4 ms·
We intentionally don't do it, after long debate. Why would you want a catch-all, curiously?
by dejan 11y ago
We intentionally don't do it, after long debate. Why would you want a catch-all, curiously?
- franciscop 11y agoMaybe set up an option to enable it if it's easy to implement? Because people make typos or you might want to make up addresses on the fly similarly to mailinator (but with corporate addresses).
- dejan 11y agoThe downside is that you will catch all spam too, and more importantly you will not bounce back the message to the sender informing them they've sent to the wrong address.
- th0br0 11y agoVery simple reason: have a separate email for each website that requires a signup. That way, you'll know directly which website leaked your email address to some spammers.
- dejan 11y agoI use aliases for that reason, much cleaner IMHO.
- th0br0 11y agoWhoops. Looks like I totally misread that OP. Yeah... aliases is what I was thinking about as well. Although, separate email adresses in conjunction with a catch-all are better. After all, with an alias, you can just cut the recipient's address off just before the + which isn't that big a hurdle to spammers...
- zaphoyd 11y agoMost aliases require adding explicitly. The primary feature of the catchall address is that it is a blacklist rather than whitelist for aliases. Gmail style + aliases (which don't require explicit adding) are almost as good, but can be easily and silently stripped and generally notify the receiver that a filtering situation is happening on the other end.
- zaphoyd 11y agoSure, I'd be happy to share my use case, especially if it might improve support for this workflow =) I've been using a catch all email address on my primary domain for 15 years. Yes, I get some spam to things like sales@domain.com, etc, but it tends to be actual companies sending small amounts of legitimate-ish ads for services that my business apparently needs, not the reams of viagra ads and phishing that one might imagine. Most of the spam I get is to email addresses that I have given to another organization or advertised somewhere. The biggest culprits are the contact email address listed on my website / domain name whois records and a handful of sleazy companies that have clearly sold my email address to spammers. :P My email workflow is to provide unique addresses to each place that requires an email address. Why? It is a flexible and low maintenance method of managing email routing, both legitimate and spam. More precisely: 1. Security. Unique addresses make it harder to link a leaked account dump from one service to another. Not impossible, obviously most of the addresses share the domain part, but it foils simple matching. 2. Cleanly blacklist individual addresses. I buy something from company X. Company X signs up me up to 18 of their mailing lists. No amount of unsubscribe button fixes this. I can just blacklist that address. More commonly, Company X is a bit shady to begin with or has an account breach that leaks their user list or goes belly up and someone else buys their accumulated personal data. Blocking the emails at the address level is a lot cleaner than trying to black list individual senders as any given company might have many addresses, spammers obviously use a different address every time, etc. 3. Easily route legit messages. This lets me adjust where different groups of addresses are delivered. If I want to make a new mailbox/folder that has all of my "quasi-legit" spam. I.e. ads from companies I actually buy stuff from. Or a set of email addresses that I give only to VIP senders that get privileged alerts on my devices. I can make a mailbox and route a whitelist of address to each. I know what addresses I gave out. I could try and route based on sender address or text keywords but that is a lot more work, more error prone, more messy. Again, people and companies change addresses, the ones I give out don't. 4. Low friction for the default case. The ratio of addresses I end up blocking is small compared to the set that I give out. Most email addresses get maybe 5-10 messages in their lifetime. The friction of going to a computer and explicitly creating a new mailbox is simply too high for this sort of arrangement to work. In my workflow right now the default (addresses not matched by a real mailbox, forwarder, or blacklist are routed to a catchall mailbox) is the correct behavior for 95% of cases. When I want something different (forwarder, blacklist) I can add that explicitly, when it is convenient. It is not convenient to add email addresses/forwarders when I am sitting in some companies office being asked for my email address on a paper form. 4.5. Wife less tolerant of technical friction than I am. My wife uses this system as well. She would never go add a new email address manually for everything but does enjoy the ability to have an address blocked or reliably and selectively route some address to her mailbox vs mine. This use workflow is likely not common so I certainly don't expect widespread support for it. Today I use a shared hosting provider to do this. I don't use the web hosting at all, just use it for email since I haven't found a good dedicated email service that supports this workflow. I don't like this setup because I'd really rather have better email related features (better TLS support, better IPv6 support, 2FA, a web control panel focused around email, etc would all be nice). I've toyed with setting up my own email setup on a VPS but would really rather just pay someone else to do it. Have yet to find a dedicated email provider that would support this workflow though. =\