Live data from Hacker News

Tell HN: After 10 years of experiments, custom username emails receive no spam

news.ycombinator.com

31–40 of 359 posts

Re: Tell HN: After 10 years of experiments, custom username emails receive no spam

#31
post #17
post #7

Earlier quoted context omitted.

Compromises are 99% of those I see (similar setup) - the last 1% is acquired companies that have pivoted/do something else. It's not quite spam, it's not quite illegitimate, but it's not what I signed up for.

I've seen a shift. Between 2005-2010, I used [company]@[mydomain.com], and I noticed that I would get spam in the form of [gibberish]@[mydomain.com], presumably from spammers who were just targeting email addresses with a catch-call filter. In fact, around that time, my hosting provider, Dreamhost, started restricting email catch-alls to deal with this problem. But then from around 2010 onward, that type of spam beca…

The gibberish name ones may be targeting backscatter. They might have a reply-to with the address they're really targeting.

And that may have dropped off because there was a concerted effort to make it harder to do that around then. In particular, that's kind of what killed qmail as an in-vogue MTA, because it wasn't being updated and you had to use awkward patches to stop backscatter.

Re: Tell HN: After 10 years of experiments, custom username emails receive no spam

#32

I'm glad you had a good experience. I had a different one. I've ran my own domain for longer than you have, and many emails have been compromised. Some are 100% from companies selling the emails to sister companies. The majority, though, is from a company itself being compromised by hackers / database access / etc. LinkedIn, Neopets, ProFlowers, TeeSpring, etc. I can go on.

Had the same experience when TD Ameritrade had an employee selling email addresses. My scheme is company+10 random digits, it was clearly not guessed.

Re: Tell HN: After 10 years of experiments, custom username emails receive no spam

#33

I'm glad you had a good experience. I had a different one. I've ran my own domain for longer than you have, and many emails have been compromised. Some are 100% from companies selling the emails to sister companies. The majority, though, is from a company itself being compromised by hackers / database access / etc. LinkedIn, Neopets, ProFlowers, TeeSpring, etc. I can go on.

The worst offender for me is an email address I used to get a fishing license from the state fish and wildlife group. As soon as I did that, I started getting advertisements from some outfitter/prepper type places. Not sure if they bought the address or if licensee info is public in my state.

Re: Tell HN: After 10 years of experiments, custom username emails receive no spam

#36
Is the fear of "people selling your email to spammers" a modern myth, or are spam filters that good?

Email databases for sale are not always for spam or malware. They are often used for tracking and cross marketing calculations. Placing a companies name in the address will signal a canary and they may likely filter your contact out of their database or at least flag it and treat it differently.

I've been using email canaries for decades but recently had to adjust my canaries to be less obvious. A few vendors got upset that I had their name in the address and one even accused me of fraud and canceled my $500 gift card. That was the Tractor Supply Company.

Either way I will continue using canaries and multiple domains as it is a good way to be filtered out of some cross marketing databases and to avoid some behavioral tracking and some machine learning. It is also useful to find companies that get upset. This is an indicator to me they lack integrity and should be avoided. Canaries are also a good indicator to detect if a company has been compromised.

Re: Tell HN: After 10 years of experiments, custom username emails receive no spam

#37
The vast majority of my spam comes from the bad old days of desktop pc viruses and people using outlook express (say 15+ years ago).

Back then, my college required us to forward our university email to a personal account. That's fine as our personal addresses were hidden and not public.

What was not fine was one day the IT department changed everyone's public email address to their private address. They also changed mailing lists from BCC to CC so that you got to see everyone's email who received the email.

A few hours later after these changes, the spam started rolling in. At first it was a moderate amount of spam, a few messages a day, but it quickly increased. At one point it was up to 200-300 spam messages a day and stayed that way for several years. In any given month my gmail spam count sat between 3,000 to 6,000.

Over the past 10 years, as botnets have been taken down, those numbers have come down an order of magnitude. I still get between 20 - 30 spam messages a day on that account.

Re: Tell HN: After 10 years of experiments, custom username emails receive no spam

#38
I have been doing the same thing, for about the same amount of time.

The only "actual" spam I ever get are for email addresses where the marketplace has shared my email address with the seller. Ebay, especially. I have to rotate my ebay email address periodically and block the old one in order to keep the spam down to a reasonable level.

However, I still use custom email addresses when signing up with various companies/services because the trend over the last five years has been for every company (large and small) to automatically subscribe you to their asinine daily newsletters and other marketing crap even when you specifically opted-out on signup. Yes, the emails themselves _usually_ have unsubscribe links, but those only have a 50% success rate in my experience. And this is from otherwise reputable companies. Easiest to just block the whole email address and move on with my day.

Re: Tell HN: After 10 years of experiments, custom username emails receive no spam

#40
> Is the fear of "people selling your email to spammers" a modern myth, or are spam filters that good?

A decade ago I worked for a service that let you send bulk emails.

Any time we thought a customer was using a purchased email list, we came down on them hard or booted them off the platform. Same for other forms of spamming, not including an unsubscribe link, etc.

This wasn't necessarily altruistic: if their emails were marked as spam it would poison the reputation of our sending IPs and threaten the business.

It's clearly imperfect, but the industry's incentives seem to help.

Post reply on HN