# Recommended Temporary Email Service?

**URL:** https://discuss.privacyguides.net/t/recommended-temporary-email-service/20561
**Category:** Questions
**Created:** 2024-09-02T21:10:47Z
**Posts:** 71

## Post 1 by @Lion78 — 2024-01-25T11:27:58Z

Hi forum!

What will you recommend using constant alias service or temporary alias service?

I wonder what is best practice:

1. Using tools like SimpleLogin (needs account, limited aliases for free)
2. Or using temporary aliases like [this](https://www.shitmail.org) or [this](https://altmails.com) (infinite aliases, address will be deleted after short period of time)\*\*

\*\*I also know `temp-mail.io/en/forwarding` and `instancemail.com` but they don’t look trustworthy

If first variant, why? What best service _you_ had used and can recommend?

- DuckDuckGo email aliases (free infinite aliases, tracking protection, free send feature (up to 20 mails per day), trustworthy)
- SimpleLogin (only 10 free aliases, no tracking protection, free reply feature, trustworthy)
- Anonaddy (free 20 general aliases, infinite username based aliases, no tracking protection, no free send/reply feature, trustworthy)
- `burnermail.io`
- DNT Blur

---

## Post 2 by @user1 — 2024-01-25T12:05:48Z

> **[Encrypted Private Email Recommendations - Privacy Guides](https://www.privacyguides.org/en/email/#email-aliasing-services)**
>
> These email providers offer a great place to store your emails securely, and many offer interoperable OpenPGP encryption with other providers.

---

## Post 3 by @landordragen — 2024-01-25T12:06:30Z

I only use a temporary email for things that I’m absolutely positive that I will never need again.

Aliases for everything else except government and health entities.

I’ve used DDG E-mail Protection and it works fine.  
Now I’m using SL because it’s included on my Proton subscription.

---

## Post 4 by @Satoshi — 2024-01-25T12:21:06Z

> [@Lion78](#):
>
> SimpleLogin (only 10 free aliases, no tracking protection, free reply feature, trustworthy)

Basically what @user1 and @landordragen said.

- Email alias or actual email for governments and institutions (e.g. [myalias@proton.me](mailto:myalias@proton.me) being an alias of [myemail@proton.me](mailto:myemail@proton.me))
- Aliasing service for general sites and apps to prevent spam (e.g. SL)
- Disposable emails when an email is needed only once and not for a permanent account (e.g. temp mail )
- Free and easy to create email providers that don’t ask any questions for any anonymous accounts (e.g. cock.li or [cyberfear.com](http://cyberfear.com))

---

## Post 5 by @exaCORE — 2024-01-25T12:34:16Z

> [@Satoshi](#):
>
> (e.g. cock.li or [cyberfear.com](http://cyberfear.com))

These are not recommended providers and have numerous issues starting with that they apparently cater to racists, fascists, and other bigoted groups. See here for more info: [Cock.li safe?](https://discuss.privacyguides.net/t/cock-li-safe/16408)

---

## Post 6 by @Satoshi — 2024-01-25T12:59:58Z

I don’t subscribe to your ideology, which seems to be more liberal, so I don’t view it as an issue. If you take issue with the providers, don’t use them. It’s as simple as that.

---

## Post 7 by @menacingbreadstick — 2024-09-02T21:10:47Z

I am currently looking into more private versions of say, emailnator or tempmail. I am aware of simplelogin and anonaddy and so on but sometimes you don’t want any emails beyond the confirmation and you dont want anything in your main email’s inbox

---

## Post 8 by @Snowmanonahoe — 2024-09-02T23:59:27Z

Use our recommended aliasing providers and delete them when you’re done. You can do this for free indefinitely on either of them.

---

## Post 9 by @Zenaida.macroura — 2024-09-03T01:04:26Z

AdGuard, who’ve been recommended in several sections of the Privacy Guides website, released [AdGuard Temp Mail](https://adguard.com/en/adguard-temp-mail/overview.html) not too long ago.

---

## Post 10 by @Shampoo — 2024-09-03T02:33:54Z

> [@menacingbreadstick](#):
>
> you dont want anything in your main email’s inbox

You could always set up a filter that directs them into a different folder. If it’s for some type of account or purchase you might want to make sure you still get the emails in case they have some kind of breach or your account has suspicious activity.

---

## Post 11 by @gitayam — 2024-09-03T03:43:52Z

Today I learned

---

## Post 12 by @Focus — 2024-09-03T12:11:37Z

Service like Tempmail without Account: [https://mailhole.de/](https://mailhole.de/)  
It’s a less known free open source service operated on donations by [adminforge.de](http://adminforge.de)  
Because it’s less used, you don\*t get blocked.  
Worked for me

But an E-mail Alias may make more sense in the long term. Maybe you want to really own that Account you create and you need the mail for the verification link for. With an temp mail, anyone can take over your account.

---

## Post 13 by @menacingbreadstick — 2024-09-05T07:34:16Z

This and the Adguard suggestion are very good, thanks for the advice.

---

## Post 14 by @anon29849 — 2025-08-22T16:33:37Z

What are best services to register to various platforms, nothing more, just confirmation mail, if it matters in any way?

I found protonmail isnt really private as it suggests, they dont allow anon registration in onion site, in clearweb if i manage to do that, they dont allow registration to any service with their mail, even their own proton services (block after 1st time)

tutanota dont let to register from tor

alias services not always work or they dont allow to register with their domains

are there better services to do that?

---

## Post 15 by @anon57862721 — 2025-08-22T16:51:48Z

For free? DuckDuckGo’s service that you can manage with @Omar’s Qwacky.

> [@anon29849](#):
>
> I found protonmail isnt really private as it suggests, they dont allow anon registration in onion site, in clearweb if i manage to do that, they dont allow registration to any service with their mail, even their own proton services (block after 1st time)

Not sure why or what you exactly experienced here but Proton’s service (with Proton pass) or with Simplelogin is fantastic. That’s what I recommend if you want to go with a paid option.

> [@anon29849](#):
>
> tutanota dont let to register from tor

This should not be the case. Anonymous registration is always possible with Tuta and Proton.

[addy.io](http://addy.io) is another option. AdGuard also has a new service along with IVPN (if you atleast buy 1 year Pro plan but this is in beta right now, albeit audited as far as I can recall).

---

## Post 16 by @anon29849 — 2025-08-22T17:00:19Z

> [@anon57862721](#):
>
> Not sure why or what you exactly experienced here but Proton’s service (with Proton pass) or with Simplelogin is fantastic. That’s what I recommend if you want to go with a paid option

when i try to register by their onion site, it says too many requests to check username or sth like that - its always like that, just impossible to register without mail on onion, on clearweb its possible to register without mail but after registration to any third service they just block it, every time i try. Ofc i need to turn off ublock bcs its impossible to input username with it on.

> [@anon57862721](#):
>
> This should not be the case. Anonymous registration is always possible with Tuta and Proton.

Im just telling what i experienced, maybe its bcs they had problems with other users from that ip’s

anyway im looking for free options, i found something working, but with a lot of trackers and on blockchain so im looking for alternatives

---

## Post 17 by @anon29849 — 2025-08-22T17:01:34Z

> [@anon57862721](#):
>
> [addy.io](http://addy.io) is another option. AdGuard also has a new service along with IVPN (if you atleast buy 1 year Pro plan but this is in beta right now, albeit audited as far as I can recall).

tried that but at least with that service i used, mails didnt arrived

---

## Post 18 by @anon29849 — 2025-08-22T17:22:09Z

on cock.li on other hand i get “thats a lot of accounts”

---

## Post 19 by @anon11657877 — 2025-08-22T18:55:20Z

There’s [this service](https://pissmail.com/) if you don’t mind the offensive domains.

---

## Post 20 by @iluvprivacy — 2025-08-22T19:01:01Z

Not sure what happened, but I got an email from Simplelogin warning me that I was “abusing” their terms when I created multiple Apple and Google accounts. I only created multiple accounts for different uses. Even then, how many is too many? The email said they’ll suspend me if I do this again. I don’t know what I’m paying for then.

---

## Post 21 by @anon57862721 — 2025-08-22T19:06:08Z

Well, if you are not abiding by their terms of service, then they can. But it’s unwise to create multiple Apple or Google accounts anyway especially with aliases because these companies are very good at curtailing such behavior and would indeed categorize as abuse no matter. You can use other aliasing services if you really want to though.

---

## Post 22 by @anon57862721 — 2025-08-22T19:06:45Z

There’s also @lanedirt’s AliasVault, FYI. Check it out, it’s actively being developed and works well for what it is in beta right now.

---

## Post 23 by @anon11657877 — 2025-08-22T20:16:07Z

If you want to go the “temporary” disposable route (not recommended)

- [https://tmail.link/](https://tmail.link/)
- [https://anonbox.net/en/](https://anonbox.net/en/)
- [https://guerrillamail.com/](https://guerrillamail.com/)

---

## Post 24 by @iluvprivacy — 2025-08-22T22:16:07Z

They don’t even tell me what the number is. I created 3 accounts each and got the warning. Isn’t that the whole point of these alias services? If not, what’s a better service for creating Apple and Google accounts? They can’t assume I’m up to no good just because I want to have multiple Apple accounts.

---

## Post 25 by @anon57862721 — 2025-08-22T22:28:42Z

Creating multiple accounts is a red flag indeed whether you’re up to no good or not. They would be in the right here if they’re abiding by their terms of service policy.

Also, no - the point of aliases is to have different aliases for different accounts and not multiple for the same type of account.

But you may also be doing something else to trigger these many issues at this level. I don’t know what that is so I’ll stop commenting on this.

Good luck to you.

---

## Post 26 by @iluvprivacy — 2025-08-22T22:35:43Z

If I shouldn’t be using alias for this, then which service is recommended? Should I use an actual email say from Proton instead of an alias? What should one do if they want multiple Apple/Google accounts?

No, the email was clear in what I did that got the warning. It wasn’t a generic email.

---

## Post 27 by @arise1984 — 2025-08-23T04:06:28Z

Yep sl and addy have strict and sensitive detection to prevent abuse so incoming reg mail from the same provider back to back will trigger their abuse mail warning you not to do that.

Ddg [duck.com](http://duck.com) and another one, erine.eu doesn’t have strict tos forbidding multiple accounts creation on the same service. They still do have tos forbidding general abuse though so creating something like 100 accounts per day on the same provider like proper spammer would still get you in trouble, still got to use common sense there.

---

## Post 28 by @iluvprivacy — 2025-08-23T06:08:37Z

Bro, I only did 3 per provider.

---

## Post 29 by @PurpleDime — 2025-08-23T06:37:48Z

> [@iluvprivacy](#):
>
> Not sure what happened, but I got an email from Simplelogin warning me that I was “abusing” their terms when I created multiple Apple and Google accounts.

Most people do not know that **Proton (Proton Pass & Simple Login), only allow ONE alias per third party website. It is against their ToS to create more than one alias for the same website.**

It’s a terrible rule that I’ve talked about [here](https://discuss.privacyguides.net/t/anonaddy-vs-simplelogin/13162/38), [here](https://discuss.privacyguides.net/t/anonaddy-vs-simplelogin/13162/41), and [here](https://discuss.privacyguides.net/t/how-do-you-use-aliases-with-substack-do-you-use-multiple-aliases-or-just-one/27876).

It is essential for privacy to be able to have multiple accounts with the same website to compartmentalize your life. But Proton is against it, and on top of that they pretend they are not in their marketing.

