Live data from Hacker News

Using a catch-all domain is a mistake

notcheckmark.com

71–80 of 304 posts

Re: Using a catch-all domain is a mistake

#71

> The only benefit is that I'm able to tell when companies are breached before wider disclosures because I start getting spam emails sent to thatcompany@. My big problem is that this is worse than useless. I started doing unique-address-emails back in probably 2002 or 2003 and did it for around a decade before giving up. A couple of times per year I would start getting spam or similar on an email address and would kn…

As you found out, it is a waste of time to report the leak. But you can still get all the benefits of nuking that email.

Nuking the actual email was of limited benefit over time.

For whatever reason I started to get spam on my real non-aliased email address and at that point it was all bets off.

Shortly after I gave up on the tagged addresses I just moved to gmail.

Re: Using a catch-all domain is a mistake

#72
post #37

> The only benefit is that I'm able to tell when companies are breached before wider disclosures because I start getting spam emails sent to thatcompany@. My big problem is that this is worse than useless. I started doing unique-address-emails back in probably 2002 or 2003 and did it for around a decade before giving up. A couple of times per year I would start getting spam or similar on an email address and would kn…

The benefit isn't that you can tell the company they were breached. The benefit is that you can tell yourself, friends, and the public.

Meh.

Some people might want to be the name-and-shame type, but, that's not me.

Re: Using a catch-all domain is a mistake

#73

> The only benefit is that I'm able to tell when companies are breached before wider disclosures because I start getting spam emails sent to thatcompany@. My big problem is that this is worse than useless. I started doing unique-address-emails back in probably 2002 or 2003 and did it for around a decade before giving up. A couple of times per year I would start getting spam or similar on an email address and would kn…

No one said you're supposed to contact anyone about the spam. If the problem could be solved on their end, this catch-all/tagging solution wouldn't need to exist in the first place. The assumption is that people can't be trusted with your email address, so you create a way that their incompetence/malice can't hurt you, and then you go about your business. Imagine criticizing helmets because children keep falling off…

> No one said you're supposed to contact anyone about the spam.

Considering that, as far as I knew at the time, nobody was doing this at all, nobody told me any of what I was "supposed" to do. Even if they had told me what i was "supposed" to do, I generally am not good at following directions or doing what i'm supposed to do.

> Btw 90+5+5+5=105%.

Case in point.

Re: Using a catch-all domain is a mistake

#74
post #38

> The only benefit is that I'm able to tell when companies are breached before wider disclosures because I start getting spam emails sent to thatcompany@. My big problem is that this is worse than useless. I started doing unique-address-emails back in probably 2002 or 2003 and did it for around a decade before giving up. A couple of times per year I would start getting spam or similar on an email address and would kn…

Your percentages don't quite add up…

There's an additional 5% chance that I did that intentionally to be funny. Does it add up now?

Re: Using a catch-all domain is a mistake

#75

> The only benefit is that I'm able to tell when companies are breached before wider disclosures because I start getting spam emails sent to thatcompany@. My big problem is that this is worse than useless. I started doing unique-address-emails back in probably 2002 or 2003 and did it for around a decade before giving up. A couple of times per year I would start getting spam or similar on an email address and would kn…

Sounds like you were the one who made it worse than useless ie. you gave yourself more work and then resented it.

I suppose. I mostly did it as a fun experiment and stopped when it ceased to be fun.

I don't resent it or regret it, I had a lot of fun writing the software which powered it.

Re: Using a catch-all domain is a mistake

#76
post #11

I've been doing this for close to a decade and sometimes salespeople and customer service people will ask to confirm, but that takes 5 seconds and isn't awkward (in my opinion.) It has more benefits than knowing who leaked your email, it lets you easily filter your incoming email by who you gave the email to, and when your email is leaked it lets you shut off that email address. Of course you can also filter your ema…

I have a single address, donotspamme@mydomain.com that I use as a throwaway and then route it to a folder to review about once a week. It draws a chuckle from salespeople when they ask for it or see it pop up in their system.

Re: Using a catch-all domain is a mistake

#78
I agree that using per-company email address to sign up is not a good idea but I love my catch-all email address.

When I'm testing my software (professional or personal) I can "create" emails on the fly for new user accounts. Yes, with Gmail, you can do the base+anything@gmail.com trick but with my setup I never need to rely on that (or worry someone might block it), I just use anything@mydomain.com and I'm good to go.

Same for my LLC, I have a catchall so I can setup things like accounts@mydomain.com and get all those emails to my main josh@mydomain.com email address and then in the future if I need to turn that into a group or it's own email address it's super easy and forward compatible. Just like support@mydomain.com, right now I'm the only one that handles that but I can hand that off in the future if I need to without any issues at all.

Tangentially related: getting your own name as your domain name is really nice in more ways than you might think. Giving my email over the phone is a cake walk, I've normally just given them my name, then I just say "josh at joshstrange dot com" and I never have to worry about spelling or them hearing me perfectly since it's just a combination of the info I just gave them (my name). I get comments about it from time to time but buying that domain in high school was the best decision I ever made when it comes to tech/email. It's stayed the same for well over a decade and I never had to give out an embarrassing email or worry about "what email did I use to sign up for that account?".

Re: Using a catch-all domain is a mistake

#79
> I also have a bunch that I've misspelled. My GrubHub account is gruhub@. I use a password manager for passwords but I also need to use it to remember the associated emails.

I find that to be a strange complaint. What password manager is being used that doesn't support a username alongside a password in an entry?

Re: Using a catch-all domain is a mistake

#80
I did it for years, until someone started dictionary spam runs on my domain. That was a pain, so I whitelisted the ones I used, and went to email-company@domain. Works pretty well, I’ve black holed 20 or 30 over time, and it’s a decent second check on phishing emails.

Sadly, because I chose - instead of plus, I’m going to be hosting my own inbound email for the rest of this domains life. (And since it’s mylastname.net, that’s going to be a while)

Post reply on HN