Mastodon Skip to content
  • Home
  • Aktuell
  • Tags
  • Über dieses Forum
Einklappen
Grafik mit zwei überlappenden Sprechblasen, eine grün und eine lila.
Abspeckgeflüster – Forum für Menschen mit Gewicht(ung)

Kostenlos. Werbefrei. Menschlich. Dein Abnehmforum.

  1. Home
  2. Uncategorized
  3. Dear services that refuse email addresses that have the name of the service in the address:

Dear services that refuse email addresses that have the name of the service in the address:

Geplant Angeheftet Gesperrt Verschoben Uncategorized
30 Beiträge 14 Kommentatoren 0 Aufrufe
  • Älteste zuerst
  • Neuste zuerst
  • Meiste Stimmen
Antworten
  • In einem neuen Thema antworten
Anmelden zum Antworten
Dieses Thema wurde gelöscht. Nur Nutzer mit entsprechenden Rechten können es sehen.
  • irrationalmethod@social.coopI irrationalmethod@social.coop

    @paul_ipv6 @j_angliss @alexr

    I have to say it's been facinating to see the + address I provided to ACE hardware show up in some fraudulent spam lists and then gradually find it being used by "legitimate" mass mailings from a major US political party that I didn't share it with, for somehow connected my identity with it.

    paul_ipv6@infosec.exchangeP This user is from outside of this forum
    paul_ipv6@infosec.exchangeP This user is from outside of this forum
    paul_ipv6@infosec.exchange
    schrieb zuletzt editiert von
    #14

    @IrrationalMethod @j_angliss @alexr

    i've had probably half a dozen emails show them leaked or compromised. more have shown that someone was bought out and their lists sold.

    the most spammed addr i have is one on an IETF RFC, where the emails in the RFC are not hidden at all. i specifically used a unique addr, knowing this. it's been fantastically useful as a canary in the coal mine of who is using really cheap crappy unvalidated lists to spam.

    j_angliss@fosstodon.orgJ 1 Antwort Letzte Antwort
    0
    • paul_ipv6@infosec.exchangeP paul_ipv6@infosec.exchange

      @IrrationalMethod @j_angliss @alexr

      i've had probably half a dozen emails show them leaked or compromised. more have shown that someone was bought out and their lists sold.

      the most spammed addr i have is one on an IETF RFC, where the emails in the RFC are not hidden at all. i specifically used a unique addr, knowing this. it's been fantastically useful as a canary in the coal mine of who is using really cheap crappy unvalidated lists to spam.

      j_angliss@fosstodon.orgJ This user is from outside of this forum
      j_angliss@fosstodon.orgJ This user is from outside of this forum
      j_angliss@fosstodon.org
      schrieb zuletzt editiert von
      #15

      @paul_ipv6 @IrrationalMethod @alexr I'm signed up for "have I been pwned" for my domain and its surprising where I see my email addresses (real or generated) appear.

      irrationalmethod@social.coopI 1 Antwort Letzte Antwort
      0
      • j_angliss@fosstodon.orgJ j_angliss@fosstodon.org

        @paul_ipv6 @IrrationalMethod @alexr I'm signed up for "have I been pwned" for my domain and its surprising where I see my email addresses (real or generated) appear.

        irrationalmethod@social.coopI This user is from outside of this forum
        irrationalmethod@social.coopI This user is from outside of this forum
        irrationalmethod@social.coop
        schrieb zuletzt editiert von
        #16

        @j_angliss @paul_ipv6 @alexr I should do that for my domains... I didn't know it was an option.

        j_angliss@fosstodon.orgJ 1 Antwort Letzte Antwort
        0
        • alexr@mastodon.onlineA alexr@mastodon.online

          Dear services that refuse email addresses that have the name of the service in the address:

          We domain owners do that because we do not trust you not to sell that address to others or otherwise use it inappropriately. Your algorithmic refusal of that address is sketchy af.

          rmq@toot.ioR This user is from outside of this forum
          rmq@toot.ioR This user is from outside of this forum
          rmq@toot.io
          schrieb zuletzt editiert von
          #17

          @alexr They must be some of the few who haven’t figured out phone numbers are better for tracking and made them mandatory. I really don’t want to give my phone number to a website. 😡

          1 Antwort Letzte Antwort
          0
          • alexr@mastodon.onlineA alexr@mastodon.online

            Dear services that refuse email addresses that have the name of the service in the address:

            We domain owners do that because we do not trust you not to sell that address to others or otherwise use it inappropriately. Your algorithmic refusal of that address is sketchy af.

            jrconlin@mindof.jrconlin.comJ This user is from outside of this forum
            jrconlin@mindof.jrconlin.comJ This user is from outside of this forum
            jrconlin@mindof.jrconlin.com
            schrieb zuletzt editiert von
            #18

            @alexr

            Fun fact!

            The crappy filter doesn't recognize when you spell the name backwards.

