You handed a store your email for ten percent off, and three weeks later a company you have never heard of is mailing you every morning. You want to know who passed your address around. Gmail has a free feature built in that answers that question, and setting it up takes about ten seconds.
Plus addressing lets you add a plus sign and any tag to your Gmail username, like
you+netflix@gmail.com, and every variant still lands in your normal inbox. Give each signup its own tag. When spam hits one tag, you know which company leaked or sold your address. It is free and built in, and it does not hide your real address.
What is plus addressing in Gmail?
Plus addressing is a Gmail feature that treats everything between a plus sign and the @ symbol as a label the provider ignores when it delivers your mail. Your address is jane@gmail.com. You hand a shop jane+shop@gmail.com. Gmail strips the +shop, reads jane@gmail.com, and drops the message straight into your inbox. You never create a second account and you never check a second place.
The industry name for this is subaddressing, and it predates Gmail. RFC 5233, published in January 2008, defines it as “the practice of augmenting the local-part of an address with some ‘detail’ information in order to give some extra meaning to that address,” with the plus sign as the usual separator. The tag you add is arbitrary, so jane+cats, jane+2026taxes, and jane+that-one-forum all reach you the same way. Google documents the trick on its own Gmail tips page: add a plus sign and any word before the @ sign, and “messages sent to your current address or any variation with the plus sign, all arrive in your current inbox.”
Because you choose the tag, it doubles as a name badge for whoever mails you. Anything addressed to jane+shop@gmail.com came from that shop, or from someone the shop handed your address to. That is the whole trick: a free forensic trail baked into an address you already own.
How do you use plus addressing to catch who leaked your email?
Give every company its own tag, then watch which tags start receiving mail they should not. Here is the routine, start to finish.
- Pick a tag that names the sender. Use something you will recognise later:
you+netflix,you+chase,you+reddit. Keep it short and lowercase so a form does not choke on it. - Sign up with the tagged address. Type
you+netflix@gmail.cominto the registration field instead of your bare address. Everything the service sends still reaches your inbox. - Add a Gmail filter, if you want tidiness. Click Show search options in the search bar, put
you+netflix@gmail.comin the To field, then Create filter and pick a label, the same flow Gmail Help describes. Now mail from that service sorts itself. - Watch for a tag that gets the wrong mail. The day a discount-code blast or a straight-up spam message arrives addressed to
you+shop@gmail.com, you have your answer. The shop either sold your address, traded it, or leaked it in a breach. - Act on the leaker. Unsubscribe from that sender, stop trusting it with a real address, and consider whether anyone else on your list deserves the same scrutiny.
The outcome is a labelled audit trail. Over a few months you build a quiet record of which companies keep your address to themselves and which ones let it wander. If you want the numbers on why that address is worth passing around in the first place, we broke down what your email address is actually worth in a separate piece.
Which email providers support plus addressing?
Gmail is not the only provider that reads the tag and ignores it. Support varies, and two of the big consumer services are shakier than their reputations suggest.
| Provider | Plus addressing (+tag) | Notes |
|---|---|---|
| Gmail | Yes | Also ignores dots in the username. Documented by Google. |
| Fastmail | Yes, automatic | No setup needed; offers subdomain addressing as a fallback for picky forms. |
| Microsoft 365 / Exchange Online | Yes, on by default | Documented by Microsoft; an admin can switch it off org-wide. |
| Outlook.com (personal) | Inconsistent | Mail to a tag may arrive, but a + address cannot be saved as a named alias. Test first. |
| iCloud Mail | Undocumented | Apple publishes nothing on it; reports are mixed. Hide My Email is the official tool. |
A few details the table flattens. Microsoft’s Exchange Online documentation says plus addressing “is enabled by default,” and describes the fallback: when Exchange cannot resolve sean+newsletter@contoso.com to a mailbox, it tries again without the plus and tag and delivers to sean@contoso.com. Consumer Outlook.com runs on the same Exchange backend, but Microsoft’s alias rules say an alias “can only contain letters, numbers, dot (.), underscore (_) or dash/hyphen (-)”, so a tagged address will not save as a named alias in account settings, and behaviour there is worth verifying before you lean on it. Fastmail needs no configuration for either scheme: “you don’t need to set up anything extra to receive mail at plus or subdomain addresses,” per Fastmail’s help centre. Apple sits at the far end. It publishes nothing about iCloud plus addressing, some users see tags deliver and others get bounces, and its documented answer to this problem is Hide My Email, an iCloud+ feature that generates unique random addresses forwarding to your real inbox rather than tagging it.
Bottom line: if you want a reliable free tag, use Gmail or Fastmail. On Outlook.com or iCloud, mail yourself a tagged address and confirm it lands before you trust it with a signup.
