You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Gmail (and Google Workspace) ignores dots in the local part of an email address. u.s.e.r@gmail.com, us.er@gmail.com, and user@gmail.com all deliver to the same mailbox. This is a well-known trick for creating "different" accounts from a single Gmail address.
This applies specifically to:
@gmail.com
@googlemail.com
Potentially Google Workspace custom domains (harder to detect without MX lookup)
This is the same class of problem as subaddressing (#3) — legitimate for personal use, but a signal worth surfacing in signup contexts.
Proposed behavior
Signal name
dotNormalization
Detection
When the domain is a known dot-insensitive provider (Gmail, Googlemail), normalize the local part by stripping dots and compare to the original:
Context
Gmail (and Google Workspace) ignores dots in the local part of an email address.
u.s.e.r@gmail.com,us.er@gmail.com, anduser@gmail.comall deliver to the same mailbox. This is a well-known trick for creating "different" accounts from a single Gmail address.This applies specifically to:
@gmail.com@googlemail.comThis is the same class of problem as subaddressing (#3) — legitimate for personal use, but a signal worth surfacing in signup contexts.
Proposed behavior
Signal name
dotNormalizationDetection
When the domain is a known dot-insensitive provider (Gmail, Googlemail), normalize the local part by stripping dots and compare to the original:
Configuration
Utility method
Add
normalizeAddress(email): string | nullthat applies both dot normalization and subaddress stripping:Open questions
normalizeAddress()combine withextractBaseAddress()from feat: detect subaddressed email aliases #3, or be a separate method?normalizeAddress()that applies all known normalizations (dots + subaddressing)?Acceptance criteria
verify()detects dot variations on Gmail/Googlemail addressesdotNormalizationsignal appears inmatchedOnwhen detectedtreatDotNormalizationAsMatchoption inBurnerGuardOptionsnormalizeAddress(email)utility method@gmail.comvs@googlemail.com, non-Gmail domains (should not normalize), interaction with subaddressingPriority: 🔴 High — same class of exploit as subaddressing, commonly used