Live data from Hacker News

Using a catch-all domain is a mistake

notcheckmark.com

31–40 of 304 posts

Re: Using a catch-all domain is a mistake

#31
I had to stop using plus-addressing (me+brand@gmail.com) because of broken email address parsers/validators. If I was on the phone with a support agent, I would give them my plus-address and their system would reject it and they'd ask for another one. Stubbornly, I'd refuse to budge and insist that is my email address that they need to use. It got to the point where I'd either have to forfeit my healthcare/tax/flight/ account or give up on the plus-address. And if they asked about it, I'd explain honestly that it's because I don't trust them.

It did reveal some interesting data leaks sometimes including on npm [1], but the hassle wasn't worth it.

I now rely solely on spam controls again.

[1]: https://twitter.com/mholt6/status/1315743799335763968

Re: Using a catch-all domain is a mistake

#32
post #25

I use "contact@" for when somebody who isn't a friend wants my email address. I have a separate, private address for people who actually matter to me. Everything addressed to "contact@" immediately gets marked as read and saved to a separate folder so it doesn't clutter my inbox.

contact@ specifically is high up in things that spammers try when they have no leads to go on though. ~50% of my spam in my catchall comes from contact@ admin@ and similar addresses.

True, but I can't be bothered to come up with anything more distinctive. And if my local gym wants to send me bullshit notifications and advertisements despite me being a longtime customer who pays for his membership annually, they can damn well go in the spam bucket alongside the cold emails from tech recruiters, Ukrainian mail-order brides, and Danielle Kennedy from Prime Equity Funding. I don't really give a shit. Email has achieved parity with snail mail: it's nice to get from friends, but otherwise an annoyance.

Re: Using a catch-all domain is a mistake

#33
post #11

I've been doing this for close to a decade and sometimes salespeople and customer service people will ask to confirm, but that takes 5 seconds and isn't awkward (in my opinion.) It has more benefits than knowing who leaked your email, it lets you easily filter your incoming email by who you gave the email to, and when your email is leaked it lets you shut off that email address. Of course you can also filter your ema…

Moreso, it's good to teach people that valid email address are in fact valid.

This part:

> Especially since all these companies ask for and verify your cell phone number

is true, though.

and

> The one outlier is political campaigns: they'll share your email till the end of time.

Because politicians exempted themselved from anti-spam laws, as they do with most laws.

Re: Using a catch-all domain is a mistake

#34
I’ve also been doing this for more than a decade. Other than my spouse rolling her eyes when I give an email address over the phone, it hasn’t been hard and definitely has helped. I have put blocks on a few email addresses that were involved in data breaches and became spam spigots.

Re: Using a catch-all domain is a mistake

#35
post #11

I've been doing this for close to a decade and sometimes salespeople and customer service people will ask to confirm, but that takes 5 seconds and isn't awkward (in my opinion.) It has more benefits than knowing who leaked your email, it lets you easily filter your incoming email by who you gave the email to, and when your email is leaked it lets you shut off that email address. Of course you can also filter your ema…

I couldn't agree more. I've been using a catch-all for probably 12 years now. Sure, sometimes you get a second look when you give an email that has the business's name in it, but who cares?

I get the benefit of blocking mail coming to me forever, doing fast sorts and searches, never have to worry if the company doesn't like a + in my email address.

Re: Using a catch-all domain is a mistake

#36

"The truth is no one really sells your email – at least no legitimate companies. " Of course, because legitimate companies used to sell your cookies, which basically are going the convey the same information about your profile. Now in the cookieless era of CDP platforms and identity stitching, having different email addresses may be more useful.

This isn't a new thing. Data brokers have been building identity profiles for decades. Snarfing up email addresses is part of that process.

Re: Using a catch-all domain is a mistake

#37

> The only benefit is that I'm able to tell when companies are breached before wider disclosures because I start getting spam emails sent to thatcompany@. My big problem is that this is worse than useless. I started doing unique-address-emails back in probably 2002 or 2003 and did it for around a decade before giving up. A couple of times per year I would start getting spam or similar on an email address and would kn…

The benefit isn't that you can tell the company they were breached. The benefit is that you can tell yourself, friends, and the public.

Re: Using a catch-all domain is a mistake

#38

> The only benefit is that I'm able to tell when companies are breached before wider disclosures because I start getting spam emails sent to thatcompany@. My big problem is that this is worse than useless. I started doing unique-address-emails back in probably 2002 or 2003 and did it for around a decade before giving up. A couple of times per year I would start getting spam or similar on an email address and would kn…

Your percentages don't quite add up…

Re: Using a catch-all domain is a mistake

#39

> The only benefit is that I'm able to tell when companies are breached before wider disclosures because I start getting spam emails sent to thatcompany@. My big problem is that this is worse than useless. I started doing unique-address-emails back in probably 2002 or 2003 and did it for around a decade before giving up. A couple of times per year I would start getting spam or similar on an email address and would kn…

Sounds like you were the one who made it worse than useless ie. you gave yourself more work and then resented it.

Re: Using a catch-all domain is a mistake

#40
I'm going to mirror most of the other commenters in saying - I've been doing this for nearly a decade and have basically never had an issue with it and have absolutely prevented some spam because of it. The "social awkwardness" problem of using "Company@example.com" can be solved by using "PineappleBanana@example.com" instead or random characters or my personal favorite throwaway "[Company]SentMeSpam@example.com". Yea, you might have to use a password manager to know which random string of nouns is tied to what account - but no more "social awkwardness" of using the company name in your email (can't say I've ever had that experience either...)

In fact the only issues I've ever had with a "non-standard" email address (aka: not @gmail, @yahoo, @hotmail, etc.) is that one of my domains is a .ru address and even before the modern-day issues surrounding Russia .ru addresses get blocked in many places. My fallback email is an email hosted by https://cock.li which being chan-adjacent also gets blocked so occasionally I simply have to accept that I am not wanted as a user because my email isn't good enough.

Post reply on HN