# Is gTmail a scam?

**URL:** <https://boards.straightdope.com/t/is-gtmail-a-scam/607749>\
**Category:** Factual Questions\
**Created:** [December 29, 2011, 7:52pm UTC](https://boards.straightdope.com/t/is-gtmail-a-scam/607749 "2011-12-29T19:52:01Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![El\_Zagna](https://avatars.discourse-cdn.com/v4/letter/e/d2c977/32.png) [@El\_Zagna](https://boards.straightdope.com/u/El_Zagna)\
**Post date:** [December 29, 2011, 7:52pm UTC](https://boards.straightdope.com/t/is-gtmail-a-scam/607749/1 "2011-12-29T19:52:01Z")

</div>

I’ve had a gmail account for a while, but recently I’m asked to sign in to a gtmail account. The URL for the “Can’t access your account” feature is:  
“h t t p s ://w w [w.google.com/a/cpanel/gtmail.com/ForgotAccountInfo](http://w.google.com/a/cpanel/gtmail.com/ForgotAccountInfo)”

(without all the spaces)

The whole thing is throwing up all sorts of red flags including the fact that googling “gtmail” returns results for “gmail” by default. Even when I insist that it’s “gTmail” that I’m searching for, I don’t get any substantive hits like you would expect for a Google based product.

Does anyone know what the deal is with gtmail?

---

<div class="post-metadata">

**Author:** ![FatBaldGuy](https://avatars.discourse-cdn.com/v4/letter/f/ecd19e/32.png) [@FatBaldGuy](https://boards.straightdope.com/u/FatBaldGuy)\
**Post date:** [December 29, 2011, 8:03pm UTC](https://boards.straightdope.com/t/is-gtmail-a-scam/607749/2 "2011-12-29T20:03:03Z")

</div>

I suspect it’s a phishing expedition. Don’t click on their link, but access your gmail account by typing [mail.google.com](http://mail.google.com) in the address bar, or by clicking on the gmail link in the Google page.

---

<div class="post-metadata">

**Author:** ![El\_Zagna](https://avatars.discourse-cdn.com/v4/letter/e/d2c977/32.png) [@El\_Zagna](https://boards.straightdope.com/u/El_Zagna)\
**Post date:** [December 29, 2011, 8:09pm UTC](https://boards.straightdope.com/t/is-gtmail-a-scam/607749/3 "2011-12-29T20:09:01Z")

</div>

Thanks. Is there a site where you can report such scams?

---

<div class="post-metadata">

**Author:** ![Lare](https://avatars.discourse-cdn.com/v4/letter/l/53a042/32.png) [@Lare](https://boards.straightdope.com/u/Lare)\
**Post date:** [December 29, 2011, 8:35pm UTC](https://boards.straightdope.com/t/is-gtmail-a-scam/607749/4 "2011-12-29T20:35:56Z")

</div>

Try this link [here](http://support.google.com/mail/bin/topic.py?hl=en&topic=1669056&parent=1668978&ctx=topic). You’ll find a couple of interesting articles about Gmail and phishing. I didn’t follow all the links, but I didn’t see one that leads to a place to report it. (!) The one about “Messages asking for personal information” gives a lot of info though. Follow **FatBaldGuy** ’s suggestion about how to get to the right site where you should be able to log in.

---

<div class="post-metadata">

**Author:** ![CookingWithGas](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/cookingwithgas/32/485_2.png) [@CookingWithGas](https://boards.straightdope.com/u/CookingWithGas)\
**Post date:** [December 29, 2011, 8:49pm UTC](https://boards.straightdope.com/t/is-gtmail-a-scam/607749/5 "2011-12-29T20:49:39Z")

</div>

The URL is a Google Apps business URL for the domain [gtmail.com](http://gtmail.com). It does appear to be a form of phishing where the app for that business will ask for your email address and then probably goes on to ask for your password. And you respond with your gmail address info. Very clever as they get you to go to a real [google.com](http://google.com) web site. I signed up for Google Apps just to see what would happen and I get a site with a URL like this:

[https://www.google.com/a/cpanel/cookingwithgas.com/SetupWizard](https://www.google.com/a/cpanel/cookingwithgas.com/SetupWizard)

The owner may be able to configure a page for Forgot Account Info intended for their own users but hoping you will enter your [gmail.com](http://gmail.com) information instead.

