Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I know you can enter email addresses as x+y@example.com where x=your regular email and y=some word/phrase to indicate who might have sold your email.

For example, if you register bill+NG@example.com with national geographic, and you find yourself getting to: bill+NG@example.com from spam, you know who sold your info. My question is, do you think companies know this trick and just remove the portion following the "+"?



> if you register bill+NG@email.com

Please use the second level domain label example[1] when writing examples of email addresses. For all you know, you just posted someone's email address.

[1] http://en.wikipedia.org/wiki/Example.com


Changed it even though someone else pointed out it bounces. Thanks for the tip.


There's nothing special about + as far as email in general is concerned, that's just a convention some mail servers (such as gmail) use. Any server using qmail, for example, uses '-' for the same purpose, but + can be part of a full name there.

While cutting out the + might still get your mail to gmail users, there's no guarantee it would for anyone else. I don't really think the people doing the spamming care, and they'd rather it arrive in an account at all than burn their sources.


Yeah you'd be surprised how many websites don't accept email addresses containing +.


Most of the time when I try to use this it just doesn't accept the email address. I've wondered if they sincerely don't think that's a valid email address or if they're intentionally thwarting that strategy.


I doubt it's intentional. Most common validation regexs that your average web dev would use tend to reject the + character.


Personally I self host a domain that accepts anything@ and file it into a special inbox. This lets me give real addresses to specific sites and blacklist them as needed.


I did that, until I got the second run of someone sending spam to [dictionary]@mydomain.


Luckily this hasn't happened yet. Last time someone spammed my "throw away" domain I just took it offline (killed DNS) for a few days, that seemed to work :P


I hope you're doing anything@subdomain.example.com otherwise you'll get catchall spam.


Surprisingly, I haven't been getting catchall spam. If that happens I'll just write a quick interface to add permitted stuff through easily or just create a pattern that catchall won't use :)


We had a meeting about privacy at work and the presenter told a story about his ISP who messed up his name when he signed up something like Roge rJones instead of Roger Jones. The ISP stated they do not sell customer information to 3rd parties.

Within a week after signing up he was getting spam and junk mail addressed to Mr. Roge rJones just copied and pasted right from the ISP customer database.

Indirectly in a way what you say to try, a unique identifier.


I get junk mail for Mr qweqwe asdasd a lot as confirmation of your point :)


Spam companies knows it but don't really care I suppose, it's not their problem. Your problem is that if you forget the password you must remember if and how you personalized the e-mail address to reset it.


Look in any email they sent to your gmail account, then "view original."


That does only work with Gmail, doesn't it? I don't think this is that widespread yet, so few companies (if any) will remove the part after the plus.


It works with many mailservers, on postfix it's called recipient_delimiter. It's enabled on dreamhost as + as far as I know.

The amount of spam/phishing I'm getting to me-macromedia@ and me-adobe@ is pretty amazing. Guess I was part of _that_ breach.

I'm not sure I'd go through that if I were doing it again. I've got hundreds of those emails out there, and being able to just drop some of them hasn't been the help that I would have hoped for.


That doesn't work with Yahoo! Mail.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: