> I was about to ditch Google completely and head over to Microsoft
That is the obvious thing to do. Don't understand why you even waste time there. You are digging a deeper hole for yourself.
If they cannot even provide proper support for sign up, what will happen when your account gets disabled for no obvious reason, and you potentially lose years of emails?
an0malous [3 hidden]5 mins ago
My business Workspace account got suspended recently, no reason given, can’t even login to contact support. I’m a solo user so I only had one admin account and that was the one locked out. There was just one text field to submit an appeal, so I did. I never got any email confirmation or tracking number for my appeal, it’s been a week now with no contact from Google. This happened about a week after they charged my credit card for the subscription.
I’m now in the process of switching to Fastmail. Google doesn’t give a shit about anything besides for their golden goose, I would encourage everyone to move away from their services before they just screw you with no warning or recourse just because they can.
pnw [3 hidden]5 mins ago
I ditched Google Workspace for Proton earlier this year and haven't looked back. Yes, the Proton apps don't integrate with everything and E2E encrypted data isn't as accessible as the data held in Google apps, but that's a bonus at this point.
Some people understand that there is naunce in the world. This is literally just the view of a single sponsor.
The way everyone gets so up-in-arms about the political views of a person three levels detached from the company is insane.
"Oh no, an individual with different views than me offhandedly mentioned Proton, the horror! I can't possibly differentiate between the views of a company and a separate individual!
Let's go grandstand about canceling our service and discouraging others from signing up because a random person thinks differently than me, and talked about the company."
evulhotdog [3 hidden]5 mins ago
I believe when the views of that person who has influence on the product, and it does not align with the services they say they desire to provide, it’s an issue.
It also can purely be choosing to not support an organization that doesn’t align with your world view. The money in our pockets is the power to change things.
pitched [3 hidden]5 mins ago
If I’m reading this right, it was a failure at due diligence before sponsoring a YouTube channel. That doesn’t sound at all like what you wrote so maybe you could expand on what the controversy was?
an0malous [3 hidden]5 mins ago
I’m also worried that this is just the future of SaaS where everything is a Kafkaesque nightmare of automated processes no one even understands anymore, and even these incidents are lost in so much complexity the businesses either don’t care or don’t even know it’s happening.
EvanAnderson [3 hidden]5 mins ago
That's pretty much the way the work did now if you're dealing with the "right" companies. The future isn't evenly distributed.
phyzome [3 hidden]5 mins ago
Dispute the credit card charge and you might be able to get in touch with someone.
danlugo92 [3 hidden]5 mins ago
I switched over to Zoho, has a lot of the same tools (mail/users/office) but UI is much more tech-y / old-school it e.g. more dense. Gets to the point.
I also use it with my own domain registered outside Zoho, so Zoho cannot actually lock me out of my email ever, only the data they host, though this is true for external domains in Google Workspace also.
dmd [3 hidden]5 mins ago
I get this sort of thing constantly because my domain, 3e.org, which I have had for 30 years, is apparently impossible. It's either too short to be real, or starts with a number (obviously impossible).
And like the author, 90% of the time I can just disable their front-end validation and go on my merry way.
ivan_gammel [3 hidden]5 mins ago
Smells like „product engineering“. So a product or an engineering lead gets a task to reduce risks of specific abuse by preventing someone from sending email from yahoo or web.de clone. As a quick solution they add this filter without „overthinking“ it. The impact is low, a few customers in a million, so its stupidity gets unnoticed and, once first complaint reaches them, quietly deprioritized to death. Removing it is cheap: the justification for taking that work is likely the show stopper. Google is an old large corp that hires and fires at a scale. Owning removal of abuse filter to increase revenue by Planck-sized amount is an impossible thing.
TLDRisk [3 hidden]5 mins ago
> Just for context, this is a premium domain with a very high premium renewal fee, no history of abuse obviously.
The registry premium domains on the new TLDs have several issues. The biggest IMO is a lack of price protection. Non-premium domains at least get the cohort based protection from section 2.10c of the registry agreement.
So, in addition to being treated as a 2nd rate domain, there’s nothing stopping the registry from cranking up the price if a domain gets popular. I don’t think it’s ever happened, but have never found contractual terms that forbid it.
