Totally agree with unique at own domain isn't actually privacy. It wouldn't take much of a paper trail to work out the details.
I continue to use it everywhere for a few reasons:
- if someone emails me acting all friendly like we've had some previous relationship but it's sent to linked@mydomain or github@mydomain I know they've just scraped my contact details and it's spam
- similarly, if a vendor leaks or sells my data and I start receiving marketing from somewhere I don't expect it's easier to trace the source of the leak (and in some cases just blackhole that entire email address)
- I already use a password manager and have different passwords on every site, but having a different email address too raises the barrier further for someone trying to script an automated attack based off some other pwned data set.
> - similarly, if a vendor leaks or sells my data and I start receiving marketing from somewhere I don't expect it's easier to trace the source of the leak (and in some cases just blackhole that entire email address)
This is exactly why I do it, it's eye opening to see exactly which companies leaked your address. As a result of being able to blackhole the leaked addresses I no longer get any spam, the Dvorak dream.
I actually caught a company outright selling my address to AWS of all places, I didn't even know Amazon purchased mailing lists.
AWS were crafty because they didn't directly sell a service, they only offered "resources" for "business leaders" because they knew nothing about what I might need.
Explore the AWS [REDACTED] where business leaders can access eBooks, guides, and customer stories to find practical advice on building or improving upon a data strategy. Learn how you can leverage data as a strategic asset, make better decisions with insights from data, and innovate faster.
I use my gmail address for everything and I don't really get spam (except from services I've subscribed to legitimately but haven't bothered to configure to not send promotional mail).
I never really get promotional mail from 3rd parties at all.
Gmail filters are very good. But if someone with the same name as you starts using your e-mail address for everything because they don't understand or care about needing to see the e-mails they receive then there's very little you can do to stop it other than unsubbing from lists they sign up for (where possible).
I've been getting someone else's e-mail traffic for about 5 years now, on two separate Gmail accounts, and while occasionally hilarious, it is somewhat scary to see how much I can know about their lives from the type of e-mails they get. I have replied to inform some of the senders about the situation with the suggestion that they could tell the other person involved to use a new e-mail address, but it is still happening. You'd think that they would need to see some of the important work-related mail they receive yet they are apparently utterly oblivious.
I occasionally also get similar mail to my own domain through a catch-all filter.
It's quite funny how little some people understand about what an e-mail address is, or how it's supposed to be used, even today.
> very little you can do to stop it other than unsubbing from lists they sign up for (where possible)
It certainly felt that way when someone was giving my GMail out to the cashier at the hardware store where I got no end of digital receipts which I couldn't unsubscribe from because they're providing the email address to the cashier each time. As they were receipts from a large verified brand Google treated them with the highest priority.
I've been in a similar situation for almost a decade now. There's an elderly woman who's email address is one character away on the keyboard from my own, and I often get emails meant for her. I tried for years to respond to inform them that they are using the incorrect email address, to no avail. At this point I've started to go in and disable/cancel anything that is signed up for with my email address and have to aggressively filter spam.
Got it years ago when Gmail was still in beta. My friend sent me an invite and yes I was actually excited to get invited to use the new 'Google Mail'. 1GB mailbox? Wow cool! How times change. The address is mostly dormant but still required for certain services/accounts so I can't just delete it. Probably better to squat it anyway, all things considered.
I agree with all of this. I’d add that it’s useful for sorting and searching. Things like keyword matching, from address, and from domain aren’t as consistent as you’d hope, but companies do need to actually email the address they were given, so you can use it to reliably identify emails from them.
True, but it requires setting up a mailbox at bigdomain.com for every use case. With your own domain you can just setup a catchall mainbox like [email protected] and don’t even need to remember any [email protected] name. Just use github@ and it will be automatically be catched by your catchall.
So any mail to [email protected] is actually received? Sounds like something that works great when only you do it, but might quickly be abused if it catches on?
Going back on topic, Apple offers mail hosting for custom domain, along with the optional “one mailbox, infinite aliases” feature we’re discussing right now. I’ve been using it for a while now and no bot spam. No spam at all actually.
> along with the optional “one mailbox, infinite aliases” feature we’re discussing right now.
They’re not exactly the same thing. Aliases are alternate addresses (under one domain) you set up yourself, while a catch-all just accepts any address in the domain as valid. While iCloud Mail does allow catch-all¹, aliases are capped at a maximum of three².
Surprisingly not. I have catch-all emails on several of my domains, and rarely get common name spam. I've blacklisted less than a dozen names on my domains in over 20 years.
I guess it varies then. When I did it (probably 15 or 20 years ago mind) I unleashed a torrent of spam so voluminous that I had to write scripts to clean it up my inbox after I turned it off again.
A friend of mine does the same. Catch-all, and buying expired domains he thinks funny or related to projects and customers he previously worked with. On multiple occasions he has received emails that truly where never meant for him, not spam but actual emails.
So far I think he's returned at least two domains to their previous owners, because letting them laps was a mistake.
It never happened to me - I use a catch all and almost never got emails like this. Why would bots try to guess emails on random domains when there are billions of known emails to send spam to.
I would like the ability that if I am in a situation that someone says "give me your email for..." and I would like the ability to just hand them something that is disposable. Would I just stand up say 10 addresses like:
random1, random2, random3... then delete them at some point in the future?
I really like Cloud's Hide My Email, but have been looking for alternatives since I am not sure where Apple is heading post Tim Cook.
I use Migadu to host my email, and they have a really cool wildcard-style system where I can basically define a regex string, and any email address matching that string goes to my main email.
In my case, I use a specific set of numbers just before the @ as the matching string (let’s say, “45”), so email to firstname45@domain works, or doctor45@domain, or library45@domain all get delivered. Since the spammers don’t know this, I don’t get any spam. But I still have the benefit of being able to make up arbitrary emails on the spot for any purpose.
For things I know ahead of time I'm going to need to give someone an email for (e.g. the dentist), I'll pre-make that address and have it ready for when they ask for it. For one-offs / unprepared asks for my email I usually just give them my 'main' [email protected] e-mail just for the simplicity... Fastmail does let you use *@personaldomain.com to forward to your main address, but for the rare circumstance in which you need to reply to one of those emails, you do need to configure it in the settings.
Thanks. I really don't use email that often; I might get 20 emails a month, and those are just notifications versus actual actionable communications that require a response.
I have been looking at Fastmail, along with Purelymail ($10/year), which seems to have similar features.
I continue to use it everywhere for a few reasons:
- if someone emails me acting all friendly like we've had some previous relationship but it's sent to linked@mydomain or github@mydomain I know they've just scraped my contact details and it's spam
- similarly, if a vendor leaks or sells my data and I start receiving marketing from somewhere I don't expect it's easier to trace the source of the leak (and in some cases just blackhole that entire email address)
- I already use a password manager and have different passwords on every site, but having a different email address too raises the barrier further for someone trying to script an automated attack based off some other pwned data set.