Give Every Company a Different Email Address
By NorwegianSpark Editorial · Published August 8, 2026 — written with AI assistance and reviewed by the NorwegianSpark SA editorial team.
Most people have one email address and give it to everyone: the bank, the newsletter, the shop they bought a lamp from in 2019, the site that wanted registration to read one article.
That address becomes a permanent identifier tying every account together. When any one of those services is breached, the address appears in the leak, and it is the same address protecting your bank.
Using a different address for each service fixes several problems at once, and it is far less work than it sounds.
What you get
You learn who leaked. If the address you gave exactly one shop starts receiving casino spam, you know precisely where it came from. There is no ambiguity and no guessing.
You can switch off an address. Spam is not filtered — it is disconnected. Delete the alias and the mail stops permanently, without affecting anything else.
Your accounts stop being linkable. Data brokers connect profiles across services using shared identifiers, and email is the most reliable one. Different addresses make that correlation much harder.
Credential stuffing gets harder. Attackers take breached email-and-password pairs and try them elsewhere. If the address is unique to the breached site, there is nowhere to try it.
Three ways to do it
Plus-addressing. Many providers let you add a suffix: yourname+shop@example.com still arrives in your inbox. It is free and instant, but the real address is plainly visible — anyone can strip the suffix, and some sites reject the format. Useful for sorting, weak as protection.
Alias services. These generate a random address that forwards to your real inbox, which stays hidden. Each alias can be disabled individually. Some are standalone, some are bundled with password managers or privacy-focused email providers.
Your own domain. If you own a domain, catch-all addressing lets you invent an address on the spot — shop@yourdomain — with no setup per address. It gives the most control, and it means you are never locked into a provider. It also means you are responsible for keeping the domain renewed.
The genuine trade-offs
Being honest about the downsides, because they are real:
- A forwarding service is a dependency. If it disappears or you stop paying, mail to those addresses stops. For anything critical, use an address you control directly.
- Replying takes a moment's care. Most services support sending as the alias; without that, replying from your real address undoes the point.
- Account recovery gets fiddlier if you lose track of which address goes with which account. A password manager that stores the alias alongside the login solves it entirely.
- Some sites block known alias domains. Occasionally you will need a fallback.
A worked example of what this actually tells you
Two years ago you bought a lamp. The shop asked for an email address, and you gave it one used for nothing else.
This morning that address receives an investment pitch, then a message about a parcel, then something in a language you do not read. You have never given the address to anyone but the lamp shop, and the lamp shop has never emailed you anything except a receipt.
You now know several things with certainty rather than suspicion. The lamp shop's customer list has left the lamp shop, whether through a breach they have not disclosed, a supplier, or a deliberate sale. Your address is on a list being traded. And whatever else was collected at checkout — your name, delivery address, possibly your order history — has very likely travelled with it.
That last inference is the valuable one. It tells you which fraudulent messages to expect: ones that know your name and where you live, which is exactly what makes a scam message convincing. Being able to anticipate that is worth more than the spam filtering.
Then you delete the alias, and the mail stops that afternoon. Permanently, with no filter rules and no unsubscribe links to click.
Compare that with the single-address version of the same story. Casino spam arrives at the address you have given to two hundred companies over fifteen years. You have no idea which one leaked, no way to find out, and no way to stop it that does not involve abandoning the address every service you own is registered with. That is the difference, and it is the whole argument.
What to check before choosing a service
The failure modes here are about continuity rather than security, so the questions to ask are unusual.
- What happens if the service shuts down or you stop paying? Some let you keep receiving on existing aliases in a reduced mode; others stop forwarding immediately. Read this before you route anything important through it.
- Can you export your alias list? A list of which alias belongs to which account is the thing you cannot reconstruct afterwards.
- Can you bring your own domain? This is the escape hatch. If the aliases are on a domain you own, you can move providers and keep every address working. If they are on the provider's domain, you cannot.
