Live data from Hacker News

Using a catch-all domain is a mistake

notcheckmark.com

281–290 of 304 posts

Re: Using a catch-all domain is a mistake

#281
I think they meant to say to avoid using email canaries named after the company one is emailing. I used to do this but it has been a problem as companies are catching on and blocking these addresses.

My most recent experience was with the Tractor Supply Company. They were upset I used an email canary so they called it "fraud" and cancelled my gift card. I've spent some of my retirement turning their customers away and might even put a few billboards up to warn residents of my state about their fraudulent behavior and lack of integrity.

Anyway since then I have been creating more realistic looking canaries that I can still tie back to the people I interact with, thus allowing me to notify them if their email databases have been compromised. I will never stop using canaries regardless of what ire and bad behavior it draws from corporations. It seems to be a good way to detect shady businesses now in addition to companies leaking or selling their contacts.

Re: Using a catch-all domain is a mistake

#282

Earlier quoted context omitted.

> I don't really know exactly, but she told me something about me using their stuff without their acceptance, when I tried to explain that's my own domain she told me I cannot use their name, because that's a copyright infringement. Weird. I can't tell you how many non-techy people think I'm part of their company because I have yourcompany@mydomain. Sigh. Big companies have ruined the internet by having everyone have…

The "best" is when you can't even sign up without having an account at a Large Company e.g. gmail or outlook. I'm not sure what that's supposed to prevent issues with. Sure, you can add "+thing" after the username portion, but those that know this bog standard trick can still automatically derive your email address and get around your filters. At least with a dedicated username portion a human has to think for a seco…

If you use Gmail then you have a couple of ways besides using the + to make a variation of your email address that will still come to your inbox:

1) Use dots (period or full stop) between letters in the username part of your email address. For example, if your email is abcdefg@gmail.com then a.bcdefg@gmail.com and a.b.c.d.e.f.g@gmail.com also get routed to you.

2) Use @googlemail.com instead of @gmail.com in your email address.

I have a Gmail address and I use these other variations whenever a company rejects email addresses with + in them.

Re: Using a catch-all domain is a mistake

#283
I’m another long-time catch-all email address user.

1. That is how I knew that Dropbox had been hacked; I had a couple temp/throwaway Dropbox accounts and the otherwise-unused email addresses associated with them started getting lots of spam.

2. Yes, sometimes it is slightly awkward when a rep cannot comprehend companyname-at-mydomain, but not enough to make me regret anything. Smile. Say "it will reach me!" or "I own my own dot-com!" It’s fine.

3. "Did I use BR or bananarepublic before the at sign?" That’s why we use a password manager :-) The author says he uses one, but then suggests he needs to guess the email before the password manager will tell him the password? Sounds messed up. Use 1Password. Be happy.

4. The most interesting 'downside' is that sometimes I get spam for addresses that have never been used. Why? Because there are spammers out there who have scraped my website for anything resembling a human name (e.g. John Smith) and then sent emails to my domain that fit the typical pattern (jsmith@mydomain.tld). So, I blocked a number of these addresses. Had I not set up a catch-all, they would have otherwise been bounced.

5. "Every so often I need to email a company from one of these emails" -- The "from" problem of catch-alls is a bit tricky at times, but using Fastmail + PHP I can easily send "from" any address at my domain when needed.

6. I am a big fan of the Fastmail + 1Password 'masked email' solution! It’s so great! Sign up at a website, get a brand-new email address that seamlessly forwards to you, it gets stored in your password manager, and you can kill it whenever it starts getting spammed. The random username generation even avoids that problem of telling the Hilton rep that your email is Hilton@hacker.tld. Using masked emails instead of a catch-all would also avoid the minor problems of #4 and #5. Shout-out to iCloud's somewhat similar solution, but Fastmail+1Password really is top-tier!

Re: Using a catch-all domain is a mistake

#284

Earlier quoted context omitted.

Not having your mailing address tied to your physical address would also have major benefits when people move. Simply update your address with the post office and you're done. The whole idea of revokable tokens would pose an issue for any company that sends bills, as I assume revoking address tokens would be common with them. I'm sure there are many situations like this.