            (Mind you, it's equally hilarious to me how few sites accept "+" in the local part of an email address. I've had some of those addresses for years, I use "+" to determine which do NOT go into the spam folder.)

            1 Antwort Letzte Antwort
            0
            • irrationalmethod@social.coopI irrationalmethod@social.coop

              @j_angliss @paul_ipv6 @alexr I should do that for my domains... I didn't know it was an option.

              j_angliss@fosstodon.orgJ This user is from outside of this forum
              j_angliss@fosstodon.orgJ This user is from outside of this forum
              j_angliss@fosstodon.org
              schrieb zuletzt editiert von
              #19

              @IrrationalMethod @paul_ipv6 @alexr definitely. You have to validate each time a report comes in but it's a click. Worth it just to see.

              1 Antwort Letzte Antwort
              0
              • alexr@mastodon.onlineA alexr@mastodon.online

                Dear services that refuse email addresses that have the name of the service in the address:

                We domain owners do that because we do not trust you not to sell that address to others or otherwise use it inappropriately. Your algorithmic refusal of that address is sketchy af.

                shapr@recurse.socialS This user is from outside of this forum
                shapr@recurse.socialS This user is from outside of this forum
                shapr@recurse.social
                schrieb zuletzt editiert von
                #20

                @alexr I use name+service@Mydomain.com

                Some services do not support +word in an email address! It's in the spec!!

                jernej__s@infosec.exchangeJ 1 Antwort Letzte Antwort
                0
                • alexr@mastodon.onlineA alexr@mastodon.online

                  Dear services that refuse email addresses that have the name of the service in the address:

                  We domain owners do that because we do not trust you not to sell that address to others or otherwise use it inappropriately. Your algorithmic refusal of that address is sketchy af.

                  toddz@social.linux.pizzaT This user is from outside of this forum
                  toddz@social.linux.pizzaT This user is from outside of this forum
                  toddz@social.linux.pizza
                  schrieb zuletzt editiert von
                  #21

                  @alexr I bet in a lot of cases you could just munge the address a bit while keeping it recognizable for your tracking. Like if you're registering for "Service", create "s3rvice@mydomain.com" or "fartservice@mydomain.com" 😈

                  1 Antwort Letzte Antwort
                  0
                  • atax1a@infosec.exchangeA atax1a@infosec.exchange

                    @alexr we handle this by rot13ing their name and then undoing the transformation on our mailserver's end 😉

                    montef@mastodon.socialM This user is from outside of this forum
                    montef@mastodon.socialM This user is from outside of this forum
                    montef@mastodon.social
                    schrieb zuletzt editiert von
                    #22

                    @atax1a @alexr That’s bloody brilliant!! 🙌

                    1 Antwort Letzte Antwort
                    0
                    • alexr@mastodon.onlineA alexr@mastodon.online

                      Dear services that refuse email addresses that have the name of the service in the address:

                      We domain owners do that because we do not trust you not to sell that address to others or otherwise use it inappropriately. Your algorithmic refusal of that address is sketchy af.

                      ken_fallon@mastodon.sdf.orgK This user is from outside of this forum
                      ken_fallon@mastodon.sdf.orgK This user is from outside of this forum
                      ken_fallon@mastodon.sdf.org
                      schrieb zuletzt editiert von
                      #23

                      @alexr

                      Agree. Although I use it for to detect data breaches.

                      I tell the shops its anti spam so we know its from you. Makes em feel special.

                      The refusal to accept their name in the email probably results more from a over zelous web site designer than anything else.

                      Reversing their name usually works

                      $ echo example.com | tac
                      moc.elpmaxe@.....

                      jernej__s@infosec.exchangeJ 1 Antwort Letzte Antwort
                      0
                      • ken_fallon@mastodon.sdf.orgK ken_fallon@mastodon.sdf.org

                        @alexr

                        Agree. Although I use it for to detect data breaches.

                        I tell the shops its anti spam so we know its from you. Makes em feel special.

                        The refusal to accept their name in the email probably results more from a over zelous web site designer than anything else.

                        Reversing their name usually works

                        $ echo example.com | tac
                        moc.elpmaxe@.....

                        jernej__s@infosec.exchangeJ This user is from outside of this forum
                        jernej__s@infosec.exchangeJ This user is from outside of this forum
                        jernej__s@infosec.exchange
                        schrieb zuletzt editiert von
                        #24

                        @ken_fallon @alexr I just insert a period (looking at you, ora.cle and ep.ic).

                        1 Antwort Letzte Antwort
                        0
                        • shapr@recurse.socialS shapr@recurse.social

                          @alexr I use name+service@Mydomain.com

                          Some services do not support +word in an email address! It's in the spec!!

                          jernej__s@infosec.exchangeJ This user is from outside of this forum
                          jernej__s@infosec.exchangeJ This user is from outside of this forum
                          jernej__s@infosec.exchange
                          schrieb zuletzt editiert von
                          #25

                          @shapr @alexr Keep in mind that many services know the + trick, and will chop it off before reselling e-mails.

