Email Forwarding

An Email Alias Per Signup, So You Learn Who Sold Your Address

By Alexey Bulygin
A row of numbered tags on envelopes leading into one open box

When spam starts arriving at an address you barely use, there's no way to tell where it came from. You gave that address to a dozen companies over three years, one of them leaked it or sold it, and the message itself won't say which. An email alias per signup fixes that permanently, and it costs nothing beyond a naming habit.

The idea is old and still underused: give every service a different address, all delivering to the same mailbox. When junk arrives, the address it arrived at names the culprit.

How an Email Alias Per Signup Works

An alias is an additional address on a mailbox you already have. Mail sent to it lands in the same inbox, and you can reply as that address, so it behaves like a real address to everyone outside.

The pattern is to derive the alias from the service. Signing up to a shop becomes shopname@yourdomain.com; a newsletter becomes newslettername@yourdomain.com. You don't need to record anything, because the address itself is the record.

Then, when unexpected mail arrives at an alias, you know exactly which relationship produced it — and you can delete that one alias without disturbing anything else. No filter to write, no sender to block, no negotiation. The address stops existing and the flow stops with it.

Why This Beats Plus-Addressing

Most people first try the you+shopname@gmail.com trick, which is genuinely useful and has two weaknesses that matter here.

It's trivially strippable. The plus convention comes from subaddressing, and its whole structure is public. Anyone processing a list can remove everything between the plus and the at-sign and recover your real address, and list brokers do exactly that. So plus-addressing tells you who leaked the address while doing nothing to stop the leak being useful.

It's also visibly a tagged address, and some signup forms reject it outright. An email alias per signup on your own domain looks like an ordinary address, because it is one.

The trade is that plus-addressing needs no setup and aliases need creating. For anything you'll hold for years — banking, utilities, your accountant — the alias is worth the thirty seconds. For a one-off download, plus-addressing is fine.

What It Costs

Aliases are included on the paid plans: 30 per mailbox on Starter, 50 on Pro, 100 on Agency. The free plan has none, which is the one limit to know before planning around this.

A hundred aliases on a single mailbox covers an ordinary person's entire commercial life with room left over. If you somehow exceed it, a catch-all on the domain will accept any address at all without creating anything — the difference being that a catch-all can't be selectively switched off, so a leaked catch-all address keeps receiving forever. That's covered in how a domain catch-all works.

The practical answer for most people is an email alias per signup for things that matter, and catch-all for everything else.

Naming Them So the System Survives

The scheme fails when you can't reconstruct it a year later. Three rules keep it working.

Use the service name, not a category. acmebank@ tells you something; banking@ tells you nothing when three banks have it.

Keep it derivable. If you have to look up which alias you gave someone, you'll stop doing it within a month. Same transformation every time, no abbreviations you'll forget.

Don't get clever with dates or codes. An email alias per signup is only useful if reading the address instantly tells you the answer. Anything requiring decoding defeats it.

The Other Things This Solves

Leak detection is the headline, but an email alias per signup earns its keep in smaller ways day to day.

Killing a mailing list that won't unsubscribe you. Deleting the alias is unilateral and instant. No unsubscribe link that doesn't work, no reply asking to be removed, no arguing.

Filing without filters. Because each sender arrives at a distinct address, sorting rules become trivial and stop breaking when a company changes its sending domain — which is the usual reason sender-based rules fail.

Separating identities cleanly. A side project, a volunteer role and a job can each have addresses on the same mailbox, replied to as themselves, without three mailboxes to check.

Knowing when a breach touched you. When a company is breached, an email alias per signup tells you within seconds whether your address was in it, rather than wondering.

Where It Goes Wrong

Two failure modes are worth naming, because both are common.

The first is deleting an alias still used for account recovery. If shopname@ is the login for that account and you delete it after the marketing gets annoying, you've also deleted your ability to reset the password. Check what an address is actually attached to before removing it.

The second is inconsistency. People start enthusiastically, drift back to their main address when in a hurry, and end up with a half-implemented system that answers nothing. Either commit to it for the accounts that matter or don't bother — a partial email alias per signup scheme has most of the effort and little of the benefit.

Aliases Versus Separate Mailboxes

People sometimes reach for a second mailbox when an alias would do, and the distinction is worth being clear about because the costs differ sharply.

An alias is an address. It has no storage of its own, no separate login, and no password — mail sent to it lands in the mailbox it belongs to. A mailbox is an account: its own storage, its own credentials, its own place in your plan's limits.

For an email alias per signup you want aliases, and it isn't close. Two hundred separate mailboxes for two hundred services would be absurd administratively and would exhaust any plan; two hundred addresses feeding one inbox is the intended use. Mailboxes are for things a different person reads, or things that need separate storage and access.

The one place a mailbox earns its keep here is a genuinely separate identity you'd hand to someone else later — a side business that might acquire staff, say. Everything else is an alias.

Replying as the Alias

An email alias per signup only works if the address behaves like a real one in both directions, and replying is where half-implemented setups fall down.

If a company mails shopname@yourdomain.com and your reply arrives from your main address, you've handed them the address you were trying to protect, and you've also confused their system, which may not recognize you. Aliases here can be used as sending identities, so the reply leaves as the alias and the arrangement holds.

Set that up when you create the alias rather than discovering it at the moment you first need to reply. It takes a moment then and is irritating later.

The Same Pattern for a Business

An email alias per signup isn't only a personal-privacy technique. The business version solves a different problem with the same mechanism.

Give each supplier, each marketplace, each software vendor its own address on a shared mailbox, and you learn immediately which relationship generated a piece of mail — useful when a company changes its sending domain after an acquisition and your sender-based rules stop matching. You also learn which vendor leaked your details, which matters more for a business than an individual, because business addresses are harvested and resold aggressively.

The other business benefit is departure. When somebody leaves, addresses tied to relationships they managed can be pointed elsewhere without anyone contacting a hundred suppliers to update records. That's the same logic as attaching correspondence to the work rather than the worker, described in a mailbox per project.

Keeping the List Manageable

After a year or two of running an email alias per signup you'll have accumulated a lot of addresses, and the scheme survives or fails on whether that list stays legible.

Review it annually and delete aliases for services you no longer use — but check first whether the address is still the login or the recovery route for that account, because that's the mistake worth avoiding. Anything you can't identify is a candidate for deletion, though the safe move is disabling before removing where that's an option.

Don't create an alias for something you'll use once. A one-off download doesn't need a permanent address, and cluttering the list with disposable entries makes the useful ones harder to find. An email alias per signup is for relationships that will last, and plus-addressing covers the rest perfectly well.

Starting Without Redoing Everything

You don't need to migrate a decade of accounts. Start with new signups only, then move the accounts you'd most want to control — anything financial, anything with your address on it, anything that mails you weekly.

Within a few months most of your incoming mail arrives at addresses that identify their source, and the question "who gave my address away?" has a one-word answer for the first time. The mechanics of creating them are in creating an email alias.

Share this article

We use cookies for essential functionality. No ads, no ad tracking.

Sign in to TrekMail

Access your dashboard, mailboxes and DNS.

or

12+ characters, and not one from a known data breach.

or

Reset email sent

If an account exists for this email, we've sent password reset instructions.

By continuing, you agree to TrekMail's Terms and Privacy Policy.