For example, I would sign-up for HN using hackernews@marak.com and for Reddit using reddit@marak.com
Simple and effective.
For example, I would sign-up for HN using hackernews@marak.com and for Reddit using reddit@marak.com
Simple and effective.
I still host my own e-mail but I no longer do catch-all. There are only a few sites and services I care about. For those I have trusted them with my e-mail address. For all others I use 3rd-party throwaway mail services.
I get less spam now than I did with catch-all.
I use a completely different domain than the one that's publicly associated with me though. Maybe that helps.
I have learned to keep a personal e-mail address for friends & somewhat trusted people, but never businesses. Businesses (and all government offices, kids' school,...) get their one-time address. If spammers somehow get to it, it is much easier to cut them off, and I also know who leaked the address to them.
Of course, http://www.mailcatch.com/ rules for those one-time "no, I will not let you spam me" registrations.
A couple of years ago, maintaining the blacklist passed the point where this was a viable technique for me.
If I configure me.example.com to accept emails matching the pattern "me<anything>mail42@me.example.com", then I can generate as many on-the-fly unique emails as I want, without maintaining any lists, and without catch-all forwarding of random spam to my inbox.
If I use me+anything@me.example.com, I get the same exact feature, but the downside is "+anything" is recognized by some and either disallowed or used to generate more patterns.
If I use subdomains (like anything@me.example.com) I have the spam issue.
With a white pattern scheme, you can choose your own pattern (so sites can't really catch on), not have to maintain any lists, and avoid spray-and-pray spam.
It has the advantage of being able to spontaneously create email addresses when signing up for things, while still blackholing most guessed addresses.
I like this idea a lot.
I suppose google domains might be OK for personal email.
The only downsides I see are that (very few) sites still complain about the perfectly legal + symbol and some sites / bots are probably starting to reverse engineer that since it still exposes your username. But so far, I've yet to have a single site or service expose my primary mail account, so it at least helps.
Finally: this is a fantastic hack for testing your own signup flows. :)
With qmail the "standard"[1] was username-alias@example.com, rather than username+alias@example.com. I rather prefer that - but then my (user)name(s) don't contain any hyphens.
Either way I think it looks better with system usernames - firstname.lastname@example.com was/is usually handled as a separate form of alias look-up anyway.
[1] http://www.lifewithqmail.org/lwq.html#dot-qmail-files See section "4.1.5. extension addresses"
[ed: and I recall using tmda as an anti-spam system - it inserts an encrypted tag in the alias portion, that can be stamped with an expiry date, and tied to a sender address (eg hmac(userkey, sender@example.com+01012018) => xyxyzzzzz - give sender@example.com the address user-xyxyzzzz@example.net - and mail to that address will be accepted from only sender@example.com until 1/1/2018.
Believe I saw this on HN recently: http://haacked.com/archive/2007/08/21/i-knew-how-to-validate...
With a service aggregating these, we see many users from NBox. Perhaps this is not a concern for your use case, but it seems a tradeoff worth considering.
Depends who is tracking you.
If I register some non-personally-identifiable domain "e.g.: bumblebutt.example" and use a WHOIS proxy, you're can only be given up by a registrar... which usually means a warrant.
Still paranoid? Pay for the domain using bitcoin you got in exchange for cash/services (there are a lot of registrars that take bitcoin).
The benefit of a public site is that you can't use the hostname as an identifer for a single person.