simple-login / app

The SimpleLogin back-end and web app

Home Page:https://simplelogin.io

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Block registration with maskmy.id (it is violating ToS)

opened this issue · comments

Provider is https://skiff.com/quick-alias and it's actually subdomains, each user can generate their own subdomain. I tested it, very easy.

The page title of https://skiff.com/quick-alias is "Quick alias burner email address". In the HTML I see

<meta name="description" content="Secure and quick-to-create burner email addresses with Skiff!

There is a browser plugin https://github.com/irazasyed/email-masker to create one email per website, skiff.com's twitter account promoted it, the github repository is tagged as 'burner-email'

You should add:

  • maskmy.id because it is there main domain
  • anything.maskmy.id because it allows you to create disposable addresses with random subdomains

IMG_1500
IMG_1501

Abusers can sign up with disposable email to bypass disposable mail block, but this can cause SL aliases being blocklisted.

So I think it is good idea to use something like this:
https://github.com/micke/valid_email2
https://github.com/7c/fakefilter

To block disposables from signing up

Also

mailbox.zip
sailmail.io

They just added new domains:
IMG_1719

The 3 domains have been added to the block lists, thanks for letting us know.