Ask HN: Please review mailop.com, an instant disposable email you don't even need to check
mailop.com
mailop.com
I run 10MinuteMail.com, which is in the same space, although with a few differentiators, so take my comments with a grain of salt:)
I worry about the lack of security (i.e. someone can easily issue a forgot password event, and grab that e-mail, and take over your account). Obviously you shouldn't use disposable accounts for things like your bank's site, but in general I think people use them for forum or site accounts that they want to use, but aren't sure won't sell their address list. The only people I can picture who 100% don't care if their account can be easily stolen are forum spammers, who unfortunately use disposable e-mail services pretty often.
I like the auto-clicking action, although many sites require you to set a new password after you click the link or login with the One Time Use initial password. Since those links are only usable once, and the site will keep auto-clicking them when the mail comes in, I think you could find yourself unable to authenticate with a large number of sites.
I will write some code to avoid the auto-clicking trap you mentioned, thanks! :)
It might be possible to right scripts to automatically create accounts at places like the new york times. So you could get people to go to your site, and they could automatically access sites. The problem with bugmenot is that people change the password on the throwaway accounts, so it is sometimes hard to find valid accounts. This way you could control the password and make sure it wasn't changed. That will get you page views, and let you put up advertising.
I like the site though, it's always nice to have another throw away email account. Especially since this one actually activates the registration for you.
you should auto-gen an email address for every new visitor, makes it easier than having to check. people don't care what the username is for a throw-away email address anyway.
after auto-gen, set a cookie so if I do have to come back for something, I don't need to remember the username and I can click a link to see the inbox (or just put the inbox on the frontpage as well)
otherwise, pretty cool! a neat hack would be a bookmarklet that auto fills-in a reg form with the email address (say some javascript that searches for an 'email' text field and inserts a new unique email).
edit: come to think of it, I would probably pay money if you did this as a service for my own domain. eg. I could point a catch-all for all my email to you, which you can use to generate throw-away emails from my domain name (in that case the emails are less likely to be blocked by services).
I hope to be able to run it off a minimal VPS account as I am doing now. The architecture is very slim (no disk access, no interprocess communication) but uses unproven libs. Still loads fast for me, though.
http://mailinator.blogspot.com/2008/11/so-our-core-duo-serve...
However, I would be concerned about the other links that might appear in the email. For instance, click here to link your site cookies with the MSN ad network, or click here to agree that everything you submit will belong to Bigcorp.
Some (admittedly poorly designed) sites might even have "click here to cancel your registration" links. Can your link follower tell what each link means? I don't think so. But yeah, for most cases, it will work beautifully.
It is a cool service but if you use this you need to create a substantially different username and password to really be safe. Even if your login credentials are different someone can go through the password recovery process via email, reset it, and do whatever they want. Why would I want this to happen on ANY of my accounts? Even the ones I care least about need to be more secure than that.
[EDIT] ...but maybe the people who use these services are more intelligent than the average web user, are aware of the risks, and only associate these "throw-away" email addresses with throwaway accounts.
My concern is that if (when) your service gets popular, sites that require registration won't allow email addresses with the mailop.com domain (if they want real email addresses).
Other than that... great for you!
-Artel
The problem is that people who actually care about blocking temporary e-mail tend to stay on top of the big sites domain lists. There are even 3rd party lists you can integrate your site/forum with that block all disposable addresses.
Good luck with the rest!
WELL DONE!
edit: Also, having the mails (subject and body) display as a xml feed would be ++, some of these temp email sites offer this, but only show the subject and a link to the message which isn't part of the feed.
looks like a good idea, just needs running through a spell checker