That’s why cybersecurity experts now recommend having a nuanced email alias strategy that combines multiple aliases and secure authentication protocols to keep your real inbox away from prying eyes. As a journalist often working on sensitive topics involving security and compliance, I’ve been using email aliases for almost a decade. Here are some tips that have saved me a lot of privacy hassle over the years.
Email aliases have been a standard practice for users who have to communicate sensitive information and maintain a degree of privacy, like journalists, lawyers, corporate executives, and public figures who expect to be targeted by spammers and cyber attackers. However, they don't replace real account security and won't stop anyone from breaking into your account if they somehow find your real email address.
Why your email aliases need a strategy
Email aliases hide your real address from the recipient, but not from your email provider or anyone determined to cross-reference your details from leaked data. So if you use the same alias everywhere or route every email to the same inbox without other safeguards, your email only looks private. Determined attackers can and will find ways to exploit that single point of failure.
And finally, your email alias provider itself may be compromised, revealing your forwarding address through email headers, as in the case of Apple Mail. Alias providers may also have other points of failure, like the broken sync features in ProtonMail that many have complained about. So relying entirely on a single provider without a custom domain setup is a major red flag.
Most users prefer to maintain a bunch of aliases dedicated to different relationships, like one for personal emails, one for their work colleagues, one for scheduling meetings and appointments, one for streaming services, and so on. This works fine as a convenience hack to keep your inbox clutter-free, but it doesn’t insulate an alias if one of the services or applications associated with it experiences a data breach.
Privacy-conscious experts recommend maintaining a separate email alias for each service, such as one for Netflix and a completely different one for Apple TV, then bundling them under a single subdomain on your custom domain that’s specific to streaming services. That means your Netflix alias ends up looking something like yourname.netflix@streaming.yourdomain.com. So if one platform experiences a breach, your other aliases for similar services still remain private.
Don’t rely on "plus addressing" if you want privacy
Instead, it’s better to use a combination of randomly generated words or hashkeys. If someone sees an email alias that reads LJzcR7cHhZ9Q3sW4MTJk@yourdomain.com, that doesn’t do anything to help them figure out the other email aliases on that same domain. This is especially useful if you aren’t using a custom domain yet and relying on a shared domain from your email provider or aliasing service, because those are even easier to guess.
But aside from being locked into an email or alias service, you may also hurt your deliverability rates: A lot of these domains have poor spam scores that don’t pass most inbox filters. With a custom domain, you can set up your own domain authentication via SPF, DKIM, and DMARC. That way, inboxes assign you a separate spam score based on your own email activity, not the collective behavior of everyone else using that shared domain.
Pay attention to the email headers
Here's what happened with people using the Hide My Email service in Apple Mail before July 7: Normally, Hide My Email generates a random two-word alias to conceal your real email from recipients, but due to a technical flaw, an attacker could easily uncover your real address by targeting your inbox with spam mail. They would simply spam your alias and wait for Apple Mail’s filters to respond back with a rejection notification, which would contain your real email address right there in the email header.
Many providers bundle their email aliases with a password manager for easy access management, but that comes with its own risks.
You should regularly back up your list of email aliases in a text document or spreadsheet so that in case they end up getting deleted, you can create fresh ones with identical names and prevent important emails from bouncing off.
Poison old email aliases before decommissioning
When you’re about to delete an old email account or alias, make sure to replace any personal details associated with that account with random values before you shut it down. This includes your name, address, date of birth, and any associated payment details that could be used to single you out.
Keep a non-aliased backup contact method
For banking platforms, important package deliveries, legal communications, and other priority email messages, consider maintaining a direct inbox that does not hide behind an alias or rely on email forwarding to receive messages. This can serve as a fallback for situations where missing an email is just not an option.
Hence then, the article about seven ways to make your email aliases even more secure was published today ( ) and is available on Live Hacker ( Middle East ) The editorial team at PressBee has edited and verified it, and it may have been modified, fully republished, or quoted. You can read and follow the updates of this news or article from its original source.
Read More Details
Finally We wish PressBee provided you with enough information of ( Seven Ways to Make Your Email Aliases Even More Secure )
Also on site :
- Macy’s Sterling Silver Butterfly Necklace Is a ‘Subtle but Eye-Catching’ Way to Embrace the Fairycore Trend
- 1977 Eagles Masterpiece, Which Scared Every Kid Who Heard It, Remains Rock's Greatest Unsolved Mystery
- Black Lives Matter Commitments Failed To Bring About “Structural Change” In UK TV Industry, Finds Diamond Diversity Report