E.g. myaddress+service1@gmail.com will go to your inbox and you can filter on it.
My earlier hypothesis was that this was on purpose, to make sure you don't use a filter on any email they might send. But these days I'm tending to think it's just a bad regexp on their side.
"I can't log in and to boot your site says there is no account matching first.last@gmail.com. What kind of Mickey Mouse operation are you running here?"
"Sir, you are an idiot."
What's important is to keep a backup of your password database in a few places. I use KeePass because I have no desire to keep passwords, encrypted or not, in a cloud service. I also don't find value in browser integration (possible attack vector?). I'm generally very DIY-inclined anyway. Your preferences may vary.
As a full disclaimer, there are some issues with KeePass [1], but known issues are detailed in full by the project and are available for review.
Then, if the spammer strips (removes) that part, it gets sent to the trash (binned).