Live data from Hacker News

Using a catch-all domain is a mistake

notcheckmark.com

41–50 of 304 posts

Re: Using a catch-all domain is a mistake

#41
I don't understand the part about awkwardness with customer service people. How often does that really come up? And, if it is predictable, just spend a minute and think of some satisfying reply and then use that whenever it does come up.

"Oh, hilton@notcheckmark.com? You must be a big fan."

"Yep, cause of the great customer service."

Done.

Regarding shooting yourself in the foot by using nonstandard naming - seems an easy solution is to just use the entire SLD. If registering in person, I guess that's a bit harder, but either way make sure you save the login in your password manager.

Re: Using a catch-all domain is a mistake

#42

I’ve also been doing this for more than a decade. Other than my spouse rolling her eyes when I give an email address over the phone, it hasn’t been hard and definitely has helped. I have put blocks on a few email addresses that were involved in data breaches and became spam spigots.

I got my wife to use a catch-all last year. She absolutely loves it.

Re: Using a catch-all domain is a mistake

#43
Just to provide a counterpoint, I've been doing the same thing for 6 years now and I haven't found the same issues to be a problem. Even as someone with pretty intense social anxiety, I haven't encountered any awkwardness, and don't find it particularly inconvenient to have to look up the correct email in my password manager.

The only actual issue I can remember encountering was a weird glitch with Crashplan that wouldn't let me register with crashplan@[myfullname].com, so I ended up using backups@ instead. Also, my full name is tedious to have to spell out, so I switched to using [firstname].cloud as my email domain instead.

In my case, while I haven't caught any notable email sharing/selling, I've still found unique per-service emails useful for filtering and organizing messages. Many orgs these days don't bother to use a consistent From email, so if I want to find everything from XYZ corp, it's easier to search for everything sent to xyz@name.cloud than everything from no-reply@xyz.com and orders@xyz.com and info@xyz.net and email-list-123@xyz.email and so on and so forth.

Re: Using a catch-all domain is a mistake

#44

> The only benefit is that I'm able to tell when companies are breached before wider disclosures because I start getting spam emails sent to thatcompany@. My big problem is that this is worse than useless. I started doing unique-address-emails back in probably 2002 or 2003 and did it for around a decade before giving up. A couple of times per year I would start getting spam or similar on an email address and would kn…

As you found out, it is a waste of time to report the leak. But you can still get all the benefits of nuking that email.

Re: Using a catch-all domain is a mistake

#45
I've had people try to guess my login with Company ABC once they learned of my CompanyXYZ@mydomain.com address. Avoiding the reuse of email addresses helps here, the same way avoiding the reuse of passwords does.

For blackhats, with catchalls you can create multiple accounts on sites that try to prevent it by assuming everyone only has 1 email address.

For me the biggest drawback is migrating ALL those emails if your provider decides to end support for catchalls (like Dreamhost).

Re: Using a catch-all domain is a mistake

#48
I don't buy it. The number of people on HN that say, "it takes non-zero effort, and it was hell to exert that little bit of effort, so you shouldn't do it."

That might be a worthwhile message for a hardware hacker site where putting effort in to email configurations might be different enough from the meat of what most people are doing, but for this site? No. Don't try to sell "hacking is slightly hard, so don't do it" to hackers, please and thanks.

I've been doing individual email addresses for ages, and I've forced more than one company to disclose breaches because I was able to show with certainty that an address couldn't have been lost any other possible way.

Re: Using a catch-all domain is a mistake

#49
post #3

reminds me a bit of the family member who owns firstname@lastname.com and can't get random non technical people to believe that their email address domain really is lastname.com "but don't you mean at gmail.co..." no

There's a 199X NYTimes article about how prestigious lastname.com is. Maybe someone can find it in the archives

Re: Using a catch-all domain is a mistake

#50
Why not just use regex/wildcard addresses which makes it less "akward".

Like "mail-recruiter@foo.bar", "mail-hilton.com@foo.bar", etc.

It's easy to configure, makes it more clear that you are in fact not trying to impersonate others and you circumvent the problem of receiving automated mailes to "sales@foo.bar", "hr@foo.bar", etc.

BTW: I've been using my solution for more than five years and only had one "awkward" moment when a recruiter was a bit sore I gave them my mail address specific for cold call recruiters.

Post reply on HN