Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Seriously.

Just get yourself a domain, and set it up on Google Apps for your Domain. Result? You now have infinite email addresses.

So, if you're bob@yourdomain.com, you can create a catch-all so that anything@yourdomain.com comes to you. This is actually the most effective spam-fighting mechanism I've found yet.

The trick is to then sign up to things as bob.thing@yourdomain.com. For example, you might sign up to HN as bob.hackernews@yourdomain.com. Then, if you ever get a spam to that email address, you know exactly where it came from. Moreover, if one of those addresses gets sold off to some dodgy email resellers and flooded with semi-legitimate spam that just seems to get through GMail's filters (e.g. if you ever buy a ticket from the scummy spam-loving bastards at TicketMaster), you can just block that specific address while keeping everything else functional.



Even better - because GMail recognises aliases, you can do "bob+siteisignedupto@mydomain.com", which means you can PINPOINT the exact site the spam comes from, and rat them out. This is without creating extra email addresses or wildcards/catchalls. It just works out of the box with your regular "bob@mydomain.com".


Except that with catchall address, you will inevitably be a collateral from spammers using your domain for fake FROM headers. You'll get a lot of people have auto-away messages, spam reply notifications, and "message undeliverable" responses from mail servers in your inbox. And since all of that is legitimate traffic, you can't train Bayesian filter over it.

Been there done that :)


My strategy is to use a catch-all and filters (with Google Apps). I have my catch-all for the domain go to an address like spam@<mydomain>, and then within that account have a filter set up such that all email with a destination that includes my code gets forwarded to my real address.

For example, I sign up to HN with the email address hn.rfg@<mydomain>. This gets forwarded to my real address because it's got the rfg string in it. If I start to get spam on that account, I can add a filter for hn.rfg on either my real or spam@<domain> account, depending on which is more convenient, and I know where it came from.

Blanket spam to <mydomain> rarely comes through to my email, since the to is unlikely to include the rfg string, and will probably get picked up by the spam filter on the spam@<mydomain> account. Backscatter spam with faked from headers rarely gets to my real account, since the faked address is unlikely to include the rfg string.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: