Nina ordered one bag of dog food in April. She used the address she uses for everything, because that is what everyone does. In August the spam started: crypto offers, a fake delivery notice, a vet clinic three states away. She had eighty accounts tied to that one address and no way to tell which of them had sold her out. So she deleted the messages and hoped it would stop. Nobody had ever told her that you can salt your email address and make the next batch of spam name its own source.
It did not. But there is a way to know next time. If you salt your email address before you hand it over, every message sent to that variant carries a label naming the site that received it. In short, the spam tells on whoever leaked it. This guide covers the method in Gmail and Outlook, how to read the result, and the point where the trick stops working.
What “salting” an address actually means
To salt your email address, you add a tag to the version you give out, so the mail still reaches you while the tag rides along. You hand nina+dogfood@gmail.com to the pet store. Mail to that variant lands in your normal inbox, and the tag stays visible on every message.
Then the tag does the work. If a crypto pitch arrives addressed to nina+dogfood, only one company ever held that string. That is the whole trick, and it is free.
One note before you start, because the word is overloaded. Spammers use “salting” for something else entirely — hidden characters stuffed into a subject line to confuse a filter. We wrote about that meaning separately. This page is about the reader-side version, where the salt is yours.
How to salt your email address in Gmail
Gmail ignores everything between a plus sign and the @ when it routes a message. So nina+dogfood@gmail.com and nina+bank@gmail.com both land in nina@gmail.com. Google documents the plus-sign variation in its own Gmail tips, and the same page notes that Gmail also ignores dots in an address.
Three rules make it useful rather than clever:
- Use the company’s name as the tag.
+dogfoodtells you nothing in a year.+chewydoes. - Use a fresh tag per site, not per category. The point is to isolate one leaker.
- Write it down, or at least keep the pattern predictable, because you will forget.
That is it. No app, no setting to change, no account to create.
Outlook, iCloud, and everything else
Outlook.com accepts the same plus suffix. But Microsoft also lets you add a real alias to your account, and an alias is stronger than a tag because you can switch it off. When a retailer leaks an alias, you delete the alias and the mail stops.
iCloud Mail accepts a plus suffix too, and Apple’s iCloud+ Hide My Email goes further by generating a separate address per site. If your provider is none of these, test it in ten seconds: send yourself a message at you+test@yourdomain and see whether it arrives.
Read the To: line, because that is where the answer is
Most people never look at the To: field of a spam message, so the evidence sits there unread. In Gmail, open the message and click the small arrow under the sender’s name to show details. On mobile, tap the recipient line. The tag you invented will be sitting there.
Now you know three things you did not know before. You know which company held the address, so you know whose privacy policy to stop believing. You know roughly when, because you know when you signed up. And you know the address is circulating, which means more will come.
What you do next is a judgment call. Unsubscribing from a list you never joined confirms a live human reads that address, so it is not the automatic move people assume — we ranked the options honestly in how to stop spam emails. If the same tag also turns up in a breach notice, the sequence that follows is predictable and worth reading.
Where salting your email address breaks, and what to use instead
Be clear about the limits, because three of them are real.
Some signup forms reject a plus sign outright, so you cannot always salt your email address at the moment you need to. Some senders strip the tag before storing it. And a list buyer can strip it too — deleting +chewy is one line of code, and anyone reselling addresses has every reason to run it.
So salting is forensics, not a lock. It names the leaker after the fact and does nothing to slow the mail. Per-site aliases hold up better, because each one is a distinct address you can switch off: SimpleLogin, Firefox Relay and DuckDuckGo Email Protection all work this way, as does Apple’s Hide My Email.
The reason people salt, and the thing that makes it unnecessary
Every one of these tactics answers the same question: which stranger got my address, and how do I get out from under the consequence? That question only exists because a personal inbox accepts mail from anyone who learns the address. Salting is a clever response to a default nobody chose.
OptMsg starts from the other end. Its patent-pending opt-in technology turns the default around: only people you approve can reach your inbox, and everyone else goes to Trash, where the app deletes it after 30 days. OptMsg does not scan your emails to sell ads, and there is no password on the account, so a login leaked by some other company is not the login to your mail. You can read the longer version of that argument on Private Always.
Salting tells you who leaked your address. An opt-in inbox makes the answer stop mattering, because the leak no longer buys anyone a way in. If you would rather not run forensics on your own mail for the next ten years, start an account and pick the senders yourself.
Create Your Account — Your Inbox. Your Rules.
Frequently asked questions
Does it cost anything to salt your email address, or need an app? No. Plus-addressing is built into Gmail, Outlook.com and iCloud Mail. You invent the tag at the moment you type the address, and nothing needs installing or configuring.
Will a site let me sign up with a plus sign in my address? Usually, but not always. Some signup forms and some older checkout systems reject the character. When one does, use a per-site alias service instead, or a dot variation if your provider ignores dots.
Can a spammer remove the tag I added? Yes. Stripping the part after the plus sign is trivial, and a company buying and reselling lists has a clear motive to do it. That is why salting is best treated as a way to identify a leaker, not as a way to stop mail.
How do I see which tag a spam message was sent to? Open the message and look at the To: line. In Gmail, click the arrow beneath the sender’s name to expand the details; on phones, tap the recipient row. The tag you created will be in the address.
What is the difference between this and the “salting” spammers do? They are unrelated. Spammers insert invisible characters into subject lines and message bodies to slip past filters. Reader-side salting is a tag you add to your own address to trace who shares it.
Sources
- Google, Tips to optimize your Gmail inbox — plus-sign address variations: https://support.google.com/a/users/answer/9308648
- Gmail Help, Dots don’t matter in Gmail addresses: https://support.google.com/mail/answer/7436150
- Microsoft Support, How to add an email address to your Microsoft account (Outlook.com aliases): https://support.microsoft.com/en-us/office/create-an-email-alias-in-outlook-com-459b1989-356d-40fa-a689-8f285b13f1f2
- SimpleLogin — per-site email aliases: https://simplelogin.io/
- Firefox Relay — per-site email masks: https://relay.firefox.com/
- DuckDuckGo Email Protection: https://duckduckgo.com/email/
Previous in Privacy Guides: OptMsg Release Notes v1.1.3
Next in Privacy Guides: Is Unroll.me Safe? What Free Inbox Cleaners Do With Your Mail