TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Open-source disposable email service

190 pointsby psarnaabout 2 years ago

13 comments

hannobabout 2 years ago
There&#x27;s a security problem with this and many other such services. Writing this here hoping that this increases knowledge about this:<p>I would be able to get a TLS certificate for this host. Why? Some TLS certificate providers allow verifying the domain via access to one of the privileged aliases like postmaster. So I could receive the verification token URL by looking at the postmaster inbox.<p>Every service offering any type of email inbox should block these aliases. They are ‘admin’, ‘administrator’, ‘webmaster’, ‘hostmaster’, ‘postmaster’. This is specified in the so-called Baseline Requirements, which is the standard for the operation of certificate authorities: <a href="https:&#x2F;&#x2F;cabforum.org&#x2F;baseline-requirements-documents&#x2F;" rel="nofollow">https:&#x2F;&#x2F;cabforum.org&#x2F;baseline-requirements-documents&#x2F;</a>
评论 #35927034 未加载
评论 #35927409 未加载
solaticabout 2 years ago
I imagine this domain will quickly end up on lists like this one: <a href="https:&#x2F;&#x2F;knowledge.hubspot.com&#x2F;forms&#x2F;what-domains-are-blocked-when-using-the-forms-email-domains-to-block-feature" rel="nofollow">https:&#x2F;&#x2F;knowledge.hubspot.com&#x2F;forms&#x2F;what-domains-are-blocked...</a><p>The real value here is the opening of the source code. Set up a cheap domain, set up a cheap VPS, use Tailscale or similar to keep the web UI private, then you&#x27;re good.
评论 #35928038 未加载
评论 #35927201 未加载
kanaryabout 2 years ago
Do you plan to shuffle the domain? If this hits scale, sites pretty quickly blacklist domains. imo anonaddy is best at scale but still gets blocked.
mdanielabout 2 years ago
this is not &quot;open source,&quot; it&#x27;s source available as the repo is missing any licensing terms. I dunno what the legal standing is of these package management fields &lt;<a href="https:&#x2F;&#x2F;github.com&#x2F;psarna&#x2F;edgemail&#x2F;blob&#x2F;master&#x2F;Cargo.toml#L5">https:&#x2F;&#x2F;github.com&#x2F;psarna&#x2F;edgemail&#x2F;blob&#x2F;master&#x2F;Cargo.toml#L5</a>&gt; since I believe at least npm defaults to some very liberal license that almost no one looks at any further and puts a sibling license file in their repo with the actual terms<p>Also, bold move implementing your own smtpd: <a href="https:&#x2F;&#x2F;github.com&#x2F;psarna&#x2F;edgemail&#x2F;blob&#x2F;master&#x2F;src&#x2F;smtp.rs#L28">https:&#x2F;&#x2F;github.com&#x2F;psarna&#x2F;edgemail&#x2F;blob&#x2F;master&#x2F;src&#x2F;smtp.rs#L...</a>
评论 #35926203 未加载
评论 #35923446 未加载
评论 #35935879 未加载
usr1106about 2 years ago
For incoming mail this is easy to do yourself if you have a little root server with a decent subdomain (the domain does not even need to be owned by you)<p>But for outgoing mail that requires real work &#x2F; knowledge &#x2F; full control over your DNS records. Recently gmail has stopped to accept any email without SPF&#x2F;DKIM.
评论 #35925864 未加载
tpoacherabout 2 years ago
Nice.<p>I wonder; if you used this with a &quot;one-payment-only&quot; disposable card, to buy stuff without being harassed by subsequent &quot;newsletters&quot; ... is there a way this could backfire spectacularly by virtue of it being a public address?<p>I&#x27;m assuming the answer is probably yes, but I can&#x27;t think of an obvious reason why.<p>EDIT: Hm, on second thought, I guess at a minimum you&#x27;d have to give a valid address to buy stuff. Unless it&#x27;s one of those &quot;give us your email to register&quot; at a physical point of sale. Or unless you have things delivered to a local shop you trust or something. dunno.
eshack94about 2 years ago
Really neat service, but how are you ensuring this won&#x27;t get abused by spammers and fraudsters?
itakeabout 2 years ago
Websites like this always seem to shutdown. Now I can’t access any accounts I created with them (since I can’t password recovery or change the email).
评论 #35923549 未加载
评论 #35923454 未加载
评论 #35922879 未加载
FpUserabout 2 years ago
&gt;&quot;All inboxes are public.&quot;<p>What does that mean exactly? Hopefully not that everybody else can look at my &quot;throwaway&quot; inbox.
评论 #35922704 未加载
评论 #35923150 未加载
jdthediscipleabout 2 years ago
Did not receive my test email for some reason
评论 #35923692 未加载
browningstreetabout 2 years ago
I got one of those duck.com addresses but I have no idea what it is or how to re-access it.
评论 #35923213 未加载
mteam88about 2 years ago
I would love something like this that forwards to a gmail address
评论 #35923375 未加载
评论 #35923742 未加载
评论 #35926252 未加载
评论 #35926942 未加载
rvzabout 2 years ago
Just like the other disposable email providers, this one will eventually get blocked pretty quickly.<p>Instead, use a forwarding email from Gmail, Hey.com, Outlook or ProtonMail.
评论 #35926094 未加载
评论 #35923871 未加载
评论 #35926794 未加载
评论 #35927607 未加载