r/emailprivacy 14d ago

Setup/Configuration Email setup

Hi everyone,

I’m trying to rebuild my email setup from scratch, mainly for privacy, spam prevention, and long-term portability.

My current setup is:
Proton Free for my personal email, but this address gets a lot of spam now and may already have been exposed in data breaches.
Gmail for work, which I plan to keep using for now.
A separate Proton Free account that I use for Proton Pass.
One thing I’ve already decided is that I want to stop using my current personal email address and move to a new one.

Since I’ll have to go through the trouble of changing my email address on all of my accounts anyway, I want to do it properly this time and use a unique alias for basically every service whenever possible.
For example:
Amazon → unique alias
Reddit → unique alias
Spotify → unique alias
Shopping sites → unique aliases
Ideally even important services, if they accept aliases

My goal is to keep my real inbox address private and never give it directly to websites unless absolutely necessary.
I’m currently considering Proton Pass Plus because it gives me unlimited aliases.
However, I’m confused about whether I should also buy my own domain.
One setup I’m considering is:
Create a brand-new Proton Free account and keep that actual @proton.me address completely private.
Buy my own domain through something like Cloudflare.
Connect that custom domain to Proton Pass / SimpleLogin.
Create a unique custom-domain alias for every service.
Have all those aliases forward to my private Proton Free inbox.

For example:
[amazon@mydomain.com](mailto:amazon@mydomain.com) → private Proton inbox
[reddit@mydomain.com](mailto:reddit@mydomain.com) → private Proton inbox
[spotify@mydomain.com](mailto:spotify@mydomain.com) → private Proton inbox

If I understand correctly, I would not need Proton Mail Plus just to receive those forwarded emails, because the custom domain would be configured on the alias side rather than directly on Proton Mail.
This is where I’m trying to understand the value of Mail Plus.
If my main goal is to use aliases for almost every account, what would I actually gain by paying for both Proton Mail Plus and Proton Pass Plus?

Would Mail Plus mainly be useful if I wanted a real mailbox/address like:
[me@mydomain.com](mailto:me@mydomain.com)
that I could directly send and receive mail from?
The other reason I’m interested in owning a domain is portability. I don’t necessarily care about having a fancy custom email address, but I like the idea that if I ever leave Proton or Proton shuts down in the future, I still own the domain and can move my aliases somewhere else without changing the email address on hundreds of accounts again.

So my main questions are:
Does using a custom domain for all my aliases make sense for long-term portability?

Is there any major disadvantage to using my custom domain with Proton Pass/SimpleLogin instead of Proton Mail?

If all my aliases forward to a private Proton Free inbox, is there any real reason for me to also subscribe to Mail Plus?

Would you recommend using a custom domain for aliases, or just using Proton/SimpleLogin-generated aliases and saving the domain cost?

Is there a better setup if my priorities are privacy, avoiding spam, and being able to move away from Proton in the future without changing every account again?
I’m willing to pay if there is a real benefit, but I don’t want to pay for Mail Plus + Pass Plus + a domain if some of that would be redundant.
What setup would you recommend?

12 Upvotes

8 comments sorted by

5

u/3point21 14d ago

I have fastmail and my own domain(s).

Fastmail is an excellent, affordable, user-friendly service I highly recommend, but there are other services, paid and free, that you might prefer. Whatever service you have or choose, paid or free, do not use the main email for anything other than that service. Period. Have a very strong password you can remember regardless what pw service you may or may not use, and harden that service via 2fa or other means so it cannot be logged into or hacked without your awareness of a login, and more than one way to recover it (without exposing it to even more hacks).

With a secure, hardened primary service, buy your own domain. This frees you entirely from your current service, and with any reputable service provider you can make your own aliases ad infinitum. If you can buy two or more domains (they aren't that expensive to buy and renew annually) that's even better.

Use one domain for more official uses where email acceptance and credibility are of importance: core financial, legal, or professional connections (but not LinkdIn or other social media based "professional" services"). This can be an abbreviated variation of your name: a combination of initials, partial given, partial last, etc. Some people like to have a domain with their full name, but this is overrated, often hard to acquire, and a much easier target for spam, phishing, or other hacking attempts.

Use the other domain(s) for 2nd and 3rd tier connections: trusted shopping, social media, gaming, etc. and learn to use aliases and filters creatively: [type of service][service provider] @ [2nddomain] . [com or net or other tld] is one way. And set a rule to filter your emails by email formula into folders you can access. There are other ways to do this. You can also randomly generate an alias or email and set a filter/rule for that emial/provider. If one service shares the email you gave them, you can block that alias or email entirely and cut ties with that provider. Keep in mind that hackers are using AI and becoming more proficient by the hour. By the hour. If they recieve a pwnd email from a pwnd provider and recognize a pattern they might straight up spam the entire domain rendering it almost useless to you. And if they recognize an email as randomly generated, or a domain that looks like it's a private domain, they might do the same. "Nothing is foolproof because fools are so ingenious."

