The problem with using one email address everywhere
When every online account uses the same primary email address, a sudden wave of spam or a suspicious login attempt gives you almost no information about which of the dozens (or hundreds) of services you've signed up for over the years actually leaked or sold your data. Every company you've ever given that address to is an equally plausible suspect, which in practice means none of them ever gets identified or held accountable.
The fix that's been available for years, underused
Most major email providers, along with dedicated alias services, support creating unique, disposable-looking addresses tied to a single real inbox — either through a "+" tag (like you+netflix@gmail.com) or a fully separate randomly generated alias address. Every account gets its own unique address, all forwarding to the same place you actually check.
What this actually buys you
The moment spam starts arriving at the alias you specifically created for one service, you know with certainty — not a guess — exactly which company is responsible, whether through a breach, a sale of your data to a third party, or careless internal handling. This turns an abstract, unattributable annoyance into concrete, actionable information: you can complain to, or simply stop using, the specific company responsible.
Why the technique fails in practice for most people
The single reason email aliasing doesn't deliver on this promise for most people who try it is simple: they stop keeping track of which alias goes with which service after the first few signups. Without that mapping, an alias receiving spam is just as unattributable as a shared primary address would have been — the technique's entire value depends on maintaining the list.
What a useful tracking system actually needs
Beyond just the alias-to-service mapping, a useful system tracks status over time: whether an alias is still clean, has started receiving spam (meaning something happened at that specific service), has been confirmed in an actual breach, or has been deliberately retired because you no longer use that service. This status, maintained consistently, turns aliasing from a one-time setup step into an ongoing, low-effort privacy monitoring system.
Acting on what you learn
Once an alias is confirmed compromised, the response is straightforward: that alias has done its job by identifying the responsible service, and you can now retire it, contact the company, or simply monitor whether the spam volume tells you anything further about how your data is being used or resold.
Frequently Asked Questions
If every service you sign up for gets its own unique alias, spam arriving at a specific alias tells you with certainty which single company leaked, sold, or mishandled your data — rather than leaving you unable to identify a source among dozens of services sharing one primary email address.
The most common failure point is simply forgetting which alias was created for which service after the first several signups. Without a maintained mapping, an alias receiving spam is just as unattributable as using one shared address would have been — the entire benefit depends on tracking the list consistently.
A '+' tag (like you+netflix@gmail.com) is supported natively by many email providers and still delivers to your same inbox, but some services strip everything after the '+' and treat it as your base address, reducing its effectiveness. A fully separate randomly generated alias address, offered by dedicated alias services, avoids that issue but requires setting up forwarding.
The alias has done its job by identifying the responsible service with certainty. From there, you can retire that specific alias, report the incident to the company or a relevant regulator if it constitutes a real breach, and decide whether to continue using that service at all going forward.
Yes — the Email Alias Breach Isolation Tracker lets you log each alias alongside the service it's used for and its current status (clean, breached, getting spam, or retired), so the moment one starts receiving spam, you immediately know which specific service was responsible.