4 ms·
This is why I love the email wildcard trick you can do with most providers [1]. Now I just update my email in Robinhood to a new wildcard, and then just block a
by bluetidepro 5y ago
This is why I love the email wildcard trick you can do with most providers [1]. Now I just update my email in Robinhood to a new wildcard, and then just block all emails to the old one since they will quickly just turn into spam emails 99% of the time. Makes email breaches way less annoying.
[1] If you have a service like Gmail or a service that supports wildcards you just do `name+[blahblah]@` or `name.[blahblahblah]@` to make the email specific to the service you are signing up for. So like `bluetidepro+robinhood@` and then if there is a breach you block all emails that go to that, and change your acct to be say `bluetidepro+rh@` or whatever new one so only legit emails go to the new one.
- vadfa 5y agoIt is much better to buy a domain and do robinhood@bluetidepro.com
- bluetidepro 5y agoYeah, that also works of course!
- rahimnathwani 5y agoThis is so common that I'm surprised spammers don't just drop the +xx part of the username.
- bluetidepro 5y agoYeah, surprised too, but they don't seem to.
- epanchin 5y agoThis is common on hacker news and other tech forums. Why waste your time trying to reach the people most likely to ignore your spam.
- lordnacho 5y agoWon't the bad people just scan for gmail accounts and take off the wildcard part?
- bluetidepro 5y agoI don't know about Gmail (I have a different service), but they don't seem to. This trick has seemed to work for pretty much all breaches I've seen. Like the recent Peloton one, I started to get spam to `blah+peloton@` and then changed it, and haven't gotten any single spam since the change. They must not put that much effort into the way they check or send the emails. ¯\_(ツ)_/¯
- jayknight 5y agoThe plus sign thing works with other email providers and servers. I used to use it with self-hosted postfix and I know it's possible with exim as well. I think exchange can do it as well. I would assume that any sophisticated spammer would try removing plus sign suffixes from harvested emails.
- deleted 5y ago[deleted]
- l33tman 5y agoJust a clarification for gmail: gmail removes the . characters but not what's after. You need the + trick for that purpose.
- ssmiler 5y agoDid same before. Now I generate emails with 33mail.com
- fairity 5y agoHave you actually seen spam emails being sent to your +wildcard addresses following a breach? My understanding is that the use case for these hacks is typically not email spam. One of my (non-wildcarded) emails has been included in many hacked email breaches, and I've yet to notice any associated spam.
- bluetidepro 5y agoI def did for the recent Peloton one. I was getting TONS of spam to my Peloton wildcard email until I changed it and blocked the old one.
- brilee 5y agoThe reason spammers don't remove the + automatically, is because their goal isn't to deliver spam, it's to get the right people to read the spam. The people who use the + trick are exactly the set of people who would never read spam email, and they're also likely to use the "report spam" feature and lower the deliverability of the rest of their spam.
- callmeal 5y ago>If you have a service like Gmail or a service that supports wildcards you just do `name+[blahblah]@` or `name.[blahblahblah] you can also add extra periods in your name: so something like na.me.blah@gmail... will aso work.
- skim_milk 5y agoIt's also great when other people do this - because it's a dead canary when you start seeing people's emails with +website being collected and shared. I remember like 6 years ago when someone compiled and publicly shared a list of emails&passwords. By simply grep'ing the +websitename out of the email I found that there were easily 800+ unique websites that leaked their login emails and passwords after some validation. I made a comment on reddit about it and some articles that cited it got millions of hits, but people have seemingly forgot since then that finding name+website@gmail.com being shared in lists is a good canary in the coal mine for hacked websites.
- 6gvONxR4sf7o 5y agoThat one gets tricky if you can’t keep track of which emails you used where. I’m paranoid that I’ll break my password manager somehow and then won’t even know the email I used for my account. For something financial, that could be devastating.