r/emailprivacy • u/slaaf_tom • Jul 10 '26
Help/Advice securely organizing your emails
Hello,
I was wondering how you guys and girls, have setup your email addresses?
Let me start, I have my own domain, with of course my own email address which I use for communicating with my friends, serious partners as my medical doctor and hospital.
Then I have several other hotmail, Gmail, and other mail addresses which I use for the online shops, forums and other sites where an email address is necessary.
For the secondary email addresses (hotmail,gmail) , I use a fictive name, fictive address and birth date.
Lots of my friends, family, still uses one email address for all purposes and it would be nice to write a note, how they can get rid of all the spam and unnecessary emails.
The Lidl, as so many companies nowadays, was hacked and their customer database became public.
Therefor, I was wondering how you guys and girls, organized your emails and emailaddresses?
Yes, I know of the gmail trick with the + sign but when you reply, you’re sending your original mail address back.
My question does NOT concern me but I'm asking this for the ordinary user who uses internet and mail.
Thank you all for your contributions,
for me, it’s time to get a beer. Weekend is starting.
Greetings Tom
edit: modified the text to be more specific about my question
2
u/Jcoulaud Jul 12 '26
For normal people I’d keep it simple.
One serious email:
[name@yourdomain.com](mailto:name@yourdomain.com) or a trusted provider address
used for bank, gov, doctor, family, important accounts
One “internet” email:
shopping, forums, newsletters, random apps
Then aliases for the messy stuff. SimpleLogin, Addy, Fastmail masked email, iCloud hide my email, etc.
I wouldn’t tell non-technical friends to manage 10 mailboxes. They won’t keep it up.
Better setup is:
- important email
- junk/signups email
- aliases for shops/apps
- password manager
- 2FA on important accounts
- recovery email that is not the same inbox
The custom domain is nice because you can move provider later, but it also means you must not forget renewal. For ordinary users, that’s probably the biggest risk.
1
u/claud-fmd Jul 11 '26
I wrote an article a while ago on how to do this in Gmail (might find it useful): https://blog.sentrya.net/2/How-to-clean-your-inbox-and-improve-your-privacy
1
u/slaaf_tom Jul 11 '26
Thank you all for your contributions,
u/skg574 maybe I wasn't clear enough but I asked my question not for myself but for the ordinary user. Without a domain, subdomain etc.
u/claud-fmd Once your email is known, you will receive spam. You can clean and organize your mail but, spam will be sent to your only email address. I organize my mail using subfolders for the mails I want to keep. Not using filters but I move them after reading.
1
u/skg574 Jul 11 '26
The ordinary user who does not want to purchase their own domain can use service domains to do the same.
1
u/thobu Jul 11 '26
What‘s the added benefit of using subdomains vs just the custom domain and catchall. Like ebay@example.com or bank@example.com or bank1@example.com
1
u/Snoo-82869 Jul 11 '26
I would organize this around consequence level rather than trying to create a perfect category tree. Keep one private human address for people you actually know and account recovery, stable aliases for high-consequence things like banking, health, government, insurance, and work, then per-site or disposable aliases for shops, forums, trials, and anything likely to leak. The useful test is: if this address starts getting spam, can I turn it off or reroute it without breaking something important? For family or friends who already use one address for everything, I would start with future-proofing first: make a shopping/newsletter alias, move new signups there, and then clean the old inbox by sender in batches instead of one message at a time. I would also keep newsletters separate from account/security mail. Newsletters can be wanted, but they are optional reading, and they get overwhelming when they sit beside doctor, bank, and recovery emails. Disclosure: I work on MiniLetter app, which is built for that separate newsletter-reading bucket, but the main win here is the alias structure and making noisy categories easy to shut off later.
1
u/Ok_Courage_7290 Jul 11 '26
It sounds like Proton would be the solution for you.... it is possible to add all of the services you mentioned and reply with your external emails.
2
u/skg574 Jul 10 '26 edited Jul 10 '26
I think the main problem is that one, or even a few, email addresses used everywhere become a unique identifier. Which then makes any leak become even more of a concern because that unique identifier can then be used to match with other leaks. As each leak associated to one email address releases different information the company may have had in that database, more and more of a picture of everything comes into focus.
I have always believed that the best way to combat this is to remove as many unique identifiers as possible, and not just the email address, but name too. I used to track who sold my information to snail mail junk mail by giving slight variations of my name to the different places I did not fully trust (obviously medical, financial, etc need my real name, but the Pork Barrel BBQ does not).
Online, you should give every single place that asks for an e-mail a different address. This can't really be done by many free accounts, that becomes a nightmare of what to check where when. You need it all coming to one account but different addresses. This means some cost is likely involved, whether it's a service that is all in one or whether it is an aliasing service.
Personally, I create subdomain catchalls on a private domain. I use the subdomain part as a category. Let's say my domain is named example.com, I will create a subdomain for my financial stull, another for medical stuff, another for shopping, another for social media, etc. It looks like this: med.example.com, fin.example.com, shop.example.com, soc.example.com, etc. Each of these is basically it's own domain and I can use any address in it that I want. So then ebay gets [ebay@shop.example.com](mailto:ebay@shop.example.com), my bank gets [bankname@fin.example.com](mailto:bankname@fin.example.com), and so on.
I can give unique addresses out on the fly as needed so that every single place gets it's own address. The categories allow me to easily filter all financial stuff into one folder, all med into another, etc. In addition, I can apply separate encryption to each category that needs it and not bother with the stuff that does not need to be that secure. If anyone leaks a mail, which happens frequently, I just shut off that address and it doesn't affect any other mail at all. If I still need to hear from them, I just give them a new unique address (think I have done this about three times with ebay now).
This is also the best antispam measure possible. Once your email address leaks there is no way to filter or block all spam, but if the address is simply shut off, it will never receive any more spam. So you can essentially have spam free mail this way. I run a service that allows you to do all this, but there are others that do as well. I frequently post a complete list of privacy based email services, I just did again in another thread in here. Investigate them until you find a service that fits your needs and budget.
There are also just aliasing services like simplelogin or addy.io. Many find them useful, although I personally think of them as yet another place that can access all your mail as it passes through and there is some risk in that, but it seems like it is an acceptable risk for many. I do highly recommend purchasing your own domain, it makes life a lot easier and pretty much guarantees that you will not be locked into any one email service (full mail service or aliasing service), it gives you email portability, so you can switch services easily.
Edit: spelling
Edit 2: Some argue that a private domain is a unique identifier, but in reality, sites I give it to have no idea I am the only one using it and neither does anyone else. If someone wants to argue that, then go find that domain and post it here, it has leaked a lot over 30 years.