Stop Using One Email for Everything

In early 2021 I got a Mozilla Monitor alert. An online store I'd bought from once had been breached, my email address, phone number, date of birth, home address, and a crackable password hash, all in a SQL dump that got posted on a hacking forum. Half a million users, and I was one of them.

I'd bought a few used books. That's what it cost me.

What got me wasn't the breach itself. It was that I had no idea what happened to that data afterward. That data gets traded. Re-sold. Combined with data from other breaches, cross-referenced with purchase history, packaged into profiles and sold again. Your email address is the thread that ties all of it together, and once it's out, you have no way to see where it goes.

I started using email aliasing about a month after that alert. This is what five years of it actually looks like.

Your email isn't a username

Most people treat their email like a login credential. It's closer to a fingerprint. You can't rotate it the way you rotate a password. You can't get a new one without losing access to years of accounts. It follows you everywhere, every service you've ever signed up for, every breach you've been part of, every data broker who bought a list with your name on it. The data broker industry runs on this. They build profiles from your purchase history, your location patterns, your estimated income, whatever leaked from the last breach you weren't told about. Your email is what lets them tie it all together across sources. That's why it's valuable. That's why it keeps getting sold.

What aliasing actually does

Every service gets its own unique forwarding address. The alias routes to your real inbox. The service never sees your actual email. When an alias starts getting spam or phishing mail, you know immediately which service it came from, and not guessing, not cross-referencing, just knowing. You disable the alias and the mail stops. That's the mechanism. What I didn't expect was how useful it would be as a detection system. Within a few months I was learning things about how data moves that I couldn't have known any other way.

What I actually found over five years

  • E-commerce and shopping sites were the fastest to leak. Sometimes within days of signing up, an alias would start getting credit card offers from financial companies I'd never heard of. Not spam exactly nit targeted, tied to what I'd just bought. The alias made the source obvious.
  • Free services and newsletters sold aliases quickly too. I expected this from obviously low-quality sites. It happened with brands I'd considered reputable.
  • The strangest pattern was loyalty programs. An alias I made for a coffee chain started receiving mortgage pre-approval offers about three months later. That's not a breach, that's a deliberate sale from the coffee chain to a data aggregator who sold it again to a financial marketing firm. The chain is two or three hops deep but the alias still traces it back to where it started.
  • Banks were slower. Not immune. One banking alias showed unexplained insurance marketing about a year in.
  • Two aliases showed up in the 2026 California data-broker registry. I found them while cross-referencing entries during the DROP rollout, wasn't looking for them specifically though. Seeing your own aliases listed in a state registry is a different kind of uncomfortable than just getting spam.

When an alias leaks: I disable it immediately. No forms, no unsubscribe links. Just off.

What I use and what it costs

My main tool is Firefox Relay Premium, about $48 a year. Simple, reliable, works well with Firefox, includes reply support so I can respond to emails without exposing my real address. I keep SimpleLogin (under Proton now) and addy.io as backups โ€” if one service goes down or raises prices, I'm not stuck. One cheap custom domain (~$12-15/year) handles portability and bypasses the rare service that blocks common forwarding addresses. Apple Hide My Email is free with iCloud+ and works well for anything Apple-connected. Firefox Relay's free tier is a reasonable starting point if you want to try this before spending anything. What I actually paid:

  • Firefox Relay Premium: ~$48/year
  • SimpleLogin + addy.io: ~$40-50/year combined
  • Custom domain: ~$12-15/year
  • First year with migration: ~$110-120 total
  • Ongoing: ~$90-110/year

The free tiers cover a lot. Paid plans mainly add reply support, unlimited aliases, and convenience. You don't need the full setup to start.

How to actually start

Get a service and try the free tier first. Firefox Relay and Apple Hide My Email are the easiest entry points. If you're planning to stick with this long-term, buy a cheap custom domain early, it'll save you headaches if a service shuts down or changes pricing later. Then go through existing accounts. For each one: generate a unique alias, log in, update the registered email, verify it went through. I tracked everything in a spreadsheet, alias, service, date created, notes on anything that leaked. The whole migration took about two weekends, with follow-ups spread over a few more weeks after that. Banks and government services were the hardest. Some required support tickets. A few didn't allow email changes at all. For those I created dedicated monitoring aliases and accepted the limited exposure. After the migration, the rule becomes automatic: every new signup gets its own alias before I even enter the site. That part doesn't feel like effort anymore. Set inbox filters for alias-tagged mail so you can actually see which service something came from. When an alias leaks: disable it, follow up with the service if it's worth the time, and use DROP (if you're in California) or broker opt-out tools for wider cleanup.

What this doesn't fix

The 2021 breach data is still out there. Disabling aliases doesn't reach it. Aliasing stops future leakage and gives you visibility into where it's happening now. It's not retroactive. Some services reject alias addresses. Usually the ones with aggressive spam filters that block forwarding domains. A custom domain fixes most of these cases. Migrating old accounts is tedious when 2FA is involved. Some services lock you out mid-change if you don't have the old verification method available. Budget more time than you think, especially for financial accounts. If one alias per service feels like too much overhead, category-based aliases is the way, one for shopping, one for newsletters, one for anything financial, give you most of the benefit. You lose some granularity on source-tracing but the system still works. None of this replaces a password manager, a VPN, or tracker blockers. This handles email specifically.

Why this matters more right now

  • California's DROP platform went live in January 2026. Residents can now submit a single opt-out request to over 543 registered data brokers at once, with enforcement kicking in August 2026. It's the most useful consumer tool built on this problem so far. It still only covers registered brokers, in one state, for people who know it exists.
  • The YODA Act was introduced on May 4th โ€” it would prohibit companies from requiring users to hand over personal data as a condition of service, and ban tracking cookies without explicit consent. Real momentum, not law yet.
  • A federal privacy bill, the Secure Data Act, dropped in April with national data minimization and deletion rights. Still being debated and its relationship to state laws is unresolved.
  • The FTC sent compliance letters to 13 data brokers earlier this year under the Protecting Americans' Data from Foreign Adversaries Act. Enforcement is starting to have real teeth.

All of this is moving in the right direction. Slowly. A $48/year service and a weekend of migration is faster than waiting for any of it to land.

Five years later

My inbox is quieter. That's the obvious part. The less obvious part is that I stopped guessing about where my data goes. The 2021 breach data is still somewhere, I can't reach that. But everything since then I can trace. That's the actual shift: from vague background dread to something concrete enough to act on.

That's worth a weekend.