<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Ahsan Luqman</title>
    <description>The latest articles on DEV Community by Ahsan Luqman (@ahsanluqman).</description>
    <link>https://dev.to/ahsanluqman</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4139469%2Fd73cf345-c787-42f7-94fa-e80342f650f1.jpg</url>
      <title>DEV Community: Ahsan Luqman</title>
      <link>https://dev.to/ahsanluqman</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/ahsanluqman"/>
    <language>en</language>
    <item>
      <title>What Is an Email Alias? The Complete Guide</title>
      <dc:creator>Ahsan Luqman</dc:creator>
      <pubDate>Fri, 02 Oct 2026 00:00:00 +0000</pubDate>
      <link>https://dev.to/ahsanluqman/what-is-an-email-alias-the-complete-guide-2pll</link>
      <guid>https://dev.to/ahsanluqman/what-is-an-email-alias-the-complete-guide-2pll</guid>
      <description>&lt;p&gt;I run &lt;a href="https://aliasfleet.com" rel="noopener noreferrer"&gt;AliasFleet&lt;/a&gt;, an email alias service: it gives every website its own email address, which forwards to your real inbox, so a leaked address can be switched off without touching anything else in your life. Before any of that makes sense, this page answers the basic question properly. An email alias is an extra address that is not your inbox: mail sent to it forwards to your real inbox, and the sender never learns the real address. That is the whole idea, and everything else is detail.&lt;/p&gt;

&lt;h2&gt;
  
  
  How an email alias actually works
&lt;/h2&gt;

&lt;p&gt;An alias is a mail-routing rule, not a mailbox. When someone sends a message to your alias, the receiving server looks up the rule, swaps the alias for your real address, and delivers the message as normal. The message itself is not changed. This is defined in the SMTP specification itself: &lt;a href="https://datatracker.ietf.org/doc/html/rfc5321" rel="noopener noreferrer"&gt;RFC 5321, section 3.9.1&lt;/a&gt; says the server "replaces the pseudo-mailbox address in the envelope with each of the expanded addresses in turn; the rest of the envelope and the message body are left unchanged."&lt;/p&gt;

&lt;p&gt;A concrete example. You create &lt;code&gt;shop@yourhandle.aliasfleet.me&lt;/code&gt; for an online store and hand that address to the store. Their order confirmations travel to the alias, the alias forwards them to your real inbox, and the store never sees the address underneath. One alias, one site. Your alias list becomes a map of exactly who holds which address, which is the part that pays off later.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fueep8wxpsj7ehpnj6vz5.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fueep8wxpsj7ehpnj6vz5.png" alt="The AliasFleet aliases list: one alias per site, each row showing its destination inbox and an on-off switch" width="799" height="387"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;From the sender's side nothing looks unusual. The alias sits in the To field like any address, and replies to it route back through the same rule. What the alias never has is storage. There is no mailbox to fill up, no quota, no login page. Creating an alias is creating a rule, deleting it is removing the rule, and pausing one keeps the rule but stops the flow. A noisy sender goes quiet without you losing the address history.&lt;/p&gt;

&lt;h2&gt;
  
  
  The four kinds of alias
&lt;/h2&gt;

&lt;p&gt;Most writing about aliases mixes up four different things. They all forward mail, but they are not the same tool.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Plus addressing.&lt;/strong&gt; If your address is &lt;code&gt;name@gmail.com&lt;/code&gt;, then &lt;code&gt;name+shopping@gmail.com&lt;/code&gt; is yours too, and the mail lands in the same inbox. Gmail, Outlook.com, iCloud, Proton and Fastmail all accept the plus form, so it costs nothing and needs no setup. Its honest verdict: a filing system, not privacy. The real address sits inside the alias for anyone to strip out. There is no off switch, and some signup forms reject the &lt;code&gt;+&lt;/code&gt; character outright.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Provider aliases.&lt;/strong&gt; Your provider gives you extra addresses inside its own walls. Outlook.com lets you add a new address to your Microsoft account; iCloud Mail lets you add a few aliases to your iCloud address. These are real addresses and they cost nothing. The trade is reach: the alias belongs to that one account and follows that provider's rules. Leave the provider and the aliases go with you.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Relay or masked addresses.&lt;/strong&gt; Services like Firefox Relay and DuckDuckGo Email Protection generate a random forwarding address for each site and pass the mail through to your inbox. The idea is the same as a dedicated alias, with the provider's own interface and limits wrapped around it. Handy if you live in that provider's ecosystem, awkward outside it, and the random addresses are hard to manage by memory.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Dedicated alias services.&lt;/strong&gt; This is the full version: an account whose job is aliases, with per-site addresses, individual pause switches, and reply routing so your answers come from the alias. It is what we built AliasFleet for. The free tier covers 10 active aliases with a verified destination, and the &lt;a href="https://aliasfleet.com/docs/email-aliases/creating-aliases" rel="noopener noreferrer"&gt;creating aliases guide&lt;/a&gt; in our docs walks through the product itself. The honest trade is the price once you outgrow the free tier, and the trust you place in the provider's forwarding servers. For the step-by-step comparison of all the methods, see &lt;a href="https://www.aliasfleet.com/blog/how-to-set-up-an-email-alias" rel="noopener noreferrer"&gt;how to set up an email alias&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F9qqlxxp1vw32t32qj9w5.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F9qqlxxp1vw32t32qj9w5.png" alt="An AliasFleet alias detail page: the alias forwards to a single verified destination inbox, with reply routing on the same row" width="799" height="359"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  What an alias is not
&lt;/h2&gt;

&lt;p&gt;Five things get confused with aliases constantly. Clearing them up is worth the space.&lt;/p&gt;

&lt;h3&gt;
  
  
  Is an email alias a second email account?
&lt;/h3&gt;

&lt;p&gt;No. A second account has its own login, its own storage, and mail that sits in it. An alias has none of those. Everything addressed to an alias arrives in your one real inbox. If you have to check two places, you have two accounts, not an alias.&lt;/p&gt;

&lt;h3&gt;
  
  
  Is it the same as a distribution list?
&lt;/h3&gt;

&lt;p&gt;No. A distribution list is a one-to-many broadcast: one message goes to the list and every member gets their own copy in their own inbox. An alias is one-to-one: one address routes to one inbox. They serve opposite directions.&lt;/p&gt;

&lt;h3&gt;
  
  
  What about a shared mailbox?
&lt;/h3&gt;

&lt;p&gt;Also no. A shared mailbox is one inbox that several people open together, like a support queue. An alias is one address that one person receives from. Shared mailboxes are about teams. Aliases are about separating your own identities.&lt;/p&gt;

&lt;h3&gt;
  
  
  What is a catch-all, then?
&lt;/h3&gt;

&lt;p&gt;A catch-all is a domain-wide net: any address at the domain that does not exist still lands somewhere. An alias is the opposite, a single named address you created on purpose. Catch-alls collect the unknown. Aliases route the known.&lt;/p&gt;

&lt;h3&gt;
  
  
  Is an alias the same as a temp-mail address?
&lt;/h3&gt;

&lt;p&gt;No, and this one matters to us. A temp-mail address is a stranger's inbox you borrow for ten minutes. It expires, you do not control it, and you cannot rely on it for anything that matters, while an alias is your own address on your own account. It persists, you manage it, and you can receive password resets and order history on it for years.&lt;/p&gt;

&lt;h2&gt;
  
  
  What email aliases are for
&lt;/h2&gt;

&lt;p&gt;With the definitions out of the way, the uses reduce to a short list. Aliases keep spam quarantined, because a noisy alias gets paused instead of polluting your inbox. They contain breaches, because a leaked per-site alias tells you exactly who leaked it and dies alone. They organise your life, because the alias list is a readable map of your accounts. And they give small businesses professional addresses like &lt;code&gt;info@&lt;/code&gt; and &lt;code&gt;support@&lt;/code&gt; without running extra inboxes.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F5q9qfqht3r8h53efg3s0.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F5q9qfqht3r8h53efg3s0.png" alt="Every AliasFleet alias carries its own pause and delete controls, so one leaked address can be switched off alone" width="800" height="333"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;One honest gap I should state plainly: I have never found a trustworthy public number for how many people use aliases, so I will not quote one. The search data says the question is being asked more every month. That is all I can verify, and it is enough.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where the protection stops
&lt;/h2&gt;

