Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I just wrote a post[1] about using the user+alias@example.com instead of user@example.com. Basically treat your "regular" email address as a spam target, and use user+alias for all wanted communications. The +alias can be a random string, making it harder for spammers to guess.

This works in gmail for both sending and receiving, although sending as you+alias@gmail.com requires messing around in the settings[2] and having to remember to select a non-default From: address in your outgoing mail.

[1]: https://alexshroyer.com/posts/2022-09-01-Default-Honeypot.ht... [2]: https://webapps.stackexchange.com/questions/3598/is-there-an...



If this gained widespread adoption, then spam would just +string and you'd have to allow-list.

Allow-list isn't the worst, but this isn't a long-term solution in and of itself


True, but the nice thing is it that allow-lists can be handled transparently by your email client.

Never saw this +string before? Mark as spam.

Is the +string missing? Spam.

Recognize this +string from your "Sent" folder? Keep.

Signing up for something? Generate a pseudorandom +string and add it to the allow-list.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: