DEV Community

Ahsan Luqman
Ahsan Luqman

Posted on Originally published at aliasfleet.com on

Gmail Plus Addressing: Why the + Trick Stops Working

The plus sign is the oldest email trick on the internet. I run AliasFleet, which gives every website its own separate forwarding address so no two sites ever hold the same one, and plus addressing has always struck me as the cheap imitation: one real address wearing infinite labels. It works until it does not, and the places it stops working are exactly the places that matter.

The trick is simple. Mail sent to you+shopping@gmail.com lands in you@gmail.com, because Gmail ignores everything between the plus sign and the @ when it routes, while keeping the full address in the To field. The part after the plus is yours to invent, and Gmail filters can act on it. PCWorld still recommends it, and it genuinely is a good filing system. The mechanism is even standardised: RFC 5233 defines subaddressing as splitting a local-part into user and detail parts around a separator like +.

It is a filing label, not a privacy tool. Here is the full inventory of where it breaks.

The limits, in one table

Limit What happens Why it matters
Signup rejection Some forms treat + as an invalid character You cannot use the trick at the moment you need it
Tag stripping Anyone removes the tag in one line of code The label dies; the trail goes with it
Address exposure Your real address is recoverable from every plus address Every recipient learns the address you wanted to protect
No off switch Filters sort mail; they do not stop it One noisy site keeps a live address forever
Provider variance Behaviour differs between Gmail, Exchange, Fastmail The trick works differently depending on who hosts your mail

Some signup forms will not even let you type it

Why do sites reject a plus sign in an email address?

Because + in a local-part is a common signal for ban-evasion behaviour, so developers and validators gate it. Fastmail's own help docs name this the main downside of plus addressing: addresses with a + are "incorrectly considered invalid by some websites, and may not allowed on some registration forms."

PCWorld says the same from the reader's side: some sign-up forms "will reject it outright or throw an error." And it is not theoretical. OpenWhispr, a real product, shipped a desktop sign-in gate that rejected any local part containing + and told users, in the shipped error string, "Email aliases with '+' are not supported." A later commit replaced that gate with a normal email regex, but the evidence stands: production code treated plus addresses as suspicious.

That is the first structural limit. A privacy trick that fails at the signup form is a trick you cannot deploy when it counts.

The tag strips off like a sticker

Who strips plus-address tags, and how hard is it?

Anyone, and it is one line of code. That is not my phrasing. The OptMsg salting guide, which independently covers this trick, puts it exactly there: "deleting +chewy is one line of code, and anyone reselling addresses has every reason to run it."

Worse, the practice is standard in the industry, not some shady spammer invention. MaxMind's minFraud normalization documentation, the fraud-scoring service merchants run on every checkout, includes this as step 14: for non-Yahoo domains, strip "everything after and including the first + character" before hashing the address. The legitimate fraud industry erases your tag as a matter of routine. A spammer with the same motive does the same in less code.

This is why the plus trick works as a tripwire and nothing more. Our leak-tracing guide uses plus tags exactly that way: a handy way to name a leaker after the fact, with the explicit warning that the tag is removable. This piece is the other half of the story: everything else the trick cannot do.

Your real address is sitting inside every plus address

Can a plus address hide your real email from the recipient?

No, and the providers admit it. Proton's own documentation recommends plus aliases only for "a quick way to organize your mailbox with filters," warning that "your real address is easy to guess from a plus address." For signups, Proton points you at hide-my-email aliases instead.

The mechanism makes this unavoidable. A plus address is your real address with a label glued on. Strip the label and you hold the address. So every site you hand a plus address to also holds, in effect, your real address. The protection you imagined is a rearrangement of the thing you wanted to protect.

A dedicated alias inverts this. The site gets an address that is not your real one and cannot be reduced to it. That difference is the whole product: what an email alias is covers the mechanics, and the forwarding keeps your real address out of the site's database entirely.

There is no off switch for one site

How do you stop mail to one plus address without breaking the rest?

You do not, cleanly. Gmail filters can label, archive, or delete mail to you+noisy@gmail.com, but the address still exists, the site still holds it, and the mail still reaches your account before the filter touches it. There is no button that turns off that one address. There is only the filter, the delete key, and your time.

Compare that with an actual off switch. A per-site alias has its own pause control: one click and that site's mail stops while the other nine aliases keep working, because each alias is a separate routing rule, not a label on your inbox. The trick is missing exactly that: the tag names the problem, but only a separate address solves it.

The details change depending on your provider

Does plus addressing work the same everywhere?

No. The RFC describes the encoding as implementation-specific, and the implementations vary in ways that bite.

Microsoft's Exchange Online documentation calls plus addresses "extensions of their actual email address" and notes they are receive-only: "they cannot send emails from plus addresses." Fastmail lets you receive at plus addresses automatically, but sending from one requires setting it up in your account first. Gmail's behaviour, the one everyone quotes, is one provider's choice, not a universal guarantee.

So the trick's reliability depends on who hosts your mail, how they implement subaddressing, and whether the site on the other end accepts the character. Three variables you do not control. A mechanism with three uncontrolled variables is not a system. It is a habit.


Plus tags are genuinely good at one thing: filing. A +receipts tag with a Gmail filter that labels and archives order confirmations is a clean, free organiser. Keep using it for that. Just do not hand a +bankname tag to a bank and believe your address is protected. Filing and privacy are different jobs.

Where the plus trick still earns its keep

To be fair to the trick: I am not telling you to delete your plus tags. For sorting your own mail, the trick is free, instant, and needs no account, no app, no setup. Gmail filters plus a tag is still the fastest way to get order confirmations out of your main inbox. The trick's fans are right about that part.

The mistake is the second job people hire it for: protection. A label on your real address protects your real address the way a name tag protects your house. Every limit above is structural, which means no amount of clever tagging fixes it. That is the whole argument of this piece.

The grown-up version of the trick

The grown-up version keeps the good part (one label per site) and fixes the structural parts. Each site gets its own real address. The site never sees your real address at any point. Each address carries its own off switch, so one noisy site dies alone. And when the site's database leaks, the address in the dump names the source without naming you, which is the mechanism our leak-tracing guide walks through.

That is what AliasFleet does: one forwarding address per site, pauseable in one click. Replies route back through the alias, so the site never learns the address underneath. The set-up guide takes about two minutes per method, and the docs cover the mechanics. The free tier covers 10 active aliases. If your address is already in a breach database, start with Have I Been Pwned and the breach response checklist before you rebuild.

Use the plus sign for your filing cabinet. Use a real alias for your front door.

Top comments (0)