7 ms·
If it's obviously-named, it might be brute forced. I have an alias (amazon@ and aws@) on my domain that I never used to sign up for Amazon and was never used at
by ev1 4y ago
If it's obviously-named, it might be brute forced. I have an alias (amazon@ and aws@) on my domain that I never used to sign up for Amazon and was never used at all, but it receives spam on a daily basis (and AWS phishing emails - it was never once used at either service).
- myself248 4y agoSounds like such emails should be mnemonic-salt@domain just to rule out such brute-forcing.
- exikyut 4y agoOr possibly even salt_hmac(mnemonic)@domain, to both make the address un-brute-forceable and also cover businesses going "why are we emailing business@yourdomain" and potentially getting huffy (apparently this happens?!). Only potential issue is that if it's a real HMAC like HMAC-MD5[:16] the nonsense address might give spam middleboxen very bad indigestion. Or maybe the crazy service addresses used in cloud infrastructure have actually inoculated everything to a reasonable extent and this might work?
- cube00 4y ago> cover businesses going "why are we emailing business@yourdomain" and potentially getting huffy (apparently this happens?!) It very much happens, I had a business owner lecture me that they owned their domain and I shouldn't be able to use in any part of their domain name in my email address.
- ThePadawan 4y agoThanks, that mixed my thoughts of inferiority for the day.
- ThePadawan 4y agoWhoops, that was supposed to read *fixed.
- cm42 4y ago"Acktchually, sir, unless you own the NFT of the domain, you don't actually own the domain! Also, that's not how resource naming works; RTFRFC, n00b."
- chunk_waffle 4y ago> and potentially getting huffy (apparently this happens?!). It does... I've had signups blocked using business@domain.tld, (some Samsung service is one I recall) and in one case I had legit sales queries completely ignored until I used an alternate email.
- ev1 4y agoHa. The more obscure the better, I guess. But you'd want some tooling to make it reasonable to handle. I have a catchall and it's interesting what type of rubbish appears. I have gotten phishing that pretends to be an AWS support case ticket reply about how my instances in us-east-whatever are about to be terminated due to a host node going out of commission sent to aws-iam-root-user@domain - a domain that has never used or touched AWS and a left hand side mailbox that has never been used once. If it's anything obvious it's probably made it onto some type of dictionary list.
- kevincox 4y agoI do this. I use the same protocol as https://blame.email/ https://blame.email/ (so that I can use their site). The nice thing about having the name in the clear is that it is easy to map it back to the sender at a glance, rather than having to loop up old messages.