Live data from Hacker News

Don't verify email addresses by sending spam to them

milek7.pl

21–30 of 67 posts

Re: Don't verify email addresses by sending spam to them

#21
There is a procedure common in mail sending where you ALMOST do this. You connect to their mail server, tell it you have a message for them, and wait to see if it rejects you or accepts the message. Then you disconnect without actually sending the message. I wonder if this is some kind of confusion among the devs behind this, or some benefit to really sending the message that I can't think of. Does it contain a tracking pixel or anything?

Re: Don't verify email addresses by sending spam to them

#22

I would make even stronger advice. If you want to verify an email, send me a one-time code with several hours expiry that I have to resubmit through my logged in web identity at your site. It drives me batty that a financial provider (retirement vendor from previous employer) won't seem to let my "paperless" setting remain active. Only because I don't ping their abusive email tracking pixels etc. To me, paperless mea…

To me, paperless means they ATTACH MY STATEMENT TO THE EMAIL. Not signing up to any paperless until they do, none yet have met this bar. The statement is supposed to be a snapshot of the status of the account at a given moment, if you have to open their website to view it they could regenerate it from whatever crap data they have lying around at the given moment. If it can change every time you look at it, it's a quantum statement, it's not a snapshot, it's a vibe. This defeats the entire purpose of getting a statement, I don't know how anyone tolerates this.

Re: Don't verify email addresses by sending spam to them

#23
post #18

I would make even stronger advice. If you want to verify an email, send me a one-time code with several hours expiry that I have to resubmit through my logged in web identity at your site. It drives me batty that a financial provider (retirement vendor from previous employer) won't seem to let my "paperless" setting remain active. Only because I don't ping their abusive email tracking pixels etc. To me, paperless mea…

I really wish you could provide a PGP public key to your bank and have them just email the damn pdf every month.

That'd be nice, but I'd even settle for the plain pdf attached to the email.

Re: Don't verify email addresses by sending spam to them

#24

I just did a signup on a brand new email address and was not able to recreate. No random spam emails reported. Just a normal verification email. It's likely that the email the author received is pure coincidence. Especially if they are using a client that downloads emails in batches. FWIW it looks like their validation email is sent by Customer.IO via Mailgun. Both have squeaky clean service agreements so it's unlike…

Mailgun's validation API, presumably the underpinnings of Pangram's, returns more than a simple yes/no validity. My educated guess is that this is part of figuring out all of those extra fields.

* https://mailgun.com/products/validate/

* https://documentation.mailgun.com/docs/validate/oas/openapi-...

Re: Don't verify email addresses by sending spam to them

#27

I would make even stronger advice. If you want to verify an email, send me a one-time code with several hours expiry that I have to resubmit through my logged in web identity at your site. It drives me batty that a financial provider (retirement vendor from previous employer) won't seem to let my "paperless" setting remain active. Only because I don't ping their abusive email tracking pixels etc. To me, paperless mea…

To me, paperless means they ATTACH MY STATEMENT TO THE EMAIL. Not signing up to any paperless until they do, none yet have met this bar. The statement is supposed to be a snapshot of the status of the account at a given moment, if you have to open their website to view it they could regenerate it from whatever crap data they have lying around at the given moment. If it can change every time you look at it, it's a qua…

Unfortunately for quite a few people in non-Western states with whom I share my email, I now have their paystubs and insurance receipts and so on. They just sent me the email after someone either made an error in data entry or optimistically assumed they have first.last@gmail.com

Re: Don't verify email addresses by sending spam to them

#28

I would make even stronger advice. If you want to verify an email, send me a one-time code with several hours expiry that I have to resubmit through my logged in web identity at your site. It drives me batty that a financial provider (retirement vendor from previous employer) won't seem to let my "paperless" setting remain active. Only because I don't ping their abusive email tracking pixels etc. To me, paperless mea…

To me, paperless means they ATTACH MY STATEMENT TO THE EMAIL. Not signing up to any paperless until they do, none yet have met this bar. The statement is supposed to be a snapshot of the status of the account at a given moment, if you have to open their website to view it they could regenerate it from whatever crap data they have lying around at the given moment. If it can change every time you look at it, it's a qua…

I tolerate it when I get a fixed period statement and can download to review and archive. I don't treat the website as my archive, nor would I treat the email system as my archive. It's just the delivery mechanism.

And they are for the well-defined accounting periods, e.g. monthly or quarterly, not some sort of ephemeral "rollup to time of download". That would drive me mad if they had different periods depending on download timing.

I can't know for certain, but my gut tells me they are just generating PDFs at the same time they perform the general reporting run that also leads to printed statements. And then they have some limited retention history to limit the storage costs.

Re: Don't verify email addresses by sending spam to them

#29
post #23
post #18

Earlier quoted context omitted.

I really wish you could provide a PGP public key to your bank and have them just email the damn pdf every month.

That'd be nice, but I'd even settle for the plain pdf attached to the email.

For things like financial records, I would not want plain PDF in the email. I think it needs encryption for confidentiality.

I am geeky enough to use PGP or S/MIME if they had the option, but I can definitely see how vendors would see this as too fringe with retail customers. I would not like the typical "secure email" which is nothing more than a volatile link back into yet another website.

Re: Don't verify email addresses by sending spam to them

#30
post #6

The idea that they really send spam to validate an email address sounds to insane to be believable. Is it possible that they are somehow leaking the address to actual spammers? For example, they (or the hypothetical email validation SaaS) use an infected email validation library that ex-fills every email supplied to it, or something like this.

Yeah. The abundance of comments that take the article at face value makes me pause. I assumed it was satire.
Post reply on HN