I had this happen a couple years ago when I was migrating to a different domain. The only difference was all of the authentication that I supplied Google said was an adequate and I got into some sort of a login loop where Authenticator, SMS, DNS record nor pass key would provide enough authentication for me to get in.
I got the automated got bought to finally send me the mythical form, after completing that I was told that they were unable to authenticate me further. I ended up emailing their support multiple times and threatening lawsuits multiple times when I got a magic call from a human at Google. They also sent me the link that put me into a login loop however after chatting with them for nearly an hour I got a different magic login link form which appeared to work.
So for my own notes, removing a phone number from my Google account before travel will risk account suspension. Hope OP resolves it, but also need to make sure this never happens to me.
This is a massive bug here. I was also surprised recently that Google won't let you enroll multiple Authenticators. If we had functional security regulations I think there would be some pretty large fines for Google's error here.
IMO, the worst part of this is Workspace support is immune to ANY explanation. I mean, credit card companies are well used to "is this your transaction?" emails.
These are the limits of scale. Too big, too complex, and not enough skilled people to maintain and/or support it. And our hubris as humans prevents us from accepting it. Why? Why can't we accept smaller but more functional things/systems?
We don't have to live like this.
I just set up google workspace and I didn't have recovery phone or anything,just password and recovery email. I didn't login for 1 week (life stuff). When I came back it allowed me to login but didn't allow any admin stuff saying it didn't recognize me and that I must use a known browser.
Well, that was the only browser I logged in with.
The solution was a weird thing where I was able to add phone recovery and authenticator, but then had to wait 2 weeks (couldn't use it). After that I performed authentication as usual.
It's horrible.
Google Drive & Workspace are their most poorly designed products with the shittiest support ecosystem. Google would rather bleed money than work on it.
That's one of reason I started DoShare Personal Cloud[₁]
Good luck to you
I gotta say, though, that my experience with trying to get them to sort out any kind of issue with their services makes me reluctant to spend any money with them.
I bought a Pixel phone. As per the sales terms, the phone came with one year of Gemini AI Pro service. Except, the redemption process to get the year of service didn't work for me. I contacted Google, they never fixed it or offered any solution. I simply didn't get the year of service I was promised.
My friend, who bought a Pixel around the same time, also wasn't able to get the year of Gemini they were promised.
That same friend has a Google One subscription, billed through their phone carrier. Recently, Google (or the provider?) discontinued that specific Google One plan, as well as the option to bill via your carrier. This was all covered in an email sent to my friend. As consolation, the email explained, my friend was given the option to switch to a different plan, billed monthly by Google (instead of their phone carrier), with 6 months free. Except, the new plan, and the 6 months free, wasn't selectable as a plan type for their account. So my friend emails Google about it and, to my complete lack of surprise, Google was unwilling/unable to provide any resolution.
At this point, I legitimately don't understand why, unless I had no other option, I would pick Google for services. They clearly put no real effort into resolving any service issues for any customer that's not spending millions with them.
Everyone who depends on the good graces of a cloud provider for something (not just Google, but Amazon, Microsoft, Apple, whatever) needs to at the very least, take a moment, and figure out what their plan is when they are suddenly banned and locked out permanently, without any way to contact the company.
Does life just go on, since you don't have anything important hosted there? (Best Case)
Do you lose some precious family photos and use it as a tough learning opportunity to stop doing what you're doing? (Next best)
Do you lose access to your E-mail and are suddenly not able to do 2FA, reset passwords, communicate with the company or the Internet in any way, and so on, and now have to panic?
Do you complain online, hoping that someone in the company sees your post and has the ability to restore your account, which you then continue to use because you learned nothing?
Having an online account suddenly suspended is a real, non-zero, but unlikely risk. You should at least have a disaster plan if you rely on these things for anything important. Or better yet, stop relying on them for important things like your identity or precious files!
As an ex-googler, the only reason I was comfortable keeping even my personal email there was because I could reach out internally if there was a problem. I left Google, and left gmail behind too.
Nothing has helped, the Google forums are tumbleweed and there's no one to reach out to for what could be an algorithm change or something gone wrong. I'm a paying Workspace customer and it's made me think I need a backup plan in case I'm ever suspended. Reports like this don't encourage.
Not only did they answer immediately whenever I had even the smallest problem or question: I twice broke my Glass, and each time I'd call the support number to ask for a replacement.
Google's policy was that no matter how you broke it or how many times it happened, they'd replace it free. They'd immediately send a box to return the broken device (prepaid) and a couple days later a brand new Glass would arrive.
Like I said, once upon a time....
It feels like the security team made this change to reduce account hijacking but it's at complete odds with the recovery flow and modern security practices. Better hope your phone number doesn't get hijacked or recycled because it's the key to your account now, security keys be damned.
It would be cool if Google (and other media giants, especially IdP ones) had an office where you could bring your passport and verify it's you. I don't think there is.
I had a Nest subscription that became a total mess. If you've ever tried to use Nest before, or are coming from a legacy Nest account, and/or also have a Workspace account that somehow got wrapped up in the mess, you'll understand how much of a clusterf Nest is for the Google ecosystem. I had signed up for this subscription on a personal Google account, cancelled it, but was still being charged for it, and the credit card being used made me think it was getting charged on my Google Workspace account (which isn't officially supported, and would never let you sign up for it, but DID share an email address with my legacy Nest account I had migrated into the non-Workspace personal account I was using for Nest).
They had to escalate the problem a couple times, which took ~24 hours. Once that happened, their rep had it resolved in minutes, and refunded me two months on the subscription.
The biggest piece of advice I can give when dealing with Google is: Never be weird. You cannot ever put yourself in a situation where your account isn't like the other billion accounts they have. If you do, something will go wrong and its rolling the dice on whether you'll ever reach someone who can help you. If you've used Google enough, you know: Their multifactor settings are weird. You cannot set it up exactly how you want; it'll always trigger some auth method you didn't configure but they have "LATENT KNOWLEDGE" you should be able to authenticate with, like a phone number you configured six years ago, or gmail installed on a tablet that's 400 miles away, and you can't turn it off, even on Workspace.
My favorite bit of Googleism: Go to any site you sign in with Google SSO and watch the URLs in the eight redirects it has to do before it signs you in. You'll see a "youtube.com" in there. Even on a Workspace account. Youtube.com is a load-bearing website in their core auth flows.
Mess of a company. I hope they invest some effort in improving things, but I was saying the same thing in 2018. They probably won't.
> Update 1 - I know I can simply change the MX record to someone else but It has its own challenges.
I don't quite get that attitude. He's describing that he needs his business emails. Not just getting a mail server back online for that, even as interim solution, points to the opposite. In the time it takes for MX TTL to expire he could easily just throw up a postfix+dovecot on some VPS, with enough time to spare to add something like sogo if he feels fancy.
In my experience Google Workspave support is very good. I’ve always been able to get a knowledgeable person on a call to debug issues without much difficulty.
But yea, if you’re locked out of your admin account, that’s another story. Very sjmilar to if you get locked out of your AWS root account. It’s a nightmare to recover.
I thought with Workspace you'd actually be spared from this kind of BS
I guess not?
Well, you have become the product here. That also happens by other "free" email providers too. I had this happen to me on inbox.lt; the guy demanded I use a smartphone to "prove" my identity. At that point I realised they want to connect this data to the account and sell it to others who are interested in that.
It's been a decade since Google broke their promise not to use information gleaned from your use of their services to sell ads.
> Google quietly erased that last privacy line in the sand — literally crossing out the lines in its privacy policy that promised to keep the two pots of data separate by default. In its place, Google substituted new language that says browsing habits “may be” combined with what the company learns from the use Gmail and other tools.
"Support" agents couldn't be bothered - this feels like AI trapping me in the tarpit maze to save a few USD on the disk storage and infefence cost, effectively scamming me.
When you pay for Google Workspace you are the client, not the customer and they do answer phone calls for support. The only two times my wife and I needed them for our SMEs, they picked up the phone and helped us resolve our issues. Super professional too. Haven't needed to give them a call in something like 8 years now.
Don't know about Pixel phone and Google One subscriptions but for SMEs Google Workspace is a godsend: it's incredibly cheap per employee and it's the way out of the Microsoft mediocrity. Everything only requires a browser, no matter the OS (wife works from Linux and now added a Mac Mini, for example): Windows can, at long last, get the middle finger in SMEs.
I'll forever be thankful to Google for allowing me to help many people get rid of Microsoft products, including Windows.
On the plus side, it does mean they have thousands of people who know how to fix problems.
I've put in a heroic effort to make sure they never get a phone number, specifically so they can't start handing my account over to the first clown who simswaps me, and have been successful. Unfortunately, this makes my account weird, which as you noted is fatal.
If your business is dependent on services you need to take a modicum of effort to protect yourself - the posts author was literally walking around with his entire business at risk from him dropping his phone or having it pickpocketed.
At the end of the day, the protagonist in this story is mad because Google won’t allow him to social engineer access to his company. He deleted his sole token (Google makes it trivial to add many) in the most fraud signally way possible.
I probably wouldn't believe him either. Google should have an option to revert to the last trusted config after some verification method. Google support is bad, I'll give him that.
All this to avoid roaming charges? And then refusing to share a personal email in this scenario and missing meetings because of that.
I'd argue that changing the MX to fastmail or Microsoft would be much faster than a postfix+dovecot solution on a VPS but I think he's just refusing any solution based on his principals.
It sounds like the mistake here is not appointing another Super Admin, and making sure they don't use their account for day to day needs. Or just having two Super Admin accounts controlled by the same person, heh.
I can't see how not using one's Super Admin account wouldn't prevent tripping some kind of fraud lockout that's impossible to recover from.
Randomly, I just remembered that I lost a GCP account because I tried logging in from Laos, and they asked me for the front and back photos of a payment card that I used ages ago that I didn't bother making scans of before it was lost. Urgh.
But maybe you logged in to your domain registrar through google oauth. If your google account is locked you can't now get into your domain's settings to change your MX records.
The real problem isn't the email address itself, it's all the access that google owns on your behalf. Lose access to Google, lose access to everything.
I think their motto of "don't be evil" was some pretty clever PR.
I started questioning it c. 2008 when they ghosted me on resolving an issue with my blogspot site that was a bug in the platform. All I could get was a condescending non-response from a "diamond" volunteer on a forum. They were apparently the gatekeepers to reaching actual support.
Contract violation. The problem is it's simply too burdensome to go to small claims court.
Back in the day they bought Feedburner, and merged it with their internal equivalent. In that process, my subscriber list was affected. They apologized and even sent out some swag. That was nice, for a small inconvenience at the time.
Today? humans don't even seem to be involved.
This is one of the most common sentiments I hear expressed on HN, next only to "if you're not building your software business around Claude Code, you're gonna left behind".
With this comment in mind, I just now called that same number with an instant pickup telling me they no longer take support calls at that number.
The Americans have done something kind of interesting along those lines, as far as an in-person IDV option to establish e-government accounts [0]. You start account setup online, then take a barcode to a post office along with your identity documents.
I have to imagine it’s hard to make a commercial case for such a system, though… especially these days with so much momentum toward the approach I resent—that is, requiring ID checks just to be online in the first place.
[0] https://www.login.gov/help/verify-your-identity/verify-your-...
Are we reading the same blog post? He had his password, 2FA authenticator set up, and backup codes -- everything Google asks you to have to be on the "golden" auth path.
He only deleted his SMS authentication path (one thing I don't understand is how he was able to do this in the first place without being logged in), which is in any case the least secure method of 2FA. Also, It should be fairly obvious that SMS is not expected to work seamlessly while traveling, how is this not a scenario that's hit by millions of Google users worldwide?
edit: looks like there are affordable managed hosting providers for keycloak.
Why the fuck would Google care in which country I live? It's a personal decision, and no corporation should have any say in this. They certainly don't have to flag an account for that, especially not if the account has 2FA enabled. This is on Google, too.
Your comment is victim blaming.
If they didn't have all their issues (discontinuing products, bad customer service) they'd probably be bigger than MS and Apple combined. But here we are.
Also for better or worse, I pay for bundled Google storage + Gemini and YouTube separately, it's still worth it, even without free months or whatever. And still better than being in MS or Apple's ecosystem.
We really need to just fix the laws.
