Remix.run Logo
YesThatTom2 a day ago

> This change does not affect Google Workspace aliases or other Gmail addresses you own.

I bet most people complaining about this change don’t even know this feature exists.

Right now you can forge email from any email address you can verify ownership.

Most of those emails will end up in a spam folder.

This doesn’t affect email addresses that Google controls DMARC records for.

john_strinlai a day ago | parent | next [-]

>Right now you can forge email from any email address you can verify ownership.

how can you "forge" something if you verify ownership? when you own something, it's not "forging" to use it.

i think the point you're trying to get at is that the mail might fail dmarc requirements?

paxys a day ago | parent [-]

Because ownership can change. I can still use Gmail to send email from my old university address that I lost access to 15+ years ago. This should not be possible.

john_strinlai a day ago | parent [-]

if the mail from that address is being delivered to mailboxes, that's your universities fault.

if it's not (i.e. spf & dkim is failing), that's just how email works and is not unique to gmail.

paxys a day ago | parent [-]

Cool try explaining any of these terms to the average sysadmin.

Email security is hopelessly broken, and the best you can do is try to limit exposure. Removing Gmail as an attack vector is one of those decisions.

john_strinlai a day ago | parent | next [-]

>Cool try explaining any of these terms to the average sysadmin.

if someone is managing a mail system and doesn't know what spf is, they should be immediately fired.

i am also not convinced this will remove or limit exposure to anything. the attack vector lives in the protocol, not the service used.

this might end up as a tiny, tiny blip in some small percentage of spammer/phisher operations.

icedchai a day ago | parent | prev [-]

Yep, SMTP itself doesn't have any security.

Anyone else remember the open SMTP relays of the 90's?

picofarad a day ago | parent [-]

One could use aol's smtp servers to send mail as clinton@whitehouse.gov

PokeyCat a day ago | parent | prev | next [-]

Isn't this just using SMTP through whatever mail server you have connected to Gmail?

Either way, this is likely going to stop me from using Gmail as my mail aggregator, I've used this feature for nearly a decade to send and receive from 6 different addresses, Gmail recognizes the to address and automatically sets the from address to the correct account.

Is Thunderbird still decent nowadays? What's a decent mobile + desktop replacement?

advisedwang a day ago | parent [-]

No, Gmail directly sends the email from their own SMTP servers (you have to set up SPF to allow them etc)

tclancy a day ago | parent | prev | next [-]

> Right now you can forge email from any email address you can verify ownership

I find this sentence confusing. Do you mean “forge” in a technical sense of “this email came from a server unassociated with the domain”? I don’t really get it. I’ve know this feature existed in Gmail for 15+ years and have made regular use of it. Plus I’ve used it to help older relatives keep an old address alive.

healsdata a day ago | parent | prev [-]

What an odd choice of inflammatory language for a feature that uses standard email headers. It doesn't forge anything since it clearly says it was sent from the GMail account on behalf of the other email address in the headers.