Live data from Hacker News

Using a catch-all domain is a mistake

notcheckmark.com

11–20 of 304 posts

Re: Using a catch-all domain is a mistake

#11
I've been doing this for close to a decade and sometimes salespeople and customer service people will ask to confirm, but that takes 5 seconds and isn't awkward (in my opinion.)

It has more benefits than knowing who leaked your email, it lets you easily filter your incoming email by who you gave the email to, and when your email is leaked it lets you shut off that email address. Of course you can also filter your email by the sender's domain, but that isn't as consistent, and doesn't help at all when your email address has been leaked.

It's true that you do have to set it up so that you can send email from the addresses to avoid not being able to reply by email, and you will want a password-manager or something to remember exactly what email you used, for convenience.

Personally I'm glad I've done this, it's made it much easier to organize my emails.

Re: Using a catch-all domain is a mistake

#12
I strongly disagree. I've also been using a catch-all domain for more than a decade and giving each sign-up it's own name@mydomain.com. I can remember one small issue. Otherwise it's never been a problem. The problem has been getting marked as spam for running my own mailserver. But it's all worth it in the end.

Re: Using a catch-all domain is a mistake

#13
I've had some of the same experiences as the author. "Do you work for..." or "You must be a big fan..." And plenty of "How do you... "

A few sites actually check for and prevent you from putting their domain name in as email (probably something about having employees sign up... ?) so that's a bit annoying.

I think it's worth it. Among other things, if any one alias becomes tainted enough, I'll throw it on a burner account so those emails go into a black hole, instead of my spam folder. And I'm always using a password manager on a computer, rather than trying to remember email when I visit a retailer. (Often, these days, if I'm in person, I just make up some kind of abbreviation - instead of "Ollies@", "olbgo@" because I don't care too much and even if I forget where it came from, it's not a big deal.)

And there's a slight security benefit if one email + password leaks, though these days every password is unique too (was not always the case... ah the naivety of my internet youth.) I don't think email addresses get sold "a lot" but they sure do get breached a lot and end up in the hands of spammers. Cadillac@ actually got sold or breached quite quickly after I signed up for a free car brochure, about a decade ago.

With my current host (NameCheap) and Thunderbird, it's very easy to change my from address - it just works without any hassle.

Re: Using a catch-all domain is a mistake

#14

I do this and my biggest regret is that I cannot easily check haveibeenpwned.com to find out if any of the accounts have been breached.

Yes you can: https://haveibeenpwned.com/DomainSearch

Oh, nice! I didn't know about this. Thank you!

Re: Using a catch-all domain is a mistake

#15

I've been using email aliases for over a decade and have never experienced the leading examples the author mentions. Although I already have email accounts setup for impromptu scenarios, setting up an email alias in one minute is easy enough.

I have several times. Generally I can just say "you can write anything before the @ and it still comes to me" and people understand it though. It doesn't need to become a big discussion about how email works and they've probably forgotten by the end of the interaction.

Maybe once or twice I've given my address to a new friend as newfriend@domain.com and it's lead to at least a small discussion about it.

Re: Using a catch-all domain is a mistake

#16
I use "contact@" for when somebody who isn't a friend wants my email address. I have a separate, private address for people who actually matter to me. Everything addressed to "contact@" immediately gets marked as read and saved to a separate folder so it doesn't clutter my inbox.

Re: Using a catch-all domain is a mistake

#18
"The truth is no one really sells your email – at least no legitimate companies. "

Of course, because legitimate companies used to sell your cookies, which basically are going the convey the same information about your profile.

Now in the cookieless era of CDP platforms and identity stitching, having different email addresses may be more useful.

Post reply on HN