I think organizations have a very hard time staying motivated once the product’s concern has moved away from any one team. While you test the product for them there’s likely people whose jobs depended on you and 7999 others doing so. But eventually a product will be considered shipped and all the various talent now pays attention to what’s next.
The own-brand forum (Google, Microsoft, Apple) seem to be infested by netizens from lower-income countries trying to build online customer support portfolios by providing utterly useless answers.
That, or trying to game the system and getting shortlisted for a free trip to Google HQ for one of their contributor summits.
It's not the same league, not even the same sport.
PS: Not defending Google here, their support for some products is abysmal
Notice how phone carries manage to have a shop in every little strip mall, you're never more than a few miles from the nearest one. Google takes in far more revenue, can easily afford the same. Or they could even just partner with the phone carriers and have a staffed desk in every tmobile/at&t/verizon shop.
“Exerting” would be more correct I guess but less fun.
I've tried everything to find someone inside Google to fix this, but so far no luck. At least with Meta you can find someone on a forum like Swapd who will take a small bribe to fix these issues.
Honestly, if you are using Gmail as your primary email I could probably ruin your entire year. I could just try and hack you (not even successfully) and Google will just shut down your entire life rather than attempt to work out who's right.
I fixed this by deleting the subscription data for Google One (which also refunded me a prorated amount for my Google One plan), and then waiting a day.
We have everything else but this alone is not enough.
That sounds like its own kind of problems. (!)
Had this happen to me. Fortunately the 'attacker' wasn't actually trying to do this, so damage was limited, but it's chilling when you think about what some motivated script kiddy can do with your Google account just by requesting password resets.
If we're comparing cloud services, surely GCP has customer service? I can't imagine any big enterprise using it otherwise.
It doesn't address this thread's concern that a single Super Admin could be locked out with no recourse, since Google's customer support is horrendously bad.
2. the response is glib and lacks any empathy
3. there's no suggestions of possible action or resolution path
4. it is all opinion and low value / low effort
So even if it's an "honest and accurate diagnosis" that you agree with, it's not helpful, valuable or even comforting. We can do better.
These players MUST be regulated or treated like utilities; hoping the EU will ratchet up the pressure even more.
This. There are something like 150 million Americans with a Google account, and these days it is more important than a phone number to have a working email.
Email is a utility. Email companies should be heavily regulated and controlled like phone or other utility companies.
This has the nefarious side effect of allowing Google or Facebook to track people across the Internet and apps. Webmasters like you are, often for no imperative reason, complicit of this by providing such login options.
What a shit tier authentication mechanism.
The SMS only fallback is when other things have failed and they suspect that there’s been a takeover. Microsoft does something similar to tie it to some tangible thing. I’m not excusing Google. Their exception handling is poor at best. I’ve seen issues at customers where phones left in flight get flagged because of GPS disruptions due to Middle East conflicts, for example. (Phones flagged as having been in Syria or Russia can be kryptonite) One scenario was a VIP whose kid was in Europe with their other parent and the VIP’s tablet, signed into work email.
Other factors apply too - there may be multiple accounts tied to the number that are in different locales, for example. No idea what obnoxious rules Australia and UK add as well.
Point is, this type of shit happens and you should have a contingency.
I assume that's just because they need to set a cookie on the YouTube domain in case you visit YouTube later on the workspace account, and not "load bearing"in the manner you insinuate
So one of the comments on one hackernews post on front-page almost somehow always refer to something within a hackernews post on the same front-page. I have seen this witnessed too many times that it might be time to name this phenomenon.
Not sure the state of keycloak now, but it was a lot of work to manage keycloak configs with the IaC pipeline. That could have gotten better now, but I think having access to the data is important because migration might not be trivial if for instance a provider starts acting up.
Let's work through what the contingency could have been. Always make sure you buy international roaming everywhere you go? Always be able to switch your MX records (from a provider whose account isn't tied to a Google-controlled email)?
They seem to get increasingly less practical to be honest. People travel all over the world everyday, this shit shouldn't be hard for a company like Google that supposedly ingests mountains of data.
More to the point, I think email has become sort of a fundamental right given how much of your identity depends on it. Companies that control this sort of identity foundation need to be heavily regulated, and perhaps nationalized.
