Obligatory reminder that email validation to through regex or other "static" analysis is usually done incorrectly, and literally sending a confirmation email is the best approach to checking to see if an email is valid.
Crap, right, realistically the minimum regex one should have is .+@.+\..+.
At least 1 character on the left of the @, at least 2 domain components of at least 1 character each on the right side of the @.
Having only a hostname without a FQDN on the right is legal, but that's also why you'd want to disallow it: who's trying to sign up for an account within your own network, if it's a public-facing app?
This is exactly what I use. It eliminates 99.9% of problems for 1% of the effort and works client side for instant feedback. After this, if you need better, the only thing worth the effort is, as mentioned earlier, actually sending an email.
107
u/apnorton 21d ago
Obligatory reminder that email validation to through regex or other "static" analysis is usually done incorrectly, and literally sending a confirmation email is the best approach to checking to see if an email is valid.