Live data from Hacker News

Using a catch-all domain is a mistake

notcheckmark.com

101–110 of 304 posts

Re: Using a catch-all domain is a mistake

#101

I agree that using per-company email address to sign up is not a good idea but I love my catch-all email address. When I'm testing my software (professional or personal) I can "create" emails on the fly for new user accounts. Yes, with Gmail, you can do the base+anything@gmail.com trick but with my setup I never need to rely on that (or worry someone might block it), I just use anything@mydomain.com and I'm good to g…

Lucky you mister Josh Strange. If however, like myself, you have a name like Mr Fair lyPopularNameNoOneInBritainCanSpellCorrectly IncomprehensibleItalianOrSpanishOrSomethingEuropeanFamilyNameNoBritHearingItWillEverAssumeStartsWithTheLetterItActuallyDoes, it's the epitome of tedium every time you have to get someone on the phone or in person to spell your name correctly. My wife fucking hates it that she switched from…

Totally fair criticism of my statement and I apologize for not taking into account names that are harder to spell or hear correctly.

I am very thankful that I don’t have those issues but yes, my advice doesn’t hold up in those situations.

Re: Using a catch-all domain is a mistake

#102

I try to disguise it a little to avoid the awkwardness, and also put the recipient into the subdomain instead of sender name. For example for grubhub I'd do: me@grb.mydomain.com No need to remember anything because it's all in a password manager. I've found this worthwhile, already blocked a couple spammers. You could also go with something fully random, you still get the same benefit. It's easy to look in your email…

Note some services won't even recognize a subdomain email address as valid.

Really? Wouldn't that catch people with `.co.uk` or similar localized domains?

Re: Using a catch-all domain is a mistake

#103
I have not encountered the author's 2nd issue because I use a password manager.

I have encountered their 1st issue (awkward encounters) and consider it a feature. I guess this depends on certain extro/intro-vert-ish human preferences, but it can be a nice talking point if you approach it right.

The author's argument can be generalised to an appeal to normativity - doing ANYTHING that isn't common practice will garner awkward interactions. It's also a necessary early-adopter stage of anything eventually becoming common practice (and catch-all domains are becoming an automatically supported feature in many services now so here's hoping it does).

Re: Using a catch-all domain is a mistake

#104
post #11

I've been doing this for close to a decade and sometimes salespeople and customer service people will ask to confirm, but that takes 5 seconds and isn't awkward (in my opinion.) It has more benefits than knowing who leaked your email, it lets you easily filter your incoming email by who you gave the email to, and when your email is leaked it lets you shut off that email address. Of course you can also filter your ema…

Eh, I did it for a while and while I think the OP overstated the "awkwardness," I didn't find that the effort was worthwhile. I only caught one entity selling or otherwise divulging my address: the Atlanta Journal-Constitution newspaper, oddly enough.

Oh, and someone did hack some FAA database and mine it for addresses.

But that's all I netted in several years. Beyond my main address at my own domain, I keep a Gmail address for mailing lists and other low-grade traffic.

Re: Using a catch-all domain is a mistake

#105
post #93

I've been doing this for over 20 years, and it hasn't really been a problem. During the occasional real-life interaction that requires someone to confirm my address and they express surprise, I just tell them that it's correct and I have advanced email needs. It never takes more than a few seconds -- nobody has ever said "please tell me all about your advanced email needs!" :) > I use a password manager for passwords…

I’ve been offered the employee discount multiple times when providing storename@firstlast.tld. I declined as I’m not going to risk fighting some fraud charge over €20.

I’ve never had difficult or negative interactions either. “I bought @firstlast.tld and now I can do whatever I want” settles it.

I also have @lastna.me. My grandma has her own and mostly her bridge club mates are puzzled about how her email address just looks like her name. The whole setup is worth a few bucks, I guess.

Re: Using a catch-all domain is a mistake

#106
I've been using a similar system, only that I additionally append a random 5 digit number, so that if e.g. hilton-68425@domain.org gets leaked, that doesn't automatically make hyatt-95813@domain.org easy to guess. Though it does sound like something that might be possible to brute force.

Also, they feed into different subfolders of the same main address.

It definitely has caused some issues, but nothing that would make me regret choosing this system. Obviously the email gets stored in the password manager. And even if not, I just look at the existing emails and check their destination address.

Honestly, the most annoying part is the setup of new addresses. I might look into a way to automate that.

Although it is true that I have not caught a single company giving the email away, but it still helps me keep the inbox organized.

Re: Using a catch-all domain is a mistake

#107
Have to say, disagree with every single point. It also feels poorly argued. The example about not being able to log into grubhub stuck out to me within 20 seconds of reading. He says he uses a password manager, then says he has to navigate many accounts while trying to login. Any sane password manager is not simply a list of emails and passwords, but also the SITES they BELONG to. This can't have happened the way he describes it.

Also, in particular, I can't understand the social awkwardness. I don't see how the interactions he has described are awkward in any way. OK, once in a while you have to explain yourself. Sometimes you might have a laugh about it. 95% of the time you just repeat yourself and move on. There's nothing awkward here. Unless he's using a different definition of awkward, as well as social.

Re: Using a catch-all domain is a mistake

#108

Earlier quoted context omitted.

Lucky you mister Josh Strange. If however, like myself, you have a name like Mr Fair lyPopularNameNoOneInBritainCanSpellCorrectly IncomprehensibleItalianOrSpanishOrSomethingEuropeanFamilyNameNoBritHearingItWillEverAssumeStartsWithTheLetterItActuallyDoes, it's the epitome of tedium every time you have to get someone on the phone or in person to spell your name correctly. My wife fucking hates it that she switched from…

Totally fair criticism of my statement and I apologize for not taking into account names that are harder to spell or hear correctly. I am very thankful that I don’t have those issues but yes, my advice doesn’t hold up in those situations.

No worries, I was a light hearted rebuttal!

I always found the firstname@lastname.com to confuse people far more than the name itself. I often get questions like "is that at gmail.com or hotmail.com or...?"

Re: Using a catch-all domain is a mistake

#109
I've been doing this for 5 years and while I agree that leaks are rare, it has been only smooth sailing.

I use thunderbird with an addon that automatically sets the responding email address, and have a script called "email" that generates a random address (no prefix or anything) and puts it in my clipboard. If I want to k ow what I used an email for, I can find it in my password manager or by checking from where that address first got mail.

Signing things up in person, I just use human-randomly generated strings.

In short: I have none of the problems the author has...

Re: Using a catch-all domain is a mistake

#110
I wish there was a simple equivalent for phone numbers. Even if I had to pay Too many services now need a phone number "for my security". I use my Google Voice whenever I can but there is no way to trace the leaker from that. Car dealerships appear to be a big source of leaks in my experience (significant uptick in spam calls and texts after I give a dealership my GV number).
Post reply on HN