Skip to content

feat: detect Gmail/Googlemail dot normalization aliases #5

Description

@mdesoto

Context

Gmail (and Google Workspace) ignores dots in the local part of an email address. u.s.e.r@gmail.com, us.er@gmail.com, and user@gmail.com all deliver to the same mailbox. This is a well-known trick for creating "different" accounts from a single Gmail address.

This applies specifically to:

  • @gmail.com
  • @googlemail.com
  • Potentially Google Workspace custom domains (harder to detect without MX lookup)

This is the same class of problem as subaddressing (#3) — legitimate for personal use, but a signal worth surfacing in signup contexts.

Proposed behavior

Signal name

dotNormalization

Detection

When the domain is a known dot-insensitive provider (Gmail, Googlemail), normalize the local part by stripping dots and compare to the original:

const result = await guard.verify('u.s.e.r@gmail.com');
// {
//     isMatch: false,
//     matchedOn: ['dotNormalization'],
//     domain: 'gmail.com',
//     normalizedAddress: 'user@gmail.com'
// }

Configuration

const guard = await BurnerGuard.create({
    treatDotNormalizationAsMatch: false  // default — informational only
});

Utility method

Add normalizeAddress(email): string | null that applies both dot normalization and subaddress stripping:

guard.normalizeAddress('u.s.e.r+promo@gmail.com');  // 'user@gmail.com'
guard.normalizeAddress('user@outlook.com');            // 'user@outlook.com' (no-op, not Gmail)

Open questions

  • Should the list of dot-insensitive providers be hardcoded or configurable?
  • Should normalizeAddress() combine with extractBaseAddress() from feat: detect subaddressed email aliases #3, or be a separate method?
  • Should there be a single normalizeAddress() that applies all known normalizations (dots + subaddressing)?

Acceptance criteria

  • verify() detects dot variations on Gmail/Googlemail addresses
  • dotNormalization signal appears in matchedOn when detected
  • treatDotNormalizationAsMatch option in BurnerGuardOptions
  • normalizeAddress(email) utility method
  • Tests covering: dots in various positions, @gmail.com vs @googlemail.com, non-Gmail domains (should not normalize), interaction with subaddressing
  • README updated with dot normalization documentation

Priority: 🔴 High — same class of exploit as subaddressing, commonly used

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions