50 comments

[ 11.8 ms ] story [ 757 ms ] thread
Inferred context: It's the (unverified) email field of a blog comment submission form. gmail.com happens to be the domain that spammers pick most often for their fake email addresses for their spam comments.
Given they accept any input that presumably matches a regex it doesn’t matter which one you choose.

But if you are looking for a new email provider and de-Google your life, I’m pretty with ProtonMail and their other offerings. Also moved my 2FA and Password manager to them, alongside their VPN.

I've been a proton user for a while but have always shied away from their other offerings...feels like too many eggs in one basket to use them for both email and password management (things I consider to be the most critical of all services I use). Vpn as well! Am I being paranoid? It would be nice to not pay for 3 separate services but I have kind of a blockage about it
Fair enough, I get the sentiment about not putting all eggs in 1 basket, but if your choice is between 1 ecosystem (Google / Apple / Proton), I’d argue in favour of Proton. :)
proton has some issues that may or may not be issues for you

- https://stateofsurveillance.org/news/proton-mail-fbi-stop-co...

- http://thoughtportal.org/2025/02/26/proton-mail-says-its-pol...

these people seem more problem free so far https://mail.tutanota.com/login

Frequently when someone mentions Proton on HN the response is along the lines of what you just did.

In the big scheme of things, I’d trust Proton more than Google and other big tech companies even if they aren’t perfect.

I'd still prefer tuta or fastmail. It doesn't matter so much about their privacy stance - competition is good. We don't want proton to become the new Gmail.
Has anyone tried Migadu? I was wondering whether it’d be a good option for if I wanted to use it for my business.
Blog is getting too much spam, so they are restricting posts/comments from Gmail.com addresses.

That's ok, I understand the desire. I also recognize that it's a lazy "fix". I have my own domain and prefer that so I can track compromised sites.

In quasi-related conversation though, in the last year I have encountered 2 "necessary" websites (insurance, and medical form) that would only accept: Gmail, yahoo, outlook, etc addresses!

It's frustrating.

I gave up on reporting spam. Almost all of the spam I get (and I get a lot of it!) comes from Google, Amazon and Microsoft. None of them care much, none of them make reporting easy, and it seems they don't follow up, because the flood of spam never ceases.

They are "too big to fail": few people can afford to just block Google. This is why I am very happy to see people starting to do just that.

Can't be preaching to others about "privacy", or disliking Ads and then at the same time be using a gmail.com address.
Some tiny blog allows comments (which is incredibly weird in 2026). Spambots fill in the email box with fake addresses. Blog lazily just sets up a filter to auto-kill all gmail tagged addresses.

This has nothing to do with Google, Gmail, spam coming from gmail, or using gmail addresses, outside of leaving a comment on this tiny blog. Yet all the other comments seem to presume they do. Are people just upvoting this thinking it says something it doesn't?

I host my own email. I also have a gmail account, that I've had since the beta.

I cannot tell you how many times I have encountered a person that asks for my email and then looked at me confused when it didn't end in gmail, outlook, or something, and then ask me for another email, as if only that would be good enough.

I wanted to take a look at Boomi.com but couldn't sign up with gmail, turned on email forwarding for a parked domain to get past it. Stupid behaviour if you are trying to sell a product.
I own my own domain in the .us TLD, and I've been using it for my email for the past 20 years. When I applied for an "Electronic Travel Authorisation" (ETA) to enter Great Britain earlier this year the app flat-out rejected my email address as invalid.

Usually, when that sort of thing happens, I just choose to take my business elsewhere or use my time in a different way. However it really ups the ante when a nation-state refuses entry based on that category of technical incompetence.

When it comes to nation-state I wouldn't consider this example as technical incompetence. I would bet 99% of people with personal email addresses/personal email servers will "just use my old Gmail instead". I'm pretty certain its easier for nation-state to subpoena Gmail or Yahoo, or probably use direct backdoors that don't even require official subpoena, rather than deal with your own email hosting contraption.
Really? I've never really had this. I occasionally get a "huh, is this right?" in person but even that is rare now. And in the past decade, I've had my email rejected by a form maybe, once? twice?

And most of the confusion in person seems to be down to my choice of TLD: .es and .io (I'm neither from Spain nor the Chagos Archipelago).