---

<div class="post-metadata">

**Author:** ![Lare](https://avatars.discourse-cdn.com/v4/letter/l/53a042/32.png) [@Lare](https://boards.straightdope.com/u/Lare)\
**Post date:** [December 29, 2011, 9:12pm UTC](https://boards.straightdope.com/t/is-gtmail-a-scam/607749/6 "2011-12-29T21:12:51Z")

</div>

> [@CookingWithGas](#):
>
> The URL is a Google Apps business URL for the domain [gtmail.com](http://gtmail.com). It does appear to be a form of phishing where the app for that business will ask for your email address and then probably goes on to ask for your password. And you respond with your gmail address info. Very clever as they get you to go to a real [google.com](http://google.com) web site. I signed up for Google Apps just to see what would happen and I get a site with a URL like this:
> 
> [https://www.google.com/a/cpanel/cookingwithgas.com/SetupWizard](https://www.google.com/a/cpanel/cookingwithgas.com/SetupWizard)
> 
> The owner may be able to configure a page for Forgot Account Info intended for their own users but hoping you will enter your [gmail.com](http://gmail.com) information instead.

If I understand domain naming convention right, what comes rightmost in the name, next to the rightmost instance of .com or .org, etc. is the domain you’re really going to and not the first one in the name string next to “http(s)://” right? So if you think you’re going to [google.com](http://google.com) based on the leftmost characters you are actually going to [cookingwithgas.com](http://cookingwithgas.com) as seen on the right?

---

<div class="post-metadata">

**Author:** ![Dog80](https://avatars.discourse-cdn.com/v4/letter/d/6bbea6/32.png) [@Dog80](https://boards.straightdope.com/u/Dog80)\
**Post date:** [December 29, 2011, 9:23pm UTC](https://boards.straightdope.com/t/is-gtmail-a-scam/607749/7 "2011-12-29T21:23:24Z")

</div>

I did go to the link in the OP and inserted my second gmail account that I have for spam. Then there was a CAPCHCA and then this message:

> [@](#):
>
> Account Assistance
> 
> There are no accounts in our system with the E-mail address [xxxxxx@gmail.com](mailto:xxxxxx@gmail.com) belonging to the organization [Gtmail.com](http://Gtmail.com). If you spelled the address incorrectly or entered the wrong address, please click here to try again.
> 
> If your address is correct, then you may not have finished registering an account with Google, even if you currently use some of our services. Please click here to quickly finish registering.

It never asked for a password or anything

---

<div class="post-metadata">

**Author:** ![BigT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bigt/32/12044_2.png) [@BigT](https://boards.straightdope.com/u/BigT)\
**Post date:** [December 29, 2011, 9:29pm UTC](https://boards.straightdope.com/t/is-gtmail-a-scam/607749/8 "2011-12-29T21:29:08Z")

</div>

> [@CookingWithGas](#):
>
> The URL is a Google Apps business URL for the domain [gtmail.com](http://gtmail.com). It does appear to be a form of phishing where the app for that business will ask for your email address and then probably goes on to ask for your password. And you respond with your gmail address info. Very clever as they get you to go to a real [google.com](http://google.com) web site. I signed up for Google Apps just to see what would happen and I get a site with a URL like this:
> 
> [https://www.google.com/a/cpanel/cookingwithgas.com/SetupWizard](https://www.google.com/a/cpanel/cookingwithgas.com/SetupWizard)
> 
> The owner may be able to configure a page for Forgot Account Info intended for their own users but hoping you will enter your [gmail.com](http://gmail.com) information instead.

And this is definitely behavior you need to report, as it definitely violates the Google Apps terms of service. Here’s the [abuse report form](https://spreadsheets.google.com/viewform?hl=en&formkey=cl9jYXFJUkwtUmduSXlSeDVyb05Gemc6MA..). Be sure to mention that they are phishing for your Gmail account information, and quote the entire email.

> [@Lare](#):
>
> If I understand domain naming convention right, what comes rightmost in the name, next to the rightmost instance of .com or .org, etc. is the domain you’re really going to and not the first one in the name string next to “http(s)://” right? So if you think you’re going to [google.com](http://google.com) based on the leftmost characters you are actually going to [cookingwithgas.com](http://cookingwithgas.com) as seen on the right?

No. It’s always the one on the left. The issue here is that Google lets you sign up for a special account if you own your own URL. This is why I’m saying this needs to be reported to Google. Someone is using their Google Apps feature to try to steal account information.

(The fact that the OP is getting an error now doesn’t mean it didn’t work previously. There’s just point in such an email unless that’s what they were doing.)

