Live data from Hacker News

Tell HN: After 10 years of experiments, custom username emails receive no spam

news.ycombinator.com

51–60 of 359 posts

Re: Tell HN: After 10 years of experiments, custom username emails receive no spam

#52
I use an alternate spam filter process. I use a "+" sign in my gmail address. So I would subscribe to a promotion/giveaway with username+company@gmail.com. This is a great way to catch which promotion/company sells your email address to unwanted companies.

Caveat, sometimes an unsubscribe website can't handle the "+" symbol in an email and you'll continue to get spam. So, just add a filter for that "TO" email to forward to the spam/trash folder.

Re: Tell HN: After 10 years of experiments, custom username emails receive no spam

#53

I'm glad you had a good experience. I had a different one. I've ran my own domain for longer than you have, and many emails have been compromised. Some are 100% from companies selling the emails to sister companies. The majority, though, is from a company itself being compromised by hackers / database access / etc. LinkedIn, Neopets, ProFlowers, TeeSpring, etc. I can go on.

I have a similar experience. I've been using this system for about 15 years, and have to block one or two address a year due to spam. A couple were due to first party spam that I could not manage to unsubscribe from (Cooks Illustrated, I'm looking at you), and a few scraped from forums (didn't realize the email would be public when signing up). The rest appeared to be due to an account compromise (based on breadth of low quality spam) - oh and less than 1/4 of those sites notified me of a compromise. I don't think I've ever received spam from what appears to be a "legitimate" "business partner" which is what I would expect from emails that were sold.

I also get a handful of spams a month from default addresses (hostmaster, etc), all of which come from Chinese IPs. I don't have any email address posted on my websites to scrape from (mailto: or otherwise), so I don't get any spam from that.

The end result is pretty much no spam. I assumed when I first setup my domain I'd have to configure spam assassin at some point, but that point has never come, thankfully.

Re: Tell HN: After 10 years of experiments, custom username emails receive no spam

#54
Given your results it certainly seems so. However, I know of quite a few companies who required people to sign up with their email addresses to play their free games and then sold their addresses to marketers. Perhaps you wouldn't count that as spam since the emails sent had some substance? Or perhaps you only reveal your email to trustworthy sites and not to free gaming sites and such?

Re: Tell HN: After 10 years of experiments, custom username emails receive no spam

#55
I use [company]@[mydomain] when signing up for things. So far the only offender is a porn site I paid for for a while. I was getting weird scam emails sent to that address daily, with text like "Hi [name of site], How are things? Is this your new email?". Surprisingly, when I cancelled my subscription, the scam emails stopped.

Re: Tell HN: After 10 years of experiments, custom username emails receive no spam

#56
I've been doing this for about two decades, and I've had to block a fair few addresses for spam over that time.

In almost all cases with companies of any significant size/reputation it was entities that either publicly admitted or were publicly called out as having been hacked – so incompetence or the bad luck rather than deliberately selling my details on.

In a few of cases (a couple of hosting providers, a physical-store electronics retailer) it has been a business that had failed before the spam started, so presumably their contacts were sold as an asset as part of the winding down.

I give different addresses to any online forum too — they have seen a much higher rate of addresses needing to be dropped due to spam.

If you use a catch-all address rather than setting up each alias individually then you may get “dictionary” attacks at some point. Early on when I used @domain.tld I saw that a few times, with someone sending to alan@, alana@, alvin@, … Since moving over to @sub.domain.tld (where “sub” is a static sub domain operating as catch-all, with only a whitelist of addresses on the main domain now accepted) I've not seen this again. I don't know if that is because name dictionary attacks like that are simply rare, are not attempted on more complex addresses, or never really worked so spammers don't use the technique at all any more.

Where an address ends in a number, I've seen guesses that increment that number – so as well as getting junk to somecompany2@sub.domain.tld I get junk to somecompany3@sub.domain.tld and so on. I assume this is an address farmer bulking out their database.

One place where passing on of your email address seems rife is kickstarter and indigogo projects. I'm on several mailing lists I've never subscribed to on those addresses, and another appears every couple of months — I don't know if it is the projects themselves or the survey management third parties that are to blame, I suppose I could test that by cycling the address but I'm not been bothered enough to make that effort. I have messages from those lists auto-filed into a folder, and if I'm tempted to support a project I search that folder first – if they have been carried by one of the spammy mailing lists I won't be giving them any of my money. I've saved money on three projects thus far with this. A petty victory perhaps, but I like my petty little victories!

Re: Tell HN: After 10 years of experiments, custom username emails receive no spam

#57
Let's consider a few things:

1) Just because it hasn't happened to you, that doesn't mean it doesn't happen. I have quite a few examples of companies selling or otherwise sharing, whether intentionally or through compromise, my email addresses.

2) If someone (some company) is going to sell email addresses, it's not unreasonable to imagine that they'd want to remove any addresses that would directly link those addresses to their source, so a quick search to remove any address with the word "adobe" in it when selling Adobe mailing lists would not be unexpected in the least.

Years ago I set out to learn more about the "missing sock" problem (https://en.wikipedia.org/wiki/Missing_sock). I bought a dozen pair of brand new socks and I ironed on labels identifying each and every sock. Guess what? The labeled socks never went missing. The act of labeling the socks dramatically affected the experiment.

Perhaps using companies' names in our email addresses is affecting our results.

Re: Tell HN: After 10 years of experiments, custom username emails receive no spam

#58

I use an alternate spam filter process. I use a "+" sign in my gmail address. So I would subscribe to a promotion/giveaway with username+company@gmail.com. This is a great way to catch which promotion/company sells your email address to unwanted companies. Caveat, sometimes an unsubscribe website can't handle the "+" symbol in an email and you'll continue to get spam. So, just add a filter for that "TO" email to forw…

What's stopping websites from just removing '+company' from 'username+company@gmail.com' and emailing you at 'username@gmail.com'?

Even if the website you provide it to doesn't do that. Anyone who buys it can.

I'm guessing the answer is, "Most companies are too lazy", but that seems like a weak behavior to depend on.

Re: Tell HN: After 10 years of experiments, custom username emails receive no spam

#59
I do the same thing. I've received span on a a few.

Interestingly Gary Johnson (the Libertarian candidate for president) sold my email to Scott Walker (the right-wing Wisconsin governor). That shows you something. Also my United Airlines email got out there in the spam world. I think there were a few others. I finally stopped doing it out of laziness.

Re: Tell HN: After 10 years of experiments, custom username emails receive no spam

#60
FWIW, I've been running a similar experiment (granted, for only 2 years) only instead of specifying the company name I'm using a random term (e.g. purplerabbit@domain.com) and found similar results. No 3rd party spam thus far (though I found a few companies that continue to send marketing materials, etc. even after using all available unsubscribe options).
Post reply on HN