your email is johnsmith@gmail.com, you own all dotted versions of your address
> If anyone tries to create a Gmail account with a dotted version of your username, they'll get an error saying the username is already taken.
> Your account is still private and secure. Emails sent to any dotted version of your address will only go to you.
Someone gets righteously indignant that this cannot happen in every thread about dots in gmail, despite the fact that there are many people it happens to. They’re not making it up, why would someone do that?
They are likely making a typeo elsewhere in their email address which is causing the confusion.
for example:
Steve.foo@gmail.com
stevenfoo@gmai.com
Notice one is Steve and the other is Steven, the dot has nothing to do with it.
I just searched for my name with no dots in my gmail. Man. It’s a dumpster fire. I have to put up with hundreds and hundred of wrong mails monthly because this feature amplifies the mistakes so much. And it adds to spam because other people type the wrong mails into forms and gmail “fixes” it by ignoring the lack of dots. It’s honestly infuriating. We know we own all versions. We get it. That’s what causes extra work for us and makes us like the product less.
My experience would be significantly improved if I could have all the non canonical addresses bounce. I agree that I would also like nobody else to own one of the other dot versions but that’s also possible.
I'm pretty sure you could set up a filter for that.
https://news.ycombinator.com/item?id=37339688
Rewritten: For various reasons, people mistype emails and they usually end up with a no-dotted address. Mine, as the catch-all, gets that mail.
A classic made up example is eg “fred.fredflintstone@gmail”. I have many times received mail for that person because I’m “fred.flintstone@gmail”. People see the double fred, remove the first and hit my account. I also get for “fredtflintstone” (notice the t, many don’t) and this last month “fredrflintstone”. Life would be much easier for all if gmail just bounced those when someone types it as “fredflintstone”. They’d check and fix it.
This is amplified by spam, because any leaks others make hits my account. They should bounce.
This morning I put up a filter to the no dot version. About a month ago someone put my no-dot version on their dodgy Microsoft ads account. I spent ages trying to get off it and somehow Microsoft still hasn’t taken me off. Now I’m just filtering that to deleted, along with mail for all the mistakes above. I’m done. Gmail’s dot policy enables this hugely.
Someone could have setup a dodgy Microsoft ads account to your main email just as easily as the dotted/non-dotted version.
Where is the problem?
The problems:
1) people who are sending important emails are ending up with the wrong person and they don’t know. Fixing that takes effort on my part, I have to tell individuals or a group mail I’m the wrong person. A bounce would fix that, instantly with no effort. I sometimes try find the right person. That also takes effort, I have to look for clues. Locations, work hints etc.
2) I’m fairly careful with my email. Others aren’t. Most of the spam I get is linked to the wrong address. Those should also be bounces. Because I get mail for all dot variants, I get a multiplied amount of spam compared to just my version.
3) I’m pretty sure a dodgy money making racket is to sign people up via affiliate programs in the hope some of those get added. I see this in a huge amount of random email lists, products etc. I’d say 80% minimum of those use the no-dot version. The problem is that 80% I shouldn’t have to put up with. The people doing this are just being lists of addresses and firing them at anything that works. They aren’t targeting me, they’re just using the strings they’ve harvested. So they don’t know about the version I use.
The Microsoft issue pushed me over the edge. I’m now going to trash that entire set of problem for my own (selfish) purposes by filtering it out. The people being harmed are those whose contacts mis-type addresses and now eg invites to funerals will go to trash.
The only possible way that I know of to provide feedback is to send a reply to the sending address. Perhaps you're asking for an addition to the email system so that a recipient can "click a button" to generate at the protocol level a response from your mail server like "errNum% - Wrong recipient. Undeliverable as addressed."?
Rule: for any email address variant that is not what the user selected, reply with “550 no such user here”.
Instant reduction in both spam and mistyped emails. Instant feedback to sender.
fred.flintstone@gmail
and user2 has
fredflintstone@gmail
forgetting a dot is far more likely than someone missing an entire word out of an email address.
The dot policy forces email addresses to be more unique across multiple users and thus would reduce emails being received by the wrong person.
Some data, sans opinion: I checked my trash this morning after clearing it out. Total messages in trash: 47. Trashed messages linked to the "fredflintstone" variant: 40, all of them spam. The other 7 are all real messages I've just deleted after reading, none of them are spam.
why would they? do you think another person would not register fredflintstone@gmail and another user could register fred.flint.stone and another user fred.flints.tone
then you have lots of people using email addresses that are the same if the end user excludes the easily forgettable punctuation marks.
Your anecdote about one person who keeps giving your email address out does not mean that Googles dot policy is bad.
I can't expand any further on what I've already said so I'm going to leave the discussion
1 only one person can own all variations
2 that person can choose to have all other variations except the selected one, blocked. Make it a checkbox. Done.
So they just get their email wrong, and it's nothing to do with dotted variants.
They never had an email address with or without dots that's made up of the same letters as your email address. Their email address is probably very different (maybe they forgot to add a number, or a middle initial, or typed Gmail when they should've typed Outlook). The dots are just a stylistic choice.
I've spent way too much time thinking about this.