&lt;p&gt;An alias changes the address a sender holds. It does not change anything else about email.&lt;/p&gt;

&lt;p&gt;It does not encrypt your mail. An aliased message travels the same servers, in the same readable form, as any other message, and if you need the content itself to be private from the servers in between, that is a different technology and a different article.&lt;/p&gt;

&lt;p&gt;It does not hide the path. Mail headers still record the servers that handled the message, and a determined recipient can see the machinery. An alias keeps your address out of a sender's database. It is not a disguise.&lt;/p&gt;

&lt;p&gt;It cannot protect an address you already handed out. The real address you have used for a decade sits in hundreds of databases, and no alias setup fixes that. It only stops the list growing, which is still the most valuable part.&lt;/p&gt;

&lt;p&gt;And it does not survive your own reply. If a site emails your alias and you answer from your normal inbox, your reply carries your real address, and you have undone the alias yourself. The reply has to come from the alias too, which is why two-way reply routing is part of the product, not a bonus.&lt;/p&gt;

&lt;p&gt;If you want the full walkthrough of getting this set up today, the &lt;a href="https://www.aliasfleet.com/blog/how-to-set-up-an-email-alias" rel="noopener noreferrer"&gt;set-up guide&lt;/a&gt; takes about two minutes per method. Start with one alias, on one site you do not care much about, and see how it feels. Most people never go back to handing out the real address.&lt;/p&gt;

</description>
      <category>emailaliases</category>
      <category>privacy</category>
      <category>basics</category>
    </item>
    <item>
      <title>Email Tracking: How Ad Platforms Track You Without Cookies</title>
      <dc:creator>Ahsan Luqman</dc:creator>
      <pubDate>Fri, 02 Oct 2026 00:00:00 +0000</pubDate>
      <link>https://dev.to/ahsanluqman/email-tracking-how-ad-platforms-track-you-without-cookies-4fb4</link>
      <guid>https://dev.to/ahsanluqman/email-tracking-how-ad-platforms-track-you-without-cookies-4fb4</guid>
      <description>&lt;p&gt;You rejected every cookie banner. You blocked third-party cookies. It changed almost nothing, because the tracking that actually follows you around the internet does not live in your browser. It lives in your inbox: your email address is the identifier ad platforms use to recognize you across websites, apps, and devices.&lt;/p&gt;

&lt;p&gt;Email tracking is the practice of using your address itself, not the content of your emails, to connect your activity. It works through tracking pixels in messages, hashed email uploads to ad platforms, and data brokers that stitch records together. None of these mechanisms need cookies, which is why cookie blocking barely dents them.&lt;/p&gt;

&lt;h2&gt;
  
  
  How email tracking works
&lt;/h2&gt;

&lt;p&gt;Three mechanisms do most of the damage. Understanding each one points directly at the fix.&lt;/p&gt;

&lt;h3&gt;
  
  
  How does a tracking pixel track email opens?
&lt;/h3&gt;

&lt;p&gt;A tracking pixel is a tiny, invisible image embedded in a marketing email, unique to each recipient. When your mail client loads the image, the sender's server records the request: your IP address, device, and the exact open time. You never have to click anything. Simply opening the email completes the tracking event and confirms your address is active.&lt;/p&gt;

&lt;p&gt;The pixel URL carries an identifier tied to you, so the open is not anonymous. It is logged against your subscriber record, which is how senders know exactly who opened what and when. Some senders also use pixels to verify that an address is live before selling or sharing the list further.&lt;/p&gt;

&lt;h3&gt;
  
  
  What is a hashed email upload?
&lt;/h3&gt;

&lt;p&gt;A hashed email upload is how advertisers match you without handing over your raw address. They scramble your email with a one-way hash and upload it to Meta or Google as a custom audience. The platform hashes its own database the same way and matches them. Scrambled matches scrambled, and a store you visited once can target you for years.&lt;/p&gt;

&lt;p&gt;Meta documents this flow openly: customer lists are hashed before upload and matched against platform users for custom audiences. The cryptography is real, but the privacy outcome is not meaningfully different from sharing the address. A match is a match.&lt;/p&gt;

&lt;p&gt;This is also why unsubscribing from a store's emails does not stop their ads. The mailing list and the ad audience are two different systems. You can leave one and stay trapped in the other indefinitely.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fr6m72701zxlkye2q58f9.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fr6m72701zxlkye2q58f9.png" alt="How hashed email uploads work: your email is scrambled with a one-way hash, uploaded to Meta or Google as a custom audience, matched against the platform's user database, and used for ad targeting. No cookies involved; the entire flow happens on company servers." width="799" height="309"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;h3&gt;
  
  
  How do data brokers use your email address?
&lt;/h3&gt;

&lt;p&gt;Data brokers buy, scrape, and stitch personal records together, using your email address as the thread. A purchase here, a newsletter signup there, a public record somewhere else: one string ties them into a single profile, which is then sold to advertisers and other buyers. Opt-out services file removals on your behalf, but the underlying trade continues.&lt;/p&gt;

&lt;p&gt;The broker does not need your permission to hold this profile in most jurisdictions. They assemble it from sources you never interacted with directly, which is why the profile often knows things you never told any single company.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why your email beats every cookie
&lt;/h2&gt;

&lt;p&gt;A tracker needs one stable string that identifies the same person in many places. Cookies are terrible at this now: they expire, they get blocked, Safari and Firefox restrict them by default, and they are different on every device you own.&lt;/p&gt;

&lt;p&gt;Your email has none of these problems. It is unique to you, it is identical everywhere, and you have probably had it for a decade. In database terms it is a join key: the column that lets you combine two tables. Your email is the column companies use to combine everything they know about you. That is the entire trick. They do not need to follow you around the web when every site hands them the same ID.&lt;/p&gt;

&lt;h3&gt;
  
  
  Why doesn't deleting cookies stop email tracking?
&lt;/h3&gt;

&lt;p&gt;Cookie blocking governs what happens inside your browser. Hashed email uploads and data-broker matching happen on company servers, where your browser settings cannot reach. You can run the strictest browser available and still get matched, because the match used an address you typed into a form years ago.&lt;/p&gt;

&lt;h2&gt;
  
  
  How to spot tracking in your own inbox
&lt;/h2&gt;

&lt;p&gt;You do not need any tools for this. In Gmail, open any marketing email, click the three-dot menu, and choose "Show original." Search the raw source for image tags with &lt;code&gt;width="1"&lt;/code&gt; or &lt;code&gt;height="1"&lt;/code&gt;, or image URLs containing words like "track" or "pixel." That is the tracking pixel, sitting in plain sight once you know where to look.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fpvog909cnkwab9pgh7dc.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fpvog909cnkwab9pgh7dc.png" alt="Annotated example of an email's raw HTML source showing a tracking pixel: an img tag with width=" height="231" width="800"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Then hover over any link without clicking it. If the address routes through a redirect domain you do not recognize, or carries a long tail of parameters after the real URL, your click is being logged and tied to your profile before you ever arrive.&lt;/p&gt;

&lt;p&gt;&lt;br&gt;
Pick a newsletter you actually like and inspect one email. Seeing your own trusted sender's tracking pixel changes how you read every email after it.&lt;br&gt;
&lt;/p&gt;

&lt;h2&gt;
  
  
  How to stop email tracking
&lt;/h2&gt;

&lt;p&gt;There is no single switch, but there is a practical stack, in order of effort.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Turn off automatic image loading.&lt;/strong&gt; Every major mail client has the setting, it takes thirty seconds, and pixel tracking dies immediately. Apple Mail now blocks remote images by default.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Stop reusing one address everywhere.&lt;/strong&gt; This is the structural fix. Give each site its own email alias and there is no single string connecting them. When one starts getting spam or turns up in a breach, you know exactly which site leaked it, and you kill just that one. Compare that with a single shared address: when the spam starts, you have no idea which of the hundred sites you gave it to is responsible, so there is nothing to do except filter and endure.&lt;/p&gt;

