I'm glad you had a good experience. I had a different one.
I've ran my own domain for longer than you have, and many emails have been compromised.
Some are 100% from companies selling the emails to sister companies.
The majority, though, is from a company itself being compromised by hackers / database access / etc. LinkedIn, Neopets, ProFlowers, TeeSpring, etc. I can go on.
Similar here. I don't recall when I started doing it, but it's been at least 20 years. I get a fair amount of spam from "well, what did you expect?" addresses (social sites, mostly) and some from addresses that are hard to pin down (paypal address might be shared to a seller; amazon address is definitely shared to sellers).
The most surprising one is ongoing spam (and semi-legitimate contacts from recruiters) to an address that I only (intentionally) used at O'reilly. I just checked HIBP and that address was exposed in the July 2018 Apollo exposure.
The worst offender for me is an email address I used to get a fishing license from the state fish and wildlife group. As soon as I did that, I started getting advertisements from some outfitter/prepper type places. Not sure if they bought the address or if licensee info is public in my state.
I have a similar experience. I've been using this system for about 15 years, and have to block one or two address a year due to spam. A couple were due to first party spam that I could not manage to unsubscribe from (Cooks Illustrated, I'm looking at you), and a few scraped from forums (didn't realize the email would be public when signing up). The rest appeared to be due to an account compromise (based on breadth of low quality spam) - oh and less than 1/4 of those sites notified me of a compromise. I don't think I've ever received spam from what appears to be a "legitimate" "business partner" which is what I would expect from emails that were sold.
I also get a handful of spams a month from default addresses (hostmaster, etc), all of which come from Chinese IPs. I don't have any email address posted on my websites to scrape from (mailto: or otherwise), so I don't get any spam from that.
The end result is pretty much no spam. I assumed when I first setup my domain I'd have to configure spam assassin at some point, but that point has never come, thankfully.
I've seen a shift. Between 2005-2010, I used [company]@[mydomain.com], and I noticed that I would get spam in the form of [gibberish]@[mydomain.com], presumably from spammers who were just targeting email addresses with a catch-call filter. In fact, around that time, my hosting provider, Dreamhost, started restricting email catch-alls to deal with this problem.
But then from around 2010 onward, that type of spam became much less common, and nowadays it's as you say. The vast majority, probably 90%, come from compromised accounts, like linkedin@[mydomain.com]. The rest hit the unique email addresses I have submitted in domain registration forms.
That's even more surprising considering that I've since shifted to using [username]+[company]@[mydomain.com]. Spammers could pretty easily strip off the `+[company]`, but I haven't seen that happen much.
The gibberish name ones may be targeting backscatter. They might have a reply-to with the address they're really targeting.
And that may have dropped off because there was a concerted effort to make it harder to do that around then. In particular, that's kind of what killed qmail as an in-vogue MTA, because it wasn't being updated and you had to use awkward patches to stop backscatter.
We've successfully pushed spam down hard enough that the only people spamming are people who never even see your email address; it's all computerized and they just don't care at all to try to do anything to clean up the lists.
You usually sign up for "company updates" or some such nomenclature, but after Bob's Discount Swords pivots to Improved Plowshares™, it's not really relevant anymore.
Then again, I actually fill out that little question after unsubscribing. The above I consider "legit" as long as unsubscribe works.
In my experience, you don't sign up for anything, but are automatically added to mailing lists against your will just for the sin of purchasing something. I never want to get emails from any company just because I purchased 1 item from them. Most people I know tell me they feel the same way, but instead of unsubscribing, they just mark it as spam and eventually it stops showing up in their inbox.
If I want emails from you, I will explicitly ask to be added to your mailing list. Anything else is spam as far as I'm concerned.
> If it's not what you signed up for, isn't that pretty much the definition of spam?
Nope. There's not much point in relying on a "definition" of spam that is essentially subjective. "Hey, I signed up for your newsletter, but what you've sent me isn't news to me, or I just don't like it; so it's spam".
No,I don't think so. If you signed up to receive email, then it's going to be hard to show that you received email that's different from what you signed-up for. And if it's not Bulk, then it's simply email - not bulk, and not unsolicited.
That's why it's important that spam continues to be defined as Unsolicited Bulk Email.
>If you signed up to receive email, then it's going to be hard to show that you received email that's different from what you signed-up for.
At least in the EU, if you make a complaint, it falls on the sender to assert the legal basis for sending the email, so it's on them to prove informed consent (if that's the basis they're relying on).
> That's why it's important that spam continues to be defined as Unsolicited Bulk Email.
I'm not sure you've made the case that's important. In the EU, spam has been long defined as unsolicited commercial communications (since the E-privacy Directive in 2002) - no requirement for it to be in bulk.
> In the EU, spam has been long defined as unsolicited commercial communications
True. But spam has existed since long before EU regulators got interested; one type of spam that isn't covered by the EU rules is political spam. At one time I used to get a lot of political spam from US politicians and parties. I've never been a US citizen, and I don't get to vote in US elections - these politicians were spamming mailing lists.
The EU rules specifically exclude spam that isn't trying to sell you something for money. Why? Possibly because the rules are made by politicians, who prefer that their own spam isn't included.
The pizza place down the street uses a third party digital order system, that was compromised. One of the first emails I actually had to blackhole due to the insane volume of spam and attacks that started coming to it.
Also.. my previous landlord. His computer or account got compromised at some point, and that was another email I had to blackhole due to the insane volume of porn spam that started coming to it.
And to compound this after doing a half ass job of what OP has done, I recently moved my custom google apps free domain to have a second reception domain i use JUST for this with a `.email` TLD (side note: the amount of tools that don't see modern TLD's as valid is enraging)>
I made the (maybe poor) choice of donating to political campaigns before the last US election using these emails
- `Biden-campaign@`
- `democrats@`
- `<specific local race@`
All of those I've had to unsubscribe from about 2-3 dozen total OTHER email lists as those emails are literally sold/given out to other campaigns. the biden one being the worst.
Also if you have your own business you'll start getting solicitations, LOTS of solicitations. And god forbid your email is on an old resume, or somewhere else.
Now, is any of this "technically" spam? Maybe but not really. Do I consider it worthless? yes.
But to site your last specific one. I did a search for an address I know was on a compromised product. Specifically a game Heroes of Newerth. They were hacked in I believe 2015 and the list was sold. My email was my old method `name+hon@email.domain`. I get like 20~ emails to that a year and all of them go to spam or are flagged as spam automatically.
Yeah, HoN was the first of my catch-alls to receive spam. Idiots didn't even acknowledge that they have been compromised and insisted that obviously I did use hon@mail.mydomain.tld somewhere else. These days I'd use the opportunity to check how well GDPR works in practice.
I've ran my own domain for longer than you have, and many emails have been compromised.
Some are 100% from companies selling the emails to sister companies.
The majority, though, is from a company itself being compromised by hackers / database access / etc. LinkedIn, Neopets, ProFlowers, TeeSpring, etc. I can go on.