It can be surprisingly difficult with a lot of SaaS products (including Google).
I saw it mentioned in a comment elsewhere in this thread, but the level of service you get really seems dependant on which pocket of Google is responsible for the product you happen to be using. Unfortunately Workspace is a giant pocket with many billions of users with suboptimal and/or perpetually exhausted support.
30 day cool down period is a reasonable response, at scale.
The other option is to contact the phone company and explain, asking an open ended question if there is any way they could help you, with the permission of the current owner of the number, to get one more text message and move your Gmail to a new number. It doesn't sound in any way like you are trying to pull a scam, so they might help.
However (and I loathe this logic) if you can get the marketplace to accept that minimal level, and the brand harm is inconsequential, why not pocket the savings
It's still repugnant to me, as compared to self-hosting, but I would never self-host for a greenfield SMB Customer today. The economics don't make sense and the talent pool of knowledgeable and reasonable sysadmins is dwindling by the day. (I wouldn't want to make a Customer so beholden to me if they were willing to pay for it.)
I miss being able to spin-up an on-prem email server on a box with reasonable hardware redundancy, some external USB disks to rotate for off-site backup, a UPS, a couple consumer-grade "business class" Internet connections, and a contracted "backup MX" to catch email in the event of an outage. It was a good enough for a lot of small SMBs who had a physical office, and was cheap.
I don’t know what the exact revenue/growth difference is, but if my paycheque depended upon getting more users to sign up, I don’t think I could justify making it into a political stance when Google isn’t going to notice my tiny boycott.
That's the thing though. Google have destroyed their brand through these kinds of actions, over many years.
As the title suggests, I have finally become the victim of Google’s account suspension. The reason given over the phone was that my account had been “hijacked” - when in reality, I was simply the one accessing it from overseas.
Despite repeatedly explaining this, they ignored my assertions and continue to hold my email hostage. I understand they may believe they’re protecting me from social engineering, but a DNS verification was already completed to prove I own the domain. While suspended, no emails are received and no forwards work.
On Saturday, April 4, around 5:00 AM I removed my phone number from the account. I am travelling to the UK for a short period and did not want to have roaming on my Australian phone. Despite setting up an authenticator and passkey, gmail insisted that I use my phone number to login via SMS. Ofcourse, this was not what I wanted. So I removed the recovery phone, expecting the system to fall back to my authenticator. I was in the UK to negotiate a business outcome - I should have realised that if Gmail fails, everything downstream fails with it.
On Saturday, April 4, at 5:06 AM, I received a notification saying my authenticator had been removed. It hadn’t. The authenticator was still active on my phone - it was the recovery phone I had removed. Google apparently conflated the two.
[

I had my logged-in laptop, phone, passkey, and backup codes, but none of it worked.
Every recovery attempt kept hitting the same “something went wrong” dead end, despite tapping the correct recovery prompt on my phone.
[

This email is the sole account on my Google Workspace - and the super admin account. A single point of failure. It has three aliases across different domains. Email, Drive, Calendar, payroll, and authentication for multiple services are all tied to it.
I had multiple email forwards configured precisely for situations like this, but because the account is suspended, forwards don’t work either. Payroll is tomorrow. I won’t be able to run it because of my reliance on Gmail-based authentication. I cannot login to Pipedrive - sales CRM because I use Google Auth. I can’t login to our Task management app. I can’t login to our internal systems because - you guessed it - it releied on Google Oauth.
Then, it get worse.
I tried account recovery and was asked to verify DNS ownership via CNAME and TXT records. I did this promptly. Meanwhile, the recovery email option told me I’d need to wait 30 days.
Thirty days of a suspended business email. No incoming mail. No forwards. Nothing.
[

So Google will suspend my email for 30 days and no emails will be received during this time.
Fortunately, I run another Google Workspace account. I logged into that admin console and contacted Google support through it. The rep told me to fill out a form at a link - which required me to log in. With my suspended account. Which I obviously can’t do.
Another rep on chat told me the account was “simply suspended” and that I could recover it in incognito mode. I told them I’d already tried this multiple times and hit the same error every time. They filed another ticket.
