Give Every Company a Different Email Address
By NorwegianSpark Editorial · Published August 8, 2026 — written with AI assistance and reviewed by the NorwegianSpark SA editorial team.
Most people have one email address and give it to everyone: the bank, the newsletter, the shop they bought a lamp from in 2019, the site that wanted registration to read one article.
That address becomes a permanent identifier tying every account together. When any one of those services is breached, the address appears in the leak, and it is the same address protecting your bank.
Using a different address for each service fixes several problems at once, and it is far less work than it sounds.
What you get
You learn who leaked. If the address you gave exactly one shop starts receiving casino spam, you know precisely where it came from. There is no ambiguity and no guessing.
You can switch off an address. Spam is not filtered — it is disconnected. Delete the alias and the mail stops permanently, without affecting anything else.
Your accounts stop being linkable. Data brokers connect profiles across services using shared identifiers, and email is the most reliable one. Different addresses make that correlation much harder.
Credential stuffing gets harder. Attackers take breached email-and-password pairs and try them elsewhere. If the address is unique to the breached site, there is nowhere to try it.
Three ways to do it
Plus-addressing. Many providers let you add a suffix: yourname+shop@example.com still arrives in your inbox. It is free and instant, but the real address is plainly visible — anyone can strip the suffix, and some sites reject the format. Useful for sorting, weak as protection.
Alias services. These generate a random address that forwards to your real inbox, which stays hidden. Each alias can be disabled individually. Some are standalone, some are bundled with password managers or privacy-focused email providers.
Your own domain. If you own a domain, catch-all addressing lets you invent an address on the spot — shop@yourdomain — with no setup per address. It gives the most control, and it means you are never locked into a provider. It also means you are responsible for keeping the domain renewed.
The genuine trade-offs
Being honest about the downsides, because they are real:
- A forwarding service is a dependency. If it disappears or you stop paying, mail to those addresses stops. For anything critical, use an address you control directly.
- Replying takes a moment's care. Most services support sending as the alias; without that, replying from your real address undoes the point.
- Account recovery gets fiddlier if you lose track of which address goes with which account. A password manager that stores the alias alongside the login solves it entirely.
- Some sites block known alias domains. Occasionally you will need a fallback.
Where to start
Do not migrate everything at once — that is the version of this plan people abandon.
Start with new sign-ups: every time you register for something from today, use a fresh alias. That costs nothing and grows the habit naturally.
Then move the low-stakes accounts you already regret — the shops and newsletters that generate the most unwanted mail. Leave your bank and government services for last, and change those only when you are confident in the setup, because a mistake there is genuinely inconvenient.
Within a few months most of your incoming mail is on addresses you can switch off individually, and the next breach notification tells you exactly which company to be annoyed at.
Affiliate disclosure
This article contains affiliate links. If you purchase through them, CyberTechVault earns a commission at no extra cost to you. Our assessments are based on vendors' published documentation, independent lab results and security disclosures — not on hands-on testing by us. Affiliate relationships never decide what we recommend.
Full disclosure: /affiliate-disclosure.