Live data from Hacker News

Using a catch-all domain is a mistake

notcheckmark.com

21–30 of 304 posts

Re: Using a catch-all domain is a mistake

#21
I use this method and experience a few of the same drawbacks, like remembering email + password per service - A password manager does make it doable. (Highly recommend KeepassXC[0])

However, contrary to OP I enjoy these somewhat awkward situations where someone doesn't quite understand my email address. I find it can naturally lead to a conversation about privacy and data protection and I'm happy to spread the awareness, if someone is interested.

[0]⋮ https://keepassxc.org/

Re: Using a catch-all domain is a mistake

#22
post #3

reminds me a bit of the family member who owns firstname@lastname.com and can't get random non technical people to believe that their email address domain really is lastname.com "but don't you mean at gmail.co..." no

I've been using firstname@lastname.com for ages and this doesn't happen to me. Usually it's "huh that's neat", but I also have a very unique last name

Mine is first@fullname.com. Most just accept it (all when I visit California, maybe that's your experience?), but I do get queried about it from time to time in my home country

Re: Using a catch-all domain is a mistake

#23
I've had sales and customer service ask me about this a handful of times and I simply said: 'It's a unique email address so that you guys can't sell my details or get hacked and lose my email.'

The only interaction that stick in my mind regarding this when one of the sales people asked me how they might set up their own version of catch-all domain. That's about it.

Re: Using a catch-all domain is a mistake

#24
Unique email @ per website, so you only have to remember one password for everything.

Handy for places where you need to sign-up but otherwise you don't care. I don't use this approach on "meaningful" accounts where I'd care about a breach.

I think this person's mistake was not having a memorable system for the username aspect.

Re: Using a catch-all domain is a mistake

#25

I use "contact@" for when somebody who isn't a friend wants my email address. I have a separate, private address for people who actually matter to me. Everything addressed to "contact@" immediately gets marked as read and saved to a separate folder so it doesn't clutter my inbox.

contact@ specifically is high up in things that spammers try when they have no leads to go on though. ~50% of my spam in my catchall comes from contact@ admin@ and similar addresses.

Re: Using a catch-all domain is a mistake

#27
> The only benefit is that I'm able to tell when companies are breached before wider disclosures because I start getting spam emails sent to thatcompany@.

My big problem is that this is worse than useless.

I started doing unique-address-emails back in probably 2002 or 2003 and did it for around a decade before giving up.

A couple of times per year I would start getting spam or similar on an email address and would know exactly what had been breached and I would try to notify the companies involved. I'd probably spend an hour or two finding emails for key contacts and send a few paragraph email explaining how I knew they were breached etc...

90% of the time I got absolutely no reply whatsoever.

5% of the time I got a pleasant reply and someone said they were already aware or they would look into it.

5% of the time I got confused emails from a non-technical person that didn't understand how their PHP shopping cart software which hadn't been updated in 2 years got hacked, and didn't know what PHP or Linux or anything else was because the neighbor's kid had installed the site one time 2 years ago and now was too busy in college and why are you bothering us about this we have orders to ship!

5% of the time I got incredulous replies from technical people who insisted that I was wrong. That email address must have leaked some other way!

Then there was the last time I ever sent one of these emails. I guess I had found and emailed the owner of a company to email who had then added in his tech person. I explained why I had huge confidence something on their side was breached, but, couldn't explain to them what or how. They eventually got rather hostile about it, first accusing me of extorting them for the information (I never asked for money, but bounties weren't really even a thing back then like they are today). Eventually culminated in them adding in their lawyer with more threats and demands for my full name / address (presumably so they could actually sue me). I ignored them and fortunately the whole thing went away.

That was the last time I sent a report about one of my emails being compromised and shortly thereafter I stopped using tagged addresses entirely.

Re: Using a catch-all domain is a mistake

#29
post #11

I've been doing this for close to a decade and sometimes salespeople and customer service people will ask to confirm, but that takes 5 seconds and isn't awkward (in my opinion.) It has more benefits than knowing who leaked your email, it lets you easily filter your incoming email by who you gave the email to, and when your email is leaked it lets you shut off that email address. Of course you can also filter your ema…

So basically, yes it's a bit of extra work, but simply worth it.

Life without it is worse than life with it.

Re: Using a catch-all domain is a mistake

#30
post #3

reminds me a bit of the family member who owns firstname@lastname.com and can't get random non technical people to believe that their email address domain really is lastname.com "but don't you mean at gmail.co..." no

I used mail@firstname.lastname.name and sometimes even like the op "service"@firstname.lastname.name for some time. This lead into all kinds of trouble, social and technical. Social as in people did not understand why I "owned" "service"@..., why I did not have something like firstname.lastname@t-online.de/web.de/gmx.de/googlemail.de, that a third level domain is even possible, or they did not recognize .name.

Technical trouble was almost the same: Systems did not recognise the new at the time .name or Systems had trouble with third level domains. Somstimes I could sign up, but something in the backend broke and I never received mails.

Post reply on HN