&lt;p&gt;That is the workflow AliasFleet is built around: one email alias per site, tracker blocking on the way in, and a one-click kill switch when an alias leaks, plus leak detection that tells you when an alias shows up somewhere it should not. See the &lt;a href="https://dev.to/docs"&gt;AliasFleet documentation&lt;/a&gt; for setup guides, including custom domains and the API.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fsxxhgoey7vg2nv7m1f6d.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fsxxhgoey7vg2nv7m1f6d.png" alt="AliasFleet alias list showing the one-click kill switch: an active alias row for grammarly.com with its toggle highlighted, and a paused alias below it." width="800" height="207"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The alias idea is not ours alone. SimpleLogin, Firefox Relay, and DuckDuckGo's Email Protection all do versions of it, and any of them beats reusing one address. What we built differently is the combination: aliases plus the kill switch plus tracker blocking plus leak detection, organized around breach containment instead of just inbox hygiene. The &lt;a href="https://dev.to/pricing"&gt;free tier&lt;/a&gt; covers 10 aliases, enough to feel the difference before paying.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F929i2587zu03iipxeuqq.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F929i2587zu03iipxeuqq.png" alt="AliasFleet composer: replying to a support email from the alias amazon-orders.7731@aliasfleet.me created for amazon.com, so the recipient never sees the real address." width="581" height="414"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;File data-broker opt-outs.&lt;/strong&gt; Removal services automate the paperwork. It is whack-a-mole and the data creeps back, but it raises the cost of profiling you.&lt;/p&gt;

&lt;p&gt;One thing I will not claim: aliases contain the future, not the past. If ad platforms have spent years joining your real address to your identity, new aliases do not un-join that profile. They do not help while you are logged into an account either, and they do not stop fingerprinting. What they buy is containment going forward: every new signup is one fewer place your real address gets typed, hashed, uploaded, and sold. I would rather tell you that than sell you a fantasy.&lt;/p&gt;

&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Meta, "Customer list formatting guidelines for custom audiences" (documents hashing of customer data before upload and matching): &lt;a href="https://www.facebook.com/business/help/2082575038703844?locale=en_US" rel="noopener noreferrer"&gt;https://www.facebook.com/business/help/2082575038703844?locale=en_US&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Meta for Developers, "Custom Audience" (API reference for hashed audience data, including SHA-256 email hashing): &lt;a href="https://developers.facebook.com/documentation/ads-commerce/gateway-products/signals-gateway/custom-audience" rel="noopener noreferrer"&gt;https://developers.facebook.com/documentation/ads-commerce/gateway-products/signals-gateway/custom-audience&lt;/a&gt;
&lt;/li&gt;
&lt;/ul&gt;

</description>
      <category>privacy</category>
      <category>emailtracking</category>
      <category>adtech</category>
    </item>
    <item>
      <title>How to Set Up an Email Alias (In About Two Minutes)</title>
      <dc:creator>Ahsan Luqman</dc:creator>
      <pubDate>Thu, 01 Oct 2026 19:56:21 +0000</pubDate>
      <link>https://dev.to/ahsanluqman/how-to-set-up-an-email-alias-in-about-two-minutes-51kp</link>
      <guid>https://dev.to/ahsanluqman/how-to-set-up-an-email-alias-in-about-two-minutes-51kp</guid>
      <description>&lt;h1&gt;
  
  
  How to Set Up an Email Alias (In About Two Minutes)
&lt;/h1&gt;

&lt;p&gt;Setting up an email alias takes about two minutes. The choice that matters is the kind: a tag on your real address, or an address you can pause.&lt;/p&gt;

&lt;p&gt;I run &lt;a href="https://aliasfleet.com" rel="noopener noreferrer"&gt;AliasFleet&lt;/a&gt;, an email alias service: it gives every website its own email address, which forwards to your real inbox, so when a site leaks the address it holds, you pause that one address and nothing else in your life changes. This guide is the setup. There are three ways to do it, they take about two minutes each, and they are not equal.&lt;/p&gt;

&lt;p&gt;One clarification before the steps. This is about a personal alias for signups and everyday accounts. If you are an IT admin adding an alias to a work mailbox in Microsoft 365 or Active Directory, you want your vendor's admin documentation, not this page.&lt;/p&gt;

&lt;p&gt;Most guides for this search teach you how to sort mail. Sorting is fine. It is not the point. The point of an alias is that a website never gets the address you actually live in.&lt;/p&gt;

&lt;h2&gt;
  
  
  The short version
&lt;/h2&gt;

&lt;h3&gt;
  
  
  What is an email alias?
&lt;/h3&gt;

&lt;p&gt;An email alias is an address that is not your inbox. Mail sent to it forwards to your real inbox. The website only ever sees the alias. Set up one alias per website and each site's copy of your address is separate from every other site's, so no single leak or spammy sender can reach the real thing.&lt;/p&gt;

&lt;p&gt;The setup follows the same five moves whichever method you pick below:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Choose the method: a plus tag, your provider's built-in alias, or a dedicated alias service.&lt;/li&gt;
&lt;li&gt;Create the alias.&lt;/li&gt;
&lt;li&gt;Confirm where it forwards. There has to be a real inbox underneath, verified.&lt;/li&gt;
&lt;li&gt;Send yourself a test message and watch it land.&lt;/li&gt;
&lt;li&gt;Use the alias on one real signup before you roll it out everywhere.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  Method 1: plus addressing
&lt;/h2&gt;

&lt;h3&gt;
  
  
  How do I set up a plus address?
&lt;/h3&gt;

&lt;p&gt;You do not set it up. It already works. If your address is &lt;a href="mailto:name@gmail.com"&gt;name@gmail.com&lt;/a&gt;, then &lt;a href="mailto:name+shopping@gmail.com"&gt;name+shopping@gmail.com&lt;/a&gt; is yours as well, and mail sent to it arrives in the same inbox. Gmail, Outlook.com, iCloud, Proton and Fastmail all accept the plus form. Google documents the behaviour in its &lt;a href="https://support.google.com/a/users/answer/9282734" rel="noopener noreferrer"&gt;guide to recipient address variations&lt;/a&gt;. The only real work is sorting: in Gmail, build a filter for mail addressed to the plus address, apply a label, and skip the inbox if you want it out of sight.&lt;/p&gt;

&lt;p&gt;Now the limits, because they are the reason the other two methods exist. Your real address is sitting inside the alias. Anyone holding &lt;a href="mailto:name+shopping@gmail.com"&gt;name+shopping@gmail.com&lt;/a&gt; holds &lt;a href="mailto:name@gmail.com"&gt;name@gmail.com&lt;/a&gt; too, minus four keystrokes. A sender can strip the tag and mail your real address directly, and there is no off switch, because the address is your address. The mail keeps coming until your filters catch it. Some signup forms also reject the + character outright, which you discover at the worst moment, halfway through a checkout.&lt;/p&gt;

&lt;p&gt;Plus addressing is a filing system. Treat it as one and it is genuinely useful. Just do not mistake it for privacy.&lt;/p&gt;

&lt;h2&gt;
  
  
  Method 2: your provider's built-in alias
&lt;/h2&gt;

&lt;p&gt;Every big provider offers some version of an alias inside its own walls. These are real addresses and they cost nothing. They also come with the provider's terms attached.&lt;/p&gt;

&lt;h3&gt;
  
  
  How do I create an alias in Gmail?
&lt;/h3&gt;

&lt;p&gt;Gmail's version is called Send mail as, and it confuses people because it only solves the sending half. It lets you send from another address you already own: Settings, then Accounts and Import, then "Send email as", add the address, and verify it. Google's own walkthrough is &lt;a href="https://support.google.com/mail/answer/22370?hl=en-GB" rel="noopener noreferrer"&gt;Send emails from a different address or alias&lt;/a&gt;. What it does not do is give you a new address that receives mail and forwards it to you. That address has to exist somewhere first.&lt;/p&gt;

&lt;p&gt;Worth knowing if you lean on this feature: Google says that from January 2027, Gmail will no longer support Send mail as for third-party addresses such as Yahoo or Outlook accounts. Workspace aliases and other Gmail addresses you own are not affected. The free workaround has an expiry date on it.&lt;/p&gt;

&lt;h3&gt;
  
  
  What about Outlook and iCloud?
&lt;/h3&gt;

&lt;p&gt;Outlook.com does the fuller version. Microsoft lets you add a new Outlook.com address to your account as an alias; mail to it lands in your inbox and you can send from it. The steps live on Microsoft's &lt;a href="https://support.microsoft.com/en-us/office/add-or-remove-an-email-alias-in-outlook-com-459b1989-356d-40fa-a689-8f285b13f1f2" rel="noopener noreferrer"&gt;add or remove an email alias&lt;/a&gt; page. The catch is that the alias belongs to that one Microsoft account, existing Hotmail, Live and MSN addresses cannot be added, and Microsoft caps how many aliases an account can create.&lt;/p&gt;

