I don't understand the part about awkwardness with customer service people. How often does that really come up? And, if it is predictable, just spend a minute and think of some satisfying reply and then use that whenever it does come up. "Oh, hilton@notcheckmark.com? You must be a big fan." "Yep, cause of the great customer service." Done. Regarding shooting yourself in the foot by using nonstandard naming - seems an…
Using a catch-all domain is a mistake
51–60 of 304 posts
Re: Using a catch-all domain is a mistake
#52I try to disguise it a little to avoid the awkwardness, and also put the recipient into the subdomain instead of sender name. For example for grubhub I'd do: me@grb.mydomain.com No need to remember anything because it's all in a password manager. I've found this worthwhile, already blocked a couple spammers. You could also go with something fully random, you still get the same benefit. It's easy to look in your email…
Re: Using a catch-all domain is a mistake
#53I strongly disagree. I've also been using a catch-all domain for more than a decade and giving each sign-up it's own name@mydomain.com. I can remember one small issue. Otherwise it's never been a problem. The problem has been getting marked as spam for running my own mailserver. But it's all worth it in the end.
I can also choose the message to send in the smtp 5xx error line and so I like to call them names. I know a person never sees it but it makes me feel good knowing my server is cursing out the spammers' servers.
[1] I would venture that roughly 30% to 40% of email unsubscribe links aren't url encoded so that the `+` in the email goes in naked to the url, resulting in the server decoding it into a ` `. Sigh.
Re: Using a catch-all domain is a mistake
#54I try to disguise it a little to avoid the awkwardness, and also put the recipient into the subdomain instead of sender name. For example for grubhub I'd do: me@grb.mydomain.com No need to remember anything because it's all in a password manager. I've found this worthwhile, already blocked a couple spammers. You could also go with something fully random, you still get the same benefit. It's easy to look in your email…
Re: Using a catch-all domain is a mistake
#55I've had sales and customer service ask me about this a handful of times and I simply said: 'It's a unique email address so that you guys can't sell my details or get hacked and lose my email.' The only interaction that stick in my mind regarding this when one of the sales people asked me how they might set up their own version of catch-all domain. That's about it.
Re: Using a catch-all domain is a mistake
#56> The truth is no one really sells your email – at least no legitimate companies. Yes, but legitimate companies leak data now and then. I get metric tons of spam to dropbox@, linkedin@, myspace@, moneybookers@, etc.
linkedin@steve.org.uk
facebook@steve.org.uk
So I'd be tempted to think that my address had been leaked from there, but I also got other messages sent to addresses like:
admin@steve.org.uk
sales@steve.org.uk
support@steve.org.uk
In the end I figured that I was just dictionary-attack, and optimistic senders, and I could never be sure that a particular company had actually leaked an address.
These days I just give steve/at/steve.fi to everybody (I moved countries, hence the new TLD). I ported over all the aliases that had received email in the past five years and started rejecting unknown local-parts. That stopped badbots from mailing things that seemed like poorly-scraped message-ids "blah-blah-1234@steve.org.uk".
Re: Using a catch-all domain is a mistake
#57I had to stop using plus-addressing (me+brand@gmail.com) because of broken email address parsers/validators. If I was on the phone with a support agent, I would give them my plus-address and their system would reject it and they'd ask for another one. Stubbornly, I'd refuse to budge and insist that is my email address that they need to use. It got to the point where I'd either have to forfeit my healthcare/tax/flight…
I run my own mail server and use a "." as the alias character. Haven't seen a system reject a single one of these.
Re: Using a catch-all domain is a mistake
#58> The only benefit is that I'm able to tell when companies are breached before wider disclosures because I start getting spam emails sent to thatcompany@. My big problem is that this is worse than useless. I started doing unique-address-emails back in probably 2002 or 2003 and did it for around a decade before giving up. A couple of times per year I would start getting spam or similar on an email address and would kn…
Imagine criticizing helmets because children keep falling off their bikes.
Btw 90+5+5+5=105%.
Re: Using a catch-all domain is a mistake
#59I try to disguise it a little to avoid the awkwardness, and also put the recipient into the subdomain instead of sender name. For example for grubhub I'd do: me@grb.mydomain.com No need to remember anything because it's all in a password manager. I've found this worthwhile, already blocked a couple spammers. You could also go with something fully random, you still get the same benefit. It's easy to look in your email…
I guess "amazon." got quite the phishing score at the time, so good call using grb instead of grub. :D
Re: Using a catch-all domain is a mistake
#60I've had people try to guess my login with Company ABC once they learned of my CompanyXYZ@mydomain.com address. Avoiding the reuse of email addresses helps here, the same way avoiding the reuse of passwords does. For blackhats, with catchalls you can create multiple accounts on sites that try to prevent it by assuming everyone only has 1 email address. For me the biggest drawback is migrating ALL those emails if your…
With Gmail for Business / GSuite / Workspace, I had gone through the trouble of adding aliases through the Gmail.com UI when I wanted a from address. And I had created a bunch of dead accounts with aliases to reduce spam.
But when I switched away from Workspace to NameCheap, I just set up my one account as a catch-all, and in Thunderbird, when I want to send from one of those aliases, I just type it in, and it works fine. (Gmail had a setting that if you got it wrong, it sent it as an alias, but also used your mail address as the actual from/reply-to, which I found annoying!)
I also stopped bothering setting up those "honeypot" accounts. I get more spam, but... it's almost all detected as spam and put in the spam folder, so I don't worry too much. A few weeks ago, I had a day where a couple dozen gibberish addresses came in, like 8aeef09lk@domain.com, but then it stopped again.
Of course, all that is to say, if my current host does end support, it would be a pain!