The scenario is I would like to only accept a unique email address from a persion ignoring gmail aliases (and if any other services do something similar)
The reason for this is we are giving away a limited amount of discount codes and to be fair we don't want someone claiming a large amount with only one email address.
From my understanding:
- If
gmail.com
orgooglemail.com
then remove the+
and anything after as that is the alias. - If is
gmail
then remove any dots from theusername
as they are ignored.john.smith@
is the same asjohnsmith@
- Don't just invalidate the
+
symbol as it is valid for email addresses.
Are there any other services I need to be aware of that allow one to alias their email address into multiple forms and any additionl considerations for my scenario.
Update I do have a database to store submissions with email addresses and claimed codes.
I also understand that it's difficult to stop people claiming multiple codes outright. Disallowing aliases is simply there to possibly reduce it.
Cheers.
Writing code to ignore a handful of known alias formats in a single service (like Gmail) isn't a big deal. However trying to prevent a single person from claiming multiple discounts based on email address alone is kind of an impossible task.
There are a LOT of different ways to create new email addresses and aliases. For example, there are services out there that let you create disposable emails, through which you can have as many different addresses as you need. Also, for as low as a few dollars, you can get your own email host with your own domain, where you can register a bunch of addresses and/or a catch all address.
It would take an exorbitant amount of resources to try to prevent anybody determined to claim a bunch of your discounts. Not without other identifying methods, other than email address.
I would consider adding other validation methods. Depending on what you are doing, that might be things like linking to Facebook, or even asking for credit-card details for verification.