Same same. People raise an eyebrow, ensure they got it correctly then they move on.
I get no end of confusion because mine is firstname@firstnamelastname.com. People have told me that isn’t correct.
I wonder if you'd get less confusion from me@firstnamelastname.com
I like to use yourname@myname.tld and people often are certain I'm confused. I have to promise them it will work.
I do this often when corresponding with businesses/companies and I've been asked before if I have a similar business or am in their line of work also...
I have no issues with Hello@firstnamelastname.com.
I have my own domain. I've been asked for my email, to which I replied "myname@foo.bar" and they've replied "myname@foo.bar.com?".

(obviously using a fake domain, I don't own foo.bar)

I had websites state that the address was invalid because I didn't have an MX record, despite it not being an RFC requirment.

Also, a lifetime ago, had Hurricane Electric (https://he.net) refuse to accept a sign-up because... I only had one MX record. I added an additional record pointing the same IP, but they weren't happy.. So I allocated an additional ipv4 address to the same server, just to satisfy them.

It's a losing battle.

You really should have an MX record though. Fallback to A is deprecated and really should have been removed by now.

HE provides professional network services and probably, perhaps even contractually, requires you to have two different ways to reach you. Everyone at that level has quick ways to get in contact with all their business partners, usually a phone number that's active 24/7.

Quoting a dead comment:

>I wish we didn't have to use email at all.

Email has big problems, but contemplate the kind of lovecraftian horror the great minds of silicon valley would replace it with today. Imagine the worst parts of Facebook, Electron, Discord, Windows 11, CloudFlare and TikTok. Secured by Denuvo and the CIA and brought to you by Dollar Shave Club and the Chinese Communist Party.

You'd wish you had email back.

You mean ATProto Spaces?
"Blog flooded in spam" but it has less than 50 comments on all posts generally? Or is it assuming they are deleting or blocking the supposed flood of spam comments that is unbearable enough to block gmail?
That ship has sailed. A far as most are concerned gmail is email. So that is now the reality. Google has successfully, without any resistance, assimilated email and the web.

I run my own mail and I faithfully avoid chrome as much as I can but the ship is long gone over the horizon.

Sad. But so it goes.

I have emails from gmail, hotmail, yahoo and my own domain. Also many browsers. I use Google stuff mostly because it works best. It's sort of how the free market is supposed to work?
Yes, largely, as long as we have all those choices, including using smaller providers and self-hosting email.

The danger is that a small number of businesses will lock others out.

With that attitude, certainly.
When i worked in small ISP, i did some stats on customer accounts (about 2k customers) and only about 10% was @gmail.com. But it was 5 years ago and in EU.
How many web.de and free.fr?
None/negligible. It was ISP in Czechia, about 50% was @seznam.cz, 15% together two smaller local freemails, 10% @gmail.com, 25% individual/unique domains.
What do you use, Fayafox?
bog standard firefox. usability is superior to chromium wrt bookmarking and custom signed extensions are easier to share across systems.
I think the difference between Google's DMARC policy for gmail.com and google.com says it all:

  bcrl@home:~/electronics/vrm/lm5017/test-lm5017-isobuck$ host -t txt _dmarc.gmail.com
  _dmarc.gmail.com descriptive text "v=DMARC1; p=none; sp=quarantine; rua=mailto:mailauth-reports@google.com"

  bcrl@home:~/electronics/vrm/lm5017/test-lm5017-isobuck$ host -t txt _dmarc.google.com
  _dmarc.google.com descriptive text "v=DMARC1; p=reject; rua=mailto:mailauth-reports@google.com"
Wait, wouldn't setting gmail.com to p=reject break anyone using legacy email-forwarding setups and mailing lists?
No. DKIM signatures were designed to work when emails are forwarded. I run a couple of Linux related mailing lists, and the DKIM signature continues to validate specified headers and the body of the email when forwarded or resent via mailing lists. Dealing with that quirk happened a decade ago, and it is why most mailing lists no longer add headers or footers to emails with instructions on how to unsubscribe.
Nice, thanks for the explanation. I haven't run a mailing list in over ten years, so I'm afraid I'm a bit out of date on the setup.
Why not just add extra verification for Gmail addresses?
I don’t use gmail anymore, it just redirect to my custom domain (I use apple mail, but since I own the domain, I can move to anywhere/anytime)
I use a custom domainm professionally. I had a client ask me to “gmail” him some information.
...and who is this?

Random blog dealing with spam problems blocks gmail (the most used email) wholesale?

Not exactly going to stop the world from turning here.

It’s 2026 and someone is genuinely shocked that an unprotected web form gets instantly destroyed by bots.