&lt;p&gt;On Apple devices, the strong option is &lt;a href="https://support.apple.com/en-gb/102548" rel="noopener noreferrer"&gt;Hide My Email&lt;/a&gt;, part of paid iCloud+. It generates a random address per site, forwards it to your inbox, and lets you deactivate an address when it turns noisy. Of everything in this section it is the closest to the real thing. Its limit is reach: it lives in Apple's apps and Safari, so it is right there on your iPhone and awkward everywhere else. iCloud Mail also lets you add a few aliases to your iCloud address without iCloud+, but those are variations on one account, not one address per site.&lt;/p&gt;

&lt;p&gt;Provider aliases earn their keep if your life already sits inside one ecosystem. What they are not is portable, and none of them was built for one address per site across everything you use.&lt;/p&gt;

&lt;h2&gt;
  
  
  Method 3: a dedicated alias service
&lt;/h2&gt;

&lt;p&gt;This is the worked example, and it is the one I built &lt;a href="https://aliasfleet.com" rel="noopener noreferrer"&gt;AliasFleet&lt;/a&gt; for. The shape is the same at any dedicated alias service; the steps below are ours.&lt;/p&gt;

&lt;p&gt;Sign up, and the email address you signed up with becomes your first destination, the inbox everything forwards to, and if you want mail to land somewhere else instead, you add that inbox under Destinations and click the verification link it receives. No verified destination, no forwarding. That check is what stops an alias service being an open relay.&lt;/p&gt;

&lt;p&gt;Then go to Aliases and open the create form: a name, a domain, and the inbox it forwards to, with room for a category and a note. Hit Create Alias and the address is live immediately. There is no propagation wait and nothing to configure at the website you are signing up to, so you just paste the alias into its email field instead of your real address.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fnb81r9pf6ui1avjqz8qr.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fnb81r9pf6ui1avjqz8qr.png" alt="The Create Alias form in AliasFleet: the alias is live the moment you save it" width="800" height="416"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;One alias per site, named after the site. That habit is the whole system, because your alias list then reads like a map of who holds your address, and six months from now, when one of them misbehaves, you will not be guessing which signup caused it.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fwni8i6lbab7dtx9amymt.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fwni8i6lbab7dtx9amymt.png" alt="An AliasFleet account with one alias per site. When one starts receiving spam, you know exactly which site is responsible" width="800" height="416"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The full product walkthrough sits in the &lt;a href="https://aliasfleet.com/docs/email-aliases/creating-aliases" rel="noopener noreferrer"&gt;creating aliases guide&lt;/a&gt; in the docs, and &lt;a href="https://aliasfleet.com/docs/getting-started/your-first-alias" rel="noopener noreferrer"&gt;your first alias&lt;/a&gt; covers the beginner path step by step. The free tier covers 10 active aliases, which is enough for the accounts that matter most while you learn whether the habit suits you. Pricing beyond that is on the &lt;a href="https://aliasfleet.com/pricing" rel="noopener noreferrer"&gt;pricing page&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Test it before you trust it
&lt;/h2&gt;

&lt;h3&gt;
  
  
  How do I know my alias works?
&lt;/h3&gt;

&lt;p&gt;Whichever method you picked, send a test before you use the alias anywhere real. From a second account, or a friend's phone, send a plain message to the new alias. It should land in your inbox within seconds.&lt;/p&gt;

&lt;p&gt;If it does not arrive, check three things in this order: the alias is switched on, the spam folder, and whether the destination inbox is verified. That is the order the failures actually happen in, in my experience.&lt;/p&gt;

&lt;p&gt;Then use the alias once, on a real signup you do not care much about. A newsletter. A shop account. Watch the mail arrive addressed to the alias. After that the habit builds itself, one signup at a time.&lt;/p&gt;

&lt;h2&gt;
  
  
  Replying without handing over your real address
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Can I reply from an alias?
&lt;/h3&gt;

&lt;p&gt;Receiving is half the story. If a site emails your alias and you reply from your normal inbox, your reply carries your real address, and now the site has it. You will have undone the alias with your own reply.&lt;/p&gt;

&lt;p&gt;In AliasFleet, forwarding is two-way. Turn on Can Reply for your destination, and when you reply to a forwarded message it goes out showing the alias as the sender. The site never sees the address underneath. Gmail's Send mail as does the sending half for addresses you own, which is why people pair it with a receiving service, but read the January 2027 change above before you build anything on it.&lt;/p&gt;

&lt;h2&gt;
  
  
  When an alias starts getting spam
&lt;/h2&gt;

&lt;h3&gt;
  
  
  What do I do when an alias leaks?
&lt;/h3&gt;

&lt;p&gt;One morning, an alias you gave to exactly one shop starts receiving lottery scams. You do not have to wonder where they got it. Only one place ever had that address.&lt;/p&gt;

&lt;p&gt;Open the alias and pause it. Mail to it bounces back to the sender, and your inbox goes quiet. Your other aliases are untouched, and so is your real address.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F8yxaxkv3ifuswthvol2c.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F8yxaxkv3ifuswthvol2c.png" alt="Every alias in AliasFleet carries its own switch. Pause the one that leaked and the rest of your mail keeps working" width="800" height="416"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;That is the entire payoff of the per-site habit, and it takes about ten seconds. For the fuller method, including how to be sure a site leaked your address before you accuse it of anything, see &lt;a href="https://aliasfleet.com/blog/which-website-leaked-my-email" rel="noopener noreferrer"&gt;which website leaked my email&lt;/a&gt;. It is also worth checking the alias against &lt;a href="https://haveibeenpwned.com" rel="noopener noreferrer"&gt;Have I Been Pwned&lt;/a&gt; to see whether it has surfaced in a known breach.&lt;/p&gt;

&lt;h2&gt;
  
  
  Your old address
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Can an alias protect the address I already use?
&lt;/h3&gt;

&lt;p&gt;No. An alias only protects addresses you have not handed out yet. The real address you have used for a decade already sits in hundreds of databases, and no setup guide fixes that. It only stops the list growing.&lt;/p&gt;

&lt;p&gt;And the free methods are fine for plenty of people. If all you want is a tidier inbox, plus addressing and two filters will do it, and you should not pay anyone for that, including me. The dedicated service earns its place when you want the per-site control, the reply routing and the off switch, working across every device and provider you use.&lt;/p&gt;

&lt;p&gt;Pick one method and set up one alias today, then use it on the next signup you meet. After that, the system mostly looks after itself.&lt;/p&gt;

</description>
      <category>emailalias</category>
      <category>howto</category>
      <category>privacy</category>
    </item>
    <item>
      <title>Times Car Data Breach Exposed 6.6 Million Accounts. Here's What to Do</title>
      <dc:creator>Ahsan Luqman</dc:creator>
      <pubDate>Wed, 30 Sep 2026 20:49:06 +0000</pubDate>
      <link>https://dev.to/ahsanluqman/times-car-data-breach-exposed-66-million-accounts-heres-what-to-do-44fo</link>
      <guid>https://dev.to/ahsanluqman/times-car-data-breach-exposed-66-million-accounts-heres-what-to-do-44fo</guid>
      <description>&lt;h1&gt;
  
  
  Times Car Data Breach Exposed 6.6 Million Accounts. Here's What to Do
&lt;/h1&gt;

&lt;p&gt;Times Car confirmed attackers stole 6.6 million accounts, including emails and driver's licence images. Here is what was taken and what to do.&lt;/p&gt;

&lt;p&gt;I run &lt;a href="https://aliasfleet.com" rel="noopener noreferrer"&gt;AliasFleet&lt;/a&gt;, an email alias service. It gives every website its own email address, so when a site is breached, the leaked address belongs to that site alone and you can pause it in one click. Times Car is the newest reason that matters: the Japanese car-sharing service confirmed this week that attackers stole data from 6.6 million accounts.&lt;/p&gt;

&lt;p&gt;What came out is worse than the usual list: not just email addresses, but full names, home addresses, dates of birth and photographs of driver's licences. If you have ever used Times Car, or held a Times Business Service corporate account, your details may be in that set. First, though, the facts.&lt;/p&gt;

&lt;h2&gt;
  
  
  What happened
&lt;/h2&gt;

&lt;h3&gt;
  
