Why I Give Every Company a Different Email Address

Sep 02, 2026By Jay Kells
Jay Kells

Why I Give Every Company a Different Email Address

I used to have one email address for everything: my bank, a clothing website I bought from once, a newsletter I signed up for out of curiosity, my actual personal correspondence, all sitting behind the same address for over a decade. That single address became the one thing every company, every marketer, and eventually every scammer trying to reach me all had in common. This isn't a general list of email security tips. It's the specific habit that's actually changed how much junk and risk reaches my inbox, and it started with something far simpler than switching providers or overhauling my whole setup.

The Trick Is Just Adding a Tag to My Own Address

Most email providers support what's called plus-addressing without anyone ever pointing it out, and I only discovered it by accident. Any address like mine can add a tag after a plus sign before the @ symbol, so [email protected] can become [email protected], and it still lands in exactly the same inbox as if I'd typed my normal address. I don't need a different account for each company. I need one extra habit at the point I type my email into a sign-up form, and mail still arrives at the one place I actually check.

How This Actually Caught the Company That Leaked My Address

The reason I stuck with this habit is that it did exactly what I hoped it would within the first year. I started getting spam addressed to jay+onlinestore, one specific tag I'd only ever given to one retailer, which meant I knew precisely which company had either sold my details on or been breached without ever telling me. A shared address gives you no way to trace that back. A tagged one hands you the answer the moment junk mail starts arriving with that exact tag attached, and I stopped giving that retailer any more of my information the same day. It's also the account I've written about separately for why it gets more protection than any other login I own, since none of this tracing matters if the inbox itself isn't secure to begin with.

Why I Don't Reuse the Same Address for Sign-Ups I Don't Trust Yet

Now, any site I'm not fully confident in, a one-off purchase, a forum I'm trying out, a free tool that wants an email before I've even seen what it does, gets its own tag rather than my plain address. I keep track of which tag belongs to which site inside my password manager, the same one I use for everything else, since it already has a note field sitting right next to the login itself. If a specific tag starts getting spam or turns up in a breach notification, I know exactly where it came from and I can block that tag entirely without touching the inbox everything else relies on.

Checking a Tagged Address Against the Same Habit I Use for Everything Else

Tracing a leak after the fact is useful, but I'd rather catch it earlier where I can. I run the same account check-in I've written about separately across every tagged address I've created, not just my main one, since a breach tracker doesn't care whether the address it's checking has a plus sign in it or not. It takes a few extra minutes to paste in a handful of tags instead of one address, and it's caught exposure on a tagged account before the spam itself ever showed up.

The Attachments and Links I Still Won't Open, Aliased Address or Not

None of this replaces basic caution about what actually lands in that inbox once mail arrives. I still don't open an attachment I wasn't expecting, even one that looks like it's from a company I recognise, since a spoofed sender name costs a scammer nothing to fake. I hover over any link before clicking to see where it actually leads rather than trusting the text it displays, and I check the sender's actual domain rather than just the display name, since "Amazon" as a name means nothing if the address behind it clearly isn't. Aliasing tells me where a message should have come from. It's still up to me to check whether it actually did.

Hands organizing color-coded scheduling notes on wooden desk with natural window light

Unsubscribing Isn't Always Safe, So I Block Instead

The other habit that changed once I started paying attention is what I do with unwanted mail itself. Clicking "unsubscribe" on a genuine newsletter is fine, but doing the same on a message I'm not sure is legitimate can confirm to whoever sent it that my address is real and actively read, which is worth more to a spammer than the one email it stops. I block and report messages I don't recognise rather than unsubscribing from them, and I only use the unsubscribe link on senders I actually remember signing up with in the first place.

None of this took a weekend or a new piece of software, just one small habit added at the point I hand my email address over to anyone new. My free Safety Toolkit covers the account-level basics that sit alongside this, and the NCSC has its own guidance on staying safe from phishing if you want to check your wider email habits against it. Giving every company its own version of my address turned my inbox from something I reacted to into something I could actually trace.