I recently setup a new domain with a wildcard forwarder (e.g. *@newdomain -> my real email). I hand out specific names to companies that want emails, and if they bug me I just blackhole that address.
It has worked well so far, though it might break down eventually if the domain gets spammed? Not sure.
Anyways, the domain I used has a 5-character TLD, and some sites have rejected it for that reason. Just a word of warning that >3 char TLDs might not be universally useful.
Those sites probably store passwords in plaintext too.