Give each website its own email tag
Sign up as yourname+shop@ and mail still reaches you — labeled. When spam arrives addressed to the tag, you know exactly who leaked your address.
Years of address-tagging veterans comparing catches and misses — the stale provider claims replaced by a test you run on your own inbox, the alias services left unnamed, and the free-trial uses deliberately not carried.
The spam that annoys people most isn’t the volume — it’s the mystery. You gave your address to a pet store and a tax site and a newsletter, and now a company you’ve never heard of knows you by name, and there’s no way to tell which door it walked in through. Except there is, and it’s free, and it takes no setup at all:
When you sign up for something, add a plus sign and a tag to your email address — yourname+thatstore@ instead of yourname@ — and the mail still reaches your inbox, labeled with who you gave it to.
The mechanism is a convention from email’s own standards: most major providers deliver anything tagged after a plus sign to the base address, treating the tag as a label rather than a different mailbox. (Whether yours does is a one-minute experiment — the try-it box above — which beats trusting any list, because provider support has shifted over the years.) From that one behavior, two honest uses fall out. Tracing: when junk mail arrives addressed to +thatstore, the To: line is a signed confession — catching exactly who leaked is what people here built the habit for, and the fork below carries how often the catch holds. Sorting: because the tag survives into your inbox, a filter can sweep a +newsletters tag into a reading folder, or send a tag that’s outlived its welcome straight to trash — surgical unsubscribing for lists that ignore the unsubscribe button.
Whether the tracing survives contact with professional spammers is genuinely contested, and the fork below carries that argument whole. The limits, though, are agreed and worth more than the trick: a noticeable share of websites reject the plus sign outright (their validation is wrong, but you still can’t sign up), and — sneakier — some accept it at registration and then fail at login, password reset, unsubscribe, or replying. Which yields this page’s one hard rule, straight from the people it bit: tags are for the low-stakes tier. Newsletters, shops, forums — tag freely. Banks, government accounts, anything you may someday need to recover or reply from — exact, bare, owned address, always.
There’s a second quirk in the same family, and it deserves more caution than celebration: one major provider ignores dots in the name part of an address, so dotted variations of its addresses all pour into the same inbox. People use that as a bonus set of aliases for sites that block the plus sign — but the same quirk is why folks with common names receive strangers’ receipts and password resets from people mistaken about their own address (the third FAQ, if that’s your inbox), and signup systems have learned to detect dot-variants, two accounts note. It’s a provider quirk, not a standard; test against your own inbox before leaning on it, and lean lightly.
If tagging clicks for you, the graduated versions are in the first FAQ — alias services that mint unlimited forwarding addresses, and the endgame of owning a cheap domain where every address is clean, permanent, and yours. But the plus sign is the right first move precisely because it costs nothing to try and nothing to abandon. One signup, one tag. The next time spam introduces itself, it can introduce its source too.
The community disagrees on this one
Does the tag actually catch leakers, or do the leakers just launder it off?
The tag names the leak
For this camp it works exactly as advertised: spam arrives addressed to +thatstore, and the question of who sold you is answered in the To: line. They've caught specific companies this way, and the naming alone — knowing rather than wondering — is worth the tiny habit.
5 independent accounts
Leakers strip it first
This camp points at the laundering: stripping a plus-suffix off a list takes one pass of a trivial script, and — this camp reports — the list trade routinely runs it, so the spam arrives at your bare address, untagged, and the tracer caught nothing. Add the bookkeeping of remembering which tag went where, and they judge the game not worth the candle.
3 independent accounts
Both are describing real mail. The deciding variable is the opponent: careless leakers still ship the tag, industrial ones scrub it. The hardened version, suggested from inside the argument itself: if everything legitimate you sign up for gets a tag, then untagged mail from strangers is by definition junk — and a filter can act on that, stripped suffix or not.
Common questions
Half the websites reject the plus sign. What then?
You've met the internet's sloppiest gatekeepers — the plus sign is valid under email's own standards, and sites that reject it wrote their checks wrong — but knowing that doesn't get you registered. Escalation options from these conversations, in order of effort: for that site, just use your bare address (a tag is a convenience, never a requirement); route around it with a dedicated alias service — several exist whose whole product is unlimited disposable addresses that forward to you, and some browsers and password managers now generate them automatically; or, the power move several people land on, buy a cheap domain of your own and turn on catch-all forwarding, which gives you unlimited clean addresses (shop@yourdomain, bank@yourdomain) that ordinary validators accept without complaint, with nothing to strip. The domain route costs a little money and setup, and it's the version of this whole idea that belongs entirely to you.
Does the tag work outside one particular email provider?
Mostly yes, and you never have to take anyone's word for it — that's what the one-minute test at the top of this page is for. Delivering +tag mail to the base inbox is a convention from email's own standards that most major providers implement; support has also shifted over the years (advice about which providers bounce these tends to go stale), which is exactly why the self-test beats any list this page could print. The DOT behavior is a different story: one major provider is known for treating dots in the name part as decorative, so its users can hand out dotted variations that all arrive home — and the people here treat that as its quirk alone. That's a quirk, not a standard — on other providers a dotted variant is simply a different (or invalid) address. Same verdict: test with your own inbox before you rely on either.
I keep getting email that's clearly meant for a stranger with my name. Was I hacked?
Almost certainly not — you're living in the dot quirk's side effect. On the provider that ignores dots, john.smith and johnsmith are the same inbox, and people with common names collect mail from every stranger who believes the dotted variant is theirs and types it into forms: their receipts, their appointment reminders, occasionally their password resets. Nothing was breached; someone else is just wrong about their own address. What to do, from the people who live with it: don't act on any of it — don't open the resets, don't use the accounts, since reading a stranger's mail can carry legal risk — a question these conversations raise and sensibly leave to the laws where you live — and where a sender offers a 'not me' or unsubscribe path, use it. You can't fully turn the firehose off, which is one more reason the advice runs one way everywhere on this page: for anything sensitive, give out exactly the address you own, character for character, and keep the games for the newsletter tier.
Full tip: https://findangel.org/tips/give-each-website-its-own-email-tag · FindAngel.org — free, always.