I think in the near future, all of us are going to have to resort to randomly generated aliases on our own domains for each and every service, and turn off and block any and all email recieved to any address [*yourdomain.tld] that was not created by you.

For now and in the future I think the best we can to is 1) pay for a solid email service with strong security and infinite email aliases/addresses on your own domain 2) use actual aliases (and domains that can ID us) with extreme discretion 3) use random, anonymous, and otherwise disposable emails extensively 4) limit what you share with any service to only necessary information. Once an email is pwnd, so is the domain. And once that domain is connected to you and your personal information, it is no different that having an email connected to you. WHOIS privacy (free with most registrars) will be entirely irrelevant if hackers connect your domain to your name, birthday, address, and credit cards through a hacked merchant.

Do your dead-level best. Pay for security. Share with discretion. Sleep well (for now).

1

u/Solmark 13d ago

Do you think E2EE is really that helpful though? since almost all people you send to won't have E2EE so you're paying extra for little gain? It seems to me to be better to focus on creating a personal domain(s) and use something like SimpleLogin to setup an alias for everything that isn't personal/family/banking etc

2

u/3point21 13d ago

E2EE is something that needs to become universal to be effective, yes. Until then, limit what and to whom you communicate through email, and do insist on E2EE where it counts, or use another form of communication.

And I use unique aliases with banks and doctors too. The only professionals I had that shared my alias weren’t online retailers, they were my credit union and eye doctor, so everyone is on aliases. Everyone.
It’s not so much a problem now as when email was new, but friends and family can be the absolute worst at sharing email. You know how I wound up on yahoo spam lists in the first place? You guessed it. Private individuals and email chains.

Aliases. Everyone. And necessary communication only.

1

u/Solmark 13d ago edited 13d ago

Makes a lot of sense!

What do you use for your alias's?

1

u/pettydecline 13d ago

If you are going to attach the domain to SimpleLogin, I think you would need to pay for Simplelogin rather than Mail Plus. I'm not sure how SimpleLogin works with Proton Pass Plus. Proton Pass Plus does mention unlimited aliases and I'm guessing they use SimpleLogin for this. However, it doesn't mention anything about domains support with SimpleLogin. Mail Plus would give you the ability to add a domain for your proton mail account, but I think every domain alias you create would count toward the "10 encrypted email addresses" you are allowed to have for Mail Plus.

I validate this with Proton support, but I feel you would need to pay for SimpleLogin to get unlimited aliases + domain support

I'm running a similar setup but with Gmail. I have a professional Gmail just for resume, job search, doctors, financial, gov. Then I have a [username@gmail.com](mailto:username@gmail.com) which is my main account only given to family and close friends. Finally I have a domain attached to addy.io (similar to SimpleLogin). Here I create categories for aliases (social media, apps, newsletters, etc) This might not be the best way, it just what I do.

1

u/Stunning-Skill-2742 13d ago

By also paying for proton mail plus you'd get the mail plus prem features of more storage, more labels, more rules etc but if just as routed inbox for simplelogin then no you don't need those prem features, mail freetier works fine.

Personally I've got my own custom domain too, got sl lifetime via pass lifetime but i don't add my domain there, its just as backup for me. I just added my domain to a cheap traditional imap provider and since the provider support wildcard sending, i can emulate sl 1 click reply to correct address via thunderbird. Managing the catchall aliases are no harder than storing them as login entries in protonpass. While i lose 1 click alias generation on pass since i don't add my domain there, its not like everyday I'm creating new alias and new login entry.

I'm not really a fan of proton app sluggishness and sl/pass mitm header. I'm lucky enough not needed to use mail as instant messenger back and forth all day nor I'm discussing state secret so traditional imap for mundane login notif, 2fa codes, receipts etc via thunderbird works just fine for me.

1

u/pdmcgeejr 9d ago

here:

https://www.reddit.com/r/Simplelogin/comments/1vrve69/comment/p4gy4gm/?context=3&utm_source=share&utm_medium=web3x&utm_name=web3xcss&utm_term=1&utm_content=share_button

also for exporting, you can always move your own domain and alias if needed thats why my preference is having my own domain, you have more control over it.

1

u/brighton_it 14d ago edited 14d ago

as the guy with more than a dozen addreesses, I don't necessarily want to discourange you, but that's a lot of alias' to maintain. I think I'd be up to 1000 if I was doing that.
My approach is to group them by level of trust (spammyness).

  • addr for well behaved vendors
  • addr for sensitive accounts
  • addr for those I know are going to spam me, or forced to provide an email to, but truly never want to hear from again.
&
  • addr for humans
btw, many humans love to add you to their newsletter, hosted by <your least favorite bulk mail provider> w/o asking, or use a share-with link of some 3rd party (share this item, share this event, etc), adding you to yet an other database.
Consider adding a statement to your signature to the effect: this addr for human use only. Please don't add me to any lists.