Rendered at 22:20:55 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
dmd 14 minutes ago [-]
I get this sort of thing constantly because my domain, 3e.org, which I have had for 30 years, is apparently impossible. It's either too short to be real, or starts with a number (obviously impossible).
And like the author, 90% of the time I can just disable their front-end validation and go on my merry way.
dutchCourage 1 minutes ago [-]
Since the author asked about Alice: it was an Internet provider in France in the early 2000's.
Some domains in that list are truly ancient. That was a trip down memory lane.
qingcharles 8 minutes ago [-]
I use a .one for a project where it makes perfect sense. Brevo, who are a huge email delivery platform, told me they don't support signing up with a .one domain. Fortunately, after a couple of weeks going back-and-forth one of their developers eventually saw sense and fixed it.
Sadly, with Google, I don't think you'll ever get the issue that far up the chain.
ivan_gammel 18 minutes ago [-]
Smells like „product engineering“. So a product or an engineering lead gets a task to reduce risks of specific abuse by preventing someone from sending email from yahoo or web.de clone. As a quick solution they add this filter without „overthinking“ it. The impact is low, a few customers in a million, so its stupidity gets unnoticed and, once first complaint reaches them, quietly deprioritized to death. Removing it is cheap: the justification for taking that work is likely the show stopper. Google is an old large corp that hires and fires at a scale. Owning removal of abuse filter to increase revenue by Planck-sized amount is an impossible thing.
petepete 27 minutes ago [-]
Just wait for someone at Google to read this post and then block the domain retrospectively.
llacb47 18 minutes ago [-]
And ban their entire Google account
qingcharles 8 minutes ago [-]
And delete all their data.
sam_lowry_ 50 minutes ago [-]
The end is really hilarious. Google had a stupid frontend-only validation, it seems.
chmod775 15 minutes ago [-]
Since Google themselves claim that's a security check, there's a bug bounty here.
The author of that article missed their chance making Google eat their words.
cube00 35 minutes ago [-]
If you could just change your company's domain name that'd be swell!
Surprising Google is happy to lose a paying company over this.
Although the author is taking quite the risk bypassing Google's validation like that. Not sure I'd be risking my company's workspace to do it in case Google wakes up ban hammer happy one morning.
bonzini 46 minutes ago [-]
alice.it is indeed an email provider's domain; based on the code snippet it seems like they are active in other countries.
alice.app however isn't registered anywhere.
sikozu 44 minutes ago [-]
This was a fun read. Absolutely baffling behaviour from Google.
t0mas88 45 minutes ago [-]
I would hope that somewhere at Google there is a policy that says you can't do anti-fraud and security checks in frontend only...
yieldcrv 5 minutes ago [-]
ooof that's bad, all levels of support missed the frontend validation and blamed you and an opaque non-existent process instead
51 minutes ago [-]
mpalczewski 31 minutes ago [-]
I wonder how this list ended up being created anyway. Was it a long standing issue, or just some ai slop? web.com, web.org, web.net don't look like an email provider.
mh- 20 minutes ago [-]
web.net, at least, absolutely is an email provider.
mpalczewski 18 minutes ago [-]
fair enough. at least not primarily an email provider. so if they offer any email.
And like the author, 90% of the time I can just disable their front-end validation and go on my merry way.
Some domains in that list are truly ancient. That was a trip down memory lane.
Sadly, with Google, I don't think you'll ever get the issue that far up the chain.
The author of that article missed their chance making Google eat their words.
Surprising Google is happy to lose a paying company over this.
Although the author is taking quite the risk bypassing Google's validation like that. Not sure I'd be risking my company's workspace to do it in case Google wakes up ban hammer happy one morning.
alice.app however isn't registered anywhere.