Live data from Hacker News

Using a catch-all domain is a mistake

notcheckmark.com

61–70 of 304 posts

Re: Using a catch-all domain is a mistake

#62
My HN account email is sleepy.home9993@[mydomain]. My email provider (FastMail) creates these "masked emails" at the click of a button, with a Description field so I can identify the purpose. Each email address consists of two random words plus a 4 digit number. Then I just store the information in my password manager.

I'm not wasting time trying to fix the breaches. I can just nuke that email forever.

Re: Using a catch-all domain is a mistake

#63

I don't buy it. The number of people on HN that say, "it takes non-zero effort, and it was hell to exert that little bit of effort, so you shouldn't do it." That might be a worthwhile message for a hardware hacker site where putting effort in to email configurations might be different enough from the meat of what most people are doing, but for this site? No. Don't try to sell "hacking is slightly hard, so don't do it…

It's not even hard, number of email provider do it for you. You just need to explain it to someone once every 3 years...

Re: Using a catch-all domain is a mistake

#64

I try to disguise it a little to avoid the awkwardness, and also put the recipient into the subdomain instead of sender name. For example for grubhub I'd do: me@grb.mydomain.com No need to remember anything because it's all in a password manager. I've found this worthwhile, already blocked a couple spammers. You could also go with something fully random, you still get the same benefit. It's easy to look in your email…

Nice! I tried this a few years ago, and while this worked nicely for inbound email, deliverability outbound was really bad, even with DKIM etc. set. Normal mails from were fine. I guess "amazon. " got quite the phishing score at the time, so good call using grb instead of grub. :D

Yeah deliverability is a good point. I'm usually only using this trick for services where I wouldn't be sending outbound email luckily. Normal emails come from mydomain.com.

Re: Using a catch-all domain is a mistake

#65
I'm also doing this and see multiple benefits.

However I've recently been bitten by my catch-all, using a money transfer service with the email worldremit@mycatchall.com (guess the company). When they asked for additional documents to verify my account after many months, they never received my reply and I ended up banned. I could not login anymore. When I reached out from another email address, they refused to process the documents because they originated from another, unauthorized email address, and asked that I resent the original email from the registered email. I suspect their anti-phishing filters just ban any email containing "worldremit", so it never got through and despite multiple thorough explanations I could never get someone to listen or reinstate the account.

I'm still getting the newsletter though, because unsubscribing requires logging in first... But then I can just ban this email address, so at least the anti-spam strategy works!

Re: Using a catch-all domain is a mistake

#66
I do this and haven't had nearly as many problems as the author for a couple of reasons. First, I refuse to give out my email in most of the situations he complains about. I almost never want or need to link my physical retail purchases to an email address, and in the cases where I do, it is usually faster and easier to ask for a loyalty packet and sign up online than to dictate all the information to a clerk.

Second, I'm not strict about it, and use a generic address (my-formal-name@example.com) in situations where I do need to give an email verbally (like contractors asking where to send a quote). And I also have my-nick-name@example.com which I give to friends and family.

Since I only use the catch-all emails for things I do online, they are all stored in a password manager so I don't have any problem forgetting them.

With these more relaxed rules, I still end up using a catchall email the vast majority of the time, with a fraction of the annoyances. The only time it really comes up is for telephone support calls with accounts I created online, and it isn't a big deal.

The benefit is that I can block 90% of spam using nothing but a black list of address that have been compromised. And the novelty of knowing who has shitty security with my information.

Re: Using a catch-all domain is a mistake

#67
post #40

I'm going to mirror most of the other commenters in saying - I've been doing this for nearly a decade and have basically never had an issue with it and have absolutely prevented some spam because of it. The "social awkwardness" problem of using "Company@example.com" can be solved by using "PineappleBanana@example.com" instead or random characters or my personal favorite throwaway "[Company]SentMeSpam@example.com". Ye…

No need to use a password manager. Simply search email history for the very first usage of the email...

Re: Using a catch-all domain is a mistake

#68
For weeks our Shopify app was getting rejected because "you cannot use the Shopify name or trademark in your app". It wasn't... repeated requests for clarification just got back the same form response.

After a several frustrating back-and-forths, finally someone at Shopify said "check your email address".

The developer contact email address we had submitted, which was only used for shopifyus communication and no customer would ever see, was shopify@ourdomain.com.

Re: Using a catch-all domain is a mistake

#69
For people who are having problem with the "hilton@domain.com" situation, consider using ROT13 or some other similar scheme (hilton becomes uvygba).

Other alternatives include:

1. shorten it so much that it's not revealing anymore (hil@domain.com)

2. use another language if you're multilingual (hiruton@domain.com for Japanese)

Re: Using a catch-all domain is a mistake

#70
I had the exact same experience! Almost verbatim. Nowadays, after one very long weekend spent changing my email address across dozens of different websites and services, I just use name@name.red instead of anything service-specific. Even now, though, the fact that it's a ".red" rather than a ".com" is too much for some people (e.g., my student loan servicer doesn't support .red domains at all). It's fun being special until it isn't.
Post reply on HN