I'm a bit skeptical Google ever treated `fname.lname@gmail.com` and `fnamelname@gmail.com` as different accounts.
I registered the `fname.lname` version very early on (before GMail was freely available), and while I do sometimes get emails sent to the `fnamelname` variant, which is consistent with someone having signed up with that variant, but is also consistent with someone just forgetting what their email address is (eg, they meant to type `fnamelname@hotmail.com`, or `fnamejlname`, or whatever). Especially since the mixups are very, veyr rare.
I can't rule out some weird collection of google bugs, but Occam's Razor suggests it's just an occasional typo. Especially until someone pulls up two screenshots of Google accounts showing colliding addresses.
My Gmail account is old enough that I needed a beta invite from a cooler friend. As a cool kid myself, I registered a name full of punctuation. For decades Google has treated the punctuated and unpunctuated addresses as one and the same. There is no distinct Google account that can be access via one username or the other.
As others said, I also believe this post to be wrong. There is simply no evidence of the double account thing. But as we are all now talking about incorrect gmail mails…
I paid 1.4€ or something on ebay back then for an invite and got a very common first.last@gmail.com, I’ve gotten everything, invoices, investment information, medical data, private photos, etc., though it has been getting better in the last few years, besides boring transactional mails and account recovery etc, I now only get such mails once or twice a year, used to be a monthly occurrence. Probably helped that I always wrote back and corrected those people ;)
I’ve been using Gmail since the first day it became available back in April 2004. I have firstname@gmail.com. My name is two syllables, and I specifically remember using another invite to try to register first.name@gmail.com. Google wouldn’t let me because it said the address was already registered.
I’m pretty sure the ignore the dot rule has always been there.
As others said, this post is wrong. I’m another owner of first.last/firstlast since 2004. There was never a period where Google got the dots wrong.
People will forget their middle initial in their email (or others won’t notice it), or they’ll add firstlast as a recovery email or something.
Receiving other people’s email never stops being funny to me. Some of them are grumpy about it (especially the one who paid for and distributed “thousands” of poorly designed business cards.)
More have a sense of humor, and I’ve enjoyed getting to know a few of the other guys with the name over the years.
This reminds me of why I'm very nervous I've been able to login to LinkedIn by just click an email LinkedIn sent me; and to someone else's Netflix account from an email that was sent to me by mistake.
You _could_ blame the users for not setting up 2FA. But two wrongs don't make a right, and these websites should always ask for another means of authentication, even if it's just a password. Url parameters in links don't count.
I have had first.last since the beta data and firstlast always comes to me when I test it out.
could it be that something changed after the beta? but something also changed much more recently I'm sure of it because it's become a huge problem for me recently!
people are using my email as their recovery email which I have no option to 'unsubscribe' from. someone signed up with chime (a US money sending service) which unless your in the US there is absolutely no way to contact them about removing your email. I ended up going through the bug bounty programme as a last resort because I was receiving all their transactions and even had their address! I've had graduation photos, blood test results, shipping confirmations, beautician appointments, wedding planning (I had to email the vicar in the end and let him know I wasn't the bride being rude!) I get emails from a primary school and I'm invested in the receipts from a garden centre every few weeks though, they have quite a few rewards points now, they're working on their lawn at the moment and the other month they bought two jellycats!
At first I thought it might be someone whose email was at ymail.com but I'm not sure anymore it seems it's not linked to any one country or person either.
Yeah people sometimes set the recovery email. I always assume it’s an attempt at setting up some kind of trail relating their fraudulent account with mine in an effort to take it over through some later social engineering attack on an engineer somewhere and I always delink it.
There shall be none but mine on mine. I have received since day one, 2005 emails at my address meant for others. Their pay stubs, their tax forms, the prospectus for the apartments they want. If I feel like it, I warn them. If I don’t, it goes to the ether. That’s life.
Sucks that you won’t get your loan. Or notice that your bank needs you to fill in a form.
I appreciate your reference to RFC-5321. I agree that "the local-part MUST be interpreted and assigned semantics only by the host specified in the domain part of the address."
However, in practice, there exist many services which have GMail's logic baked-in. Or worse, they get overzealous/underzealous with validating the email.
For example, you decide to sign up for e.g. Netflix as alice@gmail.com, which is the address for a Google account which you own completely.
There exists a small edge case where you want a second Netflix account, so you could do that by also registering alice+netflix@gmail.com. Or a.l.i.c.e@gmail.com. In that case, all the emails to these 2 addresses will be directed to the 'main' alice@gmail.com, as you might be aware of. So you'll get messages for more than one, separate Netflix accounts on the same inbox.
I'm not sure if they had this "plus aliasing" from the beginning, same as their logic with the dots.
When I say that there exist many services which have GMail's logic baked-in, I mean that certain apps will forbid you from registering again as alice+asdf@gmail.com or even a.l.i.c.e@gmail.com, because they want to stop on person from 'exploiting' multiple accounts (though Netflix is not one of them).
It is indeed important to go back to the RFC and understand what you are pointing out:
i.e. That, even though GMail redirects messages from both alice+asdf@gmail.com and a.l.i.c.e@gmail.com to plain old alice@gmail.com, it doesn't make it standard behavior, and this is likely not the case for your home-brewed mail server or your enterprise exchange server, which may treat those as separate inboxes, and this can lead and has led to unintended consequences.
I've been involved in the QA of a system which handles payments for a telecommunications provider. It's very common for the customer to land on a payment page, where he essentially clicks on a link, his telecom's account information is pre-filled, like his email address, phone number, and payment amount, and the customer just has to fill in payment information. So even though the telecoms provider can (and in some instances already has) saved a customer's email with a plus sign, the external payment processor's portal mangles it during parsing, converts the plus signs to a space, and then complains about a malformed URL.
I have a firstname.lastname@gmail account and sometimes get emails for firstnamelastname@gmail too. Mostly, it’s accounts being setup using that address then ending up in my mailbox. I assumed they were typos but, if I’m reading this blog correctly, is Google leaking emails from the other account into mine? If that the case, I’m pretty alarmed, as I use my Gmail for a lot of my accounts. Back to Hotmail, I guess?
I also have a firstname.lastname@gmail address from many years ago and quite often get emails for about five different people (based on the real-world location info in them). It seems that most of these are really sent to firsnamelastnamenumbers@gmail and somehow the number(s) get truncated by the sender, leading to firstnamelastname@gmail which then gets routed to me.
This blog is wrong. Other Sean Conners are to blame for not knowing their own email address. I know this because every other first initial j, last name chaney on this planet is a moron. I get Jennifer's receipts, Justin's bills, John's rent-2-own upcoming bill notifications, and hundreds more. Please. Make. It. Stop.
I have also been getting email in my Gmail account which are clearly unrelated to me. Some are very sensitive, related to bank account and mortgage. Tried letting google know with no success.
You can have a space in an email address. On a project I was working on at a company I was at in 2003, I had to fix our support for that a number of times because that's what one of our customers had.
I experienced this periodically on my gmail and always assumed that it was just a typo on the part of the sender, adding a period where there shouldn't be one. But there were cases that kind of defied plausibility, like when a recruiter (sharing my name but not my gmail address) sent out a mass cold email and I got the angry replies. I never figured out how that one happened, maybe they misconfigured their mailer software's replyto?
I never once considered that a gmail bug or intentional design decision could be at work there. TIL that they decided to cut down on the confusion by normalizing addresses.
I remember IBMs domain system being particularly well designed to ensure emails didnt go to the right place.
I used to cop a lot of emails intended for first.last@ca.ibm.com to first.last@au.ibm.com.
Senders got lazy, selecting the top most user alphabetically from the list, and then I popped up and just... never changed their behavior or habits.
Would have been less concerned if the canuck version of me wasn't embedded in like a bank or something, and I was embedded with a completely different customer account.
Took it to management when I got "Hey are we good for the firewall to come down ahead of the pentest to <bank> next week" and they did nothing about it lmao.
I'm a bit skeptical Google ever treated `fname.lname@gmail.com` and `fnamelname@gmail.com` as different accounts.
