I just go with full domain names. Like [email protected]. Even combos where data is shared, like [email protected] or [email protected]. But some places actually went out of their way to disallow their own domains anywhere in the field. I've encountered it maybe like 3 times across all of ~1000 logins I have in my password manager.
And the amount of times I had to explain to people that yes, this is a legit email, yes it has your company's name and your personal name in it, it is exactly as intended, so don't send me spam because I will know it was you who sent it...
I have all my admin/mail/webmaster/etc blacklisted a long time ago because those are the that get spam first when spammers parse lists of registered domains.
I wonder if abuse@'s get any spam...