  
  When was Times Car breached?
&lt;/h3&gt;

&lt;p&gt;Times Car says a third party reached its systems at the beginning of September 2026, and the company announced the incident on 25 September, blocked the unauthorised access the next day, and said it was investigating whether personal information had been taken. An update reported on 28 and 29 September changed that: the theft was confirmed. &lt;a href="https://www.bleepingcomputer.com/news/security/times-car-confirms-data-breach-affecting-66-million-user-accounts/" rel="noopener noreferrer"&gt;BleepingComputer&lt;/a&gt; and &lt;a href="https://www.scworld.com/brief/japanese-car-sharing-service-times-car-confirms-6-6-million-accounts-compromised-in-data-breach" rel="noopener noreferrer"&gt;SC Media&lt;/a&gt; both covered the confirmation, and their numbers agree.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fh6oa8k7mtfclzrcht0in.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fh6oa8k7mtfclzrcht0in.png" alt="The official Park24 notice on the Times Car breach, the second report published on 28 September 2026, confirming the investigation results" width="738" height="378"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The affected accounts number about 6.6 million: current and former Times Car members, plus current and former members of the Times Business Service corporate programme. Times Car claims 4 million active members as of August 2026, which means the 6.6 million figure includes people who left years ago. That is normal in breaches, and it is also the point. An old account does not stop being your data the day you stop using the service.&lt;/p&gt;

&lt;p&gt;The company says all services continue to operate as normal, and a forensic investigation with an outside expert is under way. Affected customers will be notified individually, in stages.&lt;/p&gt;

&lt;h2&gt;
  
  
  What was taken
&lt;/h2&gt;

&lt;h3&gt;
  
  
  What data did the Times Car breach expose?
&lt;/h3&gt;

&lt;p&gt;The company lists names, physical addresses, dates of birth, telephone numbers, email addresses, driver's licence information including images of identity-verification documents, account passwords, and linked service IDs. Corporate members lost their department names as well. Credit card details were not affected, and the company says there is no evidence the stolen data has been distributed online yet.&lt;/p&gt;

&lt;p&gt;Slow down on the licence images, because that is where this breach stops being routine. A leaked password you can fix in a minute. A leaked email address is mostly a spam and phishing problem. A photograph of your driver's licence, sitting next to your name, home address and date of birth, is raw material for impersonating you to a bank, a mobile carrier, or another car service. You cannot rotate your date of birth. You cannot reissue your face.&lt;/p&gt;

&lt;p&gt;Corporate members have an extra problem: their department names were taken too, so an attacker does not just know that you work somewhere, he knows where, and in which team. A message that names your employer, your department and your car service is not a generic lure. It is a spear built from this breach alone.&lt;/p&gt;

&lt;p&gt;The passwords, at least, were stored in a form the company says cannot be restored, which usually means hashed or encrypted, and that is better than the alternative. If the hashing holds up, nobody is logging into your Times Car account from the stolen file. The risk sits elsewhere. It sits in messages that pretend to come from Times Car.&lt;/p&gt;

&lt;h2&gt;
  
  
  The messages are the risk
&lt;/h2&gt;

&lt;p&gt;Times Car has warned members to watch for emails, text messages and phone calls claiming to come from the company, and to avoid attachments and any page that asks for passwords or card details. That warning is the whole ballgame. Whoever holds this database has what a convincing fake needs: your real name, your real address, and proof that you are a Times Car member. A message saying your licence verification needs updating is not speculation. It is the obvious next move for anyone holding that data.&lt;/p&gt;

&lt;h3&gt;
  
  
  How do I tell a real Times Car notice from a fake one?
&lt;/h3&gt;

&lt;p&gt;Mostly, you cannot, and that is the honest answer. Times Car is notifying people in stages, so a genuine notice may arrive weeks from now and look exactly like the phishing it warns against. The rule that survives this: never follow a link in any message about this breach. Open your browser and type the company's real address yourself, then log in there. Check the company's official announcements, and if you are still unsure, contact Times Car through the support channels on that site. If the message was fake, the scammer got nothing. Your click was the thing he needed.&lt;/p&gt;

&lt;p&gt;I do not know when the phishing starts, or whether this data stays quiet. "No evidence of distribution" describes last week. It makes a poor promise about next month.&lt;/p&gt;

&lt;h2&gt;
  
  
  What to do now
&lt;/h2&gt;

&lt;h3&gt;
  
  
  What should I do if my data was in the Times Car breach?
&lt;/h3&gt;

&lt;p&gt;Three things, in order. Change your Times Car password first, and change it anywhere you reused it, because credential stuffing is how one breach quietly becomes five; then treat every Times Car message as hostile until you have confirmed it on the company's real site, never through a link in the message. Then check &lt;a href="https://haveibeenpwned.com" rel="noopener noreferrer"&gt;Have I Been Pwned&lt;/a&gt; over the coming weeks: this breach has not been indexed there yet, but once it is, an address lookup will tell you whether you were in it. For the longer version of the post-breach routine, the &lt;a href="https://aliasfleet.com/blog/what-to-do-when-your-email-is-in-a-data-breach" rel="noopener noreferrer"&gt;checklist for when your email turns up in a breach&lt;/a&gt; covers passwords, freezes and the rest without my repeating it here.&lt;/p&gt;

&lt;p&gt;If the identity documents worry you, and they should, call your bank's fraud team. Ask what extra checks they can put on your accounts. Where your country offers identity monitoring or a credit freeze equivalent, this is the week to use it.&lt;/p&gt;

&lt;h2&gt;
  
  
  Make the next breach harmless
&lt;/h2&gt;

&lt;p&gt;None of the above gives you back the licence images. What the steps can do is change what the next breach takes from you. Every service you sign up for is a database that someone, someday, will copy, and the only variable you control is which address sits in it.&lt;/p&gt;

&lt;p&gt;Give each service its own email alias. The mail still lands in your normal inbox. But when that service is breached, the address in the dump belongs to that service alone. You know who leaked it, because only one place ever had that address. You pause the alias and the phishing dies with it, while your bank, your employer and your family keep using an address nobody breached. That is what &lt;a href="https://aliasfleet.com" rel="noopener noreferrer"&gt;AliasFleet&lt;/a&gt; does, and setting up your &lt;a href="https://aliasfleet.com/docs/getting-started/your-first-alias" rel="noopener noreferrer"&gt;first alias&lt;/a&gt; takes about thirty seconds per service. If you are tracing an older leak, the method for &lt;a href="https://aliasfleet.com/blog/which-website-leaked-my-email" rel="noopener noreferrer"&gt;finding out which website leaked your email&lt;/a&gt; goes deeper.&lt;/p&gt;

&lt;h3&gt;
  
  
  One honest limitation
&lt;/h3&gt;

&lt;p&gt;An alias does not un-leak a driver's licence, and nothing in this article does that either. What was taken from Times Car is taken. The alias only decides the size of the next incident: one address, tied to one service, that you can switch off. Anyone who promises you more than that is selling something.&lt;/p&gt;

&lt;p&gt;You cannot stop companies being breached. You can stop being the person whose real inbox sits in every one of them.&lt;/p&gt;

</description>
      <category>databreach</category>
      <category>emailprivacy</category>
      <category>timescar</category>
    </item>
    <item>
      <title>Your Email Was in a Data Breach. Here Is What to Do Next</title>
      <dc:creator>Ahsan Luqman</dc:creator>
      <pubDate>Tue, 29 Sep 2026 14:26:45 +0000</pubDate>
      <link>https://dev.to/ahsanluqman/your-email-was-in-a-data-breach-here-is-what-to-do-next-2p9d</link>
      <guid>https://dev.to/ahsanluqman/your-email-was-in-a-data-breach-here-is-what-to-do-next-2p9d</guid>
      <description>&lt;h1&gt;
  
  
  Your Email Was in a Data Breach. Here Is What to Do Next
&lt;/h1&gt;

&lt;p&gt;Your email is in a data breach. Find what leaked, fix reused passwords, expect phishing, then contain the next one with one alias per site.&lt;/p&gt;

&lt;p&gt;The breach notice is probably in your spam folder. Check there before you assume you never got one.&lt;/p&gt;

&lt;p&gt;Your email address is in a data breach. That address might be ten years old, so of course this feels bad. The leak itself is rarely what costs you, though. What costs you is the week after: your reused password getting tried on a hundred sites, and phishing that quotes your own data back at you.&lt;/p&gt;

