nytimes@mailsub.example.com -> jono@gmail
anything-else@mailsub.example.com -> jono@gmail
You dont even need to materialize aliases at all.
nytimes@mailsub.example.com -> jono@gmail
anything-else@mailsub.example.com -> jono@gmail
You dont even need to materialize aliases at all.
Also, another downside is that you will loose privacy by using your own domain.
And the lack of privacy makes targeted scam/phishing more likely, and targeted scam is the one we are most susceptible to.
All in all, I am not saying this is bad idea, in fact I am doing it myself, just pointing out this is not so black and white.
Using iCloud solves those problems, but puts you at risk of getting your account banned and loosing access to those emails, so there is that.
Probably best way to deal with it is to get dedicated email domain with a bunch of your friends, and hook it up with something like SimpleLogin. But that's gets complicated quickly ;)
However be warned some surprisingly large websites don't support subdomains, for example eBay will silently send user@sub.domain.tld to user@domain.tld and you'll only figure it out by looking at your server logs for rejected mail.
In those cases I have to specifically alias that username@domain.tld to the subdomain.
With this new Apple privacy subdomain maybe eBay will finally fix this.
If you are worried about privacy, get a domain just for this. Use domain privacy and dont host other things there.
Yes, some sites whitelist domains or dont allow subdomains. For those I'll use another account - or a firefox alias or something. But 9 out of 10 work fine.
I am not a fan of alias services since materializing names takes discipline. How many do you make? Maybe there is a limit of 50. When do you share them across services? My guess is many people just create 2 or 3 aliases they use for everything - which defeats the purpose. Sure, it masks your personal address, but once one gets compromised, you find it basically served as your personal address anyway.
I also dont really keep track of most of the names I use. Since most are one time things that I would never use again, like to sign a waiver or something. But I mostly stick to '{domain}@' for the names. So my nytimes account would just be nytimes@, which is predictable when I need to recover it. I used to use addy.io for this, but it was not as good since it had account limits and I had to manually manage every alias. Much easier for me to just create a mail filter to sinkhole an old name. Of course I have never really needed to do this anyway.
Someone I knew did this. Spammers used lists of common names.
Not really no. You can absolutely create a domain using bogus WHOIS information. No one will bat an eyelid.
The privacy preserving aspect of hide-my-email services is the fact that they have thousands of users using the same domain name.
[1]: This is trivial if you have a service's email database leak. You just find all domains that have exactly one user. If the service targets individuals (who would sign up with personal emails, not work emails) and is reasonably popular, you'll get a pretty good list of single-user domains.
How would that attacker gain access to such databases? Let's say HN is compromised and my email here, say hn@mydomain.com, is leaked. How does that help you track me elsewhere? If I start receiving spam at hn@mydomain.com because of the leak, I will simply revoke the alias and the spam will bounce.
Data breaches happen all the time.
Some services also expose emails, intentionally or unintentionally. Github is one example where your email might be exposed publicly.
> How does that help you track me elsewhere? If I start receiving spam at hn@mydomain.com because of the leak, I will simply revoke the alias, and the spam will bounce.
Because, as parent said, if someone deduces that you are the only user of mydomain.com, they can just search leaked or exposed records for @mydomain.com and infer that the accounts most likely belong to the same person.
That's the difference, with hide my email millions of unrelated people share the same domain, so you can't reliably link one email to another just based on the domain.
It's a non-issue. I've been using a catch all domain for at least a decade. I get a small amount of spam to random made up emails but not enough to care about plus it all gets caught and filtered.
So, it's a piece of cake to add "{random}@example.com" to the block list. Usually it's something like "msg-bestbuy@example.com".
But the people usually just nod along.
The other downside is that it's forward-in only, wish I could proxy responses without setting up a whole new inbox (and outbox).
But to the point of forward-in-only -- I use the fastmail web client and iOS client. Both of these respond using the Masked Email address if you choose to respond to an email. In fact I can choose any of my masked email addressed as I am composing mail to initial communication from that address.
In short, "it just works". I really can't say enough good things about Fastmail!
I had one small business aggressively threaten me that they fully owned their business name and I wasn't allowed to use it in my email address.
My solution was to keep my wonderful aliases and dump them. If a business is concerned but nice about it I'll offer an alternative such as plumber@
> The other downside is that it's forward-in only, wish I could proxy responses without setting up a whole new inbox (and outbox).
If you have your own domain most mail providers don't care what username@ you use on your sent mail so you shouldn't need any additional mailboxes (especially if they already offer inbound catch all)
I also use the ReplayAsOriginalRecipientUp [1] extension in Thunderbird which takes the recipient address and puts it as the sender for ongoing communication.
[1]: https://addons.thunderbird.net/en-US/thunderbird/addon/reply...
I haven't had that, but before I switched to Hide My Email I've had many businesses ask if I was an employee of the business - many people don't intuit the difference between john@bank.com and bank@john.com.
I was once on the phone with german insurance provider and they dictateted me email to send documents to: kundenbetreuung@passportcard.de
I dont speak German so it was both tough and funny EuroTrip-like moment.
Yes its really email they use.
If you try to sign up with a domain they don't support, they tell you something like "please use a popular email provider like gmail"
But keep good records!!
It gets really awkward when you’re trying to recover an account and can’t remember what custom email you used.