What this protects, and what it doesn't
Protects
- Breach containment: when one service leaks its user list, only that one alias is exposed, and you can disable it.
- Spotting who sold or leaked your address: mail arriving at the alias you gave one shop tells you where it came from.
- Spam control: an alias that starts receiving junk can be filtered or turned off without changing your real address.
- Account linking by email: services and data brokers cannot match your accounts on one shared address.
Does not protect
- The alias service sees your mail. Forwarding means the provider handles every message on its way to you, so you are trusting it.
- Replies can reveal your real address. Replying from your normal mailbox, or adding someone in CC or BCC, can expose the address behind the alias.
- Aliases do not hide content. Messages are still readable by the sender, the alias service and your mailbox provider; aliases are not encryption.
- Plus-addresses are easy to strip: anyone can remove the part after the + and reach your base address.
Prerequisites
- An email account you already use as your main inbox.
- Optionally, a password manager to record which alias you gave which service.
Step by step
-
Decide which accounts get an alias
Start with the services most likely to leak or sell your address: shops, newsletters, forums, loyalty cards, free trials. Keep your real address for people you know, banks and government services, where a stable address matters more.
Use one alias per service, not one alias for "all shopping". The value comes from being able to tell services apart and switch one off.
-
Option 1: plus-addressing (no setup)
Many mail providers deliver
you+shopname@example.comtoyou@example.com. Gmail documents this: anything after a+is ignored for delivery, and you can filter on it. Proton Mail also delivers plus variants of your address to your normal inbox with no setup, and Outlook.com deliversyou+sitename@outlook.comto your inbox too, though a plus-address cannot be used to sign in or to send mail.Plus-addressing is free and instant, but it only labels mail. Your real address is visible inside the alias, some sign-up forms reject the
+, and you cannot switch a single plus-address off. Use filters to send unwanted ones to the bin. -
Option 2: a forwarding alias service
A forwarding service creates random addresses that forward to your real inbox. You can disable each one separately, and the service never shows the destination address to the sender. Examples, in no particular order:
- Apple Hide My Email: unique random addresses that forward to your inbox; you can read and reply. Apple says it deletes messages from its relay after delivery, usually within seconds. Creating addresses yourself needs an iCloud+ subscription; Sign in with Apple also offers a Hide My Email address when you create an account with an app or website.
- Firefox Relay: email masks from Mozilla. Its FAQ says mail is stored only if delivery fails, for at most three days, messages over 10 MB are not forwarded, and replying through a mask is a paid feature.
- SimpleLogin: an open-source alias service based in Switzerland, with reverse aliases for replies and support for your own domain.
- addy.io: an open-source alias service; replying or sending from an alias needs a paid plan, and own-domain use is paid.
Read each service's own documentation for current limits and prices; they change. Pick one you expect to keep using, since moving hundreds of aliases later is tedious.
-
Option 3: your own domain with a catch-all
If you own a domain, you can accept mail for any address at it (a catch-all) and invent a new address at every sign-up, such as
shopname@example.org. You own the address, so you can change mail provider later without changing every account.The trade-off: a catch-all also accepts spam sent to random guesses, and if the domain lapses, someone else can register it and receive your password-reset mail. Renew it early and keep auto-renewal on. Several alias services, addy.io and SimpleLogin among them, can manage a custom domain for you, with catch-all on or off.
-
Create an alias at sign-up and record it
When a form asks for your email, create a new alias for that service (for example
alice.shop7@relay.examplefor a shop), and save it in the password manager entry for that site. Your password manager then becomes the map of which alias belongs to which account. -
Reply through the alias, not around it
If you need to answer a message, use the service's reply feature (Firefox Relay replies, SimpleLogin reverse aliases, addy.io sending from an alias), so the reply goes out from the alias. Replying straight from your real mailbox, or putting an outside address in CC or BCC, shows your real address. Firefox Relay's FAQ warns about CC and BCC specifically.
-
Switch off an alias that leaks
When an alias starts getting spam or phishing, check which service it belonged to, change that account's email (or close the account), then disable or delete the alias. If a breach notice names the service, rotate that account's password too.
Your ticks are saved in this browser only (see or delete local data).
Common mistakes
- Using one alias for every service, which brings back the single shared address you were trying to avoid.
- Using aliases for bank, tax or recovery email, then losing access when the alias service changes or you cancel it.
- Replying from your real mailbox or adding real addresses in CC, which reveals the address behind the alias.
- Letting a personal domain expire, so someone else can receive password resets for your accounts.
- Assuming an alias makes mail private: the contents are still readable by the services in between.
Going further
Pair aliases with unique passwords or passkeys per account (see Passkeys and hardware keys), and use your threat model to decide whether the alias service itself is an acceptable party to trust. For content privacy, aliases need to be combined with end-to-end encrypted messaging; see Signal hardening.