                          leeloo@chaosfem.twL 1 Antwort Letzte Antwort
                          0
                          • j_angliss@fosstodon.orgJ j_angliss@fosstodon.org

                            @alexr @paul_ipv6 same for ones that dont allow + in the mailbox part. It's in the RFC, even google/Gmail supports it.

                            I made myself a small script to base64 encode the site + date (in case it's a site that allows you to order stuff but not register), but its not convenient.

                            nicoduck@chaos.socialN This user is from outside of this forum
                            nicoduck@chaos.socialN This user is from outside of this forum
                            nicoduck@chaos.social
                            schrieb zuletzt editiert von
                            #26

                            @j_angliss @alexr @paul_ipv6 I have a regex alias in my postfix to treat . the same way the + does. Never came across a site which didn't like the dot, although I always use + if possible

                            1 Antwort Letzte Antwort
                            0
                            • alexr@mastodon.onlineA alexr@mastodon.online

                              Dear services that refuse email addresses that have the name of the service in the address:

                              We domain owners do that because we do not trust you not to sell that address to others or otherwise use it inappropriately. Your algorithmic refusal of that address is sketchy af.

                              alterelefant@mastodontech.deA This user is from outside of this forum
                              alterelefant@mastodontech.deA This user is from outside of this forum
                              alterelefant@mastodontech.de
                              schrieb zuletzt editiert von
                              #27

                              @alexr Some creativity is needed.

                              Google can become: g.zerozero.le
                              Git: geyet
                              Apple: aqqle

                              1 Antwort Letzte Antwort
                              0
                              • alexr@mastodon.onlineA alexr@mastodon.online

                                Dear services that refuse email addresses that have the name of the service in the address:

                                We domain owners do that because we do not trust you not to sell that address to others or otherwise use it inappropriately. Your algorithmic refusal of that address is sketchy af.

                                david_chisnall@infosec.exchangeD This user is from outside of this forum
                                david_chisnall@infosec.exchangeD This user is from outside of this forum
                                david_chisnall@infosec.exchange
                                schrieb zuletzt editiert von
                                #28

                                @alexr I don’t tend to use the company names anymore after a Schneider comment along the lines of ‘if your email address is my company at your domain, I bet I can guess what your Amazon email is’. I pick a few words that will remind me of the company. For example, for Amazon I might use something like riverinbrazil as the username part. When I read it, it’s obvious to me that this is the email address I gave to Amazon, but if you know that I have an account with Amazon then you’d need a bunch of guesses to find it (and most of the real ones are specific to how my brain works and other people would find it confusing what the connection is). The only ones where I use the company names are accounts I’ve had for well over a decade and there aren’t many of them left.

                                1 Antwort Letzte Antwort
                                0
                                • j_angliss@fosstodon.orgJ j_angliss@fosstodon.org

                                  @alexr @paul_ipv6 same for ones that dont allow + in the mailbox part. It's in the RFC, even google/Gmail supports it.

                                  I made myself a small script to base64 encode the site + date (in case it's a site that allows you to order stuff but not register), but its not convenient.

                                  an0key@chaos.socialA This user is from outside of this forum
                                  an0key@chaos.socialA This user is from outside of this forum
                                  an0key@chaos.social
                                  schrieb zuletzt editiert von
                                  #29

                                  @j_angliss @alexr @paul_ipv6 even exchange/365 supports it.

                                  I have another rule that accepts X as the too lukeXsite, but it’s annoying when + isn’t supported.

                                  1 Antwort Letzte Antwort
                                  0
                                  • jernej__s@infosec.exchangeJ jernej__s@infosec.exchange

                                    @shapr @alexr Keep in mind that many services know the + trick, and will chop it off before reselling e-mails.

                                    leeloo@chaosfem.twL This user is from outside of this forum
                                    leeloo@chaosfem.twL This user is from outside of this forum
                                    leeloo@chaosfem.tw
                                    schrieb zuletzt editiert von
                                    #30

                                    @jernej__s @shapr @alexr
                                    Consider the + part a form of password. No password, no access.

                                    1 Antwort Letzte Antwort
                                    0
                                    • svenja@mstdn.gamesS svenja@mstdn.games shared this topic
                                    Antworten
                                    • In einem neuen Thema antworten
                                    Anmelden zum Antworten
                                    • Älteste zuerst
                                    • Neuste zuerst
                                    • Meiste Stimmen



                                    Copyright (c) 2025 abSpecktrum (@abspecklog@fedimonster.de)

                                    Erstellt mit Schlaflosigkeit, Kaffee, Brokkoli & ♥

                                    Impressum | Datenschutzerklärung | Nutzungsbedingungen

                                    • Anmelden

                                    • Du hast noch kein Konto? Registrieren

                                    • Anmelden oder registrieren, um zu suchen
                                    • Erster Beitrag
                                      Letzter Beitrag
                                    0
                                    • Home
                                    • Aktuell
                                    • Tags
                                    • Über dieses Forum