DEV Community

Cover image for How to Find Out Which Website Leaked Your Email Address
Ahsan Luqman
Ahsan Luqman

Posted on Originally published at aliasfleet.com

How to Find Out Which Website Leaked Your Email Address

AliasFleet lets you create a unique email alias for every website you join. Your real inbox stays private, and if a site leaks your data, any spam will show up on that site's alias. The address itself reveals who leaked your email. The key is simple: stop using the same email address everywhere.

Here’s what most services won’t tell you: if you’ve used the same email address everywhere for years, there’s no way to trace exactly who leaked it. That address has been out there for a long time, and it’s understandable to feel frustrated. Still, there are steps you can take now to check for leaks and make sure any future leaks are easy to trace.

Check Have I Been Pwned first

Before you set anything up, see what’s already out there. Have I Been Pwned is a free site that keeps a database of email addresses found in known data breaches. Just enter your email, and it will show you which breaches your address appeared in. It’s run by Troy Hunt, and it’s always my first recommendation.

What can Have I Been Pwned tell you about a leak?

Have I Been Pwned shows you which known data breaches included your email address. For example, if your address shows up in the "Acme breach," it means Acme had your data. The service is free and very helpful. However, it can’t tell you if your address was quietly sold to spammers, since those cases don’t show up in breach databases. Also, new leaks might not appear right away because each breach has to be found, confirmed, and added.

If you have your own domain, you can search for all addresses on that domain after verifying you own it. This shows every address from your domain found in breaches. If you don’t have a domain, just use the regular email search.

The free method: Gmail plus addressing

Gmail has a built-in feature for this that’s been around for years, but most people don’t realize it exists.

How does the Gmail plus trick expose a leak?

When you sign up for a site, use you+sitename@gmail.com instead of your regular address. Gmail ignores anything after the plus sign and still delivers the email to your inbox, but the To field keeps the tag. If you later get spam sent to you+sitename@gmail.com from people you don’t know, you’ll know which site leaked your address. This method is free and doesn’t require a new account.

For example, if your email is daniel@gmail.com and you sign up at a furniture store as daniel+oakstore@gmail.com, you might start getting crypto spam a year later addressed to daniel+oakstore@gmail.com. Since only Oakstore had that address, you know they were the source.

Where does the plus trick break?

There are two main problems. First, some websites don’t accept email addresses with a plus sign, so you can’t always use this trick. PCWorld pointed this out recently.

Second, it’s easy for someone to remove the tag after the plus sign. Many fraud tools automatically strip out anything after the plus, and MaxMind lists this as a common practice. Spammers who want to hide where they got your address can do the same thing. So, the tag is more of a warning than real proof, and this method only works for Gmail users.

The method that holds up: one alias per site

AliasFleet is designed for this purpose. Rather than adding a tag to one address, you give each site a completely different email address that forwards to your inbox.

How do per-site aliases identify the leaker?

You create a unique alias for each site, such as shop@yourhandle.aliasfleet.me. Every alias forwards to your real inbox, and your email app shows which alias received each message. If you get spam on an alias you only gave to one shop, you know exactly where it came from. This address is solid evidence, and unlike a plus tag, it can’t be removed because it’s a completely separate address.

Setting up an alias for each site only takes about thirty seconds:

  1. Create an alias for the site. The browser extension lets you make one from any signup form with a right-click, and it works in Chrome, Firefox, and Edge.
  2. Enter the alias on the website, just like you would with your regular email address.
  3. You’ll read your emails as usual. Everything still goes to your regular inbox, so there’s nothing extra to check.
  4. If you get spam, just open the message and check the To line. The alias listed there tells you which site leaked your email. This simple step works with any email app.

You can create up to five aliases for free, which is enough for your most important accounts. The setup process is explained in the documentation.

What do you do once you know which site leaked it?

Once you know which site leaked your email, you have options: pause the alias, replace it with a new one for that site, or deactivate it completely. Pausing stops unwanted emails right away, and the leaked address becomes useless. Keep an eye on that alias for phishing attempts, since attackers often target confirmed addresses and may pretend to be the original site. If the breach included more than just your email, like passwords, change those passwords anywhere you reused them and turn on two-factor authentication where possible.

One honest limitation

The alias shows which site leaked your email, but it doesn’t reveal how it happened. Whether your address was sold, shared with a marketing partner, or stolen in a breach, the alias can’t tell you the exact cause. Don’t accuse a company of selling your data based only on this evidence. No matter what happened, just disable the alias and move forward.

You can’t undo an old email leak, but you can make sure any new leaks are easy to trace. That’s the main goal.

Top comments (0)