Mailhero – a more permanent temporary email
mailhero.io
mailhero.io
Please please please tell me whether or not a username is taken as a type it before I go further.
The really good news is that all mails are always buffered on another server, so even if the whole thing was to go down, all mails will reach its destination in a timely manner.
Have to say that it is always funny when a person asks for my email address and it confuses them when the address part before the @ sign contains their company name :) Often get the question whether I also work at the company or so.
And regarding the confusion about stuff before the @-sign: I have gotten "Wow, you work here?!" a million times too... :)
What I have discovered as well, is that gmail/hotmail/yahoo addresses are so ubiquitous, that call centre staff get very confused when your email address doesn't end in one of the 'big three' domain names.
Also don't get me started on the problems I've had trying to explain that yes, .io is a valid domain ending for an email address...
The best moment was my SO explaining to someone on the phone, why the email address included their company name.
Paraphrasing: If you get hacked or sell my email I will know it was you. So don't sell it, and make sure you stay on top of your security.
I used to contact companies by email after they leaked my throwaway email address, but I don't any more, because some got angry and others were just confused.
We were recently informed by a handful of users that they had received spam email at the address associated exclusively with their Box account. We scoured our own systems and checked every possible scenario, and didn't find any evidence of our systems being compromised. Thanks to information sent to us by our customers, we were able to pin down that a third-party email service we used to send our newsletter to select users in February, March and April had been compromised.
No other information beyond email addresses were ever exposed to this vendor.
We sincerely apologize for the inconvenience this has caused our users. We continue to be committed to your privacy and keeping their confidential information safe. As a result of this issue, we're leaving this particular service provider immediately and consolidating all of our customer communication efforts within a single vendor with more robust security practices.If anyone from Mailhero is here - why don't you block the bare-naked emails? If this becomes popular then marketeers can just search for @mailhero.io addresses and strip off any string followed by a dot so that they can spam you.
Later on, if the service doesn't let you unsubscribe, or sells your email to other spammers, you can just set a filter to trash emails sent to youremail+service@gmail.com
By "heavy marketing" I presume you mean spammers. If not, be warned, sub-address stripping will mean nondelivery in some cases and could trigger blacklisting via honeypots.
Unfortunately, a lot of spammers use BCC, so AFAIK for those emails there's no way to figure out which email address was compromised, and thus no easy way to filter them out en masse.
No amount of BCC'ing affects that header because it is set by gmail itself, not by the emitter.
Time to go back and look through all my spam and filter them all. =)
I only wish I kept more of them around...
1) Locate and click the "Unsubscribe" link. Usually, that is it.
2) If there is no "Unsubscribe" link, or if it requires more than one subsequent click, then "Report Spam"
3) ... if I get an email after unsubscribing, "Report Spam" straight away
A lot of shady folks already know about Gmail's plus-addressing trick. If I were a spammer and I found that foobar.username@mailhero.io didn't work, I would just try bazbaz.username@mailhero.io.
Perhaps you could set up the system to only accept aliases that have been explicitly configured. But that would make Mailhero a bit inconvenient for regular users, since they would have to add an alias before using it elsewhere.
Another possibility would be to add a big button in the dashboard that automatically generates a plausible address (e.g. barack.hillary.trump@mailhero.io) with no connection whatsoever to your regular username or other aliases. No need for the user to decide what alias to use, and no way for a spammer to figure out a working alias.
- Sent myself a photo from a Southern Californian theme park that starts with "D" and ends with a fireworks show, using a custom email address: No third-party spam, but my god their "unsubscribe" links (NOT that I ever subscribed) just don’t work, I got a promotion for everything vaguely Disney-related for a year until I blocked the address completely. Whoops, gave this one away!
- Signed up for a famous freemium file-syncing service whose name also starts with "D" using a custom email address, never used for anything else; that ended up in the hands of spammers.
Wasn't just me then. I /know/ I never used that particular address for anything else as it was specific to the D___Box service. Yet within 2 months, started getting lots of spam on it. I don't recall that company getting data breached, so totally unclear how that happened.
