Live data from Hacker News

Using a catch-all domain is a mistake

notcheckmark.com

301–304 of 304 posts

Re: Using a catch-all domain is a mistake

#301
post #295

I've been doing this for 5 years and while I agree that leaks are rare, it has been only smooth sailing. I use thunderbird with an addon that automatically sets the responding email address, and have a script called "email" that generates a random address (no prefix or anything) and puts it in my clipboard. If I want to k ow what I used an email for, I can find it in my password manager or by checking from where that…

What add-on do you use?

It's very originally named "ReplyAsOriginalRecipient":

https://github.com/ThierryBZH/ReplyAsOriginalRecipient

Re: Using a catch-all domain is a mistake

#302
post #135

> The truth is no one really sells your email – at least no legitimate companies. The one outlier is political campaigns: they'll share your email till the end of time. No matter what I do I can't get bernie@ purged from any lists. Every level of government has that email and they share it as widely as they can. I'm pretty sure I only gave him $20 a decade ago. Interestingly, when I was in Texas this never happened.…

Here in California the campaigns can get copies of the contact info on everyone's voter registrations: "pursuant to Elections Code §2188 and §2194, voter registration information is available for electoral, scholarly, journalistic and political purposes, as well as governmental purposes, as determined by the California Secretary of State."

Re: Using a catch-all domain is a mistake

#303
post #280
post #209

Earlier quoted context omitted.

Did that change? My AliExpress account is using myname@mydomain.co.uk

From memory, AliExpress wouldn't accept aliexpress@mydomain.com, but ali_express@mydomain.com was fine.

Interesting, so maybe I should have used a different prefix. Weird design.

Re: Using a catch-all domain is a mistake

#304
post #239

Never had any trouble with catch-all. Except once in about twenty years have I met a pissed off restaurant owner at my table who thought I'd hacked his website. Only thing I do different since is that I sometimes use `base64@domain.com`.

Now that I think about it: my experience with catch-all is quite the opposite: thanks to catch-all I was able to alert a number of owners their site had been breached.
Post reply on HN