Live data from Hacker News

Using a catch-all domain is a mistake

notcheckmark.com

121–130 of 304 posts

Re: Using a catch-all domain is a mistake

#121
post #119

I use catchall domain for... everything. Every account at every entity has its own unique address, since probably well before 2010. I have always more than happily accepted to have my address saved into marketing databases. I can share the frustration sometimes with employees turned sudden internet experts and "teaching" me that my email address cannot start with their employer's name. I usually retaliate by withdraw…

5) Until the tools are smart enough to detect custom domains... Until you have few domains of course :)

Re: Using a catch-all domain is a mistake

#122
post #117

Cringe take, but fair enough on the bank freaking out part. My interaction with them went like this: >staff: And what's your email address? >me: $BANK_NAME@$MY_DOMAIN >staff: chuckles And on the next day I got my bank account flagged. Edit: Turns out the restriction was not related to the email address. It was a red Canadian bank. I would say large banks like Citibank, DBS or HSBC would never care to this since all e…

Which bank was it?

Re: Using a catch-all domain is a mistake

#123
post #69

For people who are having problem with the "hilton@domain.com" situation, consider using ROT13 or some other similar scheme (hilton becomes uvygba). Other alternatives include: 1. shorten it so much that it's not revealing anymore (hil@domain.com) 2. use another language if you're multilingual (hiruton@domain.com for Japanese)

Or use a password manager.

1. Create new every with title "Hilton"

2. Generate email address (e.g. 8467588@somewhere.com)

3. Generate password

Done.

Re: Using a catch-all domain is a mistake

#124
post #112

I wish there was a simple equivalent for phone numbers. Even if I had to pay Too many services now need a phone number "for my security". I use my Google Voice whenever I can but there is no way to trace the leaker from that. Car dealerships appear to be a big source of leaks in my experience (significant uptick in spam calls and texts after I give a dealership my GV number).

Can you do it with twilio?

I recently tried to register at facebook using a twilio number (yes, I was pulled in kicking and screaming). They never actually sent the verification code until I used another number.

Re: Using a catch-all domain is a mistake

#125
> The truth is no one really sells your email – at least no legitimate companies.

`xfinity2@mydomain.com` is the only email that I've ever caught being sold via my catch-all email. I get a decent amount of phishing, scams, malware, etc. to that address. But I guess the author is still correct, since Xfinity/Comcast are sometimes less than legitimate.

Re: Using a catch-all domain is a mistake

#126
I have a catch all domain and regret it. I have a four letter TLD (idoh.com naturally) and not a day goes by where I don't catch splash damage from someone who made a typo or plugged in a fake email address somewhere.

Twitter, for example, seems to allow people to make accounts with unverified email addresses, and lately I've been getting password reset requests from a twitter user who plugged in some-japanese-name@idoh.com as their email address for Twitter.

Sometimes I get emails from, e.g., a vet's office, or some local cubs scout group. I've tried telling people that they got the wrong email address, but no way of explanation succeeds in getting people to understand that someone put down the wrong email address.

Re: Using a catch-all domain is a mistake

#127
post #120

I'm using catch all since forever. I regret nothing. Two stories: I don't use mails like facebook@domain uber@domain - that's too obvious. And knowing that may often disclose that I actually have an account registered on given page. I don't want that, so I go full random, using few words I have in mind, current few words from the song I'm listening too, etc. So password manager helps me with e-mails too. But Sometime…

I have been using a catchall domain since 2004 and it has been a lifesaver.

The sad part is when your email leaks from big companies, you definitely know. I started getting viagra spam delivered to equifax@mydomain.com back in 2007, long before their "big data breach", so it was only a matter of time before that companies pattern of poor security caught up with them.

Email should have always been a bidirectional address, representing the relationship between the sender and receiver, and not a wide open receiver for anybody who happens to have your address.

Re: Using a catch-all domain is a mistake

#129
post #120

I'm using catch all since forever. I regret nothing. Two stories: I don't use mails like facebook@domain uber@domain - that's too obvious. And knowing that may often disclose that I actually have an account registered on given page. I don't want that, so I go full random, using few words I have in mind, current few words from the song I'm listening too, etc. So password manager helps me with e-mails too. But Sometime…

Lloyd's is Pants:

https://www.theregister.com/2008/08/28/lloyds_passwords/

Re: Using a catch-all domain is a mistake

#130
post #33
post #11

I've been doing this for close to a decade and sometimes salespeople and customer service people will ask to confirm, but that takes 5 seconds and isn't awkward (in my opinion.) It has more benefits than knowing who leaked your email, it lets you easily filter your incoming email by who you gave the email to, and when your email is leaked it lets you shut off that email address. Of course you can also filter your ema…

Moreso, it's good to teach people that valid email address are in fact valid. This part: > Especially since all these companies ask for and verify your cell phone number is true, though. and > The one outlier is political campaigns: they'll share your email till the end of time. Because politicians exempted themselved from anti-spam laws, as they do with most laws.

> Because politicians exempted themselved from anti-spam laws, as they do with most laws.

Tons of companies will share/sell/buy your email address. Politicians just stand out because they're shameless about spamming, but email addresses aren't always used for spamming. They can also be used to tie logins to names and accounts across services. They can be harvested for various information they contain. Even folks with just one email address often give away their name, the year they were born, their hobbies, etc. Using an email address like uber@notcheckmark.com and Hilton@notcheckmark.com also tells a story about you and what services you use. Every scrap of data that can be collected helps build a profile of your life and email addresses are a part of that, even when they aren't used to clog your inbox with garbage.

I'd recommend using less obvious names, but I still don't see a problem with creating unique addresses for various services that demand an email account. If nothing else it's a great way to compartmentalize the crap they'll send you (spam or not). If someone questions why you have COMPANYNAME@example.com that should really just be a 2 second conversation.

Post reply on HN