7 ms·
> services should allow me to easily create lots of aliases. Right now the best defense against social engineering seems to be my fastmail account which allows
by nmjohn 11y ago
> services should allow me to easily create lots of aliases. Right now the best defense against social engineering seems to be my fastmail account which allows me to create 1 email address alias per service
What you may want is a catch-all email - which lets you do @domain.com -> nmjohn@domain.com (where is everything besides already defined addresses) - that way you can make up emails on the fly without having to setup the alias beforehand.
I've had that setup for 5 or 6 years now, and it works extremely well. A handy side-effect of this is it makes it easy to see which companies sell your email address to spammers when you included the name of the original company in the email you register with
- JoshTriplett 11y agoNote, though, that catch-all emails will also catch a ridiculous amount of spam. Creating each account name individually avoids that problem, at the cost of some extra trouble when registering a new service. An intermediate step that may work if you don't expect people to target you individually: have one or more required substrings for the email local part, and catch all mail to addresses containing that substring.
- _ikke_ 11y agoI created my catch-all on a subdomain. While it gives a problem with certain websites (don't consider it a valid e-mail address), I barely receive spam on it.
- belovedeagle 11y ago> While it gives a problem with certain websites (don't consider it a valid e-mail address) Are you saying that there are sites out there which don't accept mailbox@subdomain.example.com a valid email address? If so, that's beyond broken...
- steve-howard 11y agoMy school's student addresses ended in @u.northwestern.edu. You can imagine this was annoying sometimes when email addresses ending in .edu were used to verify student status.
- mappu 11y ago>My school's student addresses ended in @u.northwestern.edu. You can imagine this was annoying sometimes when email addresses ending in .edu were used to verify student status. Sorry, could you repeat that? yourname@u.northwestern.edu certainly matches \.edu$. Unless you're worried about the false-positive for a non-student with a different subdomain?
- thecopy 11y agoIt doesnt match \w\.edu$
- kuschku 11y agoAnd you can imagine how maddening it is when 90% of students worldwide don't have a .edu, but some do. Only one university in Germany has a .edu, and their students obviously manage to get far more benefits than those of us with an @informatik.uni-kiel.de email.
- pcora 11y ago99% of times we need to send proof that we are students, what is interesting is that many companies accept that even if it's not in English. Probably on good faith. In Brazil, universities can use .edu.br, but we have few universities providing email addresses to students and also, the majority of grad schools in Brazil are not universities but a small college called 'University Center'
- jakobegger 11y agoI receive all mails @ my domain and I get about 1 spam a day. Fastmail's spam filters are pretty good.
- bigiain 11y agoDo you have a good idea of the rate of false positives?
- jakobegger 11y agoNo, I don't check my spam folder. Never had any reason to do so in the last couple of years.
- pyre 11y agoOne method that I've seen used (heard it described by a guest one of Leo Laporte's podcasts a looooong time ago) is to iterate account names by year. For example, this year the email address would be pyre2016@example.com, and next year it will be pyre2017@example.com. Not sure how well it works, but the idea is that by that every year you start over with a fresh address (that takes a while to get onto spam lists). I'll note that I don't use this method as it seems too high maintenance and the effectiveness is unclear.
- newman314 11y agoNot a big deal if using a password manager and email acts as username.
- pyre 11y agoUsing it as your mail email for personal/business purposes could run you into trouble though. Most people aren't used to a rotating email address.
- jethro_tell 11y agoI believe the real issue here is its not uncommon for spam services to try to locate valid email addresses. Generally, an email server won't accept email to an invalid users and will probably start flagging the incoming server/domain as those attempts start to cross a threshold of some sort. OP is talking about *@example.com as a catchall which means a spammers script will sit there and email a dictionary of usernames against your domain until it crosses it's own threshold. It's not too hard to add an alias for each name as you go along but it really depends whose list your domain gets on.
- pyre 11y agoI was talking about making those actual accounts vs. aliases to the catchall address. That method makes no sense if each pyre<year>@example.com email address was just an alias to the catchall because pyre<previous_year>@example.com would still be caught by the catch-all, even if you disabled the alias.
- morgante 11y ago> Note, though, that catch-all emails will also catch a ridiculous amount of spam. I haven't found this to be true, or at least Google's spam filters have gotten sufficiently good to prevent it. I have a catch-all address @morgante.net and rarely ever see spam—maybe once a week.
- pavel_lishin 11y ago> Note, though, that catch-all emails will also catch a ridiculous amount of spam Hasn't been a problem for me.
- tyingq 11y agoYou can approximate this with gmail using the plus sign. Like myaccount+label@gmail.com. It's ignored for delivery, but gmail's filters can match on it in the to: address.
- DougWebb 11y agoEvery time I've tried to use that feature, the email field in the registration form I'm trying to fill out rejects it because they don't like + in an email address. There are a lot of not-quite-correct email form validation routines out there. Or maybe this is selection bias: the forms where I'm most likely to want to use the + are with the companies that are most likely to want to resell my email address, and they may be intentionally rejecting the +.
- 6502nerdface 11y agoLots of programmers try to write regular expressions to validate e-mail addresses, but it's extremely difficult for them to get it right, because valid e-mail addresses as defined by RFCs 822 and 5322 fall outside the set of formal languages describable by most regular expression libraries. See this fun stackoverflow answer [0]. [0] http://stackoverflow.com/a/201378 http://stackoverflow.com/a/201378
- mdavidn 11y agoFastmail and Gmail support a local suffix of the form yourname+amazon@gmail.com. That's a plus character between the local name and local suffix. If you use a password manager, you can replace a predictable suffix like "amazon" with random hex value. Unfortunately, many sites borked their e-mail address validation and do not accept the plus character. (Amazon permits it.) Also, you'll ocassionally find a customer service ticketing system that expects replies to come "From" your account's e-mail address. (Many mail clients can alter that header, but it's a pain.)
- sombremesa 11y agoI fear that customer support might still accept emails without the suffix from the "customer". These are people, not robots, so if the address is close or in the vicinity of being correct, they might accept it. Same goes for the dot characters allowed in gmail addresses.
- ajmurmann 11y agoI strongly second this concern. I generate random strings as answers to my recovery questions. When I recently got asked one of the questions the support rep let out a sigh when asking (presumably because he saw the "crazy" answer) and then said "yeah yeah, alright" when I was about half way through the answer. That any company even suggests these insane security questions that anyone can trivially research is completely beyond me.
- bigiain 11y agoAn idea I just had which is buried in a deep thread lower down... Not that I trust the "security questions", but if Amazon lets you use freeform questions as well as answers, it might help to make your first security question "Have you noticed this account has two factor authentication turned on?" with an answer like "Yes, so Amazon Customer Service will take additional care when being asked to reveal account information, right?" Even if you can't do freeform questions, perhaps the answer to "What's your mother's maiden name?" could be something like "Have you noticed this account has two factor authentication turned on? Please take extra care before disclosing account details to anyone, Thanks."
- jedberg 11y agoMake sure you keep a list somewhere of which site got which email address. I used to do this too and it was great, but then when I started trying to recover accounts that were a few years old, I had a heck of a time remembering what email address I had actually given them in the first place!
- chime 11y agoI just do compapyname@mydomain.com. That's how I knew Broderbund sold my email address.
- jedberg 11y agoI was doing that but some companies think you are "hacking" if you put the company name in. Like I don't think you can do facebook@mydomain.com on Facebook.
- Macha 11y agofb@mydomain.com is perfectly usable though.
- joshstrange 11y agoSo I think that was grand-OPs point to a degree. If you can't always do companyname@mydomain.com there is a change you will forget what you used: Example: aws vs amazon-web-services vs amazon.web.services facebook vs fb vs fbook Or for example I've used Rally the project management tool but my health insurance uses a (terrible) "rewards" program called "werally" but it's ALWAYS referred to "rally". It can get unmanageable. Now I use 1Password to track all of this stuff which works well so I think there are solution but I do understand the grand-OPs point.
- teach 11y agoI would tell you that my FB email address has that format, but maybe I'd be leaking too much information by doing so....
- 11y ago
- awqrre 11y agobut then the spammers use BCC and you don't know what email they used?
- Rondom 11y agoThere's Envelope-to, which is the only thing you should at. To, From etc. could be forged.
- beneater 11y agoI've done this and once had a phone rep from Geico who was convinced I worked for them because my email was something like geico@example.com. This was probably in the late 90s when email was still new to many people. She was really confused that I wasn't getting the employee discount. "Are you sure? Does a family member work for Geico? No? Are you sure?..." I don't think she ever did really understand what was going on. Perhaps I could have saved even more than 15% if I'd just gone with it. :D