I tried rolling my own for a while, but it was painful to make sure my mail server was always up to date and patched. I also had issues with forwarded mail being marked as spam by my email provider.
If this service becomes popular and starts forwarding lots of spam, it can result in the entire domain being blacklisted, especially since users never send replies to these addresses.
Don't rely on free mail services to get mail you might care about some day.
In Active Directory, the proxyAddresses attribute is used to stack up custom <something>@domain.com addresses for each user, which allows for many aliases per inbox. It does require management on the users part - they have to add an alias if want to use it, but that's done via a webform, so easy to do. Likewise they can yank an alias if it's been leaked and gets abused.
This solution has been running for over 5 years now, and it works very very well. The only downside is having to manually add new custom blacklist rules due to the adaptive nature of the spammers.
I wouldn't really call that a downside until AI is here.
Impressive work!
Worse would be if someone used the relay to intercept a password reset and pwn you.
Better to implement filters on Gmail or whatever, server side with the + suffix.
Good luck.
Once upon a time I considered a similar service that could be abused and ultimately chose not to go ahead because it simply "isn't my problem" to deal with those two groups of people. I wanted no part in it, for good or evil, even as an unbiased conduit.
I hand-rolled my own solution a while back on my own server, simply creating a random forwarder and "tagging" it with a description, so I can always go back and lookup what fw839kopa4 was for... It's a ugly hack, but works.
My ugly hack has the added benefit of not accepting just any email address, but only those I explicitly defined. On the flip side, I have to run this small script and can't just give out citibank.myname@mydomain.com to anyone on the fly.
Let's say I use this for my Amazon account amzn.myusername@mailhero.io and I need to get in touch with Amazon customer support. For verification they require me to actually send an email from amzn.myusername@mailhero.io.
Or another case: as soon as I have to actually send an email to a service I signed up for and use my real email address, that is then known to the service and could potentially be leaked.
Create a new uniqe mailhero email when you sign up to a new service etc. Mailhero will keep forward those emails to your real one until you choose not to.
So if that email ends up in a spamming list and you get starting to get alot of unwanted email from different spammers that could be hard to block you could just stop the forwarding.
So it works like a temporary email but is more permanent at the same time. And dont stop working after like 24h like many other temporary email services.
(Sorry for a shitty title)
EDIT: Oh, and you can download the code for it and run it yourself if you want. Fantastic.
There is a limit to the number of aliases, but you can just create more accounts with aliases that forward to your email.
See also Throttle[0], which does a similar thing using a browser extension to generate random emails addresses.
Not seeing the value prop over Mailinator.
1: https://gmail.googleblog.com/2008/03/2-hidden-ways-to-get-mo...
In my experience, though, they deny everything when you follow-up.
At one point I started receiving third-party spam to santander_currentacct@[domain]. I contacted Santander, my bank, to ask how that e-mail address had leaked. They insisted that I must have used it elsewhere since their systems were watertight.
I changed it to something like santander_dontspamme@ and sure enough after a few months the spam started. This time Santander didn't even reply to my complaints.
I subsequently moved my current accounts to another bank, leaving £0.01 in several Santander accounts just to keep them open.
What about 33Mail? Is this not the same thing with the tag shifted?
What if this becomes popular? Spammers can write a special case for @mailhero.io addresses that strips or changes the prefix. If you block those avenues, it just turns into a much easier password guessing game: the user has dozens of passwords, and they're all one common word, lowercase.
Interestingly, sometimes I receive spam from AnotherService sent to OriginalService@bla.com. From there you can see which services sell their data to 3rd party.
Fastmail has subdomain addressing. eg. hackernews@myemail.fastmail.com which is a lot harder to detect.
basename-spammerspecificsuffix@yahoo.com
Where basename is user-chosen (and not necessarily related to the real email address), and the suffix has to be registered ahead of time (so a spammer can't just start randomly generating suffixes to avoid filters).
Seems like that should be a simple fix for them.
Why not? 285e5c0452918bf77370c4a013317be4cf5e1ff690cc33a7346e837f59cdca58@foobarbaz.invalid is, I believe, a valid email address. If that's too long, you can always truncate it.