One of the really nice parts of building this out with Fastmail is that you can create Masked Emails for your own domain. So, if you ever decide that Fastmail isn’t right for you, then you still receive all of those emails when you set up a wildcard alias with your new email provider.
Similarly, if you ever decide that 1Password isn’t right for you, that doesn’t stop you from receiving your emails. And the email addresses should still be part of your 1Password export.
myaccount+alias@mydomain.com
automatically?
Disclosure - I work at 1Password, though I had only tangential involvement in this effort
Settings -> Domains -> Team Settings -> Masked email domain
It will default to fastmail.com, but easy to change it.
The full "it just works" integration seems to only work between 1password and fastmail directly.
We go one step further and generate a random email address for each new service you sign up with. It'll look something like "hot.potatoes4827@mydomain.com".
You can create a new masked email anywhere you have the 1Password browser extension, including our brand new iOS Safari extension.
Unfortunately, way too many internet services don't allow the plus sign in an email address. It's weird, but it's true.
How hard is that though? Export all email addresses from 1Password (trivial), extract generated emails (trivial), and add forwarding rules for each one in your mail server (trivial to easy depending on your setup).
Maybe not easy for non-savvy users, but neither is a custom domain or even knowing about the + trick.
It still could.
> Everything is still tagged to your identity, i.e. @mydomain.com.
If your domain is tied to your identity, then yes. But to be extra clear, this should have said "Everything is still tagged to your domain" as not everyone has their domain tied to their identity. I for example have my domain setup njal.la with zero personal details attached to the domain itself, either publicly or at njal.la.
Otherwise subaddressing with + works well with most mail hosts other than Microsoft Exchange / Office365 (which have had endless problems).
The advantage of Masked Emails is that third parties won't even know about mydomain.com. The disadvantage is that you need 1Password to recall which email address you used with a particular website.
The main thing that always held me up was, how do you plan to avoid getting blacklisted at the domain level if people start abusing the ability to create random emails? A few services I use even disallow Gmail addresses.
I can't fully speak for the Fastmail folks, but I know that there are a few upper limits for how many masked email addresses that one account can create. We tried to set them unreasonably high to allow for all manner of legitimate use while still preventing bad actors. They're also monitoring usage and tuning that limit. Plus, you can always email support and ask for a increase for your specific account, if you ever bump up against it.
mailinator's been around providing this (as a recieve only) service for decades by this point.
Edit: saw someone point out this only works for one user per domain.
I suppose the advantage with a non-custom domain is you leak no info about yourself, the masked email is 'just another Fastmail email address'. But doing it for a custom domain feels like it defeats the point, isn't it just like catch-all at that point?
It’s what I do with a custom domain (though only have a handful of custom aliases currently).
Having this integrated in a first class way is a nice surprise and a really great feature imo.
It’ll make it easy to see who leaked your email and kill the alias while also not locking you into to fastmail forever as a provider.
The Masked Email integration makes that entire process automatic. It's even easier than before. It's enough to convince a few Fastmail-using friends to start doing it.
Lately I’ve been combining this with cards via privacy.com to further limit my risk in the event of another data breach, and so far it’s working quite well, though I do have a long way to go to fully convert everything.
As for longevity, Fastmail has been around since 1999 in some form or another, and even made themselves independent again after being acquired by another company through an employee buy-out. https://en.m.wikipedia.org/wiki/Fastmail
Most of it comes to two addresses which are public via git (one from commit logs, the other explicitly stored in a repo).
0: https://www.email-validator.net/blog/validating-catch-all-em... (warning: annoying marketing page)
[1] https://en.m.wikipedia.org/wiki/Mass_surveillance_in_Austral...
It's a legal and bureaucratic not technical puzzle. I wouldn't believe any comfort statement on the point either. This sequence isn't a bug, it's a feature of the Five Eyes configuration.
Again that is more manual effort, though I don't consider it much effort given that I'm only signing up for a limited number of sites per year. And I suppose a little extra friction in one respect isn't even that bad a thing, makes me think a bit about whether I do actually want to sign up there. Ideally I'd like to see more efforts about making such things standardized across providers so that even regular people can get the benefits from near any registrar or email provider at all with whatever tooling they like. I guess that's probably either infeasible, or if it happens it'll be out of a rise of competing centralized masking providers raising the issue high enough in the general consciousness that demand drives it. If there are any existing open efforts around that I'd be delighted to know about them though!
When I sign up for a new service, I register on the spot as e.g. amazon@mydomain.com, the mails they send are considered as a 'mistaken sender' and are sent to the catch-all mailbox (which is just my regular mailbox!)
The downside is that you (and spammers) can* send email to any random address and reach me, but in practice I have not found that to be a problem; I don't actually get spam at addresses which are not posted somewhere online. And it's in your best interest to contact me at a more specific email, because if I ever do get widespread spam, I'll swap the default rule to mark as spam, and only allow specific addresses. I recommend hn+«your handle»@«my domain».
On the off chance: I'm moving to NYC soon and am in the job market; feel free to shoot me an email if you're hiring at a company that's solving real problems for humans (not, say, selling ads).
The single other significant issue I can think of which has come up actually is when one desires to actually use email for two-way communication with a site, not just receiving stuff. Sending from aliases isn't really practical, spoofing the from address even from the same domain has a high chance of trigger all sorts of spam protection for obvious reasons. I'm sure there is probably some way to handle it from one's own server but that has its own challenges. So sending mail ends up being from a different address as the account, which most places don't seem to care about but seems to hit automated edge cases and snag things up once in a while.
This is why using a different email with each website is glorious! If example.com leaks my example.com@«my domain» address, I can enable stricter filters for that address.
> I suspect if they become popular enough it's only a matter of time before spammers add some sort of "this looks like a catch-all account type email, try sending random stuff" to their logic.
This isn't game-over, either. As I noted, if this ever starts happening, I'll change my sieve filter so that any address without a filter rule gets sent to the trash, instead of my inbox. This does mean I lose the "zero friction" benefit, but adding a new address would still be just a single line in a text file. And it's much less lock-in than using the web interface of some given email provider to set up new aliases, since I can copy my filtering config over to any provider which supports sieve filters (and wildcard addresses).
That said, I don't think this will ever be a problem. Because "this looks like a catch-all account type email, try sending random stuff" is a pattern that makes you very easy to identify as a spammer. Given the possible address space, I don't see a scenario where the chance of hitting a real mailbox is worth the risk of blowing your cover and getting your mail server blocked.
For sure we recommend (and make it very easy) using your own domain. We want you to stay because we're providing you enough value to be worth staying, not due to lock-in.
> New Masked Email addresses will be created @fastmail.com. You can change this in Settings → Domains
I agree with you, and I'm looking forward to be trying this out.
I think a lot of people have been spoiled by gmail's longevity. Unless you're using your own domain it's a wash anyways right?
I think this is an acceptable trust. I personally prefer trusting something with more longevity than fastmail (apple hide my email).
> I personally prefer trusting something with more longevity than fastmail
Fastmail launched 5 years before Gmail, in 1999. It's also a paid product with a sustainable business model. It's hard to get more longevity than that.
> I personally prefer trusting something with more longevity than fastmail (apple hide my email).
Fastmail (launched 1999) is older than Gmail (launched 2004).
For people who want to do this and care about retaining ownership, would be probably wise to run their own email servers and using different patterns of catch all addresses.
Email can be portable, but I think it’s gotta be easier to come up with a portable email address than expecting everyone to buy a domain and set up the DNS records? Does a registrar of email only domains exist today?
Wait till 2038 so you can say "aha! I told you so!"
or have peace of mind during the prime of my life for the next two decades