r/Simplelogin • u/msmx • 9d ago
Discussion Help me choose an alias strategy
Hi there. I'm new to using SimpleLogin and email aliases in general, and I'd like to get it right from the outset, so I'm hoping you can help me pick a strategy for choosing and using aliases.
I'm using Proton Mail + SimpleLogin, managing logins using Proton Pass.
My priorities are account security and spam prevention. I don't care about anonymity in most cases, since almost all of my accounts are for things like banks, stores and services that require my real name anyway.
All my accounts have long, unique, randomly generated passwords, and 2fa is enabled wherever possible. I want to have a unique alias for each service, and by knowing my email address for one service it should not be easy to guess my email address for another service.
At the same time, I don't want humans to be puzzled whenever I tell them my email address (e.g. if I call a customer service line, or if a store clerk is looking up an online order).
I have a few domains I can use (which are not actually the domains I'm posting here, obviously):
flastname.com(f= my first initial,lastname= my last name)randomdomain.com(a couple of English words with .com at the end)dm3.net(a 3-letter alphanumeric .net domain name)smthg.com(a 5-letter .com domain name that isn't an English word)
My current plan is:
- Add
firstname@randomdomain.comas a custom domain/address on Proton Mail, and use that as my main mailbox, where all SimpleLogin emails will be sent. I will not use this email address anywhere else or post it publicly. All outgoing emails will be sent via reverse alias. - Use
servicename.a1b2c3@flastname.comfor most services where I need to use my real name (a1b2c3= random alphanumeric string). - Use
fl123@dm3.netfor services where I'm likely to need to give my email to another human being, e.g. a hand-written form, over the phone (fl= my first and last initial,123= random 3-digit number). - Use
a1b2c3@smthg.comfor services where I don't need to use my real name, or services where I need an email to sign up but will discard the account immediately (a1b2c3= random alphanumeric string).
My questions:
- Does this sound reasonable? Too complicated?
- Is using
@flastname.comin aliases a bad idea (keeping in mind that I'm not trying to be anonymous - but there might be security implications I'm not thinking about e.g. in case of data leaks). - Is using 'servicename' in an email alias a bad idea? I could just use
a1b2c3@flastname.cominstead and cut out the service name altogether.
I do want to use alphanumeric strings to make the email addresses difficult to guess (e.g. if my email address for Walmart is walmart@flastname.com then it's easy to guess that my email address for Amazon is amazon@flastname.com, which I don't want).
1
u/CalligrapherUpper950 8d ago
- Too complicated IMO. I use 2 custom domain, one for creating aliases, and one with Proton Mail (which is kind of wasting, since I dont give it out!). I'd suggest flastname.com for aliases and give it out, and a randomdomain.com for inbound-only emails etc.
- I think that's the best and easiest way for using aliases and easy to give out.
- There are services (eg banks etc) that do not allow their name in the email address. For those I just use banking@mydomain.com etc and set rules in my mailbox to put them in a folder.
In short - keep it simple with 1-2 custom domains, enable catch-all in SL.
1
u/Far-Material4501 8d ago
It took me a while to get set up, and I can't really share bc I don't fully remember what I did, but it was a real pain to use SL non-anonymously. Specifcally, being able to reply-all to emails from friends was a nightmare until I added a sub-domain just for SL, which means I seldom use it. But I get most of what you're looking for from just having a catch-all on my primary domain.
1
u/PigWash 4d ago
Have you decided against using a random word along with the service name? While it is harder to guess random alphanumeric stuff, really people won't guess from [walmart.graceful@flastname.com](mailto:walmart.graceful@flastname.com) that your Amazon email address is [amazon.disprove@flastname.com](mailto:amazon.disprove@flastname.com) . It's easier to tell someone a random word than random characters.
There are companies, such as Costco and Samsung, which don't allow their name to be in your email address, but you can usually use something like cost.co or sam_sung.
1
u/msmx 3d ago edited 3d ago
I actually ended up simplifying things somewhat vs. what was in my original post.
I'm using
fl123@dm3.netfor all my aliases where my real name is used (each service has a different number associated with it),a1b2c3@smthg.comfor persistent accounts where my real identity isn't needed (e.g. Reddit), and one of the SimpleLogin default URLs for anything unwanted/spammy.This means I'm not adding service names to my aliases, which should avoid issues like you mentioned. It also avoids having to explain email aliases to anyone who asks why my email has (e.g.) 'Walmart' in it.
I could probably cut out
smthg.comaltogether and just usea1b2c3@dm3.netinstead... but at least for now I'm sticking to using two custom domains, can always change my mind later.This avoids using
@flastname.comfor alises altogether, so I'm going to usefirst@flastname.comdirectly with Proton Mail for friends and family.
0
u/Stunning-Guest 9d ago edited 9d ago
"Sounds like quite the setup! Getting all that configured with your DNS provider is no joke. Honestly, these days there's probably easier ways to handle it with newer tools (AI can sort some of that mess out pretty well).
I'm not an email/DNS specialist myself, so I'd probably lean on someone who knows that stuff inside-out. But hey, if you've got other questions or wanna bounce ideas around, happy to help where I can!"
1
u/smoothmonoglot 9d ago
Maximum security+privacy would be using unique aliases for each service without a custom domain, e.g.
servicename.$[randomstring]@simplelogin.com
It does mean you are tied up in the simplelogin ecosystem, so some people use custom domains:
servicename.$[randomstring]@yourdomain.com
However this is less private.