Guides
How to find out who leaked your address
If every service has the same address, the answer is that you cannot. This is not solved by investigating afterwards — it is solved by how the addresses were arranged beforehand.
Where you are
You are probably running into these
Suddenly you are getting one industry’s marketing
The content clearly relates to a category of service you signed up for — but you signed up with several, and cannot tell which.
Phishing arrives impersonating a platform you use
The sender knows which service you use, which means the address leaked alongside that association.
You want to raise it, but have no evidence
You suspect one company, but the same address has been used in dozens of places and nothing points at any of them specifically.
Mechanism
Why one shared address makes this untraceable
Tracing a leak is fundamentally a labelling problem. Hand the same string to a hundred services, and when that string turns up on a spam list all hundred are suspects with no way to narrow it down — mail headers show you who sent it, never where the address originally escaped. Invert it: if every service receives an address used nowhere else, the address itself is the label. The day an unfamiliar sender writes to shop.pine.4417@, an address you used at exactly one store, the conclusion is unique and needs no technical work to reach. This is where aliases differ from filters at the root. A filter decides whether a message belongs in your inbox; an alias answers how the message found you at all. One is cleanup, the other is attribution. And once you know, you can switch off that single address — what the leaker holds is void immediately, while the other ninety-nine services are untouched.
What to do
Step by step
- 01
Give every service its own alias
Register with an address that exists for that one service. Put enough hint in the name to recognise it yourself, without a predictable pattern.
- 02
Forward them all to the inbox you use
Nothing changes about how you read mail. You stay in the same place, and every message now carries the entrance it came through.
- 03
On anything suspicious, read the To: line first
Which alias it was addressed to tells you where the address escaped. No tooling required for this step.
- 04
Once you know, switch that one off
The address in their hands dies immediately and no other service is affected. Issue that company a fresh one if you still want the account.
Watch out
Easy things to miss
Avoid predictable naming
amazon@ and netflix@ are too easy to extrapolate from — anyone can guess your address elsewhere. Include a random component.
A leak is not always deliberate
It may be a breach, or data sold to a partner. The alias tells you where the address escaped, not why.
Doing this later does not work backwards
Aliases only label signups made from now on. Anything already registered with your real address stays untraceable. Earlier is better.
FAQ
Questions about this case
Can mail headers reveal who leaked the address?
No. Headers show who sent the message and which servers it passed through, but carry nothing about where the sender obtained the address. That chain lives outside the mail system.
Should the alias name include the service?
A hint helps you recognise it, but add randomness. Naming purely after the service means anyone holding one address can guess the others.
What can I do once I know?
Most directly, switch that alias off and what they hold becomes void. If you want to pursue it, you also have specific evidence — considerably stronger than “I suspect it was you”.
Is one alias per service a management burden?
Creating one takes seconds, and since they all forward to the same inbox your daily habits do not change. The only thing to track is which alias belongs to which service — settled at naming time.
The features this case uses
Other situations
Start with one address
Free users can take a disposable address with no signup and no phone number. Long-lived aliases and custom domains are for the accounts you intend to keep.

