Live data from Hacker News

Email obfuscation: What works in 2026?

spencermortensen.com

111–120 of 124 posts

Re: Email obfuscation: What works in 2026?

#115

Earlier quoted context omitted.

Of course, the technical term for that setup is 'catch all', you can set this up with your email provider. You can send your email to "ghywertelling@gregegan.net", for example.

A friend gave out an email gmail@hisname.com (he owns the domain). He says it's incredible how many people "corrected" him, and how persistent some of them were. :-)

If you use the [company name]@yourdomain.com form, people who work at [company name] often say "wow, you work for [company name]??"

Re: Email obfuscation: What works in 2026?

#116
post #46

I stopped being concerned about email harvesting years ago, I just simply leave the email on my website. Spam handling is okay enough, I guess. But I like this review of techniques, even the simplest ones are very effective, that surprised me.

I’m up to more than 1,500 spam emails a month, with my email on the corp website.

Is it mostly people trying to give you their mixtapes?

Re: Email obfuscation: What works in 2026?

#117

Earlier quoted context omitted.

you know what's funny is that llms are also good at detecting spam as they are generating it. I've got an automation that scores incoming emails and it's getting better and better each day (also more expensive haha)

I can’t explain it well, but I think there is an asymmetric issue here… that the ability for an LLM to write a plausible email, and the ability for an LLM to detect that it’s spam are mismatched. If an LLM and make a plausible email, the best another LLM can do is to rank it as plausible. Blackbox creation and detection have to be on the same level. Perhaps if you said the detection LLM had all your context and webse…

But I think there's also an asymmetry strongly favouring the defense, namely that for a spam mail to be worthwhile, it needs some call to action, a way to lure in the victims.

A link to a shady website, an infected attachment, a weird freemail address in the body or Reply-To header that doesn't match the forged From header, etc. They're trying to get cleverer for sure -- I started getting phishing mails where the malicious link is only in a QR code in an embedded image -- but I think the need to somehow link to the trap is an inherent weakness against any defense. SpamAssassin rules give a good overview of stuff that help detection no matter how the rest of the mail is generated.

Re: Email obfuscation: What works in 2026?

#118

[flagged]

Just my anecdata, but several of my addresses have been in two-digit numbers of leaks, and my spam load is relatively low, at least compared to some of the numbers I read in this thread. Per leaked address, I get maybe 5-10 a week. So to me it doesn't seem like leaks are a major source for spammers.

Re: Email obfuscation: What works in 2026?

#119
post #21
post #9

I use SVG where I created a text object in Affinity Designer and converted it to curves so the SVG doesn't have text any more, just vectors for the glyphs of it. Seems to work pretty well at keeping spammers at bay.

It also keeps visually impaired people at bay.

Good point. I'll add a voice recording of me spelling out the email address.

Re: Email obfuscation: What works in 2026?

#120
post #118

[flagged]

Just my anecdata, but several of my addresses have been in two-digit numbers of leaks, and my spam load is relatively low, at least compared to some of the numbers I read in this thread. Per leaked address, I get maybe 5-10 a week. So to me it doesn't seem like leaks are a major source for spammers.

[dead]
Post reply on HN