People have learned that you can simply strip that part out of the address... it's in the standard. If you want to know where your data leaked out, you should use a different email every time (e.g. use your own domains).
I'll take "Common RFC 821/2321/5321 myths" for $300, please.
RFC 5322 and RFC 5321 are very emphatic that the local part has no semantics whatsoever except those given to it by the MTA. There is no semantics for what "+" means in the standards.