Skip to main content

How to make your email address as hard to guess as your password

How to make your email address as hard to guess as your password

/

A Gmail trick that could help protect your privacy

Share this story

If you buy something from a Verge link, Vox Media may earn a commission. See our ethics statement.

What we're apparently calling "celebgate" has probably caused you to worry that your own data in the cloud isn't secure. It certainly has me worried, but I do have one small trick that helps reduce the stress a little. The attack vectors we're seeing most often involve figuring out some public piece of data about you and then parlaying that into some social engineering (or clever password recovery) to get to your data. Getting a hold of an email address is probably the easiest step in that chain, and if you can make it more difficult, you're theoretically safer.

So I try to use a different email address for every single service that I sign up for. That sounds like a nightmare (and it kind of is), but the clever bit is that all these emails only look different to the services I use, but they're actually all the same email address.

your.email+whatever@gmail.com

The trick is pretty simple, actually. If you use Gmail, you actually have an infinite number of addresses that all go into the same inbox. Instead of simply plugging in your email address, you plug in your email address with a random string attached to it after a +. Basically, if your email is "you@gmail.com," then "you+whatever@gmail.com" is technically the same email, as far as Gmail is concerned. As far as everybody else is concerned, though, it's a totally different and unique address.

So, for example, if your email address is "you@gmail.com," then you could register at Apple with "you+apple4729@gmail.com" and register at Amazon with "you+amazon2594@gmail.com." You won't have to manually sign up for dozens of different email addresses, one for each service, since all of them end up in your same "you@gmail.com" inbox. But each service will have its own unique identifying email address and if somebody guesses the email you use for Amazon, that won't mean they know what you used with Apple.

If somebody guesses the email you use for Amazon, that won't mean they know what you used with Apple

Unfortunately, the same trick doesn't work if you use Outlook or Yahoo, but you can go through a more convoluted process on each service to create email aliases. Here's how to do it with Outlook and how to do it on Yahoo.

Now, this is not a security panacea by any stretch. You should still be using a password manager to help you keep track of all your different passwords — and now, different email addresses. If you forget the specific email address you're using, you're even more out of luck than you are if you forget your password. If you don't even know the email address you registered with, you won't be able to even get to those security questions. I personally use 1Password, which I like because it securely stores my data in the cloud (yes, there is an irony there), but there are others like LastPass that seem generally trustworthy.

Of course, you should also still be using two-factor authentication whenever possible. And, yes, we need big companies like Apple, Google, Amazon, and all the rest to figure out better ways to secure our data and harden themselves against the kinds of social engineering and password-guessing attacks that we're now realizing are ridiculously prevalent. In the meantime, our How To on managing passwords from a couple years ago can help you make sure your end of the security bargain is being kept up.

Update: As some people have noted to me, there are some websites that won't let you use a + in your email address. It's a bummer, but the trick is still worth a shot in most cases.

Today’s Storystream

Feed refreshed 39 minutes ago Meta

N
Instagram
Nilay Patel39 minutes ago
Is the iPhone 13 Pro a sneaky good upgrade deal?

Carriers are all doing huge deals on iPhone 14 models, but if you just want to buy a phone outright, a discounted iPhone 13 Pro might be the best bang-for-the-buck around.


A
External Link
Adi RobertsonTwo hours ago
I don’t think this AI-generated game actually counts as AI-generated.

This Girl Does Not Exist promises “everything you will see in this game” is created by an AI. Except... based on everything I’ve read, that includes none of the game mechanics or interface design! It’s an interesting experiment in artificially generated images and audio, but AI-generated gameplay is a uniquely weird and difficult problem. That said, I’m fascinated by the growing move toward an aesthetics of AI — and this project sits square in that zone.


A
Alex CranzTwo hours ago
Music labels are incorporating old songs into new songs to trigger your nostalgia.

The Vergecast is doing a special miniseries for the next three Mondays on the future of music. This week I spoke with music reporter and podcaster Charlie Harding about how the future of music could sound very familiar.


A
External Link
Adi Robertson6:47 PM UTC
Rick and Morty and the high-wire act of writing antiheroes.

Countless people have discussed the travails of Rick and Morty fandom. But Corbin Smith goes beyond the simple claims that obnoxious fans are just watching the show wrong, delving into the inherent difficulty of writing a character with terrible qualities who’s still undeniably cool to watch. A bonus: he lays out the precise take on Rorschach from Watchmen that I’ve always wanted to read.


E
External Link
Elizabeth Lopatto6:47 PM UTC
My “I’m not on the run” t-shirt is raising questions answered by my t-shirt.

South Korean authorities have requested that Interpol tell international authorities to arrest Do Kwon, the co-founder of the company behind the Terra/Luna cryptocurrency debacle, The Financial Times reports. Kwon tweeted this weekend that he is not on the run, actually, and authorities are just mad that he tweeted that their size is not size. Posters gonna post, I guess.


E
External Link
Elizabeth Lopatto6:19 PM UTC
The 2010s were about lifestyle brands. What’s next?

Loved this meaty essay about trends in consumerism, what we mean by “culture,” and how DTC brands led to a new understanding of community and identity. “In the 2010s, supply chain innovation opened up lifestyle brands. In the 2020s, financial mechanism innovation is opening up the space for incentivized ideologies, networked publics, and co-owned faiths,” writes Toby Shorin. “The authenticity-driven culture of ironic detachment, so present in the early 2000s, has given way to a moment where people are genuinely open to being influenced, open to sincerely participating, even if it’s cringe.”


Life After Lifestyle

[subpixel.space]

J
The Verge
Jacob Kastrenakes6:06 PM UTC
“I still stand by that tweet.”

–Figma CEO Dylan Field, in the unenviable position of having to reflect on an old tweet.

Field tweeted last year that Figma’s goal “is to be Figma not Adobe.” Fast forward to today and... Figma is going to be part of Adobe! My colleague Jay Peters spoke with the two companies’ leaders about what the merger means for designers everywhere.


R
Richard Lawler5:56 PM UTC
Steam Deck display docks, and Deck deliveries.

Steam Deck prototypes aren’t the only thing to see at the Tokyo Game Show, as one Redditor noticed (via PC Gamer) that the still-unreleased official dock is holding up display units.

That’s also relevant because Steam Decks are being delivered more rapidly than expected. Valve just announced it’s cleared the reservations in the Q3 bucket a couple of weeks ahead of schedule and is starting in on reservations slated for Q4.


A
Twitter
Alex Cranz5:00 PM UTC
The Babylon 5 reboot is in jeopardy.

Remember Bablyon 5? Alongside Star Trek: Deep Space 9, it was one of the first television shows to embrace long-term serial storytelling...on a space station. A reboot was planned at The CW, but with Warner Bros. Discovery stepping back from The CW and Nexstar gaining majority control of CW, the reboot is now in trouble, and its creator is asking fans for help.


E
External Link
Emma Roth4:20 PM UTC
Logitech might have just confirmed Apple’s next new iPads.

A product page for Logitech’s Crayon stylus, which is compatible with the iPad, lists two unreleased devices: a 12.9-inch iPad Pro and an 11-inch iPad Pro. It also notes that the devices are “coming soon.”

Apple’s rumored to release those two iPads at an event this October, in addition to an entry-level iPad that the website didn’t mention.


M
External Link
Mary Beth Griggs3:56 PM UTC
The United Arab Emirates is shooting for the Moon with plans for a lunar rover.

The country just announced that its first lunar rover is ready to go and will launch sometime in November — the exact date is still TBD. The “Rashid” rover will ride to space on a SpaceX rocket and will be carried to the Moon’s surface by a lander from Japanese company ispace, which has been working toward a Moon mission for years.


D
External Link
David Pierce3:45 PM UTC
Even Slack thinks the green “online” status was a bad idea.

Ali Rayl, the SVP of product at Slack, thinks away messages and status indicators are a good idea. But the green circle that screams “I AM ONLINE!” isn’t the right way to do it:

I never wanted to add the green dot. I think the green dot is very harmful... If your green dot is on and you get a DM and don’t [respond] it’s like, what’s the matter?


J
The Verge
Jacob Kastrenakes2:04 PM UTC
Apple Maps turns 10.

The app was released on this day 10 years ago... and immediately became a laughingstock, leading to multiple people getting canned and a public apology from Tim Cook.

Now that Maps is a good enough product to warrant advertising, my big question is: when does Apple release a version for Android or the web? Apple made an alternative to Google Maps — now it needs to make a real competitor.


B
Barbara Krasnoff1:28 PM UTC
Fingerprint-protect your Incognito Android browsing sessions.

Got a handy tip via 9to5Google: if you want to keep an Incognito Chrome tab hidden on your Android phone, you’ll soon be able to fingerprint-protect it by going to Settings > Privacy and Security > Lock Incognito tabs when you leave Chrome. If you don’t see that setting yet, either wait or try chrome://flags/#incognito-reauthentication-for-android. I tried it myself (see below), and it works like a charm.


two screens showing chrome settings
You can fingerprint-protect Incognito tabs.