Smells like „product engineering“. So a product or an engineering lead gets a task to reduce risks of specific abuse by preventing someone from sending email from yahoo or web.de clone. As a quick solution they add this filter without „overthinking“ it. The impact is low, a few customers in a million, so its stupidity gets unnoticed and, once first complaint reaches them, quietly deprioritized to death. Removing it is cheap: the justification for taking that work is likely the show stopper. Google is an old large corp that hires and fires at a scale. Owning removal of abuse filter to increase revenue by Planck-sized amount is an impossible thing.
petepete
Just wait for someone at Google to read this post and then block the domain retrospectively.
show comments
sam_lowry_
The end is really hilarious. Google had a stupid frontend-only validation, it seems.
show comments
sikozu
This was a fun read. Absolutely baffling behaviour from Google.
cube00
If you could just change your company's domain name that'd be swell!
Surprising Google is happy to lose a paying company over this.
Although the author is taking quite the risk bypassing Google's validation like that. Not sure I'd be risking my company's workspace to do it in case Google wakes up ban hammer happy one morning.
t0mas88
I would hope that somewhere at Google there is a policy that says you can't do anti-fraud and security checks in frontend only...
bonzini
alice.it is indeed an email provider's domain; based on the code snippet it seems like they are active in other countries.
alice.app however isn't registered anywhere.
mpalczewski
I wonder how this list ended up being created anyway. Was it a long standing issue, or just some ai slop? web.com, web.org, web.net don't look like an email provider.
Smells like „product engineering“. So a product or an engineering lead gets a task to reduce risks of specific abuse by preventing someone from sending email from yahoo or web.de clone. As a quick solution they add this filter without „overthinking“ it. The impact is low, a few customers in a million, so its stupidity gets unnoticed and, once first complaint reaches them, quietly deprioritized to death. Removing it is cheap: the justification for taking that work is likely the show stopper. Google is an old large corp that hires and fires at a scale. Owning removal of abuse filter to increase revenue by Planck-sized amount is an impossible thing.
Just wait for someone at Google to read this post and then block the domain retrospectively.
The end is really hilarious. Google had a stupid frontend-only validation, it seems.
This was a fun read. Absolutely baffling behaviour from Google.
If you could just change your company's domain name that'd be swell!
Surprising Google is happy to lose a paying company over this.
Although the author is taking quite the risk bypassing Google's validation like that. Not sure I'd be risking my company's workspace to do it in case Google wakes up ban hammer happy one morning.
I would hope that somewhere at Google there is a policy that says you can't do anti-fraud and security checks in frontend only...
alice.it is indeed an email provider's domain; based on the code snippet it seems like they are active in other countries.
alice.app however isn't registered anywhere.
I wonder how this list ended up being created anyway. Was it a long standing issue, or just some ai slop? web.com, web.org, web.net don't look like an email provider.