Earlier quoted context omitted.
catchall FTW I follow the following pattern with websites: If the website is important (ex. government), I use @ . My filtering rules are extremely strict, and every mail that doesn't come from the expected website gets automatically flagged as spam and deleted. If their DB leaks, I just change the 4 numbers. If I know the website and it's not an startup, I use @ , ex. facebook@example.com. My filtering rules only fl…
That seems like a lot of overhead to manage. Also, you're going to have a bad day if a spam bot decides to spam thousands of @yourdomain.com. Maybe that's fallen out of practice, but I've seen it happen before.
And about the spam to random addresses, in 8 years the most extreme problem I had faced is spam to censored addresses like git...@domain.com (thanks google code).