Live data from Hacker News

Using a catch-all domain is a mistake

notcheckmark.com

141–150 of 304 posts

Re: Using a catch-all domain is a mistake

#141

Earlier quoted context omitted.

Note some services won't even recognize a subdomain email address as valid.

Really? Wouldn't that catch people with `.co.uk` or similar localized domains?

Technically .co.uk is a TLD [1], not a subdomain.

[1] https://wiki.mozilla.org/Public_Suffix_List

Re: Using a catch-all domain is a mistake

#142
post #120

I'm using catch all since forever. I regret nothing. Two stories: I don't use mails like facebook@domain uber@domain - that's too obvious. And knowing that may often disclose that I actually have an account registered on given page. I don't want that, so I go full random, using few words I have in mind, current few words from the song I'm listening too, etc. So password manager helps me with e-mails too. But Sometime…

I have a couple too:

Panicked phone call from a jeweller who wanted to know how and why '[their] domain was in my email address'; think he sort of understood once I explained, but still said something like 'can't be too careful in this business' - well sure ok but what am I going to do with.. oh nevermind!

Password lockout/reset over the phone, reading my 100ch 'memorable phrase' as generated by pass... Gave the guy a good chuckle, and no he was not willing to concede by the umpteenth 'upper case A' or 'backward slash' that I obviously 'knew' the phrase and could surely be relieved from reciting the entire thing... I use shorter ones now.

Re: Using a catch-all domain is a mistake

#143
post #40

I'm going to mirror most of the other commenters in saying - I've been doing this for nearly a decade and have basically never had an issue with it and have absolutely prevented some spam because of it. The "social awkwardness" problem of using "Company@example.com" can be solved by using "PineappleBanana@example.com" instead or random characters or my personal favorite throwaway "[Company]SentMeSpam@example.com". Ye…

No need to use a password manager. Simply search email history for the very first usage of the email...

That only works if they have ever sent you an email.

Re: Using a catch-all domain is a mistake

#144

Earlier quoted context omitted.

As you found out, it is a waste of time to report the leak. But you can still get all the benefits of nuking that email.

Nuking the actual email was of limited benefit over time. For whatever reason I started to get spam on my real non-aliased email address and at that point it was all bets off. Shortly after I gave up on the tagged addresses I just moved to gmail.

I've had that happen but I just change the unaliased email, update the catch-all target and block the old unaliased email.

Re: Using a catch-all domain is a mistake

#145
post #142
post #120

I'm using catch all since forever. I regret nothing. Two stories: I don't use mails like facebook@domain uber@domain - that's too obvious. And knowing that may often disclose that I actually have an account registered on given page. I don't want that, so I go full random, using few words I have in mind, current few words from the song I'm listening too, etc. So password manager helps me with e-mails too. But Sometime…

I have a couple too: Panicked phone call from a jeweller who wanted to know how and why '[their] domain was in my email address'; think he sort of understood once I explained, but still said something like 'can't be too careful in this business' - well sure ok but what am I going to do with.. oh nevermind! Password lockout/reset over the phone, reading my 100ch 'memorable phrase' as generated by pass... Gave the guy…

I do the same thing, but for exactly the reasons you described, this type of passphrase can be vulnerable to social engineering.

Re: Using a catch-all domain is a mistake

#146

> The only benefit is that I'm able to tell when companies are breached before wider disclosures because I start getting spam emails sent to thatcompany@. My big problem is that this is worse than useless. I started doing unique-address-emails back in probably 2002 or 2003 and did it for around a decade before giving up. A couple of times per year I would start getting spam or similar on an email address and would kn…

One time I made up a new address to use for a SiriusXM signup, and that address got a spam email before the confirmation email. As you can expect, that was filed under "people insisted I was wrong".

Re: Using a catch-all domain is a mistake

#147
If anyone wants a tool to further systemize this, it can be worth looking into self-hosting AnonAddy[0]. You get a decent UI for managing and creating aliases (named/random/subdomain), which is useful if you want to manually add them and track which alias was used for which service.

They also have a hosted service with free and paid tiers[1].

[0]: https://github.com/anonaddy/anonaddy#how-do-i-host-this-myse...

[1]: https://anonaddy.com/

Re: Using a catch-all domain is a mistake

#148
I do the unique Email for each service thing but not with catch all.

I use https://smplelogin.io (self hosted), there is also https://abonaddy.com, and just create a random email from random words on sign up, most of the time the usernames are fine.

I have 2 alias domains, The first one wqs a bit dark, So if I want to use aliases seriously I needed something more professional, so I bought another one with a good name.

Other than that my main domain name is never used for any normal service, only for things that are sensitive to hidden emails like hosting providers, or for professional contact.

And since bitwarden now supports mail alais integration, this is going be even better.(1)

1. https://bitwarden.com/blog/add-privacy-and-security-using-em...

Re: Using a catch-all domain is a mistake

#149
I use a catch-all eMail account, but only for two reasons:

1. To catch legitimate misspellings. A property deal nearly fell through for my father because his realtor had misspelled his eMail username but gotten the domain correct.

2. To fuck with people who use bogus eMail addresses under my domains to sign up for services. That includes eBay and PayPal accounts. I mean, if you’re going to bullshit with my domain name, bend over and bite the pillow!

Re: Using a catch-all domain is a mistake

#150
I have a very short email address, containing only five characters. It looks like: a@bc.de (But not that.)

I thought that a short email address would be convenient for typing into touch screens and it is, but it's much less convenient for reading out in person. No-one ever believes that it is real, even though it is.

Post reply on HN