Hey social networks, stop sending out emails in other people’s names!

Great. I just sent a confidential email to Reunion.com… by mistake.

Now it wasn’t extremely sensitive, but it was private business correspondence between my business partner and myself, and I certainly didn’t intend for it to be read by others.

Here’s how it happened:

Social networks routinely send out updates and invitations from other users. For example, Reunion.com emails you when someone searches for your email address on their site. The incoming email looks like this:

Reunion.com email

Maybe a bit spammy, but no big deal, right? Well here’s the problem: they send the email out in the name of the person who did the search!

In other words, the incoming email’s display name will be “Edward Anderson” or whatever, BUT the reply-to address will actually be something like verify@relay05.reunion.com.

That’s such a bad idea, because the next time you go to send Edward Anderson an email, you start typing E-D-W-… and on many email apps (Outlook, eg) auto-complete will take over and spell out the full name for you.

But guess what? Even though it says “Edward Anderson” in the “To” line, you’re actually going to send that (possibly-confidential) email to verify@relay05.reunion.com now.

I would be very interested to know how many emails they receive that are intended for others. Maybe I’m the only idiot who’s ever done it… but I doubt it.


One Response to “Hey social networks, stop sending out emails in other people’s names!”

  1. Chandra Says:

    Yes, but how does it happen? I had the exact same thing to happen but only to one friend on my Google/Gmail contact list. I personally do not have a reunion.com acct. so I’m not exactly sure what’s going on. I went to my friends anme, clicked mail and noticed the email was that verify one that you mentioned. So I fixed it…and it’s back. WTH is that all about??? LOL! 😀 Thanks….

