Live data from Hacker News

Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

github.com

71–80 of 304 posts

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#71
post #51

I've started using my own domain to avoid giving out my "real" addresseverywhere. It doesn't always work, but it usually does.

Why doesn't it always work? I'm also using my own domain, not sure why'd that ever 'not work'.

As an experiment, I once tried to see if online services accepted role-based emails (like admin@domain info@domin sales@domain contact@domain).

Surprisingly, the game Eve Online was super-strict in refusing these types of addresses. Most other services were fine though.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#72
post #42

Earlier quoted context omitted.

Recently, I wanted to try a web service but they did not let me register with a disposable email address. Well, I guess I will not try the service then.

And how would you protect your service from users that just sign up with disposable Emails for the 7 day trial over and over again?

Just a few idea: Make it useful to have a persistent identity, so you have something to lose if you abandon the account (like a library of games in steam, or a network of friends on facebook). Require a payment method and limit how many free trials can be activated with the same card. Require a phone number since they a harder to get than emails.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#73
post #38

Earlier quoted context omitted.

I’m the founder of a small bootstrapped SAAS and people use disposable email addresses all the time to avoid paying for our product. We don’t sell any data.

But why would having a "valid" email address help you more getting payment? At most you may send reminders, but even then, those may end up in a spambox? Even once you've verified the email, you have not much of a guarantee it will stay verified/working long. That's more the subscriber's problem, if they want to continue to use your product.

It's easier to create many disposable email addresses than "real" email. To get a new "real" email address, you need to fill a lengthy form (e.g., try it on Gmail.com now) and it's not easy to automate the process. But it takes only one-click to create a new disposable email address. Some disposable email providers also provide APIs, so you can create addresses in batch.

People may exploit paid services by creating many new accounts -

1. Free trials: When trail period ends, create a new account.

2. Services with metered billing: Use the service, then refuse to pay. Then create a new account. Then refuse to pay. Then create a new account...

Of course, (theoretically) if the service provider has enough resources (i.e., money, time, knowledge...), they can always find a better solution than banning all disposable emails.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#74
post #42

Earlier quoted context omitted.

Recently, I wanted to try a web service but they did not let me register with a disposable email address. Well, I guess I will not try the service then.

And how would you protect your service from users that just sign up with disposable Emails for the 7 day trial over and over again?

I doubt that a meaningful number of users creates new accounts every 7 days just to avoid paying. Setting up a new account is usually enough work that it is not worth it. But if that is the case for your service, here are three things from the top of my head that might even work. If instead you just block disposable email addresses, I might as well look somewhere else.

* Reduce the trial period for users with a disposable email.

* Don't allow data import/export so that creating a new account is more work.

* Reduce cookie lifetime so that a login is needed more often.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#76

Earlier quoted context omitted.

> almost all companies will spam your email address, even if you check the box asking them not to. I find this very hard to believe. "Spam" has a specific definition; the most important bit of which is that it is unsolicited. Mails landing in your inbox that you'd rather not get, but which are not unsolicited (say, by you signing up for an account and confirming your address), are not spam by definition . "Almost all…

Most email I get from services is unsolicited. While I did sign up for the services I did not solicit every newsletter, marketing email, "notification" and so on. For 98% percent of services I use I mainly want my email for one thing: a way to reset my password. Often I need to unsubscribe from each of them individually and then navigate some sort of "notification preferences" interface. Even after that has been done…

Yes you did. When you open a relationship with a company (by signing up to use their services), they are allowed to market to you, send you newsletters, and so forth, until such time as you terminate that relationship.

It isn't spam because you don't want it. If you actually don't want it, then click 'unsubscribe' - and if they continue to bother you afterwards (which, FWIW, I've seen a reputable company do a grand total of once in years), then and only then, is it spam.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#77

Earlier quoted context omitted.

> almost all companies will spam your email address, even if you check the box asking them not to. I find this very hard to believe. "Spam" has a specific definition; the most important bit of which is that it is unsolicited. Mails landing in your inbox that you'd rather not get, but which are not unsolicited (say, by you signing up for an account and confirming your address), are not spam by definition . "Almost all…

As a user, I don't at all care about the technical/legal definition of spam. As with obscenity spam is a case of "I know it when I see it".

[deleted]

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#78
post #11

From a service provider's point of view [1], a big portion of "users" with disposable email domains have intention to do bad things, e.g., spamming, aggressively scraping contents... It's not easy to distinguish users-who-want-to-try-out-then-never come-back from users-who-want-to-do-bad-things-to-your-service. Typically, online service provider may have empathy towards users with whatever emails, including disposabl…

> From a service provider's point of view [1], a big portion of "users" with disposable email domains have intention to do bad things, e.g., spamming From a service user’s point of view, a big portion of “services” that demand their real email address have intention to do bad things, e.g. spamming

Fine, you don't have to provide your real email and can use a forwarding service. I'm gonna need you to verify your non-voip phone number, submit a picture of your government issued ID and a photo of yourself in a specific random pose as a liveliness check, or register a valid credit card in order to activate your account.

Services use emails from well-known providers specifically because they're "good enough" signal in terms of spam/bot avoidance. It's not like the need for those signals go away and "real emails" are one of the most privacy preserving because they're pseudoanonymous. The alternative is Real Name policies.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#79

Earlier quoted context omitted.

> people use disposable email addresses all the time to avoid paying for our product. From the prospective subscriber’s perspective, that’s your problem to worry about — not theirs. > We don’t sell any data. How should users know that? It’s also not just a matter of selling data — almost all companies will spam your email address, even if you check the box asking them not to.

> almost all companies will spam your email address, even if you check the box asking them not to. I find this very hard to believe. "Spam" has a specific definition; the most important bit of which is that it is unsolicited. Mails landing in your inbox that you'd rather not get, but which are not unsolicited (say, by you signing up for an account and confirming your address), are not spam by definition . "Almost all…

> Mails landing in your inbox that you'd rather not get, but which are not unsolicited (say, by you signing up for an account and confirming your address),

This itself is a redefinition of “spam” to exclude the types of spam businesses want to send.

There’s a two-part test I use to define “spam”, which I think is aligned with both the historic definition, and how most users perceive it:

1) An e-mail is a marketing e-mail if, on the balance, the e-mail primarily benefits the sender, not the recipient.

2) A marketing e-mail is spam if the user did not explicitly opt-in to receiving them.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#80

Earlier quoted context omitted.

And how would you protect your service from users that just sign up with disposable Emails for the 7 day trial over and over again?

> just sign up with disposable Emails for the 7 day trial over and over again? That's a lot of effort to go through to avoid paying for something. And I guess you can't keep your data or configuration, if the app has any.

That happens quite frequently to our SaaS where people need free access to a new API key. We try to block multiple registrations but there are people who also invest into proxies to circumvent this protection...
Post reply on HN