My thoughts on using a custom domain for email aliasing

Using a custom domain was briefly mentioned in the recent Email Aliases Tier List video. I think this deserves a clearer explanation in the future. I know this is a very popular, and somewhat basic topic. But there’s some ambiguity in how this is often presented in the privacy community

In particular, I think there should be more explicit discussion and guidance on when to use a custom domain and when not to since it’s not a zero sacrifice “upgrade.”

Initial Thoughts About Tradeoffs

When we talk about email aliasing, there are privacy and non-privacy reasons to use them. For non-privacy, it can help you better organize your inbox, block spam, better help you combat phishing, and better help you identify which accounts have been exposed to third-parties which can help you identity a data leak long before the company/organization announces it.

For privacy reasons, the major reason to use a unique email address for each account is to make it harder to identity you and harder to track you across services. Similar to how a VPN hides your IP address, hiding your real email address removes another common way companies use to fingerprint and track you.

However, using your own domain with each alias makes it pretty trivial to tie your various email aliases together. It doesn’t take much to realize that amazon@yourdomain is the same person as target@yourdomain . It’s not like they’re getting countless email addresses with your domain…it’s just you.

I think it’s also a bit of security theater. For example, if you commonly use the strategy of putting the name of the service in your email address, like amazon@yourdomain, you’re only making it slightly more tedious for an attacker compared to using the same email address everywhere. At the very least, you should at least salt your email username for each service to avoid obvious guesses if you plan to use the same custom domain across various aliases.

Making the argument that a custom domain is the same as a shared domain is like saying you can replace a commercial VPN service by tunneling through your own VPS.

The commercial VPNs and shared domains allow you to blend in whereas the custom domains and a private VPS (generally) still makes you unique, identifiable, and trackable.

Just like how VPNs are routinely blocked, the same should be expected for email aliasing services that use shared domains. That’s just unfortunately what happens in a world that wants to deprive you of privacy. I get that it’s frustrating, but I don’t think we should be reccomending anti-privacy setups to counter usability issues.

Just like how VPNs need to keep putting out new servers, a good email aliasing service should be doing the same with extra domains from time to time. We should be pushing email aliasing services to commit to adding more domains and be reccomending services that commit to doing so.

Regarding Owning Your Email Address

I get the desire to want to feel like you own your email address. But let’s be honest. You don’t really “own” it. You are effectively leasing it with permission to switch your “leasor” to another party, just like how in the banking world, you can refinance with another lender. Permission to change who you pay rent to doesn’t make that ownership.

If you stop making payments entirely or forget to renew it, you lose it. That’s not how true ownership works. It’s still effectively just a subscription like anything else.

(Yes, I’m fully aware of the parallels that the government can take away your home that you “own” if you don’t pay property taxes. Though, I don’t equate that to true ownership either. Having to make payments in perpetuity to the government (or any other party) or risk losing your home, and calling that ownership, is a subversion of language).

I’ve digressed :sweat_smile:

The biggest benefit of "owning " your own domain is that your current email provider can’t take it away from you after you leave or if they choose to terminate your account for whatever reason. This makes it easier to switch email service providers.

But, your email service provider is only one player. Your custom domain can be taken away from you by your domain name registrar. And by a hacker. And a court/arbitator. And a domain hijacker. Etc.

You’re still beholden to a someone else’s terms and they can take away what you “own” for whatever reason they can muster.

You also to have to give out more information to register your domain and have to pay to transfer “your” domain to another registrar.

Even US phone numbers have better protections than domain registrars as phone carriers must allow free porting (transfers) and cannot delete your number for at least 30 days after your service terminates. Despite this, I’ve never personally heard someone claim they “own” their phone number (which they don’t), but they do often say they “own” their domain.

What’s even the point?

While having your own domain might help you irrationally feel better about “owning” your email address, it’s pretty meaningless if it jeapordizes your privacy goals.

For the significant majority of my accounts, I don’t want them easily tied to other accounts I have both for privacy and security reasons.

The ideal solution for me is a combination of shared domains, from a reputable open-source provider that promises not to delete my aliases if I stop paying for the subscription. Personally, I think this should be a requirement for reccomended aliasing services, even if just to tell current providers that they need to raise the bar. Vendor lock-in is one thing, but subscription lock-in is also bad. The way SimpleLogin handles this, by allowing you to hold onto aliases you already created, is a major reason why I would choose them over another provider.

For the accounts that perhaps could get away with less privacy (I.e. they don’t necessarily need their own unique email), I don’t even have that many. Maybe 15-30 accounts at most for me compared to the hundreds of other accounts I have.

At which point, what am I even trying to accomplish with a custom domain? I could use a full featured email address with shared domain for those things if I absolutely must avoid the aliasing service.

If I were to pay for proton mail for example, and used their additional pm.me, protonmail.com, proton.me addresses, the worst thing that happens is that I’d have to switch the emails for those 15-30 accounts if I downgrade to the free tier. That’s at most a couple hours of work in the future. I’ve probably spent more time writing this post than that would take.

If I was truly concerned, perhaps I could forward SimpleLogin emails to a custom domain email address. SimpleLogin promises not to disable/delete aliases after your paid subscription ends, but I think they lock you in on which email they will forward your emails to once you downgrade to the free tier. So, in that regard, forwarding my simplelogin emails to my custom domain email address would remove that last bit of uncertainty of vendor lock in.

But then again, what’s the real benefit of even doing that?

Proton Mail has a free tier. So I can keep having those SimpleLogin emails forwarded to that. In the worst case scenario that I need to ditch that free protonmail account too, I can pay to renew my SimpleLogin subscription for a month and change where I have the emails forwarded to, which is still cheaper and less tedious than dealing with continuous custom domain “ownership.”

And this is all to navigate a situation that I don’t even foresee happening for a long time since at least right now, I don’t have a strong reason to switch email providers.

2 Likes

I have a domain I won’t say exactly what it is obviously but it’s like XYmail.XYZ

If for some reason a service won’t accept a traditional alias (though so far I’ve had no issues with fastmail) then I see that as the next best thing. Technically it’s still possible to piece together that XYmail doesn’t have a public presence and has only been seen a small number of times across the internet and all from similar IPs and therefore it’s the same person. But any osint thing that even bothers to go beyond “same literal email address” is still probably looking for patterns like Amazon at john smith dot com. Random.word@ZYmail is that little bit less obvious. It’s not anonymous or infallible, but probably enough to keep most noses out.