10 ms·
As an alternative, you could register a domain with a catch-all email address and simply register for new services on the fly using a unique string for each sit
by _Marak_ 9y ago
As an alternative, you could register a domain with a catch-all email address and simply register for new services on the fly using a unique string for each site. Have the catch-all forward to your main email account.
For example, I would sign-up for HN using hackernews@marak.com and for Reddit using reddit@marak.com
Simple and effective.
- chatmasta 9y agoIf you do this, make sure you lock down your account at your domain registrar. A socially engineered DNS hijack could be all it takes to obtain full read/write access to your email.
- SippinLean 9y agoCan you elaborate on the steps needed to ensure your security in this case?
- ryanlol 9y agoSpend a decent chunk of money to become a registrar yourself or go with MarkMonitor. I suppose google domains might be OK for personal email.
- sverige 9y agoThe other thing that happens is spammers use your domain to spam others. That catch-all will work for systems that test email validity for the spammer's made-up address on the From line.
- threatofrain 9y agoWould you mind elaborating? Do you mean socially tricking a GoDaddy or other domain registrar employee into changing DNS records?
- vr3690 9y agoYep. I do this and route my email through mailgun that allows me to setup rules for forwarding emails. Their free tier is pretty generous and works great for my needs. Also solves the problem of shoddy websites selling my email because I gave them an unique email address and can block all emails coming to that address easily, if needed.
- bdav24 9y agoHi Marak, you're right, this is an alternative. You'd have to implement the filtering of the addresses you don't want any more though.
- greggyb 9y agoBut it's also more easily traceable to you. With a service aggregating these, we see many users from NBox. Perhaps this is not a concern for your use case, but it seems a tradeoff worth considering.
- jszymborski 9y ago> more easily traceable to you Depends who is tracking you. If I register some non-personally-identifiable domain "e.g.: bumblebutt.example" and use a WHOIS proxy, you're can only be given up by a registrar... which usually means a warrant. Still paranoid? Pay for the domain using bitcoin you got in exchange for cash/services (there are a lot of registrars that take bitcoin).
- Psilidae 9y agoIts certainly more traceable from the perspective of metadata aggregation. If you were looking at the users from multiple sites, you could easily consider "*@bumblebutt.example" to be one person thus linking all accounts together. The benefit of a public site is that you can't use the hostname as an identifer for a single person.
- eriknstr 9y agoBeen there done that. If you catch all e-mail you will also get a lot of spam to random addresses like say sven@marak.com, lollerskates95@marak.com and so on and so forth. So then you need spam filtering anyway, or you need to configure which addresses are valid. I still host my own e-mail but I no longer do catch-all. There are only a few sites and services I care about. For those I have trusted them with my e-mail address. For all others I use 3rd-party throwaway mail services. I get less spam now than I did with catch-all.
- water42 9y agowhat kind of accounts do you use throwaway mail services for? the use case where NBox would be useful for me is sites I don't use often, i.e. a clothing site or online video game store. but i wouldn't trust those to a throwaway email
- dannysu 9y agoI actually haven't gotten any spam through my catch-all emails. Hopefully it stays that way. I use a completely different domain than the one that's publicly associated with me though. Maybe that helps.
- amenod 9y agoOr you can use hackernews.really@marak.com and reddit.really@marak.com and only forward *.really@marak.com. I have learned to keep a personal e-mail address for friends & somewhat trusted people, but never businesses. Businesses (and all government offices, kids' school,...) get their one-time address. If spammers somehow get to it, it is much easier to cut them off, and I also know who leaked the address to them. Of course, http://www.mailcatch.com/ http://www.mailcatch.com/ rules for those one-time "no, I will not let you spam me" registrations.
- deleted 9y ago[deleted]
- e12e 9y agoIf you host your own domain you'll likely need spam filtering for abuse@ or at least postmaster@ (or ignore RFCs, like most unfortunately do..).