I registered the `fname.lname` version very early on (before GMail was freely available), and while I do sometimes get emails sent to the `fnamelname` variant, which is consistent with someone having signed up with that variant, but is also consistent with someone just forgetting what their email address is (eg, they meant to type `fnamelname@hotmail.com`, or `fnamejlname`, or whatever). Especially since the mixups are very, veyr rare.
I can't rule out some weird collection of google bugs, but Occam's Razor suggests it's just an occasional typo. Especially until someone pulls up two screenshots of Google accounts showing colliding addresses.
My Gmail account is old enough that I needed a beta invite from a cooler friend. As a cool kid myself, I registered a name full of punctuation. For decades Google has treated the punctuated and unpunctuated addresses as one and the same. There is no distinct Google account that can be access via one username or the other.
Both this post and the quoted one seem to be confused. Adding periods to a Gmail address never ever, since day one, went to a different mailbox.
I would like to see some of the evidence that two different people are logging in to accounts that are only different by periods.
As others said, I also believe this post to be wrong. There is simply no evidence of the double account thing. But as we are all now talking about incorrect gmail mails…
I paid 1.4€ or something on ebay back then for an invite and got a very common first.last@gmail.com, I’ve gotten everything, invoices, investment information, medical data, private photos, etc., though it has been getting better in the last few years, besides boring transactional mails and account recovery etc, I now only get such mails once or twice a year, used to be a monthly occurrence. Probably helped that I always wrote back and corrected those people ;)
I’ve been using Gmail since the first day it became available back in April 2004. I have firstname@gmail.com. My name is two syllables, and I specifically remember using another invite to try to register first.name@gmail.com. Google wouldn’t let me because it said the address was already registered.
I’m pretty sure the ignore the dot rule has always been there.
As others said, this post is wrong. I’m another owner of first.last/firstlast since 2004. There was never a period where Google got the dots wrong.
People will forget their middle initial in their email (or others won’t notice it), or they’ll add firstlast as a recovery email or something.
Receiving other people’s email never stops being funny to me. Some of them are grumpy about it (especially the one who paid for and distributed “thousands” of poorly designed business cards.)
More have a sense of humor, and I’ve enjoyed getting to know a few of the other guys with the name over the years.
This reminds me of why I'm very nervous I've been able to login to LinkedIn by just click an email LinkedIn sent me; and to someone else's Netflix account from an email that was sent to me by mistake.
You _could_ blame the users for not setting up 2FA. But two wrongs don't make a right, and these websites should always ask for another means of authentication, even if it's just a password. Url parameters in links don't count.
I have had first.last since the beta data and firstlast always comes to me when I test it out.
could it be that something changed after the beta? but something also changed much more recently I'm sure of it because it's become a huge problem for me recently!
people are using my email as their recovery email which I have no option to 'unsubscribe' from. someone signed up with chime (a US money sending service) which unless your in the US there is absolutely no way to contact them about removing your email. I ended up going through the bug bounty programme as a last resort because I was receiving all their transactions and even had their address! I've had graduation photos, blood test results, shipping confirmations, beautician appointments, wedding planning (I had to email the vicar in the end and let him know I wasn't the bride being rude!) I get emails from a primary school and I'm invested in the receipts from a garden centre every few weeks though, they have quite a few rewards points now, they're working on their lawn at the moment and the other month they bought two jellycats!
At first I thought it might be someone whose email was at ymail.com but I'm not sure anymore it seems it's not linked to any one country or person either.
Yeah people sometimes set the recovery email. I always assume it’s an attempt at setting up some kind of trail relating their fraudulent account with mine in an effort to take it over through some later social engineering attack on an engineer somewhere and I always delink it.
There shall be none but mine on mine. I have received since day one, 2005 emails at my address meant for others. Their pay stubs, their tax forms, the prospectus for the apartments they want. If I feel like it, I warn them. If I don’t, it goes to the ether. That’s life.
Sucks that you won’t get your loan. Or notice that your bank needs you to fill in a form.
I appreciate your reference to RFC-5321. I agree that "the local-part MUST be interpreted and assigned semantics only by the host specified in the domain part of the address."
