Live data from Hacker News

Using a catch-all domain is a mistake

notcheckmark.com

151–160 of 304 posts

Re: Using a catch-all domain is a mistake

#151
post #142
post #120

I'm using catch all since forever. I regret nothing. Two stories: I don't use mails like facebook@domain uber@domain - that's too obvious. And knowing that may often disclose that I actually have an account registered on given page. I don't want that, so I go full random, using few words I have in mind, current few words from the song I'm listening too, etc. So password manager helps me with e-mails too. But Sometime…

I have a couple too: Panicked phone call from a jeweller who wanted to know how and why '[their] domain was in my email address'; think he sort of understood once I explained, but still said something like 'can't be too careful in this business' - well sure ok but what am I going to do with.. oh nevermind! Password lockout/reset over the phone, reading my 100ch 'memorable phrase' as generated by pass... Gave the guy…

Bitwarden can generate xkcd style English-word pass phrases that can be useful for this kind of scenario.

Re: Using a catch-all domain is a mistake

#152

I've been using a similar system, only that I additionally append a random 5 digit number, so that if e.g. hilton-68425@domain.org gets leaked, that doesn't automatically make hyatt-95813@domain.org easy to guess. Though it does sound like something that might be possible to brute force. Also, they feed into different subfolders of the same main address. It definitely has caused some issues, but nothing that would ma…

Oh, hey, that reminds me... Any T-Mobile techies reading this?

I know someone who recently was signing up with T-Mobile and discovered that the sales rep was unable to enter their email address in the system because it was rejecting emails containing a dash. They had to give him a different address, and later logged in and successfully updated it to the correct one online. Seems like there is some incorrect filtering going on in whatever UI they use in-store for account creation.

Re: Using a catch-all domain is a mistake

#153

I try to disguise it a little to avoid the awkwardness, and also put the recipient into the subdomain instead of sender name. For example for grubhub I'd do: me@grb.mydomain.com No need to remember anything because it's all in a password manager. I've found this worthwhile, already blocked a couple spammers. You could also go with something fully random, you still get the same benefit. It's easy to look in your email…

Note some services won't even recognize a subdomain email address as valid.

Yup, I've been rejected from a couple things, but it works for the vast majority

Re: Using a catch-all domain is a mistake

#154
I've been doing this for a while, I've only really gotten static about it once. A small online retailer, their fraud department cancelled my order after it had already been charged and shipped. It was interesting, I didn't realize they could even do that but they had the carrier recall it. The customer service rep said they thought it was fraud somehow, despite my card address matching the shipping address, because I was impersonating their business by using [buinessname]@[mydomain]. I pointed out I wasn't sending anything with that address, only receiving. She didn't seem to understand my point. Oh well. They resent it overnight and I haven't purchased anything from them since. I love this setup, that experience didn't deter me in the least.

Re: Using a catch-all domain is a mistake

#155
post #120

I'm using catch all since forever. I regret nothing. Two stories: I don't use mails like facebook@domain uber@domain - that's too obvious. And knowing that may often disclose that I actually have an account registered on given page. I don't want that, so I go full random, using few words I have in mind, current few words from the song I'm listening too, etc. So password manager helps me with e-mails too. But Sometime…

I have been using a catchall domain since 2004 and it has been a lifesaver. The sad part is when your email leaks from big companies, you definitely know. I started getting viagra spam delivered to equifax@mydomain.com back in 2007, long before their "big data breach", so it was only a matter of time before that companies pattern of poor security caught up with them. Email should have always been a bidirectional addr…

>Email should have always been a bidirectional address, representing the relationship between the sender and receiver, and not a wide open receiver for anybody who happens to have your address.

Ideally, this would also be the case for physical mail. Multiple revokable tokens, not publicly tied to your physical address.

Re: Using a catch-all domain is a mistake

#156
post #120

I'm using catch all since forever. I regret nothing. Two stories: I don't use mails like facebook@domain uber@domain - that's too obvious. And knowing that may often disclose that I actually have an account registered on given page. I don't want that, so I go full random, using few words I have in mind, current few words from the song I'm listening too, etc. So password manager helps me with e-mails too. But Sometime…

I have been using a catchall domain since 2004 and it has been a lifesaver. The sad part is when your email leaks from big companies, you definitely know. I started getting viagra spam delivered to equifax@mydomain.com back in 2007, long before their "big data breach", so it was only a matter of time before that companies pattern of poor security caught up with them. Email should have always been a bidirectional addr…

> Email should have always been a bidirectional address, representing the relationship between the sender and receiver, and not a wide open receiver for anybody who happens to have your address.

That does seem beneficial for the most part, but do you have ideas about how to handle the use cases like establishing new relationships (what, if anything, do you put on business cards?) or allowing the general public or a broad audience to contact you (what, if anything, do you put in advertisements, on your web site, on slides of a conference presentation, in an e-mail signature on mailing lists?).

Re: Using a catch-all domain is a mistake

#157
post #135

> The truth is no one really sells your email – at least no legitimate companies. The one outlier is political campaigns: they'll share your email till the end of time. No matter what I do I can't get bernie@ purged from any lists. Every level of government has that email and they share it as widely as they can. I'm pretty sure I only gave him $20 a decade ago. Interestingly, when I was in Texas this never happened.…

I think they are mostly using a tool that proxies the SMS communications between you and the volunteer. But I don't know what tool or what its privacy or security features might look like.

Re: Using a catch-all domain is a mistake

#158
I find a catch all is a spam magnet, but a little finesse with regular expressions can work wonders. On Google Workspace for example I have a rule for prefix_(.*)@domain.com that way the automated spam attempts fail because they usually just use lists of names.

I then sign up, for example as prefix_netflix@domain.com

But yes, I've often been accused of stealing the domain, even though it's not their domain. Also some companies don't send outbound email that matches their domain no matter where it matches, for example I couldn't do prefix_amex@domain.com I just never received the emails. As soon as I changed it to prefix_chargecard@domain.com the emails came through.

Re: Using a catch-all domain is a mistake

#159
post #11

I've been doing this for close to a decade and sometimes salespeople and customer service people will ask to confirm, but that takes 5 seconds and isn't awkward (in my opinion.) It has more benefits than knowing who leaked your email, it lets you easily filter your incoming email by who you gave the email to, and when your email is leaked it lets you shut off that email address. Of course you can also filter your ema…

> you do have to set it up so that you can send email from the addresses Fastmail's webmail allows you to specify the sending email address for a catch-all mailbox in the message composition page, so there is no additional setup there.

And it conveniently pre-fills the from address with the correct one if you reply to an email which came to an alias.

Re: Using a catch-all domain is a mistake

#160

Earlier quoted context omitted.

As you found out, it is a waste of time to report the leak. But you can still get all the benefits of nuking that email.

Nuking the actual email was of limited benefit over time. For whatever reason I started to get spam on my real non-aliased email address and at that point it was all bets off. Shortly after I gave up on the tagged addresses I just moved to gmail.

> I started to get spam on my real non-aliased email address and at that point it was all bets off.

Why is that? You can also nuke your non-aliased email address and just update your forwards.

Post reply on HN