4 ms·
If you have your own domain name with a wildcard, it's really helpful to enter: someservice@mydomain.com as your email. That way if it leaks you'll know who did
by e0m 10y ago
If you have your own domain name with a wildcard, it's really helpful to enter: someservice@mydomain.com as your email. That way if it leaks you'll know who did it and can setup much more robust rules to block. I'll use the domain name as the main address so I remember which name goes to which site.
For physical address mailings, you can hyphenate (or use a middle name) as the service. So First Service-Last as the addressee name. While harder to setup "mail rules" for, at least you'll know who to never trust again.
- Sephr 10y agoI've been doing exactly this for a while. Here is my list of companies that have leaked the email address I gave them to spammers: https://gist.github.com/eligrey/5084991 https://gist.github.com/eligrey/5084991
- mehrdadn 10y agoNote that (I think) Adobe was hacked, so that doesn't mean your email was "leaked" by them per se, not in the sense we mean anyway. Also, out of curiosity, how long did it take these companies to leak your info, generally? Days, weeks, months, years...?
- Sunset 10y agoDropbox was hacked as well.
- lucb1e 10y agoAwesome work! I do the same with email addresses, but receive very little spam. Mostly I block addresses that start spamming me with newsletters. I've thought about keeping a list, but most companies actually stick to the Dutch anti-spam laws (which are quite good). Only Dropbox and one personal contact ever actually sold/leaked my email address, and Paypal of course but they hand my email address out to all merchants so they're almost certainly not to blame themselves (not beyond the fact that they hand it out in the first place).
- danielk_ 10y agoEven easier is to use john+someservice@doe.com. Works with any e-mail provider, ends up in your normal mailbox. Gmail even adds tags based on what follows the plus. Might not work for some services due to ignorance of the spec or to prevent users doing this.
- mehrdadn 10y agoDoesn't really work since anyone with half a brain would remove the plus sign and after, knowing the email is more useful without that part. I've never caught anyone this way.
- avh02 10y agoproblem with that is websites who think they're super smart and believe that + is not a valid character in an email... sometimes it's just the javascript though and you can submit it via manual POST request.
- Faark 10y agoI do the same, using mailgun to forward them to my usual account. Thou the day i will actually have to send / reply to e.g. customer support with one of those mail addresses will be annoying. Any suggestions on that part?
- literallycancer 10y agoGoogle apps can kind of do it[1] (although it appears to leak the main address on purpose), so I guess you can also do it with your own mailserver? 1 - https://support.google.com/mail/answer/22370?hl=en https://support.google.com/mail/answer/22370?hl=en
- avh02 10y agoI just started doing the wildcard domain thing last month, I'm happier knowing that I can shut the taps. I get annoyed just knowing that there's spam in my spam list. First time I was on the phone with a customer service rep. after using the <website>@<domain>.com format I was asked if i was sure my email address was correct. I lol'ed and told them not to worry about it.
- megous 10y agoI use random 20 char string for the local part. That way there's no question about the leak. Spammers use a lot of dictionary words in the local part of the email address, so it's better to have a random string. If you're using password manager anyway, there's no reason not to make email/username random too. For smaller e-shops you might find some with actively exploited 0days this way. I did.
- avh02 10y agonot a bad tip, i'll do this for less reputable websites i suppose.
- Sephr 10y agoThat is useful, but how do you manage to remember the mappings? I want to know what random string corresponds to what service without having to search my password manager. The best of both worlds would be random local part + a Chrome extension that manages the mappings. The Chrome extension can then replace the local part in Google Inbox with the corresponding site name.
- Sephr 10y agoUpdate: Just use service name + random string concatenated for the local part. Seems like the best solution.
- rootsudo 10y agoYou can do this with gmail. For example if your gmail is root@gmail.com You can do root+yahoo@gmail.com, root+reddit@gmail.com and such on.
- clubm8 10y agoIt's relatively easy to use regular expressions to strip that out though. I set up a catch all for my domain, and give each entity it's own unique addy to guard against this.