&lt;p&gt;The last section is the one I'd read twice. One email alias per site, which is what &lt;a href="https://aliasfleet.com" rel="noopener noreferrer"&gt;AliasFleet&lt;/a&gt; is for. It's the part that protects you next time.&lt;/p&gt;

&lt;h2&gt;
  
  
  Find out what leaked
&lt;/h2&gt;

&lt;h3&gt;
  
  
  How do I check what a breach exposed about me?
&lt;/h3&gt;

&lt;p&gt;Type your address into &lt;a href="https://haveibeenpwned.com" rel="noopener noreferrer"&gt;Have I Been Pwned&lt;/a&gt;. It lists every known breach containing it, and what each one took.&lt;/p&gt;

&lt;p&gt;Then read paragraph four of the company's notice. Paragraph one says "we take security seriously." Paragraph four says what was taken.&lt;/p&gt;

&lt;p&gt;While you're there, turn on its breach notifications. Next time, you'll hear about it from Troy Hunt's database before the company's PR gets around to you.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fwtnxu7109n0a93hogchn.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fwtnxu7109n0a93hogchn.png" alt=" " width="800" height="456"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;What leaked decides everything below. An email alone is mostly a spam problem. If passwords or ID numbers were in the dump, keep reading carefully. I wrote a longer piece on &lt;a href="https://aliasfleet.com/blog/which-website-leaked-my-email" rel="noopener noreferrer"&gt;tracing which website leaked your email&lt;/a&gt; if you want to go deeper on finding the source.&lt;/p&gt;

&lt;h2&gt;
  
  
  Change the passwords
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Which passwords do I change first?
&lt;/h3&gt;

&lt;p&gt;The breached site's. Then every site where you reused it.&lt;/p&gt;

&lt;p&gt;This is called credential stuffing. Attackers feed the leaked pair into software that tries it on site after site, while they sleep. It works for one reason: most people reuse passwords. &lt;a href="https://sqmagazine.co.uk/password-statistics/" rel="noopener noreferrer"&gt;Bitwarden's 2025 survey&lt;/a&gt; put the figure at 78%.&lt;/p&gt;

&lt;p&gt;I've done this twice. The first time I changed them by hand and it took a weekend I won't get back. The second time I had a password manager and it took twenty minutes.&lt;/p&gt;

&lt;p&gt;Start with your email. Every password reset flows through it, so it gets a unique password and two-factor authentication first. Then the bank. Forty unique passwords is not a memory task. Get a manager. Where a site offers passkeys, take it. Nothing to stuff.&lt;/p&gt;

&lt;h2&gt;
  
  
  Expect the phishing
&lt;/h2&gt;

&lt;h3&gt;
  
  
  What does breach phishing look like?
&lt;/h3&gt;

&lt;p&gt;It knows your name, your old password, and the site that leaked it. The classic is the extortion email: "we have your password, it's hunter2, pay up." The password is real. It came from the breach. It's still a bluff. Delete it.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F1xrcn62lraigdmo03ndk.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F1xrcn62lraigdmo03ndk.png" alt=" " width="484" height="585"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;This is what one looks like in the wild, documented by &lt;a href="https://krebsonsecurity.com/2018/07/sextortion-scam-uses-recipients-hacked-passwords/" rel="noopener noreferrer"&gt;Brian Krebs&lt;/a&gt;. Note the real password in the opening line. That is the whole trick.&lt;/p&gt;

&lt;p&gt;A week after a big breach, inboxes fill with this stuff. That's the dump being worked through, address by address. The fakes copy the company's real follow-ups, so don't click links in any of it. If an email tells you to act, get there yourself. Fresh tab, type the address.&lt;/p&gt;

&lt;p&gt;I don't know how long it lasts. Months, in my experience.&lt;/p&gt;

&lt;h2&gt;
  
  
  Don't make it worse
&lt;/h2&gt;

&lt;p&gt;Two mistakes I see every time. First: replying to the phishing to tell them off. All that does is confirm the address is live, and the mail gets worse. Delete, don't engage.&lt;/p&gt;

&lt;p&gt;Second: posting the breach notice on social media with your address visible in the screenshot. Now it's in two dumps. Crop it or don't post it.&lt;/p&gt;

&lt;h2&gt;
  
  
  Lock it down if ID data leaked
&lt;/h2&gt;

&lt;h3&gt;
  
  
  When do I need a credit freeze?
&lt;/h3&gt;

&lt;p&gt;If the dump included your national ID number, passport number, or bank details. Then someone can try to open accounts as you, and this stops being an email problem.&lt;/p&gt;

&lt;p&gt;In the US, &lt;a href="https://www.identitytheft.gov/" rel="noopener noreferrer"&gt;IdentityTheft.gov&lt;/a&gt; builds you a recovery plan for exactly what was exposed. Ask one credit bureau for a fraud alert; it notifies the other two. A freeze is stronger, and it stays until you lift it.&lt;/p&gt;

&lt;p&gt;Outside the US, call your bank's fraud team first. Faster than any guide.&lt;/p&gt;

&lt;p&gt;Keep the breach notice somewhere. Dates, company name, what was taken. You'll want it if you ever dispute a fraudulent account.&lt;/p&gt;

&lt;h2&gt;
  
  
  Make the next breach harmless
&lt;/h2&gt;

&lt;h3&gt;
  
  
  How do I stop the next breach hurting me?
&lt;/h3&gt;

&lt;p&gt;You can't. Every company you sign up for is a database waiting its turn.&lt;/p&gt;

&lt;p&gt;What you can decide is what the next breach gets. Give every site its own email alias, and the next leak exposes an address that belongs to one site only. The spam arrives on that alias. Pause it. Done.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fcamlity43ltcwv0043fp.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fcamlity43ltcwv0043fp.png" alt=" " width="800" height="450"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Six months from now another notice lands in your spam folder. You check which alias the mail is hitting, pause it, and get on with your day. That is the whole system.&lt;/p&gt;

&lt;p&gt;It takes thirty seconds per site. The full method is in the &lt;a href="https://aliasfleet.com/blog/which-website-leaked-my-email" rel="noopener noreferrer"&gt;leak-tracing piece&lt;/a&gt;; five aliases are free, and the steps are in the &lt;a href="https://aliasfleet.com/docs/getting-started/your-first-alias" rel="noopener noreferrer"&gt;docs&lt;/a&gt;.&lt;/p&gt;

&lt;h3&gt;
  
  
  One honest limitation
&lt;/h3&gt;

&lt;p&gt;No step on this list un-leaks your address. It's in the dump and it's staying there. What you did is limit what it can do, and set things up so the next one matters less. Anyone selling you a service that scrubs your data from a breach dump is selling you nothing.&lt;/p&gt;

&lt;p&gt;You can't undo this breach. You can make the next one irrelevant.&lt;/p&gt;

</description>
      <category>databreaches</category>
      <category>howto</category>
      <category>email</category>
      <category>privacy</category>
    </item>
    <item>
      <title>How to Find Out Which Website Leaked Your Email Address</title>
      <dc:creator>Ahsan Luqman</dc:creator>
      <pubDate>Tue, 29 Sep 2026 02:38:52 +0000</pubDate>
      <link>https://dev.to/ahsanluqman/how-to-find-out-which-website-leaked-your-email-address-3dn8</link>
      <guid>https://dev.to/ahsanluqman/how-to-find-out-which-website-leaked-your-email-address-3dn8</guid>
      <description>&lt;p&gt;&lt;a href="https://aliasfleet.com" rel="noopener noreferrer"&gt;AliasFleet&lt;/a&gt; lets you create a unique email alias for every website you join. Your real inbox stays private, and if a site leaks your data, any spam will show up on that site's alias. The address itself reveals who leaked your email. The key is simple: stop using the same email address everywhere.&lt;/p&gt;

&lt;p&gt;Here’s what most services won’t tell you: if you’ve used the same email address everywhere for years, there’s no way to trace exactly who leaked it. That address has been out there for a long time, and it’s understandable to feel frustrated. Still, there are steps you can take now to check for leaks and make sure any future leaks are easy to trace.&lt;/p&gt;

&lt;h3&gt;
  
  
  Check Have I Been Pwned first
&lt;/h3&gt;

