Earlier quoted context omitted.
Please no. I hate services that do this, it takes longer to jump over to email and open a link then to autofill the info with a password manager and click submit.
Password managers should start supporting this flow. Allow the password manager to read your Gmail, or for cloud-based managers log up with an @1password.com email... Not trivial technically, and maybe turning password managers into SSO providers, but that's a lucrative business in itself.
Mozilla's Firefox Relay to be added to disposable-email-domains blacklist
231–240 of 304 posts
Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist
#232Earlier quoted context omitted.
I've just started marking these as spam. Not worth my time to go through their unsubscribe flow so they can try to trick me into not actually unsubscribing
I think that's completely appropriate. Any unwanted email is spam. I hate to admit this, but we send a lot of email like this at work, and I always get tickets like "all of our email is being marked as spam, can you fix DNS?" Usually it is a DNS issue (people add email senders without setting up Spam Permitted From and DKIM), but nobody will address the elephant in the room that maybe users don't want to read our mar…
It's apparently a public feature, since I remember being annoyed by the tabs and disabling them in Gmail preferences.
Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist
#233Earlier quoted context omitted.
No. Apple's "Hide My Email" uses the same `icloud.com` domain as the rest of their email addresses (unless you're using the "Sign-in with Apple" feature which uses `privaterelay.appleid.com`). Blocking `privaterelay.appleid.com` would be kinda pointless since you'd be breaking your "Sign-in with Apple" feature, but if you don't support that feature you could block it (theoretically, one could create a login for SiteA…
Genuinely curious, does anyone actually use an "@icloud.com" address to sign up for anything? I was under the impression that iCloud emails were only used as a FQDN for internal Apple services, but it's been ages since I've had an iCloud account.
Yep! one of my primary email accounts is an iCloud domain. It only gets used for services I know I’ll be using for a long time, or it’s particularly important.
Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist
#234I don'get this list. It just seems to be about being explicitly hostile towards users. Any useful disposable email service will only allow *receiving* emails. As a user this protects me against possible bad actors that for some reason need me to give out my email to them. Any service allowing *sending out* mail from their mailservers will quickly find their mailservers blocked - this is also list based. A common one…
it is. The idea is to prevent users from being able to sign up anonymously, and try a service risk-free. It ensures that a user has something to lose by trying a service (aka, their real email address), in the hopes that said user would not abuse the free-trial, and also to allow the service to send marketing reminders on paying.
I have made it my policy to not sign up to any service that require an email address, if that service does not accept a disposable email address, nor will i pay for such a service.
Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist
#235I wish Google would start offering disposable relay emails that were indistinguishable from their regular ones, since nobody could afford to block all of @gmail.com.
This is obviously distinguishable but you can use the "+" aliases. For example, if you are bob@gmail.com, you can use bob+blah@gmail.com and use that to filter email. The problem is that even though "+" is a perfectly valid character, a lot of services don't accept it.
did you know that the `.` character is also ignored? So you can actually devise a scheme where you put in dots into your email address (unfortunately, it has to be your email address, not any additional suffixes), and bypass these checks and filters.
E.g., youremailaddress@gmail.com is the same as your.email.address@gmail.com
and for some extra fun, you can do both - add a unique set of dots to your email, and also add a `+` suffix, and if the service emails you without the `+` suffix, you know they deliberately filtered it out to spam you.
See https://gmail.googleblog.com/2008/03/2-hidden-ways-to-get-mo... for details on it
Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist
#236The reason disposable email addresses exist and are popular is because services have abused users' trust to not use these emails for shady ad revenue and marketing schemes. It's further compounded by shoddy security that leads to leaks and exposure of people's personal email addresses to pwned compromised lists. People don't want to give up their personal email addresses so that they can be spammed or hacked. Until s…
It’s also a privacy concern. A single email address ties your identity across platforms, which may be convenient, but could potentially be abused.
Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist
#237Earlier quoted context omitted.
Thanks, the first idea is a really good one for our use case. (the other ideas won't work unfortunately) And yes, it is not a meaningful number of people that do so, but over time this is very ugly and frustrating (as it requires manual intervention) and you block the disposable Email provider they used ...
Your free trial is too generous. Suggest using the Standard plan but with significant rate limiting. Like 5/day. If they want to remove that, enter credit card details which you verify. You can still have the trial expire and the credit card isn't ever charged; but you can track people on trials more easily.
I think that someone who doesn't want to give their real email address to try out a service is even less likely to trust an unknown service with their credit card number. There are just too many "free trials" that promise to not charge your credit card and then make you jump all sorts of hurdles (e.g., having to call) to cancel the free trial.
Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist
#238My solution to email spam is a second Gmail account. I use this email to sign up for everything, and it forwards to my main account, but all those emails get auto-archived on receipt. That way if I need a password link or something it’s as easy as checking my “All Mail” folder but I never see any of the spam.
Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist
#239Earlier quoted context omitted.
Out of curiosity, what does your service do and how do you know that these users would've paid for the service otherwise? As in with piracy, the argument is that it hurts sales but it's very difficult to determine whether that is really true.
I can't speak for the OP but free trial period abuse is very common. "Would have paid for the service" vs "Are actively working to use the service without paying for it" are two different things. I worked for a company that had some free tools on the web, with no published API. Those tools were scraped well above the T&C limitations to be mined by other companies. We had a "free forever" account that you could use to…
Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist
#240Earlier quoted context omitted.
I’m the founder of a small bootstrapped SAAS and people use disposable email addresses all the time to avoid paying for our product. We don’t sell any data.
> I’m the founder of a small bootstrapped SAAS and people use disposable email addresses all the time to avoid paying for our product. So, make it worthwhile to pay for the product.
If it is now mainstream to basically feel you're entitled on setting the terms for other businesses or stealing their software then nobody needs to complain when any email relay service gets just blacklisted. If people now think it's okay to abuse multiple accounts to avoid paying for software that they use and that costs money to build then nobody needs to be surprised that everything gets an identity verification.