- toddmorey 9y agoGmail allows you to create unlimited unique addresses by using the + symbol. so you could do: username+trello@gmail.com. It's worked well for me for a few years. The only downsides I see are that (very few) sites still complain about the perfectly legal + symbol and some sites / bots are probably starting to reverse engineer that since it still exposes your username. But so far, I've yet to have a single site or service expose my primary mail account, so it at least helps. Finally: this is a fantastic hack for testing your own signup flows. :)
- carc1n0gen 9y agoNot a Gmail specific thing. That's something you can do with email in general.
- amenod 9y agoI believe it is Gmail specific. Cursory search reveals that sendmail does that too, but I don't think it is specified in RFC. Feel free to correct me if I'm wrong.
- e12e 9y agoIt's more Sendmail and Exim and others did it, and Gmail does it too - not the other way around;) With qmail the "standard"[1] was username-alias@example.com, rather than username+alias@example.com. I rather prefer that - but then my (user)name(s) don't contain any hyphens. Either way I think it looks better with system usernames - firstname.lastname@example.com was/is usually handled as a separate form of alias look-up anyway. [1] http://www.lifewithqmail.org/lwq.html#dot-qmail-files http://www.lifewithqmail.org/lwq.html#dot-qmail-files See section "4.1.5. extension addresses" [ed: and I recall using tmda as an anti-spam system - it inserts an encrypted tag in the alias portion, that can be stamped with an expiry date, and tied to a sender address (eg hmac(userkey, sender@example.com+01012018) => xyxyzzzzz - give sender@example.com the address user-xyxyzzzz@example.net - and mail to that address will be accepted from only sender@example.com until 1/1/2018. http://tmda.sourceforge.net/cgi-bin/moin.cgi/AboutTmda http://tmda.sourceforge.net/cgi-bin/moin.cgi/AboutTmda ]
- rokhayakebe 9y agothat's great for the average hacker news reader, but not so great for the average Joe
- peeky 9y agoI've been doing this for years. It's fascinating (and sometimes horrifying) which addresses end up on spam/scam lists. I used to inform companies when it happened, but they almost always go for plausible deniability with "spammers try random addresses at a domain sometimes, it must have been that".
- e12e 9y agoJust a reminder that Adobe, LinkedIn and Dropbox have all been hacked/suffered data leaks - those aliases are the main source of my spam. The other is through mandatory public company registration in Norway that's consistently mined by some halfwits apparently selling stamps etc.
- jtwebman 9y agoWith gmail you can just do username+hackernews@gmail.com and it will send it to username@gmail.com. The nice thing about this service though is you can just remove the fake email and they can't email you anymore.
- mmanfrin 9y agoThere are a fair number of sites with broken regexes/validations that reject emails with +s in them.
- massaman_yams 9y agoI have also observed emails tagged with "+" to break unsubscribe links in cases where the address is included in the link and the link is not properly URL-encoded.
- rhizome 9y agoRFC-violating email regexes cause problems less and less all the time, and much less often than just 5 years ago.
- daxelrod 9y agoI used to do this. The amount spam of mail I received to mailbox names I had never used started to dwarf my actual email. This is apparently made worse because spammers take the fact that these addresses will receive mail as a signal that they're valid, causing them to send more mail to them. A couple of years ago, maintaining the blacklist passed the point where this was a viable technique for me.
- jjnoakes 9y agoThis is why you might consider maintaining a white list or white pattern instead.
- rhizome 9y agoEasier to use sub-/plus-addressing rather than maintaining a list.
- jjnoakes 9y agoThat seems like a white pattern to me.
- rhizome 9y agoIf only delivering mail to existing email addresses is a white pattern, sure.
- jjnoakes 9y agoI don't follow. If I configure me.example.com to accept emails matching the pattern "me<anything>mail42@me.example.com", then I can generate as many on-the-fly unique emails as I want, without maintaining any lists, and without catch-all forwarding of random spam to my inbox. If I use me+anything@me.example.com, I get the same exact feature, but the downside is "+anything" is recognized by some and either disallowed or used to generate more patterns. If I use subdomains (like anything@me.example.com) I have the spam issue. With a white pattern scheme, you can choose your own pattern (so sites can't really catch on), not have to maintain any lists, and avoid spray-and-pray spam.