Live data from Hacker News

Using a catch-all domain is a mistake

notcheckmark.com

171–180 of 304 posts

Re: Using a catch-all domain is a mistake

#171
post #120

I'm using catch all since forever. I regret nothing. Two stories: I don't use mails like facebook@domain uber@domain - that's too obvious. And knowing that may often disclose that I actually have an account registered on given page. I don't want that, so I go full random, using few words I have in mind, current few words from the song I'm listening too, etc. So password manager helps me with e-mails too. But Sometime…

> I don't really know exactly, but she told me something about me using their stuff without their acceptance, when I tried to explain that's my own domain she told me I cannot use their name, because that's a copyright infringement. Weird. I can't tell you how many non-techy people think I'm part of their company because I have yourcompany@mydomain. Sigh. Big companies have ruined the internet by having everyone have…

The "best" is when you can't even sign up without having an account at a Large Company e.g. gmail or outlook. I'm not sure what that's supposed to prevent issues with.

Sure, you can add "+thing" after the username portion, but those that know this bog standard trick can still automatically derive your email address and get around your filters. At least with a dedicated username portion a human has to think for a second.

Re: Using a catch-all domain is a mistake

#172
post #11

I've been doing this for close to a decade and sometimes salespeople and customer service people will ask to confirm, but that takes 5 seconds and isn't awkward (in my opinion.) It has more benefits than knowing who leaked your email, it lets you easily filter your incoming email by who you gave the email to, and when your email is leaked it lets you shut off that email address. Of course you can also filter your ema…

> you do have to set it up so that you can send email from the addresses Fastmail's webmail allows you to specify the sending email address for a catch-all mailbox in the message composition page, so there is no additional setup there.

Edit: oh god, leaving this in place for posterity but I am completely misrepresenting fastmail here. It is protonmail that I recently tried and had these limitations. Apologies! How embarrassing. Also, I have no idea why the child comment correcting me would be so downvoted. It’s apparently correct.

Yes, but fastmail has a couple dealbreaker limitations when doing this: First, you can’t originate mail from that address; you can only respond. This makes it unusable for a lot of mailing list control messages and other systems where you are required to make inquiries from a registered email address. Second, you must explicitly set up each of the unique recipient addresses, which is a huge burden when you want to be able to generate them on the fly when signing up for web accounts (and when you already have hundreds in use because you’ve spent decades giving every company a unique address).

If they addressed these and I could have an unlimited number of suffixes directed to a single fastmail address, I’d sign up for a paid account in a heartbeat. Looks like a great service but those are fatal flaws IMO.

Re: Using a catch-all domain is a mistake

#173

What’s weird is I’ve noticed some sites and apps don’t like their name in the account name and won’t validate. For example, I tried signing up for the Chronometer app using chronometer@prepend.com and can’t make it through their sign up process. I’ve always wondered what kind of programmer makes their domain name as email not work. I’m guessing it’s some testing or debug shortcut but won’t have closure. I’ve probably…

My theory is that it's to dissuade less advanced spammers/fraudsters who use manually-created, consumer-grade email addresses that take time & effort to create, thus rejecting them could actually slow them down or piss them off enough to give up.

The intent is probably to ban spam/free trial abuse or obviously-incorrect addresses (though for the latter case why not just send a verification email).

Re: Using a catch-all domain is a mistake

#174
I have been using email-per-account since forever. My personal scheme I recently settled upon is two letters to give me idea what is this for, plus two digits indicating when it was created. For example twitter would be tr25@domain, where 2 stands for last digit of 2022 and 5 for May. That is a must for me now. When some company I trusted my email with leaks it, I know instantly. There are cases when you MUST know. For example, a phishing mails started coming from email I gave to crypto wallet coinomi support. Would I rather not know? Hell no. You can lose a lot of money by not knowing such things

