Yes. Use a different email address for every website. Not two hundred real inboxes and not two hundred passwords to memorise. One alias per site, every one of them landing in the inbox you already open, so your real address reaches almost nobody. I run AliasFleet, an email alias service, and this is the entire thesis the product is built on.
The question sounds paranoid until you look at the arithmetic: Have I Been Pwned now tracks 1,041 breached sites and more than 17.8 billion exposed addresses. If you have held the same email for a decade, it is sitting in several of those files. That alone is survivable. The problem is what one shared address lets an attacker do next.
Why one address everywhere is the actual problem
A breach rarely ends at the site that got breached. The stolen file holds your email and, very often, a password. Attackers feed those pairs into automated tools and try them against banks, shops, and streaming services by the thousand, and Verizon's analysis of single sign-on logs says this is a median of 19% of all login attempts. The password side is worse: infostealer data shows the median person reuses passwords so heavily that only 49% of their passwords are distinct across services.
Read that again. Half your passwords open more than one door. When the email is identical everywhere too, the attacker's job is trivial. They do not need to work out who you are on each site. You already told them.
This is the part most "use strong passwords" advice misses. A unique password per site fixes the credential-stuffing half. It does nothing about the identity half: every breach still hands the same identifier to whoever buys the file, and that identifier stitches your accounts together across every future leak. addy.io, the open-source alias service, puts it plainly in their guide to this exact question: reused addresses let bad actors cross-reference your details and link your information together.
What a different address per site buys you
Three things, in order of how much they matter.
Containment. When the forum you joined in 2019 gets breached, the address in the file belongs to that forum and nothing else. It cannot be stuffed into your bank's login page, because your bank never saw it. The blast radius of any single breach is one site.
Attribution. Spam starts arriving on the alias you gave one shop. You do not need to investigate. The alias is the investigation: that shop leaked it, sold it, or got breached. Our leak-tracing guide is built on this mechanism, and it works precisely because the address existed for exactly one purpose.
A phishing check no fake can pass. This is the one people underrate. If a "PayPal security alert" lands on any address other than your PayPal alias, dismiss it: it is fake by definition, because a phish pretending to be PayPal that does not arrive on your PayPal alias outs itself. addy.io's guide makes the same point. After the Amazon phishing surge we covered this week, that one-glance test is worth more than any spam filter.
None of this asks you to trust the alias service with your secrets. The alias is a forwarding rule. Which raises the obvious objection.
Is managing all these addresses not chaos?
Done by hand it would be chaos, so nobody is suggesting a spreadsheet of two hundred logins. The system is two tools. An alias manager creates and labels each address; a password manager stores it next to the password. addy.io's guide recommends exactly this: password managers keep track of the individual aliases and passwords you create for each account.
The habit, once set, is one extra click at signup: generate the alias, save it, move on. I wrote a two-minute setup guide for the mechanics, but the discipline is one you already apply to passwords: unique password per site, unique address per site. Same idea, different clothes.
Why the Gmail plus trick does not count
Someone always suggests you+netflix@gmail.com. Fair enough: it is a real standard, RFC 5233 subaddressing, and Gmail has supported it forever. It still fails as a per-site identity for three boring reasons.
First, the base address is visible. Anyone reading you+netflix@gmail.com already knows your real address, because stripping the tag is trivial. Once the tag is gone, the whole scheme collapses. addy.io's guide notes that a script can strip these extensions in bulk, and then you cannot even tell where the spam came from.
Second, Gmail ignores dots entirely (Google's own support page says so), which tells you how seriously the plus tag is treated as identity. It is not identity. It is a label.
Third, some sites reject plus addresses at signup as invalid. I documented the full list of ways the trick breaks in our Gmail plus-addressing piece. A real alias looks like an ordinary address and reveals nothing. That is the entire difference.
What aliases can not do
Honesty first, because the pitch is strong enough without overselling.
Aliases do not fix reused passwords. If your password is identical everywhere, a unique address per site slows the attacker without stopping them. Verizon's 49% figure is the reminder: fix the password half with a manager at the same time, or you have built half a system.
Some sites reject alias addresses outright. Researchers at Fudan and Tsinghua tested 28 email providers and 18 platforms and found only five platforms even attempt alias detection, but the ones that block tend to block shared alias domains specifically. addy.io's guide admits the same problem and the same fix: sites sometimes block shared-domain signups, and your own domain sidesteps it. Real friction, rare enough that it should not decide the question.
And do not alias your bank. Mozilla's Relay documentation advises against masks on sites you trust, like your bank or credit card company.
Banking, government, and anything you must reach reliably for years gets one dedicated, stable address you never hand out elsewhere. Aliases are for the other hundred-odd sites.
The rule is simple: the more a site needs to reach you reliably for years, the more boring and permanent its address should be. Everything else gets an alias.
The setup that actually works
Start where the damage is worst: shopping sites, forums, newsletters, free trials, anything that has ever sent mail you did not ask for. Give each a fresh alias going forward. Keep the old address on the accounts that already have it. You are containing the future, not rewriting the past.
On AliasFleet the free tier covers 10 active aliases, which is the honest starter set: your ten leakiest categories, one alias each. Mozilla's Relay gives 50 free masks and calls a unique mask per account the most secure option. Either way the shape is the same. The alias list becomes the inventory of who holds your address, and the toggle next to each one is the kill switch. Ours bounces the mail back to the sender with a standard delivery failure when you flip it. Nothing about you leaks in the process.
Pair it with the password manager you should already be using, and check whether the old address has been breached while you are at it. Our breach-response checklist walks through what to do with whatever it finds. If you are still unsure what an alias even is, start here; if you are wondering whether to change the old address entirely, read this first.
One address everywhere made sense when the web was thirty sites you trusted. It is not thirty sites anymore, and you do not trust most of them. Stop giving them the key to all the others.
Top comments (0)