However, in practice, there exist many services which have GMail's logic baked-in. Or worse, they get overzealous/underzealous with validating the email.
For example, you decide to sign up for e.g. Netflix as alice@gmail.com, which is the address for a Google account which you own completely.
There exists a small edge case where you want a second Netflix account, so you could do that by also registering alice+netflix@gmail.com. Or a.l.i.c.e@gmail.com. In that case, all the emails to these 2 addresses will be directed to the 'main' alice@gmail.com, as you might be aware of. So you'll get messages for more than one, separate Netflix accounts on the same inbox.
I'm not sure if they had this "plus aliasing" from the beginning, same as their logic with the dots.
When I say that there exist many services which have GMail's logic baked-in, I mean that certain apps will forbid you from registering again as alice+asdf@gmail.com or even a.l.i.c.e@gmail.com, because they want to stop on person from 'exploiting' multiple accounts (though Netflix is not one of them).
It is indeed important to go back to the RFC and understand what you are pointing out:
i.e. That, even though GMail redirects messages from both alice+asdf@gmail.com and a.l.i.c.e@gmail.com to plain old alice@gmail.com, it doesn't make it standard behavior, and this is likely not the case for your home-brewed mail server or your enterprise exchange server, which may treat those as separate inboxes, and this can lead and has led to unintended consequences.
I've been involved in the QA of a system which handles payments for a telecommunications provider. It's very common for the customer to land on a payment page, where he essentially clicks on a link, his telecom's account information is pre-filled, like his email address, phone number, and payment amount, and the customer just has to fill in payment information. So even though the telecoms provider can (and in some instances already has) saved a customer's email with a plus sign, the external payment processor's portal mangles it during parsing, converts the plus signs to a space, and then complains about a malformed URL.
As always, this gets filed as out of scope.
I have a firstname.lastname@gmail account and sometimes get emails for firstnamelastname@gmail too. Mostly, it’s accounts being setup using that address then ending up in my mailbox. I assumed they were typos but, if I’m reading this blog correctly, is Google leaking emails from the other account into mine? If that the case, I’m pretty alarmed, as I use my Gmail for a lot of my accounts. Back to Hotmail, I guess?
I also have a firstname.lastname@gmail address from many years ago and quite often get emails for about five different people (based on the real-world location info in them). It seems that most of these are really sent to firsnamelastnamenumbers@gmail and somehow the number(s) get truncated by the sender, leading to firstnamelastname@gmail which then gets routed to me.
This blog is wrong. Other Sean Conners are to blame for not knowing their own email address. I know this because every other first initial j, last name chaney on this planet is a moron. I get Jennifer's receipts, Justin's bills, John's rent-2-own upcoming bill notifications, and hundreds more. Please. Make. It. Stop.
I have also been getting email in my Gmail account which are clearly unrelated to me. Some are very sensitive, related to bank account and mortgage. Tried letting google know with no success.
You can have a space in an email address. On a project I was working on at a company I was at in 2003, I had to fix our support for that a number of times because that's what one of our customers had.
I experienced this periodically on my gmail and always assumed that it was just a typo on the part of the sender, adding a period where there shouldn't be one. But there were cases that kind of defied plausibility, like when a recruiter (sharing my name but not my gmail address) sent out a mass cold email and I got the angry replies. I never figured out how that one happened, maybe they misconfigured their mailer software's replyto?
I never once considered that a gmail bug or intentional design decision could be at work there. TIL that they decided to cut down on the confusion by normalizing addresses.
I remember IBMs domain system being particularly well designed to ensure emails didnt go to the right place.
I used to cop a lot of emails intended for first.last@ca.ibm.com to first.last@au.ibm.com.
Senders got lazy, selecting the top most user alphabetically from the list, and then I popped up and just... never changed their behavior or habits.
Would have been less concerned if the canuck version of me wasn't embedded in like a bank or something, and I was embedded with a completely different customer account.
Took it to management when I got "Hey are we good for the firewall to come down ahead of the pentest to <bank> next week" and they did nothing about it lmao.