this post was submitted on 25 Aug 2023
14 points (100.0% liked)

Proton

4909 readers
95 users here now

Empowering you to choose a better internet where privacy is the default. Protect yourself online with Proton Mail, Proton VPN, Proton Calendar, Proton Drive. Proton Pass and SimpleLogin.

Proton Mail is the world's largest secure email provider. Swiss, end-to-end encrypted, private, and free.

Proton VPN is the world’s only open-source, publicly audited, unlimited and free VPN. Swiss-based, no-ads, and no-logs.

Proton Calendar is the world's first end-to-end encrypted calendar that allows you to keep your life private.

Proton Drive is a free end-to-end encrypted cloud storage that allows you to securely backup and share your files. It's open source, publicly audited, and Swiss-based.

Proton Pass Proton Pass is a free and open-source password manager which brings a higher level of security with rigorous end-to-end encryption of all data (including usernames, URLs, notes, and more) and email alias support.

SimpleLogin lets you send and receive emails anonymously via easily-generated unique email aliases.

founded 1 year ago
MODERATORS
 

So i've set up a custom domain to use with protonmail and was curious if anyone else uses the catch all in this manner.

I was thinking that when a new account is created on $website I would use a custom email address that would then be caught by the 'catch-all'. So say the domain is catata.fish, and the website is target.com, then when signing up I would use [email protected]. Previously when using gmail I would use [email protected].

Does anyone see any issues doing it this way? Thanks!

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 3 points 1 year ago* (last edited 1 year ago) (1 children)

Assuming ProtonMail supports catch-all (I don't use Proton), this is fine and a typical use of the catch-all. You may get weird looks when you give a business their name back as your email, and if anyone figures out that you have a catch-all they might just spam you regardless, at any email address they want, e.g. "[email protected]". I would add a string of numbers/letters at the end, like "[email protected]" so you can be sure when someone sells your email.

All said, it's a little bit weak to any determined adversary. Any human who figures out your plan can easily start playing around with it - Target may sell your email as "[email protected]" and you'll never know who sold it.

Edit: Also, you're trivial to track across different accounts if anyone figures out that you own the email domain.

[–] [email protected] 1 points 1 year ago

Makes sense. I’m not too worried about privacy in that regard considering bad actors are going to do what they do. This was more for the automated systems, plus I don’t see how it would be any less privacy focused than just a standard email + aliases.