That's cool, thanks!
It must've been vacuumed up from other people's contact or email data.
I know that e.g. GMX has had a leak at some point (or sold data), as an email I created there ages ago was used in phishing. Okay, that's lame, but they've also used the fake name I had given to GMX, spelled perfectly. I've never used that name anywhere when signing up, so it must come from the database.
Seems anybody who doesn't use Chrome is automatically flagged even if you are logged in with a >12 years old gmail account that is linked to paid storage.
Recaptcha is hostile to end users and makes my like a fucking hell. But your right, it's my fault.
Edit: three personal domains registered nothing. One corporate domain registered a double digit hit. If I discern any clues I'll get back to the thread.
Maybe Mozilla could partner with HaveIBeenPwned to help dealing with that?
1: https://www.troyhunt.com/ive-just-launched-pwned-passwords-v...
I'd be interested to see the whole dump to see my full record...