Live data from Hacker News

Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

github.com

271–280 of 304 posts

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#271

Earlier quoted context omitted.

I started the repo and have nothing to do with Google.

There are 2 members in the disposable-email-domains organization on GitHub.[1] You (martenson) are one of them. The other member (di), who is a "core maintainer" of the project according to the README changelog,[2] is also a member of the Google organization on GitHub.[3] di describes himself as part of the "@google open source security team"[3] and the website linked from his profile says that he is "a Developer Adv…

Thanks for summing it up. All of this is correct afaik. What I wanted to respond to was the implication that Google is somehow part of this. It is not. This project started before Dustin joined Google open source and was already couple of years old when Dustin himself joined.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#272
post #268

Earlier quoted context omitted.

> Gmail .. should be on the list as well, because creating email addresses there is so quick and easy GMail does antispasm. It’s easy to create a disposable gmail, but it is much harder (I supposed) to use that address for outgoing spam/fraud/etc.

(I'm an engineer on Relay.) Relay has anti-abuse protections too, which is why it was removed from a similar list: https://github.com/wesbos/burner-email-providers/pull/339

Thanks for this info.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#273
post #268

Earlier quoted context omitted.

(I'm an engineer on Relay.) Relay has anti-abuse protections too, which is why it was removed from a similar list: https://github.com/wesbos/burner-email-providers/pull/339

Thanks for this info.

Thanks for adding it to the issue!

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#275
One thing I learned operating a payment processor for a decade is that by far the email domains of choice for people trying to do evil were big free email providers like google, ms, yahoo and so on. A few operators would use something like mailinator (the kind of thing that is being blocked here). By evil I mean everything from attempting to hack us and our users, to financial fraud, to just trying to get a merchant account after being blacklisted by Visa.

A lot of the logic I see in replies here is that people use services like mailinator to abuse free trials. I think this is also the logic for blocking or stripping RFC 2822 email addresses (something+somethingelse@gmail.com). On the RFC 2822 stripping / blocking, you are just breaking the internet. Disposable emails seem like a problem, but I suspect the trend is towards more "private" email forwarders like Mozilla's relay, Indeed's private emails and iCloud's hide my email.

If you are having problems with free tier abuse, one small thought... This isn't universally applicable advice... but it may be helpful. If having an account on your service does not accrete value for the user, the user will be ok with abandoning the account and starting from scratch to get free service. If it is not possible to accrete value, you may have a product that is not a good fit for the freemium model. Try alternative models. You may find you are leaving money on the table.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#276

Earlier quoted context omitted.

Your free trial is too generous. Suggest using the Standard plan but with significant rate limiting. Like 5/day. If they want to remove that, enter credit card details which you verify. You can still have the trial expire and the credit card isn't ever charged; but you can track people on trials more easily.

> You can still have the trial expire and the credit card isn't ever charged; but you can track people on trials more easily. I think that someone who doesn't want to give their real email address to try out a service is even less likely to trust an unknown service with their credit card number. There are just too many "free trials" that promise to not charge your credit card and then make you jump all sorts of hurdl…

> I think that someone who doesn't want to give their real email address to try out a service is even less likely to trust an unknown service with their credit card number.

I think you'd be surprised. Credit cards are easier to dispose of then email addresses, and they offer greater protection with fraud and billing dispute processes. Some banks even offer virtual cards that let you set limits on duration or amount.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#277

Earlier quoted context omitted.

> I’m the founder of a small bootstrapped SAAS and people use disposable email addresses all the time to avoid paying for our product. So, make it worthwhile to pay for the product.

that's not really how it works. If you create something and unless you license it permissively that product is yours and you get to set the terms and conditions. If it is now mainstream to basically feel you're entitled on setting the terms for other businesses or stealing their software then nobody needs to complain when any email relay service gets just blacklisted. If people now think it's okay to abuse multiple a…

> that's not really how it works. If you create something and unless you license it permissively that product is yours and you get to set the terms and conditions.

It's exactly how it works, if you want to succeed. If you don't offer value that enough people are willing to pay, you still own the product, but it's worthless.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#278

Earlier quoted context omitted.

I've just started marking these as spam. Not worth my time to go through their unsubscribe flow so they can try to trick me into not actually unsubscribing

I think that's completely appropriate. Any unwanted email is spam. I hate to admit this, but we send a lot of email like this at work, and I always get tickets like "all of our email is being marked as spam, can you fix DNS?" Usually it is a DNS issue (people add email senders without setting up Spam Permitted From and DKIM), but nobody will address the elephant in the room that maybe users don't want to read our mar…

Ha! At a previous company the marketing people swore that our mail setup was miss configured because very often people from the mkting team would get their gmail work account blocked for spam.

They were linking their accounts to use some spammy marketing software to mass send "campaigns ".

Marketing should be forbidden.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#279
post #73
post #38

Earlier quoted context omitted.

But why would having a "valid" email address help you more getting payment? At most you may send reminders, but even then, those may end up in a spambox? Even once you've verified the email, you have not much of a guarantee it will stay verified/working long. That's more the subscriber's problem, if they want to continue to use your product.

It's easier to create many disposable email addresses than "real" email. To get a new "real" email address, you need to fill a lengthy form (e.g., try it on Gmail.com now) and it's not easy to automate the process. But it takes only one-click to create a new disposable email address. Some disposable email providers also provide APIs, so you can create addresses in batch. People may exploit paid services by creating m…

> It's easier to create many disposable email addresses than "real" email.

The difference between real and disposable is manufactured. A novice could register a domain, sign up for email hosting, and set up a catch all for cheap.

Re: Mozilla's Firefox Relay to be added to disposable-email-domains blacklist

#280

Earlier quoted context omitted.

> I can see my opinion on this matter isn't a common one on HN. Your opinion isn’t common among anyone other than marketers trying to justify sending spam.

..And people who spend a lot of time fighting actual spam , as in, actual unsolicited junk email, who have to deal with false positives from uninformed users who think the 'report spam' button is the appropriate response to them getting an Amazon email they don't like. I'm disappointed to see that attitude here.

> false positives

It's not a false positive. The filter needs to be tuned to what your users think is spam, that is what spam filters are for. You are not the gatekeeper of what other people are allowed to think is spam.

Post reply on HN