Well, specifically about the kind of person who would use an email address they don't own to (a) buy a house, (b) apply for a FL sheriff's job, (c) conduct financial transactions, etc. (all actual examples I've received).
You think you have a bead on how ignorant people are, and then you realize there's a long tail you weren't aware of...
You could own steve.brown@gmail.com but someone you only occasionally do business with might have accidentally put down steven.brown@gmail.com when you first met. Emails back and forth will work (because they can reply to your emails) but when they try to send you email, someone else will receive it.
This can also go unnoticed (i.e. when someone sends an email stating "when are you sending the documents?" -> "I already did, maybe they ended up in spam, here you have them again"). People probably won't notice unless the unintended recipient tells the sender that they got the email address wrong. I imagine that might happen a few times, but after a few years of other people using your email address, you'd stop bothering.
Responses have been pretty bizarre though. I usually get what amounts to an "Okay".
I would have expected some sort of "Could you please delete those sensitive documents we sent you?" at minimum.
Also bizarre... I don't have a very common name or email address for my main Gmail.
I can only imagine what john.smith@gmail.com has to deal with.
From a solution / feature perspective, it'd be nice to have a auto-response + trash on anything other than allowlisted dots and plusses. Maybe Gmail supports this? The worst offenders finally got the picture, so I didn't dig into it.
The point is that without the dots rule I'd never get those emails, and the senders would get their message bounced back right away.
You can write rules on f.oo to go a different path than fo.o.
Genuinely confused - which other people? There are no other people with your Gmail address but added/removed '.' characters. What you're seeing is people sending emails to the wrong email address - nothing to do with presence or absence of '.' characters.
Allowing addresses to subtly differ based on '.' presence/absence would result in more wrongly addressed emails, hence the aliasing.
I've been getting wrong Gmail emails all the time for years because a woman in Saskatchewan keeps getting her email wrong when signing up to stuff online. Quite funny really but nothing to do with .'s
The most humerus conversation I got added to involved a local residential community dispute where everyone assumed my insistence of being removed from the thread was actually my namesake trying to avoid the conversation.
His wife finally stepped in to resolve the situation.
I have the same problem but multiplied by 25x due to having a <first initial><last name> gmail address from 2004 when it was still invite only. It’s really annoying that there’s so many services that don’t verify email addresses…
It is quite the odd situation. I reply to their friends saying they have the wrong email, but they don’t seem to believe me. And they keep signing up for things despite presumably never being able to actually access many of these services that require email verification.
My guess is it is someone not very computer literate. But it is always amusing.
Given how reliably this happens, I guess the answer is "no". It's also probably a very small number of people, just 1 or 2 with each commonly used name. But still every common name has those 1 or 2.
I wish it was just edge cases! I've bumped into so many services that can't handle "+" in email addresses, some seem to be on purpose (presumably to prevent signing up multiple accounts to the same address) but others are just old school bugs. My fav is services that send the email address to an API including the email address as a URL parameter, but forget to escape the email address so the + gets butchered in the process.
And just to put it out there: "+" addresses aren't specifically a Gmail thing, they've been supported by most(?) mail servers for a very long time.
It's been a nightmare. Apple lets account creation succeed without email verification and with SMS verification. So with my very common name, as soon Apple allows it, someone with a similar name uses my email to make an apple id, preventing me from using it. Without knowing or owning their phone number, it's impossible for me to fix. It takes 2-3 weeks and multiple hour long phone calls with apple to free the email again, at which point someone else uses it and the process repeats. Every phone call is horrible, it is really confusing to explain the problem. Every phone call starts with the support staff believing I am typo'ing my email address. After a few times I gave up trying to fix it.
Which can create problems with services who don't consider them the same. A decade or so ago I had an awful time trying to sort out two of my Xbox Live accounts that only varied by the dot, and couldn't figure out why I was still being charged when my account page said it was canceled.
I have used “.” Variations to create multiple accounts on a service.
I wonder what the limit is?
Can I do …first.name@ and first……name@ and so on for infinite names!
iCloud has auto anonymous emailing with plus, Firefox does to, but tying my services to such a feature rather than even just an email seems fragile.
What other providers do you recommend?
If you own foo@gmail.com, you also own every combination of it using dots left of the @. for example:
f.oo@gmail.com
fo.o@gmail.com
Nobody else can register these addresses because they're all owned by foo@gmail.com automatically.
I sent email to aaaaa.a@gmail and to aaa.aaa@gmail and receive both.
I remember a Lotus Notes-based on in a bank I worked at the early 90's. I think it only stopped when the Chief of Staff did a reply-all with "The next person to reply-all to these emails is sacked."
(Don't do this in real life, please.)
Any other fun easter eggs in the XKCD counter?
- https://xkcd.com/404/ 404s (obviously)
- https://xkcd.com/1337/ is about hackinghttps://web.archive.org/web/20190328010454/https://plus.goog... (via explainkcd)
"I am currently on leave" could be the Wikipedia page.
https://old.reddit.com/r/talesfromtechsupport/comments/420oa...
The NHS's 1.2M employees are trapped in a 'reply-all' email hell
Action: Play sound [if working in office], Forward to "[initial sender]", Mark as read, Move to trash