ProtonMail / WebClients

Monorepo hosting the proton web clients
GNU General Public License v3.0
4.23k stars 537 forks source link

Block account verification with maskmy.id disposable domain #368

Open ghost opened 6 months ago

ghost commented 6 months ago

Provider is https://skiff.com/quick-alias and it's actually subdomains, each user can generate their own subdomain. I tested it, very easy.

The page title of https://skiff.com/quick-alias is "Quick alias burner email address". In the HTML I see

<meta name="description" content="Secure and quick-to-create burner email addresses with Skiff!

There is a browser plugin https://github.com/irazasyed/email-masker to create one email per website, skiff.com's twitter account promoted it, the github repository is tagged as 'burner-email'

You should add:

IMG_1500 IMG_1501

ghost commented 6 months ago

Abusers can sign up with disposable email to bypass disposable mail block, but this can cause Proton being blocklisted.

So I think it is good idea to use something like this: https://github.com/micke/valid_email2 https://github.com/7c/fakefilter

To block disposables from signing up

ghost commented 6 months ago

@acasajus @bartbutler

ghost commented 6 months ago

Also

mailbox.zip
sailmail.io

They added new domains: IMG_1719

ghost commented 6 months ago

@acasajus @bartbutler @jeremybenaim