Live data from Hacker News

Using a catch-all domain is a mistake

notcheckmark.com

111–120 of 304 posts

Re: Using a catch-all domain is a mistake

#111
I've been doing this for well over a decade and while I had similar experiences sometimes, I don't see how this was a mistake by any means. Yep, not many companies sell or leak your email, but some do. And let's not forget that 10+ years ago we had much worse spam filters. (Though we had less spam as well.) And using a unique email for each provider and company it's pretty easy to block them when they start spamming you or when they give away your address.

In theory, one could use generated addresses in some cases. E.g. for throw away ones or when you have to give it in person. The problem is that then you'd have to keep track which one you gave to whom.

It also helps with filtering as services may change the from address or use multiple from addresses while you may want to label all email from them the same.

Then in some cases, where you do want to make your email public still you want to know how people found you. I think this one would be called "role based addresses". E.g. I think it's pretty nice to have your paypal address as paypal@yourdomain.com (when people were still using them for a lack of alternatives), same for github, etc.

Re: Using a catch-all domain is a mistake

#112

I wish there was a simple equivalent for phone numbers. Even if I had to pay Too many services now need a phone number "for my security". I use my Google Voice whenever I can but there is no way to trace the leaker from that. Car dealerships appear to be a big source of leaks in my experience (significant uptick in spam calls and texts after I give a dealership my GV number).

Can you do it with twilio?

Re: Using a catch-all domain is a mistake

#113

I wish there was a simple equivalent for phone numbers. Even if I had to pay Too many services now need a phone number "for my security". I use my Google Voice whenever I can but there is no way to trace the leaker from that. Car dealerships appear to be a big source of leaks in my experience (significant uptick in spam calls and texts after I give a dealership my GV number).

this doesn't solve the SMS 2FA problem but if you know what you're doing with voip you can set up a DID to answer with a filtering message like "please press 8675 to be connected", and it'll only ring your actual phone if somebody follows the instructions. cuts down on 98% of telemarketing and scams.

then only give out the DID number not your direct phone to things like car dealerships.

i had one car dealership that I took my car to for an oil change one time that persisted in sales calls for six months until I finally escalated the matter to their general manager.

Re: Using a catch-all domain is a mistake

#114

I wish there was a simple equivalent for phone numbers. Even if I had to pay Too many services now need a phone number "for my security". I use my Google Voice whenever I can but there is no way to trace the leaker from that. Car dealerships appear to be a big source of leaks in my experience (significant uptick in spam calls and texts after I give a dealership my GV number).

this doesn't solve the SMS 2FA problem but if you know what you're doing with voip you can set up a DID to answer with a filtering message like "please press 8675 to be connected", and it'll only ring your actual phone if somebody follows the instructions. cuts down on 98% of telemarketing and scams. then only give out the DID number not your direct phone to things like car dealerships. i had one car dealership that…

Such thing do exist in some countries. I remember one of my relatives protected their phone number by adding an incoming call password.

Re: Using a catch-all domain is a mistake

#115

I try to disguise it a little to avoid the awkwardness, and also put the recipient into the subdomain instead of sender name. For example for grubhub I'd do: me@grb.mydomain.com No need to remember anything because it's all in a password manager. I've found this worthwhile, already blocked a couple spammers. You could also go with something fully random, you still get the same benefit. It's easy to look in your email…

What do you use to manage all the subdomains?

Re: Using a catch-all domain is a mistake

#116
I’ve done this for 30 years. I didn’t do it to catch people selling my info, but I do enjoy it when I do. I do it so they don’t send me email to my personal email address which I only give to people I want to email me. I can also blackhole someone that’s marketing to much and it is easy to search my email for any correspondence to and from that vendor.

It is awkward sometimes when I say It on the phone but I’m also in senior leadership at a big company so my skin is about as thick as it comes with regards to awkward situations. My entire career now is a series of awkward situations I’m asked to fix.

Also, I use a password manager (dude it’s 2022, if you’re not using a unique password already you ought to reconsider your life choices and once your password is unique who cares if your email is too?)

Re: Using a catch-all domain is a mistake

#117
Cringe take, but fair enough on the bank freaking out part.

My interaction with them went like this:

>staff: And what's your email address? >me: $BANK_NAME@$MY_DOMAIN >staff: chuckles

And on the next day I got my bank account flagged.

Edit: Turns out the restriction was not related to the email address. It was a red Canadian bank.

I would say large banks like Citibank, DBS or HSBC would never care to this since all external emails are written to have a huge 'EXTERNAL' in the subject and a disclaimer before the content.

Re: Using a catch-all domain is a mistake

#118
post #93

I've been doing this for over 20 years, and it hasn't really been a problem. During the occasional real-life interaction that requires someone to confirm my address and they express surprise, I just tell them that it's correct and I have advanced email needs. It never takes more than a few seconds -- nobody has ever said "please tell me all about your advanced email needs!" :) > I use a password manager for passwords…

The USPS is one of the worst offenders for selling email addresses.

Re: Using a catch-all domain is a mistake

#119
I use catchall domain for... everything. Every account at every entity has its own unique address, since probably well before 2010. I have always more than happily accepted to have my address saved into marketing databases.

I can share the frustration sometimes with employees turned sudden internet experts and "teaching" me that my email address cannot start with their employer's name. I usually retaliate by withdrawing my consent to be registered into their database.

And that ends there, I disagree with everything else in the blog post.

1. Catchall facilitates blacklisting when it becomes necessary: whatever rotating address is used by the sender, I blacklist myself as the recipient.

2. It helps detect who shares databases with whom. This is not necessarily about "selling" but more often it taught me which companies operate with which companies under the umbrella of that "and our partners" statement found in every privacy policy written by legal consulting firms.

3. It's a smoking gun for companies wbo get hacked without even knowing it. I have been informed several times of a compromise before the company itself knew it.

4. I also use suffixes on my catchall addresses, this allows me optimize my email filters.

5. It makes correlation more difficult across databases and anything that helps achieving this goal is a win for me.

6. I use a password manager, I use both the login and the password fields. The title of the entry always allowed me to find the account very efficiently.

I can probably find other reasons, I'd just conclude that after more than 10 years using a catchall domain, I still can't imagine sharing the same identifier across all my interactions.

Re: Using a catch-all domain is a mistake

#120
I'm using catch all since forever. I regret nothing.

Two stories:

I don't use mails like facebook@domain uber@domain - that's too obvious. And knowing that may often disclose that I actually have an account registered on given page. I don't want that, so I go full random, using few words I have in mind, current few words from the song I'm listening too, etc. So password manager helps me with e-mails too.

But Sometimes when a website annoys me (stupid rules for passwords, crippled UX for forms, because re-writing a select component in javascript is such a brilliant idea, etc) I tend to insult the company I'm registering with using my e-mail or password, I mean mail: this.freaking.store.is.dumb@domain.com and pass: goDieInPain1312323$$$$. Once I registered account for a supermarket loyality card with some very little insult towards the supermarket. Later I got some huge amount of the points collected and their system crashed and I had to contact the support (the bonus was too high for me to give up on that). First via e-mail then via phone, when they were confirming my address. They helped me and said nothing about the name I was using.

Another story:

When I started with catch-all I was actually using mails like companyname@mydomain, and when I once contacted them via phone the person talking with me was not very into tech I think and were accusing me of... I don't really know exactly, but she told me something about me using their stuff without their acceptance, when I tried to explain that's my own domain she told me I cannot use their name, because that's a copyright infringement. Weird.

Post reply on HN