Could email aliasing services ever leak your actual email?

I don’t think this has ever happened and don’t have a reason to believe it will. I’m just thinking for high risk things, like ordering a hardware wallet, if it could be even better practice to have a genuine burner email, rather than your man email hidden by an alias?

How does the infrastructure work on the back end, and is it extremely unlikely this would ever happen?

Thinking mostly for SimpleLogin and addy io

Side question: what’s your favourite email aliasing service and why

1 Like

It absolutely can happen and has to Apple’s alias service:

Alias services like Simple Login are good for basic privacy like preventing spam/corporate surveillance. However, for anything very sensitive (like ordering a hardware wallet) I would recommend a dedicated burner account.

3 Likes

Oh shit I thought that was just the IP address it could leak, not the whole email. Thanks for the source.

1 Like

Forwardemail vanity domains are worth looking into.

If you send a password protected email in ProtonMail from a proton pass alias, Proton reveals your actual proton email to the recipient.

The recipient will receive an email from your alias in which the body says:

“You have received an encrypted email from [your actual Proton email address].”

1 Like

Holy shit I just just tested that and you’re right. Is Proton aware of this, if so for how long, and are they doing anything to fix it? That’s really bad.

1 Like