&lt;p&gt;Before you set anything up, see what’s already out there. &lt;a href="https://haveibeenpwned.com" rel="noopener noreferrer"&gt;Have I Been Pwned&lt;/a&gt; is a free site that keeps a database of email addresses found in known data breaches. Just enter your email, and it will show you which breaches your address appeared in. It’s run by Troy Hunt, and it’s always my first recommendation.&lt;/p&gt;

&lt;h3&gt;
  
  
  What can Have I Been Pwned tell you about a leak?
&lt;/h3&gt;

&lt;p&gt;Have I Been Pwned shows you which known data breaches included your email address. For example, if your address shows up in the "Acme breach," it means Acme had your data. The service is free and very helpful. However, it can’t tell you if your address was quietly sold to spammers, since those cases don’t show up in breach databases. Also, new leaks might not appear right away because each breach has to be found, confirmed, and added.&lt;/p&gt;

&lt;p&gt;If you have your own domain, you can search for all addresses on that domain after verifying you own it. This shows every address from your domain found in breaches. If you don’t have a domain, just use the regular email search.&lt;/p&gt;

&lt;h3&gt;
  
  
  The free method: Gmail plus addressing
&lt;/h3&gt;

&lt;p&gt;Gmail has a built-in feature for this that’s been around for years, but most people don’t realize it exists.&lt;/p&gt;

&lt;h3&gt;
  
  
  How does the Gmail plus trick expose a leak?
&lt;/h3&gt;

&lt;p&gt;When you sign up for a site, use &lt;a href="mailto:you+sitename@gmail.com"&gt;you+sitename@gmail.com&lt;/a&gt; instead of your regular address. Gmail ignores anything after the plus sign and still delivers the email to your inbox, but the To field keeps the tag. If you later get spam sent to &lt;a href="mailto:you+sitename@gmail.com"&gt;you+sitename@gmail.com&lt;/a&gt; from people you don’t know, you’ll know which site leaked your address. This method is free and doesn’t require a new account.&lt;/p&gt;

&lt;p&gt;For example, if your email is &lt;a href="mailto:daniel@gmail.com"&gt;daniel@gmail.com&lt;/a&gt; and you sign up at a furniture store as &lt;a href="mailto:daniel+oakstore@gmail.com"&gt;daniel+oakstore@gmail.com&lt;/a&gt;, you might start getting crypto spam a year later addressed to &lt;a href="mailto:daniel+oakstore@gmail.com"&gt;daniel+oakstore@gmail.com&lt;/a&gt;. Since only Oakstore had that address, you know they were the source.&lt;/p&gt;

&lt;h3&gt;
  
  
  Where does the plus trick break?
&lt;/h3&gt;

&lt;p&gt;There are two main problems. First, some websites don’t accept email addresses with a plus sign, so you can’t always use this trick. &lt;a href="https://www.pcworld.com/article/3223931/gmails-hidden-trick-one-inbox-endless-custom-addresses.html" rel="noopener noreferrer"&gt;PCWorld&lt;/a&gt; pointed this out recently.&lt;/p&gt;

&lt;p&gt;Second, it’s easy for someone to remove the tag after the plus sign. Many fraud tools automatically strip out anything after the plus, and &lt;a href="https://github.com/maxmind/dev-site/blob/HEAD/content/minfraud/normalizing-email-addresses-for-minfraud.md" rel="noopener noreferrer"&gt;MaxMind&lt;/a&gt; lists this as a common practice. Spammers who want to hide where they got your address can do the same thing. So, the tag is more of a warning than real proof, and this method only works for Gmail users.&lt;/p&gt;

&lt;h3&gt;
  
  
  The method that holds up: one alias per site
&lt;/h3&gt;

&lt;p&gt;AliasFleet is designed for this purpose. Rather than adding a tag to one address, you give each site a completely different email address that forwards to your inbox.&lt;/p&gt;

&lt;h3&gt;
  
  
  How do per-site aliases identify the leaker?
&lt;/h3&gt;

&lt;p&gt;You create a unique alias for each site, such as &lt;a href="mailto:shop@yourhandle.aliasfleet.me"&gt;shop@yourhandle.aliasfleet.me&lt;/a&gt;. Every alias forwards to your real inbox, and your email app shows which alias received each message. If you get spam on an alias you only gave to one shop, you know exactly where it came from. This address is solid evidence, and unlike a plus tag, it can’t be removed because it’s a completely separate address.&lt;/p&gt;

&lt;p&gt;Setting up an alias for each site only takes about thirty seconds:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Create an alias for the site. The browser extension lets you make one from any signup form with a right-click, and it works in Chrome, Firefox, and Edge.&lt;/li&gt;
&lt;li&gt;Enter the alias on the website, just like you would with your regular email address.&lt;/li&gt;
&lt;li&gt;You’ll read your emails as usual. Everything still goes to your regular inbox, so there’s nothing extra to check.&lt;/li&gt;
&lt;li&gt;If you get spam, just open the message and check the To line. The alias listed there tells you which site leaked your email. This simple step works with any email app.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;You can create up to five aliases for free, which is enough for your most important accounts. The setup process is explained in the &lt;a href="https://aliasfleet.com/docs" rel="noopener noreferrer"&gt;documentation&lt;/a&gt;.&lt;/p&gt;

&lt;h3&gt;
  
  
  What do you do once you know which site leaked it?
&lt;/h3&gt;

&lt;p&gt;Once you know which site leaked your email, you have options: pause the alias, replace it with a new one for that site, or deactivate it completely. Pausing stops unwanted emails right away, and the leaked address becomes useless. Keep an eye on that alias for phishing attempts, since attackers often target confirmed addresses and may pretend to be the original site. If the breach included more than just your email, like passwords, change those passwords anywhere you reused them and turn on two-factor authentication where possible.&lt;/p&gt;

&lt;h3&gt;
  
  
  One honest limitation
&lt;/h3&gt;

&lt;p&gt;The alias shows which site leaked your email, but it doesn’t reveal how it happened. Whether your address was sold, shared with a marketing partner, or stolen in a breach, the alias can’t tell you the exact cause. Don’t accuse a company of selling your data based only on this evidence. No matter what happened, just disable the alias and move forward.&lt;/p&gt;

&lt;p&gt;You can’t undo an old email leak, but you can make sure any new leaks are easy to trace. That’s the main goal.&lt;/p&gt;

</description>
      <category>emailprivacy</category>
      <category>howto</category>
      <category>databreaches</category>
    </item>
    <item>
      <title>AliasFleet: Give Every Website Its Own Email Address</title>
      <dc:creator>Ahsan Luqman</dc:creator>
      <pubDate>Mon, 28 Sep 2026 02:44:46 +0000</pubDate>
      <link>https://dev.to/ahsanluqman/aliasfleet-give-every-website-its-own-email-address-427o</link>
      <guid>https://dev.to/ahsanluqman/aliasfleet-give-every-website-its-own-email-address-427o</guid>
      <description>&lt;p&gt;&lt;strong&gt;AliasFleet&lt;/strong&gt; is an email alias service. Every website you sign up for gets its own forwarding address, your real inbox stays hidden, and when a site leaks your data you shut that one alias down. I spent the past year creating it. Last month, Brave shipped a similar feature inside its browser, which tells me the problem is real.&lt;/p&gt;

&lt;h3&gt;
  
  
  Your email address is a join key
&lt;/h3&gt;

&lt;p&gt;Brave's VP of Privacy called the email address "a durable, universal identifier." He is right, and that's a very polite way to describe the problem.&lt;br&gt;
Ad platforms use server-side matching. A business uploads a hashed list of customer emails, and the platform matches them to your ad profile. No cookies are needed. The browser is not involved. Your tracker blocker can't catch it. Your email follows you to every site that asks for it, and you can't opt out because you already agreed, one signup at a time.&lt;br&gt;
Then there are data breaches. Last month, 4.6 million Chess.com addresses were leaked. Each email acts like a key, linking your chess account to your shopping and bank accounts, because it's the same everywhere. You can change a password in thirty seconds, but you can't easily change the email address your bank, employer, and family all use.&lt;/p&gt;

&lt;h3&gt;
  
  
  Why is reusing one email address dangerous?
&lt;/h3&gt;

&lt;p&gt;It's risky because you use the same address everywhere. When 4.6 million Chess.com addresses leaked, attackers got more than just emails, they got the key that links your chess account to your bank account. Breaches are only part of the problem. Ad platforms buy hashed email lists and match them to your profile. No cookies are needed. Using one address means every leak and tracker points back to you.&lt;/p&gt;

