Privacy Tools

The Free Gmail Trick That Tells You Who Sold Your Email in 2026

Gmail and other providers let you create unlimited email variants for free. Here's how to use them to catch exactly which site leaked your address.

๐Ÿ“… Jul 28, 2026ยทโฑ๏ธ 4 min readยทโœ๏ธ Cikal Studio Labs
๐Ÿ“ง

The Problem: One Email, Everywhere

Most people use the exact same email address for their bank, their favorite shoe store, a newsletter they signed up for once, and a sketchy free-trial site they've since forgotten about. When spam starts flooding in, or when that address turns up in a data breach, there's no way to know which of those dozens of sign-ups is actually responsible. The fix doesn't require a new inbox, a paid service, or a browser extension โ€” it's a free feature already built into the email system.

The Gmail Dot Trick

Gmail (and Google Workspace) treats every dot in the part of an address before the @ sign as if it isn't there. j.doe@gmail.com, jo.e@gmail.com, joe@gmail.com, and even j.o.e@gmail.com all deliver to the exact same inbox. Gmail has confirmed this is intentional and permanent behavior, not a bug โ€” dots are simply ignored during delivery.

This means you can hand out jo.e@gmail.com to one retailer and j.oe@gmail.com to another, and both emails land in your one real inbox โ€” but you'll always know, just by looking at the "To:" address, which sign-up the message is tied to.

+Tag Sub-Addressing

The second trick works on far more providers: adding +anything right before the @ sign. yourname+amazon@gmail.com and yourname+newsletter@gmail.com both deliver to yourname@gmail.com, but the full tagged address is preserved in the message headers. This is supported by Gmail, Outlook/Hotmail (added in recent years), Yahoo Mail (which calls it a "disposable address"), Fastmail, and ProtonMail on paid plans.

Not Every Provider Supports These

This is where a lot of guides get it wrong by assuming Gmail's rules apply everywhere. They don't:

  • Outlook, Hotmail, Yahoo: Dots ARE significant โ€” a dotted version is a genuinely different address, not an alias. Only +tag works.
  • iCloud Mail: Neither trick works. Apple instead offers Hide My Email, a separate built-in feature (Settings โ†’ [your name] โ†’ Name, Phone, Email) that generates real random forwarding addresses per site โ€” arguably even better, since the random address reveals nothing about your real one.
  • Fastmail: Supports both tricks, plus fully custom aliases on your own domain.
๐Ÿ’ก Test before you rely on it: If your domain isn't in the well-known list, send yourself a test email using the +tag format before using it for anything important โ€” some smaller or corporate mail servers reject unrecognized address formats entirely.

Building the Habit: A Per-Site Log

The trick only pays off if you actually track which alias went where. The simplest approach is a running log: service name on one side, alias used on the other. Keep it updated every time you sign up for something new, and when spam or a breach notification arrives at a specific alias, you'll know immediately which company to blame โ€” and which to stop trusting with your data.

It's worth logging the alias at the moment you create the account, not after the fact โ€” it's easy to forget which variant you used for a given site six months later, and the entire point of the exercise is having a reliable record when you actually need it. A simple two-column log (service name, alias used) takes seconds to update and turns a vague suspicion ("I think it was that shoe site") into a certainty. It's also worth revisiting old sign-ups you no longer use and swapping their aliases out entirely if you suspect they've already been sold.

What This Doesn't Fix

Aliasing doesn't hide your real inbox from services that specifically try to normalize it (some marketing platforms strip dots and +tags before storing an address), and it doesn't protect against a company that simply doesn't care where the leak came from. But for the extremely common case โ€” figuring out which of dozens of sign-ups is responsible for a flood of spam โ€” it's the fastest, free, zero-setup fix available, and it works with the email address you already have.