I'm concerned about recent spam to Simplelogin aliases

Over the past month I’ve received two emails to two separate Simpleogin aliases. One is used for the registrant details for a personal domain, and that domain has whois protection enabled. The other alias I use for Amazon.

A couple weeks ago I received a spam email to the alias for my domain. Like I mentioned, the domain has whois protection and I have no idea how the email address could be obtained.

Today, I received an email to my Amazon alias regarding some DeCoster vs Amazon lawsuit that I’ve been automatically opted-in to apparently. At first I assumed it was spam, but the fact it was sent to my Amazon alias gave me pause, and I’ve done some searching and the lawsuit does seem legit. I’m alarmed at how they have gotten my email address and what other details they might have obtained.

I guess these are just coincidences; I certainly hope they are. My Simplelogin account is protected with a passkey and I can’t see any indicators anyone has accessed it. Does anyone have any thoughts about how the two aliases I’ve mentioned could’ve been accessed?

  1. Re your simplelogin alias connected to your domain, Have you used the alias? I.e connected the alias to a service?
  2. Has the domain been registered before?
  3. Re De Coster et al. v. Amazon.com. It’s legit and you have to opt-out (by last day of August 2026) if you wish to not be included in the class action. However, it is spam, if your email suggests a settlement fund/pay-out already exists.

Occam’s razor. Considering that the lawsuit email appeared legitimate to you, it would seem most likely Amazon shared the email on record to facilitate the legal process. I would go a step further and say the commonality between all these events is not SimpleLogin.

I’d treat them as two separate cases. The Amazon one is probably just the address Amazon has on file being passed to the settlement/claims administrator; I’d still verify it by going from Amazon/legal notice pages manually, not from email links. For the domain alias, WHOIS privacy only protects the current public record, so I’d check whether that address was ever used with the registrar, exposed before privacy was enabled, or listed in old WHOIS/history. If it was one random spam message, I’d disable or recreate that alias and watch for a pattern before assuming SimpleLogin itself was accessed.