This has two benefits: I can easily route/filter incoming email from that vendor, and if I ever receive spam at that address I know which vendor sold my info.
This has two benefits: I can easily route/filter incoming email from that vendor, and if I ever receive spam at that address I know which vendor sold my info.
Obligatory mention: https://haveibeenpwned.com
It would be important to stress it out on the page that it may be due to security negligence/failure rather that just data sale.
I’m working on something I call “datapoint tax”
Make this hoarding of data a (tax) liability. A policy like this will solve most problems.
> This has two benefits: I can easily route/filter incoming email from that vendor, and if I ever receive spam at that address I know which vendor sold my info.
There's just nothing actionable to do with this information. OK, so I caught badcompany.com giving my email address to marketingfirm.com. But the damage is already done. Sure, I can send them a nasty email, but it'll just get ignored or whatever.
And I just never really had that big of an issue with spam where I needed to black-hole a specific email address. So for me it just wasn't worth the effort.
The footer had no unsubscribe option and the "manage communication preferences" requires a login/password combo that I couldn't be bothered to reset for my new geolocation.
I doubt this'll make a dent in Microsoft.com's spam score.
While I think this scheme is perfection in terms of privacy and security in knowing which company sells or breaches my email address... the fact is I haven't gotten a single unsolicited email in the entire 3+ years. Not a single message that hit a spam/junk filter, and not one email that wasn't expected based on whitelisted rules. The closest exception is Amazon who shares your email address with their shippers for delivery notifications; while I do receive 3rd party mail regarding legitimate Amazon deliveries, I've never received any spam to that Amazon address.
I have come to a conclusion as to why I have never received a single spam email since switching to this scheme. When I transitioned my GitHub account away from the old gmail address, I used the privacy option to not publish my REAL email address in Git logs pushed to GitHub. I deleted my old repos, and re-imported using the GitHub-wrapped email address. Thus I surmise that for those of us who are developers pushing code to public Git repositories, the vast majority of the spam you receive is because your email address can be very easily scraped from those Git logs.
I expect to migrate back to a single email address in the future, for a singular reason: as I get older I cannot imagine managing these email filters and password manager entries. Eventually I will need to simplify things.
The action one can take is that if the address is distributed and you start receiving unwanted mail, you can filter out messages to that address.
If you're in the EU, then send it to their DPO instead, and CC the national data protection authorities.
If you were in the EU, they wouldn't have to have presence in the EU to fall under GDPR.
> And then which company do I send it to?
Both! One shared your data with a third party without your explicit consent, for non-essential reasons, the other one is processing it without your explicit consent.
> And what are the chances someone who has resorted to these sorts of tactics is going to care anyway?
Depends. A lot of business do awful stuff for as long as nobody cares enough to start raising fuss about it.
Speaking of that, for extra effect, complain about it on Twitter and Facebook, linking relevant companies' public profiles/pages. In general, it seems a lot of companies (particularly non-tech ones) are extremely sensitive about social media posts.
https://www.enforcementtracker.com/
(And the rules here: https://gdpr.eu/fines/)
Of course there is. When it happens I add an entry to my procmailrc that routes those emails directly to my spam folder, and I never see them again. And I never do business with that company again.
It happens occasionally that they get confused, but so far I haven't run into any issues.
I do agree in principal that it would be better to have some sort of hash that maps their domain to the e-mail in a way that is easy for me to know but hard for someone else to figure out. Ideally in a way that is still reasonably easy to pronounce over the phone.
What would be really slick is to have such functionality integrated into a password manager.
1. Use a catch all alias (zero-effort)
2. Just use the domain or in some cases company name
3. Use a sub-domain
The sub-domain is essential for catch-all, otherwise you get a crazy amount of spam. I forward it all to a single Gmail address, have a rule to move it to a specific folder (based on "to" address), and otherwise let Gmail spam filtering do it's thing.
I've been doing this since early 2000's, and had very few issues with using domain/company. One or two that dis-allowed it, a couple confused humans.
Seconding this. I get a larger portion of targeted spam (addresses that I gave out in the past) with a sub-domain catch-all. At a normal second-level domain catch-all, I get more random spam addressed to common addresses like accounts@, billing@, and sales@.
I used to use this earlier, but then I couldn't find the setting easily on their mobile web interface and got tired of either switching to the desktop version or waiting to get to a desktop to complete a signup. Nowadays, I just report spam if there's no unsubscribe option.
providersWithSuffixSupport = ["icloud.com", "gmail.com", "googlemail.com", ...];
if email.endsWithAnyOf(providersWithSuffixSupport) {
email = email.trimBetweenFirstOccurrence("+", "@");
}I thought it was an interesting blend of technical literacy both to notice and be bothered by that!
I got two mails telling me I cannot use the company name in my e-mail, they'd file for fraud if I would.
(got resolved by explaining how e-mail works, but still)
But really you could just set up a 'catch all' and have everything routed to one inbox, then use filters to filter the emails to separate folders.
So emails to $PERMUTE1@domain.com could be filtered to a $PERMUTE1 folder, and so on.
And you can also reply from such addresses without extra configuration. On the desktop I use MailMate as my email client, which works great with dynamic aliases. The win is that you don't have to configure anything extra when signing up for some online service.
https://www.fastmail.com/help/receive/addressing.html
You can do this in Google Suite btw, as you can configure a forwarding rule. The problem with Google Suite, last time I tried, is that they no longer want to sign emails with DKIM for such dynamic aliases, so you can receive emails just fine, but sending emails from such addresses is a problem if you have SPF/DKIM domain rules.
I had them handle my DNS for that domain so I'm assuming this won't require any extra setup.
(asterisk) means the character itself, I can't figure out how to type one on this site though.
Edit: this wasn't a feature 3 years ago, I only discovered this 4 months ago when I added a few domains to my account and they added the (asterisk) aliases for those automatically.
For example: myemail+twitter@example.com or myemail.youtube@example.com both go to myemail@example.com
Last I remember, dots aren’t a separator like plus is, they just don’t count as part of the name.
So Gmail treats my.email@ and m.y.e.m.a.i.l@ as aliases of myemail@
exampl.e@protonmail.com == example@protonmail.com == e.xample@protonmail.com
This is a good guide on how you can leverage this technique to identify which website you signed up for, and who sold your email to third parties.
https://www.reddit.com/r/ProtonMail/comments/7425v7/protonma...
In my experience, very, very few companies sell email addresses. Maybe 1% or fewer. The vast majority of spam tied to company-specific addresses is the result of data breaches. I get spam to my (old) linkedin, dropbox, equifax addresses - all starting after they were hacked.