$50/year and Fastmail will let you alias anything@yourdomain.com to your inbox. I use a different email for every company or website I interact with, so I know who spams me.
I’ve surprisingly found that I have started to have to use mydomain.com with Fastmail. Sometimes banks used for a business account, or accounts at b2b companies don’t treat fastmail.com as a large email provider, and otherwise try to associate me with other fastmail customers as though we are colleagues at Fastmail.
This is genuinely hilarious. Are you able to elaborate? Which banks? Which B2B? There is probably a shared product stack here that is making some hilariously poor decisions.
I couldn’t figure out why US Bank business card applications using a sole proprietorship EIN kept disappearing into a black hole or being denied. Eventually after a few phone calls they complained about the email address.
The other was ferguson.com, so that I could order specialized furnace parts and larger diameter plumbing fittings than I could order from Home Depot. I don’t remember the details, but I think the Ferguson business application kept trying to autofill an address for me. It probably would have required a confirmation from the person who had been turned into the administrator of “fastmail” before I could have been added to their organization and been able to make purchases using their account.
It might not be a problem at larger suppliers like Grainger or Digikey, but it does suggest a vulnerability if you set up a corporate account at a small supplier using a fastmail address. Their backend could assume that anyone able to receive emails on “your” fastmail.com domain is at least authorized by your IT department to use email. If they assume your IT department has an email retention policy, then they might default to treating it like your problem if one of your employees makes an unauthorized purchase.
Not only that, I used to use businessname@mydomain.com for setting up aliases to interact with different businesses. On more than a few occasions I had some very confusing back and forth until realising the issue, when they asked which department I was from.
When they saw their own business name in the email address they just straight up assume I am part of their company. No wonder phishing works.
My domain at Hetzner including mail costs less than 20€/year and all emails to <whatever>@mydomain.com which are not part of predefined mailboxes land in my catchall@mydomain.com mailbox.
Services like this are great for some things, like adding and removing forwarding, and vacation mails, and organising mails to make life and work easier, but the provider still links everything. It is only, at best private in a single direction. That is fine for some things, not so great for others (and it has nothing to do with legality).
That doesn’t provide additional privacy, however, because it’s easy to determine that all emails at @yourdomain.com belong to the same user, so you can be tracked across services.
I love this feature from Fastmail but I have used a few websites (smaller of course) that will not accept anything outside of the big few email domains.
Are you implying that plus addresses are part of RFC 2822? Because they aren’t. AFAIK, no RFC documents specify the plus address convention. The RFCs merely specify that, in an email address, whatever is to the left of the @ sign is to be interpreted by the receiving system, and nobody else should make any assumptions about any of it, and certainly never alter it. And also that the + character is one of the many permitted characters to the left of the @ sign in an email address.
The plus address convention is just that, a convention, widely implemented by many email programs and servers, but not required by any standard, nor universally implemented.
“Talked about” is exactly correct. That RFC describes it as an existing practice and describes one common use where the + sign is used. Which is correct. But this is all completely independent of the email protocols and the RFCs which define them. This specific RFC is about how to handle email filtering where you want to take such an extra “detail” string into account, if such a string is present and can be parsed out of an email message, once it has been recieved. Note that this RFC does not describe the + sign convention as the only one – it shows two other possible syntaxes.
The normalised version is what gets redirected to trash, according to GP's proposal. Legitimate senders who do not normalise have their mail delivered to the inbox.
It's become a fairly regular occurrence that any email with + just shows an error saying the email isn't valid. Bad actors can also easily strip it out after