Comment Re:You ARE the weakest link (Score 1) 47
I manage my own domain and create aliases for each online account I create.
I do a very similar thing with my email domain, using both aliases and catchall. And I get tons of spam in my catch-all to made-up addresses. Lots of the same ones over and over. Eventually I create aliases for the largest offenders and route those to a particular mailbox I hope fills up and stops receiving.
The most infuriating was when PayPal accounts (spit!) started getting opened to addresses in my domain. No way anyone can receive those to complete the registration validations. Well, no way I think, without considerable infrastructure compromise. Or unless my email provider is compromised. Or unless I am well and truly pwned . . . I did immediately change my passwords to the service.
Worse still was when a couple of those eventually got activated by PayPal after they seemingly relented on the repeated validation requests. That's when I had enough and reached out to PayPal "support". Needless to say they were not responsive. Few agents could even make out what I was describing. Once I finally escalated to someone with half a brain, they still claimed "Oh those are only PARTLY activated. They still can't send or receive payments without linking a bank account." No apology for how/why they got activated in the first place. They were totally unconcerned. I eventually did a password recovery on one of them, logged in, and found a name and address in another city in my state. I couldn't verify that it did have a bank account associated. So maybe the PayPal security guy was not totally lying. But what a cavalier attitude toward financial security!