Skip to content

Comment on Ask HN: A business sold my email. What can I do about it?

Comments

I do the same thing, but instead of plus addressing I give each vendor a unique email at my domain. I now receive spam on my mint, geico, tumblr, lendingclub, disney, adobe, and dropbox addresses. In my case it's always outright spam instead of something remotely legitimate.

Your situation seems different than mine. I think my addresses were taken during a security breach instead of being sold by the company.

In my case I just change my address with the company to dropbox2@, and block the original address.

I also have a friends-and-family email address that isn't published anywhere online that finally started receiving spams. I think it was taken from a neighbor's address book in hotmail when he got phished.

I think a possible long-term solution would be for everyone to have a unique address for everyone else. The email software would auto-negotiate a unique address after your first communication with the person, creating a pairing similar to a friendship on a social network. I'm getting off-topic, but here's a link explaining what I mean a bit more: http://stevenjewel.com/2014/02/clearskies-chat/ (It's about decentralized IM instead of email, but the same antispam technique would work for either.)

In my case I just change my address with the company to dropbox2@, and block the original address.

I suspect some spambots just try common dictionary and business words at domains with valid MX records.

I don't think so. Here is my experience so far. For background, I don't run a spam filter at all and host my own mail on a enterprise fiber line that's unlikely to have ISP-level filtering. (If they do have it, it's terrible, since it doesn't even block email that has a certain product targeted at males mentioned in the subject line and spelled correctly.)

I've only seen what would be considered dictionary attempts for four addresses, info@, admin@, sales@, and support@ but only on a few of the domains.

A few years ago I started getting spam at random hexadecimal addresses at two of my domains, such as 72da48ba6@, about two spams per address per day. There turned out to only be ~ 800 unique addresses that were targeted, and so it was easy to block. What I think happened is this case is a address-to-spam-list creator padded his lists manually before selling them to make the list size bigger. I still get email at those 800 addresses, but no new hexadecimal addresses since I blocked the original set.

I have a different explanation for the hexadecimal addresses.

I get maybe 30 a day, from numerous sources, and they actually turn out to be legitimate message-IDs which were generated by my host when replying to public mailing-lists.

I think some kind of automated spider decided they were mail addresses.

Oh, I hadn't thought of that. That makes perfect sense.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.