Sounds about right. Yes, I've been doing it for decades now and besides telling you who's selling email lists, it makes filtering much easier. Filtering by To: is pretty low effort compared to Bayesian spam filters etc. They get tossed in a Sieve filter as soon as they become a problem, and I'll send a bitch letter to the leaker with another random email address to see how dedicated they are to screwing me.
All companies know this and it is trivial to strrip the +label from the address automatically.
If you are using +labels on your addresses and think you are being clever enough to spot companies that sell your data, I can tell you I have personally seen companies use code to strip these labels before selling profiled data.