A · Identity core
Banks, government services, primary devices, and password managers.
Rule: Use a dedicated long-term address; enforce 2FA; never share it with shopping services.
Alias Zone Playbook
It’s not about creating a handful of extra addresses. Each address should have a clear purpose, a predictable lifespan, and its own breach switch.
Account segmentation canvas
Banks, government services, primary devices, and password managers.
Rule: Use a dedicated long-term address; enforce 2FA; never share it with shopping services.
Clients, collaboration tools, portfolio platforms, and professional networks.
Rule: Separate by organization or role; hand over access when leaving or when a project ends.
Shopping, travel, subscriptions, warranties, and ticketing.
Rule: Use a separate alias for each merchant; keep it until refunds and warranty claims are complete.
Forums, events, downloads, and one-time verification.
Rule: Start with a temporary email; upgrade to an alias only after confirming the service’s long-term value.
Naming decision tree
Prefer a service abbreviation or category, such as shop.north or travel.rail. Never use your name, birthday, phone number, or address.
Add a stable purpose suffix, such as vendor.billing and vendor.team. Don’t rely on random numbers to tell you which address belongs to which account.
Keep public portfolio pages separate from private login addresses. A public contact alias should be replaceable on its own and must not serve as the username for an identity-core account.
Rotation timeline
Log spam samples, unusual login alerts, or breach notices, then identify the affected alias and linked services.
Create a new alias and update the target account first. Verify that the new address receives security notifications.
Keep the old address active briefly while you wait for all orders, refunds, or account changes to be confirmed.
Pause the old alias and record the date. Delete it only after legitimate messages stop, keeping an incident note rather than the email body.
Change the target account email → Change the password → Revoke unfamiliar sessions → Check 2FA → Verify the new alias → Pause the old alias → Record the source and date.
Quarterly maintenance
Delete entry points for canceled services with no pending refund, warranty, or account-recovery needs. Unlink the alias from the target site first.
If the same alias is used for both financial services and shopping, migrate the higher-risk account to the identity-core segment.
Confirm that your real inbox, alias forwarding, and authenticator are all accessible, then update your offline recovery records.