Live data from Hacker News

Using a catch-all domain is a mistake

notcheckmark.com

51–60 of 304 posts

Re: Using a catch-all domain is a mistake

#51

I don't understand the part about awkwardness with customer service people. How often does that really come up? And, if it is predictable, just spend a minute and think of some satisfying reply and then use that whenever it does come up. "Oh, hilton@notcheckmark.com? You must be a big fan." "Yep, cause of the great customer service." Done. Regarding shooting yourself in the foot by using nonstandard naming - seems an…

I also use custom addresses with the company name as the first part of the address and it does sometimes (not often) lead me to explain how email works to a customer support rep.

Re: Using a catch-all domain is a mistake

#52

I try to disguise it a little to avoid the awkwardness, and also put the recipient into the subdomain instead of sender name. For example for grubhub I'd do: me@grb.mydomain.com No need to remember anything because it's all in a password manager. I've found this worthwhile, already blocked a couple spammers. You could also go with something fully random, you still get the same benefit. It's easy to look in your email…

That’s exactly how I’ve been doing it for more than a decade. (Without the subdomain part but with the disguising.) I feel it’s been worth it so far.

Re: Using a catch-all domain is a mistake

#53

I strongly disagree. I've also been using a catch-all domain for more than a decade and giving each sign-up it's own name@mydomain.com. I can remember one small issue. Otherwise it's never been a problem. The problem has been getting marked as spam for running my own mailserver. But it's all worth it in the end.

I agree with you. So many companies end up with absolutely terrible unsubscribe code that just flat out doesn't work[1]. With my own server I can just burn a particular email with one line in a file, or I can block their whole domain. I end up having to do this fairly regularly.

I can also choose the message to send in the smtp 5xx error line and so I like to call them names. I know a person never sees it but it makes me feel good knowing my server is cursing out the spammers' servers.

[1] I would venture that roughly 30% to 40% of email unsubscribe links aren't url encoded so that the `+` in the email goes in naked to the url, resulting in the server decoding it into a ` `. Sigh.

Re: Using a catch-all domain is a mistake

#54

I try to disguise it a little to avoid the awkwardness, and also put the recipient into the subdomain instead of sender name. For example for grubhub I'd do: me@grb.mydomain.com No need to remember anything because it's all in a password manager. I've found this worthwhile, already blocked a couple spammers. You could also go with something fully random, you still get the same benefit. It's easy to look in your email…

Using custom subdomains for each account is a great idea. Once you start getting spam on this subdomain, you just need to remove the DNS entry and the spammer's attempts to deliver spam will be unsuccessful (versus if you use different local part names, you have to filter / reject the mails explicitly).

Re: Using a catch-all domain is a mistake

#55

I've had sales and customer service ask me about this a handful of times and I simply said: 'It's a unique email address so that you guys can't sell my details or get hacked and lose my email.' The only interaction that stick in my mind regarding this when one of the sales people asked me how they might set up their own version of catch-all domain. That's about it.

Right? Every time someone remarks, that's a good thing.

Re: Using a catch-all domain is a mistake

#56

> The truth is no one really sells your email – at least no legitimate companies. Yes, but legitimate companies leak data now and then. I get metric tons of spam to dropbox@, linkedin@, myspace@, moneybookers@, etc.

When I used wildcard support I got spam to :

linkedin@steve.org.uk

facebook@steve.org.uk

So I'd be tempted to think that my address had been leaked from there, but I also got other messages sent to addresses like:

admin@steve.org.uk

sales@steve.org.uk

support@steve.org.uk

In the end I figured that I was just dictionary-attack, and optimistic senders, and I could never be sure that a particular company had actually leaked an address.

These days I just give steve/at/steve.fi to everybody (I moved countries, hence the new TLD). I ported over all the aliases that had received email in the past five years and started rejecting unknown local-parts. That stopped badbots from mailing things that seemed like poorly-scraped message-ids "blah-blah-1234@steve.org.uk".

Re: Using a catch-all domain is a mistake

#57
post #31

I had to stop using plus-addressing (me+brand@gmail.com) because of broken email address parsers/validators. If I was on the phone with a support agent, I would give them my plus-address and their system would reject it and they'd ask for another one. Stubbornly, I'd refuse to budge and insist that is my email address that they need to use. It got to the point where I'd either have to forfeit my healthcare/tax/flight…

GMail has supported the "+" alias since the service was announced, one would think there'd be no excuse to not support it everywhere at this point. My consipiracy-theory hypothesis is that many companies "know" that any address with a + in it is an alias and actively filter it out. Because they don't want an alias, they want your _real_ address.

I run my own mail server and use a "." as the alias character. Haven't seen a system reject a single one of these.

Re: Using a catch-all domain is a mistake

#58

> The only benefit is that I'm able to tell when companies are breached before wider disclosures because I start getting spam emails sent to thatcompany@. My big problem is that this is worse than useless. I started doing unique-address-emails back in probably 2002 or 2003 and did it for around a decade before giving up. A couple of times per year I would start getting spam or similar on an email address and would kn…

No one said you're supposed to contact anyone about the spam. If the problem could be solved on their end, this catch-all/tagging solution wouldn't need to exist in the first place. The assumption is that people can't be trusted with your email address, so you create a way that their incompetence/malice can't hurt you, and then you go about your business.

Imagine criticizing helmets because children keep falling off their bikes.

Btw 90+5+5+5=105%.

Re: Using a catch-all domain is a mistake

#59

I try to disguise it a little to avoid the awkwardness, and also put the recipient into the subdomain instead of sender name. For example for grubhub I'd do: me@grb.mydomain.com No need to remember anything because it's all in a password manager. I've found this worthwhile, already blocked a couple spammers. You could also go with something fully random, you still get the same benefit. It's easy to look in your email…

Nice! I tried this a few years ago, and while this worked nicely for inbound email, deliverability outbound was really bad, even with DKIM etc. set. Normal mails from were fine.

I guess "amazon." got quite the phishing score at the time, so good call using grb instead of grub. :D

Re: Using a catch-all domain is a mistake

#60

I've had people try to guess my login with Company ABC once they learned of my CompanyXYZ@mydomain.com address. Avoiding the reuse of email addresses helps here, the same way avoiding the reuse of passwords does. For blackhats, with catchalls you can create multiple accounts on sites that try to prevent it by assuming everyone only has 1 email address. For me the biggest drawback is migrating ALL those emails if your…

> For me the biggest drawback is migrating ALL those emails if your provider decides to end support for catchalls (like Dreamhost).

With Gmail for Business / GSuite / Workspace, I had gone through the trouble of adding aliases through the Gmail.com UI when I wanted a from address. And I had created a bunch of dead accounts with aliases to reduce spam.

But when I switched away from Workspace to NameCheap, I just set up my one account as a catch-all, and in Thunderbird, when I want to send from one of those aliases, I just type it in, and it works fine. (Gmail had a setting that if you got it wrong, it sent it as an alias, but also used your mail address as the actual from/reply-to, which I found annoying!)

I also stopped bothering setting up those "honeypot" accounts. I get more spam, but... it's almost all detected as spam and put in the spam folder, so I don't worry too much. A few weeks ago, I had a day where a couple dozen gibberish addresses came in, like 8aeef09lk@domain.com, but then it stopped again.

Of course, all that is to say, if my current host does end support, it would be a pain!

Post reply on HN