The + trick is useless to protect you, obviously. Instead, use a a service like simplelogin to create unique emails for every place you sign in.

Correct, but you get to see who leaked you.

Depends if the criminals are smart enough to strip the +.. part when sending you phishing.