Speaking of such (which is a valid concern) I always use a nice feature from gmail which gives the ability to append +anything to your username. Mail will be forwarded to your inbox as usual where you can apply filtering to know whom as leaked your email. Hence you can use username+foobar@gmail.com while registering for foobar webapp.
This assumes that foobar webapp accepts + as a valid email local part character which is not always the case unfortunately (and against RFC) but that is another story.
Just sayin