---

<div class="post-metadata">

**Author:** ![tellyworth](https://avatars.discourse-cdn.com/v4/letter/t/977dab/32.png) [@tellyworth](https://boards.straightdope.com/u/tellyworth)\
**Post date:** [December 29, 2011, 9:31pm UTC](https://boards.straightdope.com/t/is-gtmail-a-scam/607749/9 "2011-12-29T21:31:16Z")

</div>

> [@Lare](#):
>
> If I understand domain naming convention right, what comes rightmost in the name, next to the rightmost instance of .com or .org, etc. is the domain you’re really going to and not the first one in the name string next to “http(s)://” right? So if you think you’re going to [google.com](http://google.com) based on the leftmost characters you are actually going to [cookingwithgas.com](http://cookingwithgas.com) as seen on the right?

No. It’s always the leftmost one. In [http://foo.com/bar.com/](http://foo.com/bar.com/) the hostname is [foo.com](http://foo.com). /bar.com/ is the path.

The only other thing that might be to the left of the hostname in a URL is a _user : pass_ combo, in the form [http://username](http://username): [password@foo.com](mailto:password@foo.com)/bar.com/ (no space) - again the hostname here is [foo.com](http://foo.com).

---

<div class="post-metadata">

**Author:** ![BigT](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/bigt/32/12044_2.png) [@BigT](https://boards.straightdope.com/u/BigT)\
**Post date:** [December 29, 2011, 9:36pm UTC](https://boards.straightdope.com/t/is-gtmail-a-scam/607749/10 "2011-12-29T21:36:32Z")

</div>

Okay, having read more information, it’s possible this is a bug of some sort. But that’s still something Google needs to sort out, so I’d still report it.

---

<div class="post-metadata">

**Author:** ![davidm](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/davidm/32/225_2.png) [@davidm](https://boards.straightdope.com/u/davidm)\
**Post date:** [December 29, 2011, 10:01pm UTC](https://boards.straightdope.com/t/is-gtmail-a-scam/607749/11 "2011-12-29T22:01:44Z")

</div>

> [@tellyworth](#):
>
> No. It’s always the leftmost one. In [http://foo.com/bar.com/](http://foo.com/bar.com/) the hostname is [foo.com](http://foo.com). /bar.com/ is the path.
> 
> The only other thing that might be to the left of the hostname in a URL is a _user : pass_ combo, in the form [http://username](http://username): [password@foo.com](mailto:password@foo.com)/bar.com/ (no space) - again the hostname here is [foo.com](http://foo.com).

“Always on the left” does have a caveat, and it’s an important one.

Note **tellyworth’s** second example above; the one with “username:password”. Phishers sometime use that format to fool people into thinking that the link is for a valid domain. They do so by using a valid domain in the “username” position.

For example: [http://www.google.com:password@evil.phisher.com](http://www.google.com:password@evil.phisher.com)

This can fool people who don’t look too closely into thinking that the link goes to [www.google.com](http://www.google.com) when it actually goes to [evil.phisher.com](http://evil.phisher.com).

So the rule to use is actually “the leftmost thing _after any username:password prefix_.”

---

<div class="post-metadata">

**Author:** ![Dr.Strangelove](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/dr.strangelove/32/6613_2.png) [@Dr.Strangelove](https://boards.straightdope.com/u/Dr.Strangelove)\
**Post date:** [December 29, 2011, 11:45pm UTC](https://boards.straightdope.com/t/is-gtmail-a-scam/607749/12 "2011-12-29T23:45:34Z")

</div>

> [@davidm](#):
>
> So the rule to use is actually “the leftmost thing _after any username:password prefix_.”

Another trick is that scammers will use subdomains to make it look like something more official. Recently I’ve been receiving phishing attacks on World of Warcraft accounts that started with something like:  
http://www.blizzard.com.xml-login.net/more/stuff

The real domain here is [xml-login.net](http://xml-login.net), not [blizzard.com](http://blizzard.com).

---

<div class="post-metadata">

**Author:** ![StephenG](https://avatars.discourse-cdn.com/v4/letter/s/7feea3/32.png) [@StephenG](https://boards.straightdope.com/u/StephenG)\
**Post date:** [December 30, 2011, 12:22am UTC](https://boards.straightdope.com/t/is-gtmail-a-scam/607749/13 "2011-12-30T00:22:35Z")

</div>

> [@davidm](#):
>
> So the rule to use is actually “the leftmost thing _after any username:password prefix_.”