Re: Using a catch-all domain is a mistake

#175
post #142
post #120

I'm using catch all since forever. I regret nothing. Two stories: I don't use mails like facebook@domain uber@domain - that's too obvious. And knowing that may often disclose that I actually have an account registered on given page. I don't want that, so I go full random, using few words I have in mind, current few words from the song I'm listening too, etc. So password manager helps me with e-mails too. But Sometime…

I have a couple too: Panicked phone call from a jeweller who wanted to know how and why '[their] domain was in my email address'; think he sort of understood once I explained, but still said something like 'can't be too careful in this business' - well sure ok but what am I going to do with.. oh nevermind! Password lockout/reset over the phone, reading my 100ch 'memorable phrase' as generated by pass... Gave the guy…

That is a major downside with putting gibberish in for answers to security questions… let’s hackers socially engineer support into letting you get access by saying something like, “oh man, I just mashed on my keyboard for that I don’t remember!”

You would hope it wouldn’t work, but it probably will.

Re: Using a catch-all domain is a mistake

#176
post #93

I've been doing this for over 20 years, and it hasn't really been a problem. During the occasional real-life interaction that requires someone to confirm my address and they express surprise, I just tell them that it's correct and I have advanced email needs. It never takes more than a few seconds -- nobody has ever said "please tell me all about your advanced email needs!" :) > I use a password manager for passwords…

Yeah I don't understand what the kerfuffle is. Sometimes they express disbelief or surprise, but it's never been a problem beyond telling them "I control the whole domain, you get a special address so I know if your database gets hacked and/or my information sold via this channel" and that almost always results in the employee being interested in getting the same thing for themselves.

Re: Using a catch-all domain is a mistake

#177
post #57
post #31

I had to stop using plus-addressing (me+brand@gmail.com) because of broken email address parsers/validators. If I was on the phone with a support agent, I would give them my plus-address and their system would reject it and they'd ask for another one. Stubbornly, I'd refuse to budge and insist that is my email address that they need to use. It got to the point where I'd either have to forfeit my healthcare/tax/flight…

GMail has supported the "+" alias since the service was announced, one would think there'd be no excuse to not support it everywhere at this point. My consipiracy-theory hypothesis is that many companies "know" that any address with a + in it is an alias and actively filter it out. Because they don't want an alias, they want your _real_ address. I run my own mail server and use a "." as the alias character. Haven't s…

Supported since forever by Cyrus IMAP for routing into subfolders.

For some unknown reason at Pitt people were taught to finish write their email as username+@pitt.edu ca. 1995. While it supported that as the inbox, most people were unaware that you could put +foo and have it go to the folder foo if one existed. But the address without the plus also worked.

Re: Using a catch-all domain is a mistake

#178

Earlier quoted context omitted.

> you do have to set it up so that you can send email from the addresses Fastmail's webmail allows you to specify the sending email address for a catch-all mailbox in the message composition page, so there is no additional setup there.

Edit: oh god, leaving this in place for posterity but I am completely misrepresenting fastmail here. It is protonmail that I recently tried and had these limitations. Apologies! How embarrassing. Also, I have no idea why the child comment correcting me would be so downvoted. It’s apparently correct. Yes, but fastmail has a couple dealbreaker limitations when doing this: First, you can’t originate mail from that addre…

This doesn't match with my experience. I have a single catchall *@my-domain.com address that will receive anything sent to the domain (without setting up separate accounts ahead of time).

You can also send from any address, but I agree that the UI is a bit hidden. You first choose from the from-address dropdown "*@my-domain.com", and then a new textbox appears where you can type what address to send from. As another commenter pointed out, if you are replying to an email it will automatically fill in the custom from-address, but you can overrule it.

Re: Using a catch-all domain is a mistake

#179

For weeks our Shopify app was getting rejected because "you cannot use the Shopify name or trademark in your app". It wasn't... repeated requests for clarification just got back the same form response. After a several frustrating back-and-forths, finally someone at Shopify said "check your email address". The developer contact email address we had submitted, which was only used for shopify us communication and no cus…

I wonder what they'd have said about tobias.luetke@ourdomain.com

"Actually, my name is Sam Hopify..."
Post reply on HN