[

I tell them - I have already done this numerous times and it fails with the same error I got previously.
[

This back-and-forth repeated several times over 24 hours. There are now four open cases. None of the case managers seem to know what’s happening - one case gets closed in favour of another, then reopened because the other was closed.
I read community forums and reach out Google Workspace on X.com. They ask for case numbers which I promptly give and they tell me to wait.
I finally reached someone by phone and explained that I had removed the phone number myself. I asked them to verify the DNS record, confirmed I’d passed their “knowledge test.” They said everything checked out and that there would be a resolution within a few hours. They confirmed as much in a follow-up email.
[

More than 40 hours have passed. Having chatted to someone on the phone. I’ve since been told the person handling my case isn’t on shift for another 90 minutes. This means I will likely miss payroll. A negotiation with a business associate will need to be rescheduled. I could give them my personal email, but I’d rather keep business and personal separate.
Update 1 - I know I can simply change the MX record to someone else but It has its own challenges.
Update 2 - Sadly, its 2 PM in the UK and I will miss the meeting that I had scheduled via Google Meet because emails are not working and neither is anything Google. I have been on chat with Google reps since the morning. First an update was promised in 1-2 hours. Then on followup , 3 hours later another update is promised in 90 mins as the reps shift hasn’t started. Then 90 mins later, received a call where another update is promised in 60 mins.
Upadte 3 - I have finally been able to log in. Someone very kind from Google reached out and they were able to help me login with the help of another kind person at Google. Thank you, kind stranger !
Some people on HN are noting that I tripped all red flags I could - namely 1) Changed country 2) Didn’t want to use roaming 3) Removed recovery phone. 4) Didn’t just change MX records. Some are saying I did not consider the dependency tree.
To clarify, I removed the phone number 6 days after changing the country until which point I was using this email just fine with the same IP address in the new country. I could have just changed the MX to fastmail or Protonmail but that would not have retroactively gotten me my old emails or my calendar invites. Not to mention the Oauth login issues I might faced logging into other services.
I also did not realise that the account was actually suspended/disabled until the next day at which point I tested sending a test email only to discover no emails were being forwarded.
I had authenticator via Google app setup for 2FA , had a passkey on my laptop, was logged in on my phone, had access to backup codes, was using the same mobile phone, same laptop, had access to the recovery email and also had access to the Australian number which I removed. None of this worked.
No posts
I admit once it didn't work I didn't reach out to support but the entire experience was shit sandwich after shit sandwich.
App developers have repeatedly stated that offering those options increases user account creation. There is lower friction to using “login with <big tech>” than to create username/password creation flow. My guess is that most of the world hasn’t figured out a password manager workflow that works for them (or they aren’t willing to pay for it).
Aren't cellular providers inherently tied to the country they're in?
How do you move to another country without changing cellular providers at the same time?
But the EU’s approach is often backwards. When product managers have to ask the government if it’s ok to ship a feature, something is wrong. When the government responds that it can’t say in advance, you’ll just have to ship and see if you get fined, something is really seriously broken.
"Sign-in methods: Email, passkey, Google account, Apple account, GitHub, GitLab, Bitbucket".
I also tried to get blackhat and tried to find anyone who can intercept the text, but I've not been able to, even on some rather shady forums...
For cheaper rates than roaming, typically you install a secondary eSIM for the country you're traveling. 99% modern phones support dual SIM for this reason
The only people who seem to get un-suspended are the ones who can generate news media outrage or who can call their friend who is a director/exec at the company. (Obviously this intuition is flawed, but it’s hurting the reputations of these SaaS providers.)
I’d be at a complete loss for any obscure Windows issue though.
That doesn't make any sense. There are still plenty of people who are not doing weird things and getting screwed over.
Google fanboys have always fallen for their "don't be evil" nonsense, and it looks like they still are even after it was changed.
It's not hurting them enough. Hence the regulation is needed.
But, if you'll re-read my comment, my complaint is that the EU will not pre-clear features. They will only punish after the fact if they decide it was a bad feature.
And that's even assuming you're correct that the bureaucrats themselves know what is a good idea. Which I'm skeptical of. I think they're more likely to be correct than, say, Facebook... but that's a pretty low bar.