What are the Gmail-specific dot and plus rules?
Gmail ignores dots as well as tags, which gives you a second free trick. According to Google’s support documentation, johnsmith@gmail.com and j.o.h.n.s.m.i.t.h@gmail.com are the same address and reach the same inbox. Sprinkling dots changes nothing about delivery.
That matters for three reasons. First, you can combine the rules: j.o.h.n+shop@gmail.com still lands in john@gmail.com. Second, the dot rule stops at consumer Gmail. Google adds a warning on the same page: “If you use Gmail through work, school, or other organization (like yourdomain.com or yourschool.edu), dots do change your address.” Third, most other providers treat dots as significant, so j.o.h.n@fastmail.com is not the same mailbox as john@fastmail.com. Do not carry the Gmail habit over to another service and assume the mail will find you.
Do some websites reject the plus sign?
Yes, and it is the most common annoyance with the whole technique. A plus sign is perfectly legal in an email address, but plenty of signup forms use lazy validation that flags it as invalid and refuses to submit. Fastmail flags this directly, noting that addresses with a + “are incorrectly considered invalid by some websites.”
You have three workarounds when a form rejects the plus. On Gmail, fall back to the dot trick and give that particular site a dotted username instead. On Fastmail, switch to subdomain addressing, which slots the tag before the domain rather than after the local part. For anything you genuinely want to keep at arm’s length, skip the tag entirely and use a real forwarding alias, which we get to below.
What plus addressing can’t do
Plus addressing is a smoke detector, not a lock. It tells you when something is wrong; it does not keep the intruder out. Four limits matter before you rely on it.
It does not hide your real address. Your base address sits in plain sight, right before the plus sign. Anyone reading jane+shop@gmail.com can see that jane@gmail.com is the real target. This is not anonymity, and treating it as such will burn you.
A determined seller can strip the tag. Because the base address is recoverable, a list broker who wants a clean file can delete everything from the + to the @ and sell jane@gmail.com on its own. So the very spam you were hoping to trace sometimes arrives at your bare address instead, with the tag already scrubbed off. US law draws one line here, though it only bites after you act: the FTC’s CAN-SPAM compliance guide says that once people have told a sender they want no more messages, the sender “can’t sell or transfer their email addresses, even in the form of a mailing list.”
It is receive-only. Microsoft states it outright for Exchange Online: users “cannot send emails from plus addresses.” Treat a tag as a label on incoming mail and nothing more.
It does not reduce your mail. Every tagged variant still pours into your one inbox. The tag labels the flood; it does not slow it. You keep getting a sender’s mail until you unsubscribe, no matter how clever the tag was. That is the same wall masked forwarding aliases run into, and the reason a tag alone never quiets an inbox.
Plus addressing vs aliases vs burner emails: which should you use?
Think of these as three tiers of the same idea, compartmentalising your identity so one leak does not spill onto everything else.
Plus addressing is the free built-in tier. It costs nothing, needs no new account, and gives you a diagnostic trail. Use it to label signups and catch leakers. Its weakness is that it hides nothing and stops nothing.
Forwarding aliases are the concealment tier. A masked email alias is a separate randomly generated address that forwards to your inbox and never reveals your real one. When a sender turns spammy, you switch the alias off and the mail dies at the relay. That is a real off switch a plus tag cannot offer.
Burner addresses are the throwaway tier. A burner email is a disposable inbox for a one-time download or a sketchy signup you never want to hear from again. You use it once and abandon it.
Start with plus addressing because it is free and instant. Reach for a forwarding alias when you want to actually cut a sender off, and a burner when you never wanted the relationship in the first place.
What to do once you know who leaked your address
Finding the leaker is step one; getting off the list is step two, and plus addressing does not do the second part. The tag tells you a company sold or lost your address. It does nothing to stop that company, or the dozen it sold you to, from mailing you tomorrow. For that you have to unsubscribe for real, from every sender already sitting in your inbox before you ever started tagging.
Doing that by hand across years of accumulated senders is slow, and some footer links carry their own risk. Email Unsubscriber scans your Gmail or Outlook in your own browser, lists every subscription sender, and fires the real one-click opt-out wherever the sender supports it. The scan runs on your device, and we never read, analyze, or monetize your email content. There is one payment and nothing to cancel afterward. If your inbox is already buried, start by mass-unsubscribing from the senders flooding you now, then let plus tags flag any new leaker that shows up.
Use the two together and your inbox stays quiet for two reasons at once: you can see exactly who betrays your address, and the senders already on your list have been told to stop. A plus tag is the alarm. Unsubscribing is what actually turns the noise off.
