Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I have had a similar problem for about two decades now in regards to eCards (virtual greeting cards). I own youknowwhat.com and one of my email addresses is youknowwho@youknowwhat...

Turns out that thousands of people every year think they are being super clever by putting my email address in the "From" field. So of course I get zillions of "receipts" for these eCards.

"Sister, I hope you feel better soon"

...is the most popular by far.

I stopped looking at them years ago but there's often some very personal information included and if I were an evil supervillain it would be trivial for me to use a lot of these eCards to blackmail people!

Fortunately for these people there's a highly ethical person at the helm of that email address that filters them all right into the trash.



I get something similar. I was an early adopter of a popular email service, so I managed to get <firstname><lastname>@<emailservice>.com. Pretty neat, pretty simple, right? Except I have a really common name, and people seem think that if the email address has their name in it, it must be their email address. I get sign-ups for Facebook all the time. I get emails about credit scores that make me panic until I realize I didn't sign up for that service. The other day I got an appointment reminder to take my Vauxhall into the shop for service (I live in the US, we don't have Vauxhall here).

Email is hard and confusing for a lot of people. It's easy for us to forget that.


I'm amazed how many people get their email address wrong. I have <firstname>.<lastname>@gmail.com, which is fine, and hardly gets any mail meant for someone else. <firstletter><lastname>@gmail.com however, is basically unusable. Funny thing is, the latter was the one I created first, but I forgot the password so had to create the other. I managed to recover it later and I'm glad I have the former.


I have a <firstletter><lastname>@gmail.com and I get everything from online shopping receipts to legal notices. You'd be amazed at just how uninterested a law firm is in knowing they just sent a bunch of legal correspondence to someone who isn't their client.


Sort of off topic, but did you know that the '.' gets ignored in gmail addresses, you can remove it or add extras and you will still get the email.


And you can also interchange `gmail` and `googlemail`, append `+anything` to alias.

It's a slippery slope though - forget worrying about remembering or managing passwords, you have to deal with variations of an email address too.

Further, email clients will reply from whatever address you used to setup the client. Maybe you can add aliases, but that will be time-consuming, and even where supported there's usually a single-digit limit. This can cause real headaches - e.g. "reply with `UNSUBSCRIBE` in the subject line to be removed from this list" and being unable to reply from the right email address.


This is true in general, but some of the very early Gmail addresses do differentiate based on the '.'

For instance, my very early-adopter Gmail address has a '.' in the address but it is an entirely different account from the one without. If you send mail to the one without the '.' I do not receive it.


God I love edge cases / grandfathering


I have <lastname>@gmail.com because I'm an early adopter (TM). My mailbox is almost unusable.


I've got my nick doubled as gmail account. Guess how many stray mails in moonspeak I get on a regular basis from China, Brazil and other weirdo locales?


I have a <firstletter><lastname>, my lastname is very uncommon but it turns out that someone in another country has the same first name and last name and you can get my email by googling my name. So, I have received few emails for him and kindly replied that I wasn't him.


I have a very uncommon name (3 of us in the country, as far as I can tell), and this happened to me for the first time this weekend. Someone bought a stereo at Best Buy 500 miles from me and gave them my email (<firstname><lastname>@gmail.com) for the Geek Squad protection plan. I thought someone had stolen my credit card until I realized what happened.


I have something of a young name which is also uncommon, not many people over 30 with it, when I was young I googled my full name and got only one result, today when I google myself I find a ton of people who are usually my age or younger.

There aren't a lot of people who are using my email, one is an older folk who uses it, and I always mean to contact him, and one was a DJ which accidentally used my email address instead of his.


Someone signed up with my email address on to hotmail and then a couple of months later hit "forgotpassword", attempted changing the password multiple times, then got in and changed the email address. I got so sick and worried that I got hacked. Turns out they selected the wrong email address when signing for hotmail, and then changed the address to the correct one.

it threw me in circles.


Yup :(

My email is <first name><middle initial>@gmail.com (six characters total) and I get about 1-1.5 misdirected emails per day. Receipts, phone bills, homework, meeting minutes, personal messages that someone passed away, angry email from a homeowner to his general contractor (in Botswana), and even a international love letter.

It's quite annoying, but the worst is sites that make it very hard to unsubscribe, or don't understand that it's possible for someone to enter an email address that doesn't belong to them in a form. In one case (a bank), I actually had to call customer service on the phone to get them to disassociate my email address with someone's account.

In the case of the love letter, I thought I should reply to say that the intended recipient didn't get the message, but when I did, the sender got really confused and didn't understand that she had mis-typed the address.


Good thing you're not sucked into the systems of UPS. They refuse to talk to anyone not the sender or receiver.

I've got an annual delivery of an expensive watch in my inbox like clockwork every year.


I have <firstname>@alum.wellknownuniversity.edu. Apparently I was early on in getting an alumni forwarding address. It hasn't happened in a while but I used to regularly get emails for other people--including, for a time, board meeting notices and info for some company or other. (I did send a reply to the effect that maybe they shouldn't be sending these to me but never got a response.)


Relevant xkcd: https://xkcd.com/1279/


I have the same problem with gmail. 90% of the email I get to my gmail account is for someone else.

I'd stop using that account in a second, except I bought ~$100 worth of Android apps over the years using that email address and last time I looked I couldn't transfer them to a new account.


The English NHS has a similar problem.

firstname.lastname AT nhs dot net

Or firstname.lastnameNUMBER if there's more than one person with your name.

Since the NHS is one of the largest employers in the world you'll find things like john.doe58@

It sucks.


Sounds similar to the problems test.com endures.

http://contactx.test.com/contactX/contact-spam.cfm


It's a surprisingly hard task to educate developers and testers to use the designated test domains (example.com and example.org) in automated or manual tests.


A friend and ex co-worker of mine, at our first job, had to write some code to send emails. Not knowing any better, he ran his manual tests using a clearly non existent email address, just a combination of letters. Or, so he thought: he soon received an email from said combination of letters, begging him to please stop spamming.


I thought the TLD test was meant for this, like mydomain.test.


The relevant RFC lists a couple of options. .test as TLD is valid as well


According to RFC 2606:

> ".example" is recommended for use in documentation or as examples.

Using example.[com|org] for testing feels like shoehorning. I wish IANA had reserved test.com, because that's what feels right when testing.


If you prefer .test then by all means do so. The whole TLD is restricted for that use. Some TLD also have dedicated test domains, any of those is perfectly fine - test.com (or test.de) for that matter is not.


.test TLD is reserved for this kind of testing situations.


Surely example.com has these problems too, although to be fair they don't really need to receive any email.


example.com does not receive e-mail. It is specifically set aside (along with example.{net,org} and a few TLDs) for testing:

https://tools.ietf.org/html/rfc2606


example.com has an empty MX record, so you can't really send email to it anyway.


I believe SMTP attempts delivery to the A record if there is no MX record.


Indeed, if no MX record is known, but an A record is, mail will be sent to that host. However, example.(com,org) are designated testing domains by RFC and any self-respecting mail server should know not to forward mails there. And on top of that, since the domains are designated testing domains, they do not accept mails.


The right thing to do in this situation is to use RFC 7505[1] (Null MX Records).

[1] https://2rfc.net/7505


Cool, didn't know that. Thanks for teaching me something today.


“Empty”? It does not have an MX record.


You're right; I must have misread the dig output. I thought it showed an MX record with no hostname, but that was probably the question section.


Interesting they don't seem to have SPF/DMARC configured properly. That would probably get rid of most spam, at least at major providers.

After setting up a DMARC reporting address for my own domain I was surprised at the amount of emails supposedly from my addresses that are getting rejected, mostly by gmail and yahoo.


The worst for me, is when I get account creation notifications for a given site, and can't even contact anyone to correct it, etc... For a few months, I was getting student loan account notices for someone else, but not enough PII to actually contact them, and layers of crap and people unable to fix it contacting the company in question.

I'm not getting rid of my gmail address... mine ... though I do have another address I use, and may start using that one more once I move the email hosting (on my todo list for over a year).


I've had that experience tons of times, where companies are happy to unsubscribe me if I just give them the account number that I don't have because I'm not their customer.

On the other hand, I was getting Allstate billing notices for someone else and I was surprised how well they handled it. When I called, they understood that I was a third party and apologized. They were able to look at a record of all the email sent and verify I had not received any sensitive information (only last 4 digits of account number, first name, and bill total). They removed my email address and said they would contact their customer immediately.

The only way they could have handled it better would have been following best practices and sending a verification link as their first email. :)


I started getting DirecTV bills with some random person's name on them that I don't recognize (but with my street address). This weekend I also received an overnight fedex with my address, an apartment number, and someone else's name (I don't live in an apartment).

Turns out people don't know their actual physical addresses either any more.


> Turns out people don't know their actual physical addresses either any more.

Just move countries and cities often enough, and throw some business travel in for good measure, and it's pretty easy for that to happen. I've e.g. had similar sounding zip codes in a variety of cities and countries, and nearly the same street name within a city. After a while you start to very easily make mistakes.


Kind of a pain in the ass to do retroactively, but one approach to prevent this to have your email address be random gibberish.

Whereas "firstname.lastname@example.com" (or more likely gmail.com) can be arrived at by multiple people named "Firstname Lastname", you don't have to worry about it if your email address is generated via:

    echo "$(< /dev/urandom tr -dc a-z0-9 | head -c 12)@example.com"


Yes, then every time I need to give someone my email in person or over the phone I just need to say "it's two zed six bee oh, sorry, zero, you ess eight see why you are at example dot com". And then they're going to read it back to me and pretty much invariably have something incorrect. And then I'll have to read it to them again.

You'd be better off taking an "xkcd" or "gfycat" approach and making your e-mail "correcthorsebattery@example.com" or "ableorganicanchovy@example.com".


How often are you verbally giving your email over the phone that this an issue? Unless you're ordering daily from the Home Shopping Network and want to get an email receipt, what's the big deal? In my experience either I'm entering my email in a web page form or texting it to the other person.


Or you could write a bot that auto-publishes parts of the eCard emails you get to e.g. twitter. Would be interesting for the rest of us :)


I have a very similar problem! I own a very short domain name, with letters that appear exclusively on the home row of the US layout keyboard. It accepts emails at the wildcard address, *@<my domain>, so I get a looooot of email from people signing up to services by hammering the home row of their keyboard randomly, with a dot in the middle.


Those e-card providers should of course do some rudimentary sender e-mail verification.


I get loads of verification emails too. eCard sites don't usually require email validation but that doesn't stop them from trying!




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: