Live data from Hacker News

Tell HN: After 10 years of experiments, custom username emails receive no spam

news.ycombinator.com

91–100 of 359 posts

Re: Tell HN: After 10 years of experiments, custom username emails receive no spam

#91

Let's consider a few things: 1) Just because it hasn't happened to you, that doesn't mean it doesn't happen. I have quite a few examples of companies selling or otherwise sharing, whether intentionally or through compromise, my email addresses. 2) If someone (some company) is going to sell email addresses, it's not unreasonable to imagine that they'd want to remove any addresses that would directly link those address…

> remove any address with the word "adobe" in it when selling Adobe mailing lists

That's a good explanation.

Re: Tell HN: After 10 years of experiments, custom username emails receive no spam

#93
post #23

Maybe not 3rd party spam, but definitely first party spam. I gave a custom username email to a in-person store (big chain) with a rewards program because they were offering a huge discount if you did. Since then they've sent at least 1 email a day, with an average of about two (I've redirected all their emails to a folder I never look at). Which is a particularly remarkably obnoxious rate of sending emails... I've al…

So just unsubscribe from the mailing list then?

Why are you setting up these custom filters instead of just clicking the link and opting out?

Re: Tell HN: After 10 years of experiments, custom username emails receive no spam

#94
I've been doing the same for so long I can't even remember when I started. Yes, I do get spam to some of those emails, and yes, it is nice to block them. That said, the thing that's kept me doing this so long is this: on two occasions, an address given to a financial institution started getting spam - clearly they were hacked or had an internal user selling emails (I remember when that was worth good money - I doubt it is anymore).

It was an early warning for me to change my password at that bank (this was pre-2fa), so the practice has kinda stuck with me.

Re: Tell HN: After 10 years of experiments, custom username emails receive no spam

#95
post #93
post #23

Maybe not 3rd party spam, but definitely first party spam. I gave a custom username email to a in-person store (big chain) with a rewards program because they were offering a huge discount if you did. Since then they've sent at least 1 email a day, with an average of about two (I've redirected all their emails to a folder I never look at). Which is a particularly remarkably obnoxious rate of sending emails... I've al…

So just unsubscribe from the mailing list then? Why are you setting up these custom filters instead of just clicking the link and opting out?

> So just unsubscribe from the mailing list then?

I've encountered many companies that let you unsubscribe, then add you to a 'new' mailing list a few months later. You can usually identify these companies because when you click to unsubscribe they take you to a page with a dozen or more 'newsletters' that you have to uncheck to remove yourself from if you can't find the 'all' link.

Re: Tell HN: After 10 years of experiments, custom username emails receive no spam

#96

Earlier quoted context omitted.

> A few vendors got upset that I had their name in the address I have had this happen a few times. > Canaries are also a good indicator to detect if a company has been compromised. Yep, this is a fantastic use case.

This is exactly my use-case and experience after many years of custom catch-all'ing. I've noticed a couple breaches, and also a few unexpected transfers of my email address between semi-related parties. Just once it appeared an address was sold via a marketing list, after filling out a lead-form for a free online conference hosted by multiple companies that you've seen on HN. Surprisingly, unsubscribing tends to stop…

Slightly easier* than running a domain, i've had luck with myemail+CompanyX@gmail.com when signing up to CompanyX. Gmail handles the '+' transparently (in the same way as it ignores '.') and delivers the email to myemail@gmail.com.

It is fun to receive a survey about "an anonymous company you have used in the past"... sent to myemail+uber@gmail.com.

*yet less reliable, '+' in email addresses isn't always accepted, and when it is sometimes only partly, e.g. signup works but password reset doesn't

Re: Tell HN: After 10 years of experiments, custom username emails receive no spam

#97
post #46

Earlier quoted context omitted.

> A few vendors got upset that I had their name in the address When it happens, I say "this is because your company is so important to me that it has its own mailbox to be prioritized accordingly" It worked every single time :)

Same, though go with “I use the incoming address name to file things into the right folder, so work things, banking things, shopping, and such, are separated” – I don't butter them up by making them sound important enough that I created a mail inbox just for them. If they still object then I don't sign up. I've had web form refuse to accept an email address with their company name in, so that sale went elsewhere, and…

I guess ROT13 could also be a last resort if signing up is important enough.

Re: Tell HN: After 10 years of experiments, custom username emails receive no spam

#98

I'm glad you had a good experience. I had a different one. I've ran my own domain for longer than you have, and many emails have been compromised. Some are 100% from companies selling the emails to sister companies. The majority, though, is from a company itself being compromised by hackers / database access / etc. LinkedIn, Neopets, ProFlowers, TeeSpring, etc. I can go on.

I've noticed a lot of "mid size" compromises.

The pizza place down the street uses a third party digital order system, that was compromised. One of the first emails I actually had to blackhole due to the insane volume of spam and attacks that started coming to it.

Also.. my previous landlord. His computer or account got compromised at some point, and that was another email I had to blackhole due to the insane volume of porn spam that started coming to it.

Re: Tell HN: After 10 years of experiments, custom username emails receive no spam

#99

Is the fear of "people selling your email to spammers" a modern myth, or are spam filters that good? Email databases for sale are not always for spam or malware. They are often used for tracking and cross marketing calculations. Placing a companies name in the address will signal a canary and they may likely filter your contact out of their database or at least flag it and treat it differently. I've been using email…

Someone should sign up for all the mailing lists with a email address used nowhere else and track the cross-mailings. Maybe a bubble babble hash of the company name as the email prefix, and a big mailer like gmail or protonmail as the server. When the email is leaked and the company does not inform the user, report the company via GDPR.

Re: Tell HN: After 10 years of experiments, custom username emails receive no spam

#100
post #65

Is the fear of "people selling your email to spammers" a modern myth, or are spam filters that good? Email databases for sale are not always for spam or malware. They are often used for tracking and cross marketing calculations. Placing a companies name in the address will signal a canary and they may likely filter your contact out of their database or at least flag it and treat it differently. I've been using email…

> Placing a companies name in the address will signal a canary and they may likely filter Oh, good point. I guess I may have invalidated all my research! :|

If you're interested in getting "true" results, perhaps you could do something like this:

name1@website.com

name2@website.com

etc.

In a spreadsheet, you have one column with the number, and another with the company name. You might want to change this up, putting the identifier in different parts of the email address, to avoid similar "canary" signals.

Personally, I use BitWarden to generate usernames for each website, to help keep my fingerprint (somewhat) scrambled. LastPass also has a good username generator. [1] I would just avoid using complete non-sense words, since there might be some amount of human review.

[1] https://www.lastpass.com/features/username-generator

Post reply on HN