Hacker News new | ask | show | jobs
by mmcclure 2373 days ago
This is a really cool project, so I don't mean to be overly negative, but personally this workflow feels quite a bit more laborious than just having a catch-all email address. Before signing up for a service, I need to email myself to get an address to use for the service?

I have all emails for my domain route to me, so when I use a service I just do [service-name]@my-domain.com. If a bad actor gets a hold of it I set up an inbox filter or black hole the email address at the service level. The big advantage of this project seems to be that you can reply, but I've found that a huge proportion of these email aliases are inbound only for me.

I'm using GSuite for my personal email but I've been considering Fastmail. Just checked and it looks like they also support sending from those catchall aliases: https://www.fastmail.com/help/receive/alias-catchall.html

5 comments

Totally agreed, I do not want to manage my own workflow in a manner like this. I actually just put a doc together[1] last month for anyone looking to do the same through providers that support this workflow.

The one killer feature that is missing in Fastmail right now is the ability to reply to email as the same alias it was received as. I.e. if Airbnb support emails me at airbnb@mydomain.com, it'll default replay as me@mydomain.com unless I go manually setup the airbnb alias.

[1] https://btmiller.com/2019/12/12/regain-control-over-your-inb...

I remember thinking the same thing last time I looked into Fastmail, but earlier when I was checking before posting, it appears that's gotten much, much better. From the Fastmail docs[1]:

> Creating an [wildcard] alias also creates a matching sending identity. This means you can also send mail using this wildcard alias. When sending from a wildcard alias, you'll be able to manually type the From address (to sales@mydomain.com or accounts@mydomain.com, etc) when writing a message.

So, yes, it appears you still have to manually set the from address, but at least you don't have to actually go do anything outside of the composition interface anymore!

[1] https://www.fastmail.com/help/receive/alias-catchall.html

Oh neat! Now this needs to be in the native iOS Mail client.
I am using Exchange Online, and I cannot reply using aliases that I've created. It also always defaults to the primary username. Anyone figure out a way to make this work in Exchange Online?
I can't find the link on mobile but this was a recently announced "coming soon".
You're going to get an astronomical amount of junk mail with a catchall email address. Google is great at filtering spam, but not perfect. If you're running your own mail server, you're going to have a hard time dealing with it, even if you use SpamAssassin and other tools. It's also going to get worse over time, because every address that accepts delivery is going to get added to a database for future spamming.

I use Postfix and ViMbAdmin to manage my whitelist via a simple web UI, and I don't find it to be onerous. I don't sign up for new services every day, and it takes about ten seconds to add or delete a service-specific alias.

I disagree with the "astronomical amount of junk mail" statement. I've been using FastMail with a catchall email address for years, and get very little spam; most of which is correctly classified as such (I did have to 'train' FastMail for a while with custom spam/no spam folders though).
Yeah, I've also been using this approach for years now and see significantly less spam on this personal, catch-all account than I do on my work email (both are Gsuite). I will say I was honestly surprised at just how little email I see coming into random email addresses via the catch-all; over years I'd say (anecdotally) that number basically rounds down to 0 versus my "legitimate" email.

Most of the time I do see an influx of spam it's because of one of the aliases clearly having made its way on a list, so I'd say the system is working as intended.

I have a catch all address vor two years now and I never got spam through an address that I didn't create by myself.
No worries, thanks for the feedback (I appreciate all feedback whether positive or negative).

A catch-all email address is actually less complex to build and test, but there are a couple of reasons I chose to use this approach:

1. It seems that in the workflow you described, there is some work to be done in setting up an inbox filter/black-holing the email address too. In a way, my workflow simply shifts this work to the start?

2. I don't think it's laborious because I don't really need new email addresses that often. It's also really easy to generate a new email address imo - no logins or portals required, just email generate@mydomain.com and you get a reply with an email address within seconds.

3. You're welcome to fork it and tweak it for personal use too if you want! :) I'd love that.

Thanks for the reply!

1. I don't really think your workflow shifts any work over the catch-all workflow, it simply adds another step. In my workflow I essentially already have that alias you create in your first step. Then, if that alias gets abused, both systems require shutting off that alias.

2. Yeah, that's definitely just a different usage pattern. I'm one of those folks that enjoys testing out different onboarding workflows, etc, so I'm constantly signing up for services, etc.

3. I'm quite happy with the alias approach, but best of luck with the project :)

For groups of people, you can also do,

[service-name]@[user-name].my-domain.com

to provide everyone the same capability.

Email aliases ([user-name]+[service-name]@my-domain.com) isn't the best solution when spammers can remove the alias part (+[service-name]) and you can't know who leaked it.

Set a dns record for catch-all