- Does it support replying as the alias, and does the reply arrive looking normal to the recipient?
- How does it handle attachments and size limits, if you will use it for anything beyond newsletters?
- Is the provider's own domain widely blocked? Some sign-up forms reject known alias domains, and the more popular a service becomes, the more often that happens.
The failure modes that catch people
Three specific ways this goes wrong, all recoverable if you know about them in advance.
You disable an alias, then need a password reset. The account still exists and still uses that address as its login. The reset email goes to an address that no longer accepts mail, and you cannot get in. Disable aliases for services you have genuinely finished with; for the rest, filter the mail rather than switching the address off.
You forget which alias belongs to which account. Some services show a randomly generated address with no clue to its purpose, and six months later you cannot tell what it was for. The fix is to store the alias in your password manager entry alongside the username, at the moment you create it. If you do that consistently this problem disappears entirely; if you do not, it becomes permanent.
Something important goes to spam because of the forwarding hop. A forwarded message can look slightly less trustworthy to a receiving system than one sent directly. It is not common, but the day it happens to a flight confirmation or a bank notice is a bad day to discover it — which is the practical reason to leave banking, government and medical accounts on an address you control directly rather than one that forwards.
Where to start
Do not migrate everything at once — that is the version of this plan people abandon.
Start with new sign-ups: every time you register for something from today, use a fresh alias. That costs nothing and grows the habit naturally.
Then move the low-stakes accounts you already regret — the shops and newsletters that generate the most unwanted mail. Leave your bank and government services for last, and change those only when you are confident in the setup, because a mistake there is genuinely inconvenient.
Within a few months most of your incoming mail is on addresses you can switch off individually, and the next breach notification tells you exactly which company to be annoyed at.
The fair objection
Someone will point out that an email address is not the sensitive part of a breach, and they are largely right. The password is what causes real damage, and a unique password per site — which a password manager gives you almost for free — already breaks the credential-stuffing attack described above without any of this admin.
That is a genuine argument, and it means aliases are not the first thing to do. Unique passwords are, then two-factor authentication on the accounts that matter. Anyone who has not done those two should do them before thinking about email addresses at all.
Where aliases earn their place is in the layer above: the correlation and the traceability. Unique passwords stop an attacker moving between your accounts. They do nothing about data brokers linking your profiles by email address, nothing about the volume of unwanted mail, and nothing about identifying which company leaked you. Those are the specific problems aliases solve, and no other tool solves them.
The honest summary is that this is a quality-of-life and privacy measure with a modest security benefit attached, rather than a security measure. Sold as the latter it disappoints. Understood as the former it is one of the few privacy habits that gets easier rather than harder over time — and one of the few where you can actually see it working.
Where this fits
The address is only half the credential. Pair it with unique passwords from a password manager, and check whether your existing addresses have already appeared in known leaks — what to do after a data breach and how data ends up on the dark web explain what happens to an address once it escapes. If the spam you are receiving has moved from your inbox to your phone, scam text messages covers the same problem in its other form. The managers and masking services that provide aliases are compared in our security tool comparison.
Affiliate disclosure
This article contains affiliate links. If you purchase through them, CyberTechVault earns a commission at no extra cost to you. Our assessments are based on vendors' published documentation, independent lab results and security disclosures — not on hands-on testing by us. Affiliate relationships never decide what we recommend.
Full disclosure: /affiliate-disclosure.
Continue reading
privacy
End-to-End Encrypted Does Not Mean Private
Most messaging apps encrypt your messages. They differ enormously in what they record about who you talked to, when, and how often — and that is usually the more revealing half.
privacy
The Free Fraud Protection Almost Nobody Turns On
A credit freeze stops new accounts being opened in your name. It is free in many countries, takes minutes, and is more effective than most paid identity-theft products.
guides
Bitdefender Review 2026: Still the One to Beat?
An in-depth Bitdefender review for 2026: who Total Security suits, how its engine and phishing protection hold up, and how it compares to Norton.
