I've been doing the same for 20+ years (started in 2001, at the time hosting my own sendmail), so I have used custom email aliases in thousands of sites, from retailers, banks, government websites, and everything else you can possibly imagine. My recent experience has been similar to yours, but it is a more recent development.
In the beginning I used to receive a lot of spam -- sometimes dozens per day. I'd frequently get blasted with dozens of the same spam, to every possible alias they had access to. Sometimes they would use randomized From: addresses or other small customizations to trick spam filters, but frequently not even that.
Also I remember receiving spam on addresses used for companies which had never publicly disclosed they'd been hacked (looking at you, NYC MTA [1]). A few times I tried reaching out to the company to alert them, but it was always met with skepticism, plain denial, or outright passive-aggressiveness (e.g., "_How do you know?_", potentially implying I was involved). Fool's errand.
At some point I moved to Gmail when they started offering Google Apps for Business with custom domains. At the beginning their spam filter was very weak, but it got progressively better.
Over the last 5-6 years, the volume decreased dramatically. At most I get a couple of dozen emails per week (almost all flagged as Spam). I'd imagine the combination of IP filtering, email authentication (DMARC, SPF, DKIM), and ML-based spam filtering got so good that spam isn't profitable for anymore.
I also monitor my domains with Have I Been Pwned [2]. As of today, I have 59 of my aliases in leaked databases -- which is a small fraction of the leaks I've experienced firsthand over the years.
[1] https://twitter.com/GuiAmbros/status/1555358970516328449
[2] https://haveibeenpwned