"Simply update your address with the post office and you're done." Welcome to the 19th century! Which is when mail redirection to a new address was introduced in the UK. I'd be amazed if it wasn't around then or earlier in the USA as well. Simply fill out a form and your mail will be redirected for up to two years (albeit at a cost). Or use a PO box and a mail forwarding service which offers filtering of junk mail. I…

The US has mail forwarding for 1 year, but that doesn't solve the problem, as you still need to update the source information with all the companies. I usually end up spending several hours changing addresses when I move. It's better to do this right away than to rely on the forwarding completely. Some places get the change of address info automatically and update their records, but it's never the ones you actually want (usually catalogs and marketing mail).

A PO box would be fine, but it's not an acceptable address with many businesses, so it's not a universal solution to the problem.

Re: Using a catch-all domain is a mistake

#285
post #120

I'm using catch all since forever. I regret nothing. Two stories: I don't use mails like facebook@domain uber@domain - that's too obvious. And knowing that may often disclose that I actually have an account registered on given page. I don't want that, so I go full random, using few words I have in mind, current few words from the song I'm listening too, etc. So password manager helps me with e-mails too. But Sometime…

regarding 'copyright infringement,' you gotta love it when people get aggressive about IP without knowing what they are talking about; the relevant law would be trademark, not copyright

Re: Using a catch-all domain is a mistake

#286
post #120

I'm using catch all since forever. I regret nothing. Two stories: I don't use mails like facebook@domain uber@domain - that's too obvious. And knowing that may often disclose that I actually have an account registered on given page. I don't want that, so I go full random, using few words I have in mind, current few words from the song I'm listening too, etc. So password manager helps me with e-mails too. But Sometime…

The phone thing has veered into outright fraud. Twitter just paid a $150,000,000 fine to the (US) FTC for letting advertisers match on telephone numbers provided for 2FA.

I am really tired of people selling my burner phone to the credit people; and no, I don't own that phone number. Prove I do.

Take my local credit union. Please. Jackasses let someone have access to my checking account. I don't bank online with them either, or I didn't, but last summer was trying to talk to them about a refi and I had to register online and they wanted a phone for 2FA. So of course instead of calling the land line, which is clearly and incontrovertibly mine, they called the burner. Several times.

Eventually I answered it with "fuck you you frauds" and they were "oooh sir, call me back on my direct line" so I tried... from my land line in the same area code, you get the idea... and their system won't route the call to their fraud department. So I ignored them for a couple of weeks.

Seriously they were so incompetent that when the actual fraudsters were probing, the first transaction was a /deposit/. When they were finally trying to clean their mess up, they /credited/ me the same amount. I'm the one who figured it out and told them well you gave me 2x their original deposit, when you really should have debited the amount in the first place.

People like that are not going to safeguard your information.

Ob relevance: I have my own reasons for not wildcarding domains and use this instead: https://github.com/m3047/trualias

Re: Using a catch-all domain is a mistake

#287

Earlier quoted context omitted.

With all those similar stories I wonder why people even bothering with changing an email recipient when some random guy asks about it. Like... delivery guy asked and?..

And they don't want to keep having that conversation, presumably.

Chances are there but slim.

Personally I had a similar conversation only once and only because it was a one-man AliBaba reseller shop, so he personally processed all orders.

Re: Using a catch-all domain is a mistake

#288

I think they meant to say to avoid using email canaries named after the company one is emailing. I used to do this but it has been a problem as companies are catching on and blocking these addresses. My most recent experience was with the Tractor Supply Company. They were upset I used an email canary so they called it "fraud" and cancelled my gift card. I've spent some of my retirement turning their customers away an…

Have you explored a Small Claims case?

Re: Using a catch-all domain is a mistake

#289

I think they meant to say to avoid using email canaries named after the company one is emailing. I used to do this but it has been a problem as companies are catching on and blocking these addresses. My most recent experience was with the Tractor Supply Company. They were upset I used an email canary so they called it "fraud" and cancelled my gift card. I've spent some of my retirement turning their customers away an…

Have you explored a Small Claims case?

I could but I decline to play that game. That would in no way dissuade their bad behavior.

Re: Using a catch-all domain is a mistake

#290
I got unsolicited email from DHL just today addressed to a catch-all that I used with a retailed who shipped via DHL. I didn't sign up for a newsletter ... I still find it useful to use special addresses, as the author described.
Post reply on HN