I made a website about it a while ago after a registry reclassified one of my domains from standard to premium.
I use a .one for a project where it makes perfect sense. Brevo, who are a huge email delivery platform, told me they don't support signing up with a .one domain. Fortunately, after a couple of weeks going back-and-forth one of their developers eventually saw sense and fixed it.
Sadly, with Google, I don't think you'll ever get the issue that far up the chain.
sam_lowry_ [3 hidden]5 mins ago
The end is really hilarious. Google had a stupid frontend-only validation, it seems.
chmod775 [3 hidden]5 mins ago
Since Google themselves claim that's a security check, there's a bug bounty here.
The author of that article missed their chance making Google eat their words.
pigbearpig [3 hidden]5 mins ago
I was under the impression Google engineers went through a rigorous hiring process, yet this is the sort of thing you get from lowest bidder consultants who have inexperienced devs.
twostorytower [3 hidden]5 mins ago
All that leetcode, whiteboarding, and Googly-style interview questions just to put front-end validation for security.
soraminazuki [3 hidden]5 mins ago
As usual, this is more than just an honest mistake from Google. Not only is the given justification complete gibberish, it has AI written all over it. They have zero respect for users and it shows.
dutchCourage [3 hidden]5 mins ago
Since the author asked about Alice: it was an Internet provider in France in the early 2000's.
Some domains in that list are truly ancient. That was a trip down memory lane.
petepete [3 hidden]5 mins ago
Just wait for someone at Google to read this post and then block the domain retrospectively.
llacb47 [3 hidden]5 mins ago
And ban their entire Google account
qingcharles [3 hidden]5 mins ago
And delete all their data.
sunaookami [3 hidden]5 mins ago
*make it hidden, they will of course keep the data for themselves :)
sandeepkd [3 hidden]5 mins ago
the last paragraph was probably most important one here, and the lesson is If you truly want to enforce a validation then it has to be in the backend, the client side validation is just additional luxury if you can afford it.
On a different note, the validations were added for genuine reasons and most likely there would be some discussions/debate on the scope/cost/benefits. I would imagine if some one were to do it a a business seriously then they would have some way to override it on use case basis.
cube00 [3 hidden]5 mins ago
If you could just change your company's domain name that'd be swell!
Surprising Google is happy to lose a paying company over this.
Although the author is taking quite the risk bypassing Google's validation like that. Not sure I'd be risking my company's workspace to do it in case Google wakes up ban hammer happy one morning.
fillthegap [3 hidden]5 mins ago
I think ditching google would've been a better choice.
necovek [3 hidden]5 mins ago
Well, if the alternative was going to be Microsoft 365... not so sure :)
soraminazuki [3 hidden]5 mins ago
Or just ditch both. These companies have nothing but contempt for their users and signing up for their services is just asking for trouble. There are alternatives for email and whatever else is needed from these services.
Elliott-Diy [3 hidden]5 mins ago
Crazy that .one gets locked, but .arpa is fully okay.
soraminazuki [3 hidden]5 mins ago
That's not going to pass the domain ownership validation though.
sikozu [3 hidden]5 mins ago
This was a fun read. Absolutely baffling behaviour from Google.
bonzini [3 hidden]5 mins ago
alice.it is indeed an email provider's domain; based on the code snippet it seems like they are active in other countries.
alice.app however isn't registered anywhere.
t0mas88 [3 hidden]5 mins ago
I would hope that somewhere at Google there is a policy that says you can't do anti-fraud and security checks in frontend only...
yieldcrv [3 hidden]5 mins ago
ooof that's bad, all levels of support missed the frontend validation and blamed you and an opaque non-existent process instead
mpalczewski [3 hidden]5 mins ago
I wonder how this list ended up being created anyway. Was it a long standing issue, or just some ai slop? web.com, web.org, web.net don't look like an email provider.
layer8 [3 hidden]5 mins ago
The rationale probably was that end users primarily identify the email provider by the subdomain, not the TLD, and therefore to prevent spoofing they block all domains where the subdomain corresponds to an email provider, regardless of the TLD. Like, they don’t want to allow gmail.<anything>, and the same for all other email providers they know of.
mh- [3 hidden]5 mins ago
web.net, at least, absolutely is an email provider.