Or, to say it another way, the domain just to the left of the first slash, after the “http(s)://” prefix.

---

<div class="post-metadata">

**Author:** ![davidm](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/davidm/32/225_2.png) [@davidm](https://boards.straightdope.com/u/davidm)\
**Post date:** [December 30, 2011, 1:02am UTC](https://boards.straightdope.com/t/is-gtmail-a-scam/607749/14 "2011-12-30T01:02:11Z")

</div>

> [@StephenG](#):
>
> Or, to say it another way, the domain just to the left of the first slash, after the “http(s)://” prefix.

That’s probably a better way to put it, considering **Dr. Strangelove’s** example.

The problem of course is that most people have no clue as to how URLs are constructed. Which is completely understandable if they’re not IT professionals.

Scammers will always find a way to slip things past non-technical (and sometimes technical) people. I don’t know what the answer is.

---

<div class="post-metadata">

**Author:** ![Dog80](https://avatars.discourse-cdn.com/v4/letter/d/6bbea6/32.png) [@Dog80](https://boards.straightdope.com/u/Dog80)\
**Post date:** [December 30, 2011, 1:11am UTC](https://boards.straightdope.com/t/is-gtmail-a-scam/607749/15 "2011-12-30T01:11:17Z")

</div>

All browsers nowadays will automatically grey out the rest of the URL while keeping the domain black so it stands out.

---

<div class="post-metadata">

**Author:** ![Lasciel](https://avatars.discourse-cdn.com/v4/letter/l/e79b87/32.png) [@Lasciel](https://boards.straightdope.com/u/Lasciel)\
**Post date:** [December 30, 2011, 1:23am UTC](https://boards.straightdope.com/t/is-gtmail-a-scam/607749/16 "2011-12-30T01:23:07Z")

</div>

> [@Dog80](#):
>
> All browsers nowadays will automatically grey out the rest of the URL while keeping the domain black so it stands out.

Minor nitpick: All \*updated \*browsers will grey out the non-domain segments of the URL.

If you’re still using an older release, (and lots of people don’t have the latest releases of browsers) then that’s not the case.

---

<div class="post-metadata">

**Author:** ![iamthewalrus\_3](https://avatars.discourse-cdn.com/v4/letter/i/258eb7/32.png) [@iamthewalrus\_3](https://boards.straightdope.com/u/iamthewalrus_3)\
**Post date:** [December 30, 2011, 1:44am UTC](https://boards.straightdope.com/t/is-gtmail-a-scam/607749/17 "2011-12-30T01:44:02Z")

</div>

> [@davidm](#):
>
> The problem of course is that most people have no clue as to how URLs are constructed. Which is completely understandable if they’re not IT professionals.

It doesn’t help that URLs are sort of odd and confusing to begin with.

The domain name part is read in one direction, the path in another, and there’s seldom-used access control that can be put at the beginning and obfuscate things more. It’s a mess.

If URLs looked like:

com.google.www/foo/bar it would be easy to just always read them left to right. The left edge would always be the top of the tree.

user:pass is still weird to deal with, but it should probably just not go at the front. If we want to be able to tell where links go by reading them, then there needs to be a well-demarcated starting point that’s always there.

---

<div class="post-metadata">

**Author:** ![davidm](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/davidm/32/225_2.png) [@davidm](https://boards.straightdope.com/u/davidm)\
**Post date:** [December 30, 2011, 1:56am UTC](https://boards.straightdope.com/t/is-gtmail-a-scam/607749/18 "2011-12-30T01:56:18Z")

</div>

> [@iamthewalrus\_3](#):
>
> It doesn’t help that URLs are sort of odd and confusing to begin with.
> 
> The domain name part is read in one direction, the path in another, and there’s seldom-used access control that can be put at the beginning and obfuscate things more. It’s a mess.
> 
> If URLs looked like:
> 
> com.google.www/foo/bar it would be easy to just always read them left to right. The left edge would always be the top of the tree.
> 
> user:pass is still weird to deal with, but it should probably just not go at the front. If we want to be able to tell where links go by reading them, then there needs to be a well-demarcated starting point that’s always there.

I don’t disagree but I doubt that it’s fixable at this point.

The browser feature mentioned by **Dog80** is certainly a help, but people need to be taught to use it. Maybe an extra field in large type showing just the top and second level domain names would help. It could say something like “You are at this domain: [yourbank.com](http://yourbank.com)”
