But you know what really happened? I wound up with hard to remember email logins and caught less than a handful of services sharing my email address without my permission.
It wasn't worth it.
But you know what really happened? I wound up with hard to remember email logins and caught less than a handful of services sharing my email address without my permission.
It wasn't worth it.
Big mistake.
First off, I got FLOODED with e-mail bounce-back spam because spammers send e-mail with forged From: headers and I'd get all the errors.
Second, I discovered that nobody is actually selling my e-mail address except for one gaming forum I used years ago. Not even Facebook has sold my e-mail address.
Third, I've run into issues when replying to e-mails. I filed a support ticket with a company once, where the e-mail address I had registered with them was company@mydommain.com. They responded via e-mail, and when I replied to said e-mail, their ticket system rejected it since the From: address was my main address of myname@mydomain.com.
Now that I want to just switch to a single e-mail account with gmail, I find myself needing to try to find every e-mail address I've used @mydomain.com and changing them with the website. Meh...not worth it.
Won't FB be among those least likely to sell your email address? FB has tons of ways to make money using your data. Your email address offers very low marginal utility over all the rest of your data.
"thus the marginal utility of a good or service is the change in the utility from an increase in the consumption of that good or service." [1]
The third problem is more serious. I use Thunderbird. I googled and there are a couple of addons that makes it easy to edit the from address without having to create new Thunderbird identities.
https://github.com/absorb-it/Virtual-Identity
https://freeshell.de//~kaosmos/index-en.html#editsender
Both are somewhat unsafe, one because of the site certificate, the other because of the download site.
The first problem looks like a showstopper tough.
This is the one I use.
These days I don't even use Thunderbird. I just have gmail retrieve all my e-mail from my POP3 server. Though FWIW, I still have Thunderbird installed with all my e-mail going back to 2003. I imagine there's a way I could capture every e-mail address I've used then manually go to each web site and change my registered e-mail address.
If your Fastmail address is dfinniger@fastmail.com then you can randomly create emails like:
some-domain@dfinniger.fastmail.com
and it will automatically send them to your main email.
It's very convenient, and the cost per year is likely to be less than your hourly rate multiplied by the number of hours it'd take to set up self-hosting.
* monster.com
* linkedin
* Pragmatic Programmers (pragprog.com)
* audioscrobbler (now part of last.fm)
* The London Cycling Campaign
* The Economist's subscription department * Dropbox
* Adobe
* ...
The list is long!These aren't small numbers, either. We're talking about 68 million logins for Dropbox and 150 million for Adobe. To put those huge numbers in perspective, combined that's over half the population of the USA.
Can you elaborate ? I have been meaning to set up just such a mechanism as it has always seemed like a good idea ...
It seems like "rsync.net@example.com" would be very easy to remember and associate with the site (rsync.net, in this example) ...
As you say, using a password manager, or just picking a nameOfService@example.com style of email, means remembering the email addresses is pretty easy. n.b. you may need to also set up your email client to let you send emails with a customisable address too.
Spammers who send stuff to randomAddressTheyMadeUp@example.com can be mostly blocked because these tend to have a messy jumble of text and numbers - I use a simple regex to throw away these kind of spams. I use procmail to do the blocking, but I'm sure there are many other tools that would work just as well.
Recently I came up with another solution that I know some have used:
Stick to one email address and have a whitelist. Anything not in the whitelist is "spam" (including irritating LinkedIn emails, etc). If I get email from anyone not in the whitelist, they get sent an email with a website link asking them to confirm their identity by submitting their email address. Once they do that, they are whitelisted and all their quarantined emails show up in my inbox.
The only remaining part is constructing that whitelist. I wrote a script to go extract all the From addresses and just dumped them in there. So people who've emailed me in the past will not deal with going to the website to confirm their identity.
If I get email from an entity I no longer want to see in my inbox, I press a keystroke to remove them from the whitelist. Likewise, if I go to my quarantine folder and see an email I'd like to whitelist, it's done with a keystroke.
Been using it for less than a month, and it is quite effective so far.
You know, the sender header is just a text string... What stops you from putting whatever e-mail alias you registered with as sender, for those occasions?
Cognitive load. I don't want to:
1. Think about it. 2. Figure out which email address goes with which To: field. 3. Find a way to automate all this.
In the end, my solution would be less work to get rid of unwanted emails than using a catch-all. Why should I do the extra work in maintaining the system, when the sender can do the tiny amount of extra work instead? More fundamentally, why should anyone feel they have the right to just insert anything into my inbox? I should control the inbox - not them.
By default I only ever receive a limited number of emails from any new emailx@mydomain, unless I explicitly go to @mydomain and allow a specific emailx@mydomain to pass that limit.
My only irritation is that some vendors block @mydomain as a valid email address, in which case I use an ancient email address in its place. Needless to say that vendor will never see my main email.
This is to stop somebody eventually gaining control of the domain when it expires, setting up a catchall on it, and then being able to login to every single account you used with that address.
Some registrars protect a domain after expiration so nobody can hijack it and claim it as their own, but you often have to pay extra for this service.
Only downside, is when company merges or renames: if it merged I end up with to accounts which have half of the history; if it renames -- hard to remember original email (recent example wayfair's old name was something else).
Now, I'm switching to single email -- it's just simpler
I sore it in a password manager, so remembering the address is no problem.
If you use a "regular" character like "." as a separator virtually all sites will accept the email as valid vs using something like "+".
You could easily argue this is a symptom of a different problem.
1. Before the actual sending of the mail data, the sending server connects to your mail server and after a polite introduction sends 'RCPT TO: xxxx@yyyy.com'. This is where your unique-for-that-site email address is used.
2. Later on during the transmission, all the 'real' mail headers are sent, and this is where the To, From, Subject, and CC headers are set. If you were BCC'd there is no 'BCC' header, so the 'To' header normally has the mail address of the original 'To' recipient. Or in a lot of cases the 'To' header is omitted entirely. Depending on your mail client, you will either see your name in the To field, or something like 'Undisclosed Recipients'.
Spammers typically shake it all up, so that the 'To' header rarely matches the 'RCPT TO:' value.
In my bespoke anti-spam system, I re-inject the 'RCPT TO:' and 'MAIL FROM:' into the mail headers (prefixed with X-) so i can easily see in my client what is actually going on.
It's worth it and only 1 password
s/+.*@/@/g