0x073 [3 hidden]5 mins ago
web.de is also a big email provider in Germany.
brewmarche [3 hidden]5 mins ago
Yes and gmx (listed next to it) as well, and I’m pretty sure that gmx offered/offers multiples TLDs (gmx.net, gmx.de, gmx.at, …)
I think the same goes for Alice (big ISP, offering mail addresses, in multiple countries)
It looks like some of these wildcards are for mail providers who use multiple TLDs.
mpalczewski [3 hidden]5 mins ago
fair enough. at least not primarily an email provider. so if they offer any email.
nom [3 hidden]5 mins ago
scroll through a list of known email providers and you will notice they registered tlds for the countries they operate in, very typical for the old ones like yahoo yandex Freemail Hotmail etcpp
web.de is an oldschool German provider, as is gmx.de (and .at, .fr, .com, ...)
the regex smells like an inexperienced developer trying to be clever
croes [3 hidden]5 mins ago
Or an pretty old regex from before all those new TLDs
spl757 [3 hidden]5 mins ago
that's a trip. nice catch!
xyst [3 hidden]5 mins ago
The engineer that implemented this probably used it to justify promotion.
"Reduced fraudulent signups by <made up metric>. Reduce business risk exposure."
Google engineering has certainly taken a nosedive.
That is the obvious thing to do. Don't understand why you even waste time there. You are digging a deeper hole for yourself.
If they cannot even provide proper support for sign up, what will happen when your account gets disabled for no obvious reason, and you potentially lose years of emails?
I’m now in the process of switching to Fastmail. Google doesn’t give a shit about anything besides for their golden goose, I would encourage everyone to move away from their services before they just screw you with no warning or recourse just because they can.
The way everyone gets so up-in-arms about the political views of a person three levels detached from the company is insane.
"Oh no, an individual with different views than me offhandedly mentioned Proton, the horror! I can't possibly differentiate between the views of a company and a separate individual!
Let's go grandstand about canceling our service and discouraging others from signing up because a random person thinks differently than me, and talked about the company."
It also can purely be choosing to not support an organization that doesn’t align with your world view. The money in our pockets is the power to change things.
I also use it with my own domain registered outside Zoho, so Zoho cannot actually lock me out of my email ever, only the data they host, though this is true for external domains in Google Workspace also.
And like the author, 90% of the time I can just disable their front-end validation and go on my merry way.
The registry premium domains on the new TLDs have several issues. The biggest IMO is a lack of price protection. Non-premium domains at least get the cohort based protection from section 2.10c of the registry agreement.
So, in addition to being treated as a 2nd rate domain, there’s nothing stopping the registry from cranking up the price if a domain gets popular. I don’t think it’s ever happened, but have never found contractual terms that forbid it.
I made a website about it a while ago after a registry reclassified one of my domains from standard to premium.
https://tldrisk.com/beyond-basics/premium-domains/
Sadly, with Google, I don't think you'll ever get the issue that far up the chain.
The author of that article missed their chance making Google eat their words.
Some domains in that list are truly ancient. That was a trip down memory lane.
On a different note, the validations were added for genuine reasons and most likely there would be some discussions/debate on the scope/cost/benefits. I would imagine if some one were to do it a a business seriously then they would have some way to override it on use case basis.
Surprising Google is happy to lose a paying company over this.
Although the author is taking quite the risk bypassing Google's validation like that. Not sure I'd be risking my company's workspace to do it in case Google wakes up ban hammer happy one morning.
alice.app however isn't registered anywhere.
I think the same goes for Alice (big ISP, offering mail addresses, in multiple countries)
It looks like some of these wildcards are for mail providers who use multiple TLDs.
web.de is an oldschool German provider, as is gmx.de (and .at, .fr, .com, ...)
the regex smells like an inexperienced developer trying to be clever
"Reduced fraudulent signups by <made up metric>. Reduce business risk exposure."
Google engineering has certainly taken a nosedive.