this post was submitted on 24 Feb 2024
76 points (90.4% liked)
Technology
74663 readers
2627 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
every provider who supports aliases. like foo+baa@bzz.tld where everything after the + is exchangeable. so you can use a 'different' mail for every service you use and just block where spam comes from via the alias.
Isn’t it pretty widely known that many email providers support this?
I just assume spammers would know enough to remove everything from the ‘+’ until the ‘@‘. It’s not like they’re trying to be sparing with recipients. Why not just send to both?
Personally I'm not a fan of "plus aliasing" because it gives away your base address, and it's trivial for spammers to strip the alias. I prefer aliases that completely hide the base address.
Its also VERY poorly and haphazardly handled in websites. Often they won't let me create an account with it. Or I will be able to create an account using the alias, but then I am left unable to login.
That's why we need formal rules. Once regulations are in place (with big penalties) websites magically start to function properly.
... Until they randomize the part before the plus
They don't need to randomize it, just strip it.
They strip the part after and including the plus. And yea, that's exactly what is done. People need to stop assuming malicious actors are dumb and incapable of reading an RFC.
Not best solution I guess. How about generic sites? Like Git commit mail, my website, Mastodon etc. where I can't add that postfix.
Why can't you use +-aliases in Git, Mastodon, etc.?
Edit:
git config --local user.email "something+someotherstuff@example.com"
shouldn't cause any issues.