Remix.run Logo
jb1991 7 hours ago

One thing I have never understood in this current age is how in the world so many companies, including ones that handle confidential data like banks, don’t require a user to verify their email address after it’s entered. I have an unfortunately very generic email address that’s easy to mistype, and I am almost every day receiving order receipts for expensive vacation hotels, bank transfer or wire transfer confirmations, a very long list of things that I should not be receiving simply because the companies sending those emails never had the user verify if they entered the right email address. They are legitimate emails, they are often addressed to someone with the same first name as me but a different last name, so that person simply typed the wrong email address accidentally.

It’s bonkers to me that there’s any developers out there working for these companies that never thought to implement simple email verification.

letier 7 hours ago | parent | next [-]

I have a very early gmail address. A very common first name plus two letters. It is almost unusable by now. Invoices, subscriptions, important documents about some persons real estate dealings. They all end up in my inbox.

I have around 20 or 30 google accounts attached where i am the backup email address. Those people forget their passwords or stop using their accounts and i get email notifications about that. No confirmation from my side necessary.

I set up a new address that is less likely to end up with this problem. But migrating away from the old one is not easy…

deltoidmaximus 9 minutes ago | parent | next [-]

> I have around 20 or 30 google accounts attached where i am the backup email address. Those people forget their passwords or stop using their accounts and i get email notifications about that. No confirmation from my side necessary.

Does google not require a verification when you setup a backup email address?!

pixelesque 7 hours ago | parent | prev [-]

Exactly the same situation with me in terms of gmail address (although my names are less common).

I get so many other $MY_NAME emails, including bills (including multiple credit cards and things like Afterpay), deliveries, medical details/reports, family communications, etc, etc.

And it's very clear that quite a few online services blatantly don't verify email addresses, they just assume the email is valid and allow the person to start using it.

xmcqdpt2 2 hours ago | parent | prev | next [-]

As is often repeated, the optimal amount of fraud is not zero

https://www.bitsaboutmoney.com/archive/optimal-amount-of-fra...

They are optimizing towards making it easy to purchase things on a whim.

Gigachad 7 hours ago | parent | prev | next [-]

Because confirming the email introduces friction. And everyone is optimising for low friction even if it risks private data leaks, which you can always blame on the user for typing their email wrong.

pprotas 7 hours ago | parent | prev | next [-]

This is intentional. Email verification is friction, so it gives users a chance to reconsider whether their purchase is really necessary. This is bad for business, because they’d prefer if you were impulsive.

Also, people usually type their emails correctly, especially these days with auto-fill. So not sending confirmation emails is optimizing for the happy path.

jb1991 7 hours ago | parent [-]

Not just talking about purchases. I receive transaction details with bank numbers for wire transfers around the world. It’s ridiculous.

I was once even sent all of the legal proceedings for a court case by a lawyer who was sent to the wrong address.

wodenokoto 7 hours ago | parent | prev | next [-]

I know e-mail has a faster round-trip, but they also don't ask you to confirm snail mail.

I think it would be quite annoying to have to verify my purchase everywhere, just like how I don't wanna sign up to every single merchant online. Let me purchase as guest without having to enter OTPs.

withinboredom 32 minutes ago | parent [-]

Email isn't guaranteed to have a faster round-trip. https://groups.io/email-provider-status -- sometimes goes into hours of latency.

plagiarist 7 hours ago | parent | prev | next [-]

I am dismayed that it is legal to create an account attached to an email without validation of that email. It should be straight-up massive fine illegal to send any email other than account confirmation until validated. Validation emails should have a "do not contact me again" that works with a single click and a massive fine if it does not.

nobodywillobsrv 7 hours ago | parent | prev | next [-]

Yes it is insane. I am in same boat and have received mortgage applications, police details, applications for police jobs, massage receipts you name it. Many would be considered important leaks of customer data.

I have even had founder level emails that presumably are confidential sent to me because I share the name of someone operating in tech.

I respond or report when it's obviously some real person running a small group but for large monoliths there is very little to do except quickly reply to corporate email.

Really wish there was some kind of high level discussion about building something for this specific problem of non malicious wrong person same name errors.

Google could do it it's just not something that is monetizable at a scale they care about IMO and I have not been able to think of a way to make this work operating outside of email monoliths.

Would love to hear if anyone has ideas.

jb1991 7 hours ago | parent | next [-]

Commend your effort to actually contact the companies to let them know the error. I stopped doing that a long time ago when I stopped getting response or stopped getting any kind of meaningful reaction that I was actually trying to do something good by reporting it.

fragmede 7 hours ago | parent | prev [-]

What Google has done, is add profile pictures for users, so if I'm emailing girlfriend@gmail.com I get her picture, but if I email giirlfriend@gmail.com, I see someone else's pfp which is enough to get me to realize I've spelled it wrong. I'm sure there's more they could be doing, but they're aware of the problem at least.

jb1991 6 hours ago | parent [-]

But that only works if you’re emailing from another Gmail account yes?

annie511266728 7 hours ago | parent | prev [-]

[dead]