Live data from Hacker News

Using a catch-all domain is a mistake

notcheckmark.com

211–220 of 304 posts

Re: Using a catch-all domain is a mistake

#211
Someone could go just a little bit further and build an app that generates a random, but short and easy-to-say email address on demand from your domain and links it in a database to the company you want, when you created it, etc.

Instead of jcrew@yourdomain.com it would be ec5@yourdomain.com or mz2@yourdomain.com and an email client could replace the "to address" in your inbox with some description field linked to that email like "jcrew"

Re: Using a catch-all domain is a mistake

#212
post #135

> The truth is no one really sells your email – at least no legitimate companies. The one outlier is political campaigns: they'll share your email till the end of time. No matter what I do I can't get bernie@ purged from any lists. Every level of government has that email and they share it as widely as they can. I'm pretty sure I only gave him $20 a decade ago. Interestingly, when I was in Texas this never happened.…

I've not had this issue with the UK Labour or Green parties, or the Canadian NDP - I still get their mail sometimes, but nothing else.

Re: Using a catch-all domain is a mistake

#213
post #120

I'm using catch all since forever. I regret nothing. Two stories: I don't use mails like facebook@domain uber@domain - that's too obvious. And knowing that may often disclose that I actually have an account registered on given page. I don't want that, so I go full random, using few words I have in mind, current few words from the song I'm listening too, etc. So password manager helps me with e-mails too. But Sometime…

I have been using a catchall domain since 2004 and it has been a lifesaver. The sad part is when your email leaks from big companies, you definitely know. I started getting viagra spam delivered to equifax@mydomain.com back in 2007, long before their "big data breach", so it was only a matter of time before that companies pattern of poor security caught up with them. Email should have always been a bidirectional addr…

Dang, you could trade stocks with information like that.

Re: Using a catch-all domain is a mistake

#214
post #156

Earlier quoted context omitted.

I have been using a catchall domain since 2004 and it has been a lifesaver. The sad part is when your email leaks from big companies, you definitely know. I started getting viagra spam delivered to equifax@mydomain.com back in 2007, long before their "big data breach", so it was only a matter of time before that companies pattern of poor security caught up with them. Email should have always been a bidirectional addr…

> Email should have always been a bidirectional address, representing the relationship between the sender and receiver, and not a wide open receiver for anybody who happens to have your address. That does seem beneficial for the most part, but do you have ideas about how to handle the use cases like establishing new relationships (what, if anything, do you put on business cards?) or allowing the general public or a b…

Phone numbers too. Can you imagine if you could give out a different phone number to each company and you could put a call limit, allowed call times, as well as a date expiration on the phone number you gave out. It could all be linked to specific companies, where if you got a spam call, you could report it and the company you entrusted it with would get a fine, or possibly the call would simply not go through.

Re: Using a catch-all domain is a mistake

#215
I’ve been using a catchall, same as in the article for ~20 years. I’ve had some support people confused. All I have to say is “I have a system that helps sort my emails”. People get it after that. I’ve caught 10’s of email leakers. I don’t fear signing up for a sales led webcast (or other unsavory types) that I know will sell my info. Interesting how the author didn’t have a similar experience. I must say that modern spam filter have made the utility of this less critical. I’d never go back to the old way.

Re: Using a catch-all domain is a mistake

#216
post #209

Earlier quoted context omitted.

Which companies are those? Is there a list somewhere? The only time I ever encountered this was with AliExpress.

Did that change? My AliExpress account is using myname@mydomain.co.uk

I don’t know, I registered some time last year. Maybe it’s also the TLD? I have .me.

Re: Using a catch-all domain is a mistake

#217
post #156

Earlier quoted context omitted.

I have been using a catchall domain since 2004 and it has been a lifesaver. The sad part is when your email leaks from big companies, you definitely know. I started getting viagra spam delivered to equifax@mydomain.com back in 2007, long before their "big data breach", so it was only a matter of time before that companies pattern of poor security caught up with them. Email should have always been a bidirectional addr…

> Email should have always been a bidirectional address, representing the relationship between the sender and receiver, and not a wide open receiver for anybody who happens to have your address. That does seem beneficial for the most part, but do you have ideas about how to handle the use cases like establishing new relationships (what, if anything, do you put on business cards?) or allowing the general public or a b…

hello@mycatchall.com

Or if for a specific forum - hello_slashdot@mycatchall.com

Re: Using a catch-all domain is a mistake

#218
Been using a catch all email domain since 2005. I've not had any major issues with it.

The entire "calling up and having to explain the username" thing is few and far between. Had that conversation in person and over the phone dozens of times, at most I get a little ask to verify I spoke correctly. Customer support doesn't care. They have people calling them up with an email address of "420hotcock69 at something dot tld". The entire "your company name at silly domain dot tld" generally doesn't phase them.

Mispelled accounts? Rarely happens. Copy and paste the domain. Use a password manager. The only time I have trouble logging in is when I can't remember if I used social auth or created an account.

As for getting email accounts purged? Don't bother. Stop using it for whatever legit reason. Then set a filter to mark all email to that user@ to be sent to spam/deleted. Problem solved.

The ONL time I've had issues was a few random systems that had funky rules for verifying fake email addresses. Oddly they sometimes look for their own domain name in the email address. So I can't use the exact domain name at those.

Re: Using a catch-all domain is a mistake

#219
post #120

I'm using catch all since forever. I regret nothing. Two stories: I don't use mails like facebook@domain uber@domain - that's too obvious. And knowing that may often disclose that I actually have an account registered on given page. I don't want that, so I go full random, using few words I have in mind, current few words from the song I'm listening too, etc. So password manager helps me with e-mails too. But Sometime…

I actually got a call from a company I bought something from, direct from their website. I had bought it using the email $company@$mydomain. Got a call (in the days before most of my calls were not spam and I answered the phone!) from a marketing person and the guy tried to bully me into ... not sure what. I couldn't even tell, like you, what he was accusing me of... I'll say, it felt really good to school him about the internet and how it worked.

Re: Using a catch-all domain is a mistake

#220
I've used VERPs¹ sometimes, even for individual mail. It's a pity that so few general-purpose email clients will generate them out of the box. You can make it happen with MTA configuration, which is one of many reasons I still run my own mail server.

[1] https://en.wikipedia.org/wiki/Variable_envelope_return_path

Post reply on HN