• hperrin@lemmy.ca
    link
    fedilink
    English
    arrow-up
    8
    ·
    3 days ago

    It’s one of the awesome features of my email service, https://port87.com/

    I’ve yet to prominently display it on the home page, but it’s on the home page of the help site.

    • paraproto@szmer.info
      link
      fedilink
      arrow-up
      1
      ·
      1 day ago

      For some years I am thinking about making a similar service, but as a receive only box with a twist. I wanted aliases to be done on domain level and tunnel encrypted traffic straight to user’s device as the TLS certificate for e-mail server would reside on user’s device. Thanks to that I wouldn’t need to store anything and I wouldn’t be able to snoop anything (at least without being seen). That way user’s phone would be their e-mail server. When an address would get compromised it could be filtered on the DNS level before it even would reach the user’s device. There are lots of challenges that way that I have ideas to overcome somewhat, but yeah I would trade one kind of complexity for the other.

      My worry for addresses in style user-alias@example.com is that alias is not random by default meaning someone can imply what addresses you have based on a single address. At the same time this keeps things simpler for users, because otherwise it gets janky and you of course need a mapping between a random address and what it means as well as a wanting for password manager integration or a browser extension at least.

      I guess it is a balance, but by not allowing the perfect become an enemy of the good your service works right now. I acknowledge that you might have struck the perfect balance so please don’t take it as a jab at you. I see that you have this “Patented Spam Filtering”, so cheers! :)

      • hperrin@lemmy.ca
        link
        fedilink
        English
        arrow-up
        2
        ·
        edit-2
        23 hours ago

        When an SMTP connection comes in, you don’t know who it’s for (RCPT TO) until after the STARTTLS handshake, so you wouldn’t know whose phone to forward that traffic to. The only reliable way to do that would be a dedicated IP address for every user. Since SMTP is pretty much exclusively IPv4, that would be expensive. Not impossible, but expensive. If you’re doing it for only a handful of users, it could definitely work. Let me know if you do build it, because it sounds cool.

        Also, thank you for the compliments. :)

      • hperrin@lemmy.ca
        link
        fedilink
        English
        arrow-up
        1
        ·
        edit-2
        1 day ago

        The entire website doesn’t work without JavaScript. It is super duper duper reliant on JavaScript and I don’t plan on changing that. The reason is that JavaScript lets you prevent cross site request forgery. Without it, I wouldn’t be able to tell if you actually made a request to send an email, delete an email, create an alias, etc, or if that request came from some website tricking you into clicking some malicious link/button. (To be more accurate, it is possible, but would be much harder and require managing a lot more state objects in the DB.) Also, without JS, you couldn’t have push notifications, and you’d have to refresh the page to see new email.

        If you’re worried about trackers, there are none. The only things that are loaded from external domains are Google Fonts, Cloudflare Turnstile, and the Stripe payments script. The site would still work if you blocked all of those, except for the specific things they’re used for.

          • hperrin@lemmy.ca
            link
            fedilink
            English
            arrow-up
            1
            ·
            edit-2
            1 day ago

            SquirrelMail is a completely different kind of product…

            Port87 is a hosted email service. SquirrelMail is a self-hostable webmail client.

            SquirrelMail also predates AJAX and nearly predates JavaScript itself. It came out 24 years before Port87. The latest official release of SquirrelMail is also 13 years old at this point. You should be using Roundcube if you want self hosted webmail (which also requires JavaScript).

    • moldy_rice@piefed.keyboardvagabond.com
      link
      fedilink
      English
      arrow-up
      1
      ·
      2 days ago

      Sharing a different address with every app or service keeps them from tracking you. If a company leaks your email, you can easily change a label’s address and block the address that was leaked, preventing spammers from reaching you.

      Can the customers send emails using these aliases too?

    • BottleBoardBakon@lemmy.ml
      link
      fedilink
      arrow-up
      2
      ·
      2 days ago

      Legitimately the first random comment ad I’m considering.

      I’m trying to figure out if I could use this in combination with my alias service.

      • hperrin@lemmy.ca
        link
        fedilink
        English
        arrow-up
        3
        ·
        2 days ago

        You can. I encourage you to. The only reason it isn’t anonymized is that places tend to block anonymous email services, but it works really well with anonymous alias services.