5 ms·
I run with a custom domain and a catch-all email rule, so all inbound mail goes to the same inbox, so I can use whatever@domain.com. Maybe it's still trackable
by antonyh 4y ago
I run with a custom domain and a catch-all email rule, so all inbound mail goes to the same inbox, so I can use whatever@domain.com. Maybe it's still trackable but at least helps identify leaks.
- maccard 4y agoHow many leaks have you found with this approach?
- oddlama 4y agoNot parent, but I'm doing the same thing and I have had 5 leaks out of (currently) 387 accounts over the past 4 years (which is when I started doing this). Oh and none of the involved entities ever acknowledged the leaks. I'd also be highly interested in the rates other people encounter.
- jrochkind1 4y agoThe "leak" could be the company selling their email list, yes?
- martin_a 4y agoOr some kind of involuntarily passing on the mail addresses, like a breach of some kind.
- jrochkind1 4y agoCould be. If they sold the email addresses, that is one reason they would not "disclose" it, it was just routine business (and not business they are eager to disclose, although I suppose it's mentioned in some fine print in their privacy statement somewhere, hypothetically, maybe).
- ttyprintk 4y agoI haven’t counted, but have had a similar rate over 10 years.
- seusscat 4y agoI've been doing the same over a similar time span. 5 years for me. However, i am yet to find any leaks. I get a ton of spam, but they ALL are sent to my publicly listed email address in my git commits. I'm seriously considering turning that email into a honey pot.
- deleted 4y ago[deleted]
- EvanAnderson 4y agoI've been doing the same thing for nearly 20 years. In that time I've helped two site owners identify data breaches they were unaware of. I can also see evidence of several of the compromises identified in the "Have I Been Pwned" data set.
- spacedcowboy 4y agoI have been doing the same for ~30 years now, and having an email address that established has its downsides - I’ve lost track of the number of times the trap has sprung. The most-recent was Tesla, though. I did a lot of work on iCloud’s “Hide My Email”, and I’m involved (the DRI for) quite heavily in other privacy-focused work at iCloud. It’s something I feel strongly about.
- SSLy 4y agoThank you for the service, I'm just surprised AAPL lets you talk about it.
- spacedcowboy 4y agoYou will notice a complete dearth of detail in the above on anything not already known outside of Apple... It's generally fine to talk about something already public, and say you worked on it - there are projects that haven't released yet that I've worked on, and I absolutely will not talk about those until they are :)
- xur17 4y agoI just started doing the same (~ a month ago). Within a week of creating an account for bestbuy, I started receiving spam to that address. Do you do anything when you catch someone, or just note it to yourself, block the address, and move on?
- spacedcowboy 4y agoThe latter, generally. It's not worth trying to retaliate because these things come from addresses that aren't monitored, for the 99% case... I do make a point of telling people how shitty the company is though.. Like Tesla for example :)
- phyzome 4y agoI've been doing this for maybe 10 or 15 years. It has given me evidence of several database breaches (such as Avvo, who still deny it) but as far as selling my data, I think I've only seen that happen with a Kickstarter campaign.
- antonyh 4y agoSurprisingly zero on one domain. Not because it's ineffective, but because it hasn't leaked as far as I can tell. The other however has leaked, but that's because it's designed to - it's for social media where the email is available for use and has been abused by third parties.
- denton-scratch 4y ago> and a catch-all email rule I don't relish the prospect of getting tons of mail to <random-name>@mydomain. I do actually check my spam folder; I'm afraid that if I used a catch-all, that would become impractical.
- jeroenhd 4y agoMaybe it's just me, but I rarely receive catchall spam. I think some scummy company guessed mail@domain.tld but other than that the spam has only come to account names I've actually registered with. I have aliased all the email addresses I know leaked to a special mail box that marks every email it receives as spam. The rest just ends up in the normal mail filtering system. Probably should move towards random usernames instead of service@domain.tld at some point, oh well.
- phyzome 4y agoI worried about this as well (after I had set it up and started relying on it) but in practice I've only gotten spam to a handful of addresses that I didn't make up myself. Into a filter they go.
- antonyh 4y agoI get surprisingly little. There's about 15 addresses that are persistent, and they're all caught by the spam filters. The most important job is to set up SPF and DKIM properly so spammers can't impersonate your domain and send as though FROM you, rather than TO you.