Live data from Hacker News

Using a catch-all domain is a mistake

notcheckmark.com

91–100 of 304 posts

Re: Using a catch-all domain is a mistake

#91
I was purchasing a car at local Honda dealership and the salesman refused to believe that my email address was honda@mydomain.com. He just insisted that I should tell him my "real" email address. If it happens today, I would just walk away. But back then I was a new grad who just got a new job and really wanted a new car in a new city, so I said "fine, does mylastname@mydomain.com sound more legit?" He was ok with that. I brought the car back home, and set a new inbox rule that blocks all emails to mylastname@mydomain.com. Because I can't think of a reason to use mylastname@mydomain.com in any cases. I have never heard anything from Honda ever again.

I once got a text message from an agent after a dealership visit, he asked me why I just couldn't give him a good feedback since he worked so hard and I seemed to be happy with the result. I was like "sorry, but for some reason I can't receive emails from Honda, including after-visit survey".

> The truth is no one really sells your email – at least no legitimate companies.

Speaking of this, I actually did sometimes catch someone sold or leaked my email addresses. They usually came from spam emails with "Undisclosed recipients" that I had to dig into headers to find out which one of my addresses was leaked.

Most of addresses used in spams are the ones I shared with individual/small business and I would like to believe that they were not intentional.

The only legit, big company that sold/leaked my email was Docker. I applied for a new job with docker@mydomain.com and a year later a bunch of recruiting spams came to me via that address. Although it was possible that it's just that particular recruiter forgot to shred my resume after I rejected their interview invite.

Re: Using a catch-all domain is a mistake

#92

> The only benefit is that I'm able to tell when companies are breached before wider disclosures because I start getting spam emails sent to thatcompany@. My big problem is that this is worse than useless. I started doing unique-address-emails back in probably 2002 or 2003 and did it for around a decade before giving up. A couple of times per year I would start getting spam or similar on an email address and would kn…

[deleted]

Re: Using a catch-all domain is a mistake

#93
I've been doing this for over 20 years, and it hasn't really been a problem. During the occasional real-life interaction that requires someone to confirm my address and they express surprise, I just tell them that it's correct and I have advanced email needs. It never takes more than a few seconds -- nobody has ever said "please tell me all about your advanced email needs!" :)

> I use a password manager for passwords but I also need to use it to remember the associated emails.

I do this, too. It never occurred to me that you might not populate the email/username field -- it's kind of the password manager's job to keep track of that. :)

> The truth is no one really sells your email – at least no legitimate companies.

I think that on the whole, this is true. However, I have had a number of these addresses start receiving spam over the years. I think this is due to the companies' databases being compromised due to poor security. At the end of the day, the cause of the leak isn't greatly important, and I'm glad I can simply turn off those particular addresses.

Re: Using a catch-all domain is a mistake

#94
The only issue I've had was with that real estate data website that rhymes with Willow. They have a strict policy against usernames that contain their branding and my first support ticket resulted in them demanding I change my E-mail address.

Re: Using a catch-all domain is a mistake

#95
bulls*hit.

1)

It's true that trying to use a "pure" solution ("[source]@[yourdoma.in]" - e.g. "amazon@mydomain.com") causes a lot of problems (red flags being issued on the remote site).

On the other hand with a mixed solution ("[partial_source_mixed_with_something_else]@[yourdoma.in]" - e.g. "zeama@mydomain.com") I never had any problems (I anyway keep files/keepass-entries to track which userid&pwd&email I'm using for which URL).

2a)

My common&real email address gets quite some spam (no filtering applied) (but I admit that the amount during the last years was stable).

2b)

My custom email addresses almost never get spam (even the ones that I used for "weird" sites) => I assume that whoever gets in some way email addresses performs some kind of healthcheck on them to get rid of the ones that might identify the source (from where they were extracted).

2c)

The few spam emails that I got during the last years on my custom email addresses indicated that they originated from 1) the garage which I use to swap winter/summer tires and 2) my doctor (?!) => it was interesting (e.g. is my doctor's IT compromised + did the garage sell my email address because I didn't visit them during the last two years?) => anyway changing address (which got rid of the spam) was super easy in these cases :)

Re: Using a catch-all domain is a mistake

#96
I have stuff like "info@" "register@" or "support@" that I filter through in my inbox. The only problem I've had with catch-call email is getting a ton more spam from bots... for some reason they'll add randomname@ bc our name shows up with some other company name, some spam CRMs will confuse some other company's staff with our email address and send to that address

Re: Using a catch-all domain is a mistake

#97

I agree that using per-company email address to sign up is not a good idea but I love my catch-all email address. When I'm testing my software (professional or personal) I can "create" emails on the fly for new user accounts. Yes, with Gmail, you can do the base+anything@gmail.com trick but with my setup I never need to rely on that (or worry someone might block it), I just use anything@mydomain.com and I'm good to g…

Lucky you mister Josh Strange.

If however, like myself, you have a name like Mr Fair lyPopularNameNoOneInBritainCanSpellCorrectly IncomprehensibleItalianOrSpanishOrSomethingEuropeanFamilyNameNoBritHearingItWillEverAssumeStartsWithTheLetterItActuallyDoes, it's the epitome of tedium every time you have to get someone on the phone or in person to spell your name correctly.

My wife fucking hates it that she switched from her easy, unmistakable English family name to my shit show of a Phonetic spelling exercise.

I guarantee I'd never receive a single spam message because nobody is EVER spelling my FirstnameLastname.com correctly, Mr MyNameExistsInAutocorrect Strange.

Jokes aside, seriously, my family name starts with "El" and the second you start saying it you see people write "L" and pause.

Re: Using a catch-all domain is a mistake

#98

I did it for years, until someone started dictionary spam runs on my domain. That was a pain, so I whitelisted the ones I used, and went to email-company@domain. Works pretty well, I’ve black holed 20 or 30 over time, and it’s a decent second check on phishing emails. Sadly, because I chose - instead of plus, I’m going to be hosting my own inbound email for the rest of this domains life. (And since it’s mylastname.ne…

> Sadly, because I chose - instead of plus, I’m going to be hosting my own inbound email for the rest of this domains life.

What do you mean? I use migadu and they support address aliases with wildcards, so I could just alias something-* to something@example.com and add a sieve script to sort it into a corresponding folder. I assume most email hosts do not support that, but I doubt they are the only one.

Re: Using a catch-all domain is a mistake

#100
post #91

I was purchasing a car at local Honda dealership and the salesman refused to believe that my email address was honda@mydomain.com. He just insisted that I should tell him my "real" email address. If it happens today, I would just walk away. But back then I was a new grad who just got a new job and really wanted a new car in a new city, so I said "fine, does mylastname@mydomain.com sound more legit?" He was ok with th…

> Most of addresses used in spams are the ones I shared with individual/small business and I would like to believe that they were not intentional.

Sounds very much like the computers/address books of the business owners get compromised and harvested.

Post reply on HN