&lt;h3&gt;
  
  
  What AliasFleet actually is
&lt;/h3&gt;

&lt;p&gt;With AliasFleet, you get a separate email alias for every website you use. Any mail sent to an alias is forwarded to your real inbox, just like regular mail. The website never sees your real address. If someone steals that website's database, they only get an alias for that one site. That's where the damage stops. If a site is breached, you can open that alias and shut it down. The rest of your aliases keep working, and your real address was never exposed.&lt;br&gt;
Brave now ships something similar inside its browser. Theirs is a feature; this is a service that goes anywhere&lt;/p&gt;

&lt;h3&gt;
  
  
  How it works
&lt;/h3&gt;

&lt;p&gt;How does an alias forward mail to my inbox?&lt;br&gt;
You create an alias, like &lt;a href="mailto:store@yourhandle.aliasfleet.me"&gt;store@yourhandle.aliasfleet.me&lt;/a&gt;, and give it to a website instead of your real address. Our servers receive the mail, process it in memory, and forward it to the inbox you choose. Your mail client shows which alias the message came through, so you always know who sent it.&lt;br&gt;
You can make an alias, random or custom, like for newsletters. The browser extension lets you do this from any signup form with a right click. It works in Chrome, Firefox, and Edge.&lt;br&gt;
Hand it to the site. Use it wherever you would type your email.&lt;br&gt;
Read mail normally. It all lands in your existing inbox. Nothing new to check.&lt;br&gt;
Reply normally. Two-way forwarding is built in, so replies go out from the alias, not your real address.&lt;/p&gt;

&lt;h2&gt;
  
  
  What happens when a website leaks my alias?
&lt;/h2&gt;

&lt;p&gt;You open the alias and choose what to do: pause it, rotate it for a new address at that site, or deactivate it for good. The leaked address is now useless. Nothing else you own is affected.&lt;/p&gt;

&lt;h3&gt;
  
  
  A Tuesday morning example
&lt;/h3&gt;

&lt;p&gt;You buy a lamp from an online furniture store and give them the alias oakstore. Six months later, the store is breached and the customer list ends up on a forum.&lt;br&gt;
On Tuesday, the alias starts getting phishing emails. You deactivate it before your coffee cools. Now, the attackers have an address that leads nowhere.&lt;br&gt;
Now imagine the same breach, but with your real address. You can't deactivate that. Changing it means updating your bank, your accounts, and everything else. So you keep the same address, and the phishing emails keep coming.&lt;/p&gt;

&lt;h3&gt;
  
  
  What AliasFleet is not
&lt;/h3&gt;

&lt;p&gt;AliasFleet is not a disposable email service. Throwaway addresses are anonymous and expire in ten minutes. AliasFleet aliases are permanent. You keep them for as long as you use a service, organise them with categories and notes, and set rules for each alias. These are identities you control, not addresses you throw away.&lt;/p&gt;

&lt;h3&gt;
  
  
  What we do with your mail
&lt;/h3&gt;

&lt;p&gt;We don't keep your mail. It arrives, is processed in memory, and then forwarded. The only mail that is saved is what you ask us to keep. If you turn on Quick Send body storage in Privacy Controls, your sent mail is stored encrypted with AES-256-GCM so you have a record. Another case is quarantine: when the spam filter or one of your Custom Rules catches something, we hold it for your review instead of delivering it.&lt;/p&gt;

&lt;h3&gt;
  
  
  Pricing
&lt;/h3&gt;

&lt;p&gt;The free plan is the whole idea in miniature: 5 aliases, one inbox, and the extensions. Enough for the accounts that matter most. Pro and Business are for people who want their own domains, unlimited aliases, and heavier machinery: PGP, tracker blocking, and the API. Prices are on pricing. If the free tier hasn't earned its keep within a week, the one-click purge deletes everything and you are gone.&lt;br&gt;
Your email address does not have to be public property. Give every site its own alias, and take it back.&lt;/p&gt;

</description>
      <category>product</category>
      <category>email</category>
      <category>productivity</category>
    </item>
    <item>
      <title>4.6 million Chess.com emails leaked. Changing your password won't fix it.</title>
      <dc:creator>Ahsan Luqman</dc:creator>
      <pubDate>Wed, 23 Sep 2026 15:52:30 +0000</pubDate>
      <link>https://dev.to/ahsanluqman/46-million-chesscom-emails-leaked-changing-your-password-wont-fix-it-4okc</link>
      <guid>https://dev.to/ahsanluqman/46-million-chesscom-emails-leaked-changing-your-password-wont-fix-it-4okc</guid>
      <description>&lt;p&gt;On 13 September 2026, &lt;a href="https://haveibeenpwned.com/" rel="noopener noreferrer"&gt;Have I Been Pwned&lt;/a&gt; added 4,653,212 Chess.com email addresses to its database. If you have a Chess.com account, there is a good chance yours is in there. Here is what actually happened, what it means, and the one fix that actually works.&lt;br&gt;
What actually&amp;nbsp;happened&lt;br&gt;
This was not a hack, at least not in the way most people picture it. Nobody broke into Chess.com's servers. &lt;a href="https://hackread.com/hacker-leaks-scraped-chess-com-user-records/" rel="noopener noreferrer"&gt;Chess.com confirmed it themselves&lt;/a&gt;: attackers took email addresses harvested from older breaches and ran them through the platform's "find friends" API, matching those addresses to real Chess.com accounts. Usernames, ratings, membership details and account dates got scooped up alongside.&lt;br&gt;
Security researchers verified the data was genuine by decoding timestamps hidden inside the account identifiers. The match rate was 100 percent. So the file is real, even though no intrusion took place. About 99 percent of the emails had already appeared in earlier, unrelated breaches. This incident just connected the dots.&lt;br&gt;
What leaked, and what&amp;nbsp;didn't&lt;br&gt;
Leaked: email addresses, usernames, names, countries, ratings, membership info.&lt;br&gt;
Not leaked: passwords, payment details, anything financial. You do not need to change your Chess.com password because of this, and you do not need to panic about your bank account.&lt;br&gt;
What you should worry about is quieter: targeted phishing. Whoever holds this file knows your email, your chess username, and roughly how active you are. An email saying "suspicious login on your Chess.com account, verify here" just got a lot more convincing.&lt;br&gt;
The uncomfortable part&lt;br&gt;
Here is the bit most breach advice skips. The emails in this file were already out there. The damage was done years ago, in breaches you probably never heard about. Changing passwords and enabling 2FA are good hygiene, but they do nothing about the root problem: your one real email address is sitting in dozens of databases you have never heard of, waiting for the next scrape to connect it to something new.&lt;br&gt;
Every new account you create with that same address makes the next incident worse, because it gives attackers one more place to match it against.&lt;br&gt;
What actually&amp;nbsp;works&lt;br&gt;
Stop giving your real email address to websites. Give every service its own alias instead.&lt;br&gt;
An alias is a real, managed email identity that forwards to your inbox. When a breach like this one happens, two things are different:&lt;br&gt;
The leaked address is not your real one, so it cannot be matched against your other accounts. The whole "find friends" trick falls apart because there is nothing to match.&lt;br&gt;
You know exactly who leaked it. Spam arrives addressed to one specific alias, and that tells you which service lost it. Then you shut that alias off in one click and the spam stops, while everything else keeps working.&lt;/p&gt;

&lt;p&gt;This is not about hiding. It is about compartmentalisation: one leak should never poison your entire digital life.&lt;br&gt;
Why I wrote&amp;nbsp;this&lt;br&gt;
I am Ali, and I build &lt;a href="https://www.aliasfleet.com/" rel="noopener noreferrer"&gt;AliasFleet&lt;/a&gt;, an email alias service designed around exactly this problem: unique aliases per site, leak detection that tells you which vendor exposed you, and one-click shutoff when one does. There is a free tier with five aliases, which is enough to cover your most important accounts tonight.&lt;br&gt;
But honestly, even if you never touch my product, take the principle with you. Check your address on haveibeenpwned.com, watch for phishing that uses your chess username, and from today onward, stop handing out your real email like it is nothing. It is the single most reused identifier you own.&lt;/p&gt;

</description>
      <category>security</category>
      <category>webdev</category>
      <category>beginners</category>
      <category>cybersecurity</category>
    </item>
  </channel>
</rss>
