Hacker News new | ask | show | jobs
by jonpurdy 1552 days ago
So I've been tracking companies that don't honour the unsubscribe link for 10 years. I've found that a few companies per year (out of hundreds I'm tracking) end up emailing me 4-5 years after I unsubscribe, as if a new marketing intern got a copy of the old customer DB from years ago and figured it'd be okay to just spam it.

Aside from my article※ explaining the basics of email aliasing to avoid this sort of thing, a few more suggestions:

You can use a service like Mailinator or Mailnesia for one-time disposable emails, but I actually use it for services that I will use for a limited time, even if I pay for them. Sometimes companies make it hard to delete an account, and others make it impossible. So just generate a very long random email and it'll be unlikely that anyone would collide with it. Then just fill in random or fake data for anything personally identifiable. When it comes time to delete the account, just abandon it rather than jumping through hoops to delete it.

If you need something that is more secure and still trivially easy, I highly recommend AnonAddy. Just make up an email alias (for you_subdomain.anonaddy.com or a domain you point to it) and those emails will get forwarded to an email address you specify. All emails forwarded from AnonAddy have some controls on the top, so if you get spammed with automated email from PMs asking for your feedback you can just delete the alias from the email.

This would not be of use for something like Cloudflare though as it's a critical service, but very useful for less important services that cost between $0-10/mo). If they end up being critical you can just change the address to an alias on your main domain.

※ - https://jonpurdy.com/2020/06/using-email-aliasing-to-detect-...

2 comments

I've moved most of my marketing mails to unique Fastmail Masked Emails: https://www.fastmail.help/hc/en-us/articles/4406536368911-Ma...

And with 1Password integration, most new services that I wouldn't give my real name to will get a Masked Email too.

If I get spam, I know exactly where the adress came from and I can just destroy the address with one click.

This is how I've been managing my personal email account for some time.

Have you noticed that some services won't let you use their name in the email through?

Samsung, for example, wouldn't let me spell out the word "samsung" in the email field at all.

> Samsung, for example, wouldn't let me spell out the word "samsung" in the email field at all.

I wonder if this is, in their mind at least, a sort of phishing prevention/deterrent.

I also use the [foo-company]@[my-domain] structure, and the number of times a customer service rep has asked me "Oh, do you work for [foo-company]?" is more than I can count.