That’s why it’s better to go with [Addy.io](http://Addy.io) who allow you to create multiple aliases for the same website.

---

## Post 30 by @iluvprivacy — 2025-08-23T07:08:29Z

I had no idea! Does that ever reset? Say I disable the alias and then delete it. Can I create a new one afterwards or it’s once per life of the account? I can’t afford to make a mistake because I don’t want my Proton account shut down. I got emails and everything.

---

## Post 31 by @iluvprivacy — 2025-08-23T07:15:24Z

Interesting you got a warning after using 3 alias per site. Just like me. Is the next warning an account shut down?

---

## Post 32 by @anon57862721 — 2025-08-23T07:26:31Z

Instead of wondering and continueing to worry, why do you want to risk continue doing what you’re doing? Try [addy.io](http://addy.io) and other options mentioned and see what works.

---

## Post 33 by @iluvprivacy — 2025-08-23T07:28:44Z

I stopped after the warning. Obviously I’ll have to use another service because I don’t want to lose my Proton account. This is now one of my most important accounts and I’m paying for it. They don’t care though. They sure sound like they’ll shut down my account if they have to.

---

## Post 34 by @anonymous409 — 2025-08-23T07:39:41Z

Sadly, that IS the case.

Anonymous registration for Tuta was never possible in the first place. Not only do they block Tor exit nodes, but also VPNs and many residential IPs(including mine). Just to make it clear, I have never created any Tuta accounts before using my fixed residential IP

Although Proton, in some cases, do allow Tor/VPN IP addresses for registration, signing up on their onion address is not possible. Only their clearnet address is open for registration, which often requires SMS or email verification.

---

## Post 35 by @anon57862721 — 2025-08-23T07:44:15Z

There are ways to bypass this hurdle though. Using other “anonymously” made email addresses can be used to get your Tuta or Proton account verified.

But its been a year or so since I created a new account with them so not sure if anything has changed.

---

## Post 36 by @anonymous409 — 2025-08-23T07:54:21Z

I believe that is not a good idea.

IP addresses are one of, if not the most, critical information used for identifying an individual. And using a secondary burner email (like smailpro, tempmail, etc) does not solve the problem. Tuta completely blocks account registration based on the IP address, so whether or not you’re willing to give your phone number, gmail account, or anything else, you still wouldn’t be able to sign up.

Proton is a little more generous on this. They allow registration when verified with emails or SMS. But that poses another problem; How do you make an “other anonymously made email”? And it is clear that the more data you give, the more you are likely to be unique and identified.

Any sign up procedures other than those made through the tor network (preferrably, onion address) without requiring any SMS/email verifications, should not be considered anonymous

---

## Post 37 by @anon57862721 — 2025-08-23T07:59:48Z

> [@anonymous409](#):
>
> And using a secondary burner email (like smailpro, tempmail, etc) does not solve the problem.

I never claimed this is the only way to make other email accounts privately. You can always sign up with other privacy forward email service providers.

And changing your IP or using obfuscation in Mullvad or IVPN could also help between system reboots.

My comment about being able to still bypass stands.

---

## Post 38 by @SwampTrainer — 2025-08-23T08:20:34Z

Did you not read the Tuta signup message asking you to confirm you don’t have another account?

If you’re doing this all at the same time from the same IP than it’s very obvious to them you’re violating their TOS. Tuta has also dinged me for starting an account and using it to register for a new site immediately, so Tuta seems to know more about what you do than they like to say.

---

## Post 39 by @anon57862721 — 2025-08-23T08:23:10Z

> [@SwampTrainer](#):
>
> so Tuta seems to know more about what you do than they like to say.

Inferring something is not exactly “knowing” it with certainty. They try to fight spam and other things with probability, not with invading privacy as you’re implying or with any certainty.

You have worded your comment to reflect @Tuta_Official negatively which is unwarranted.

---

## Post 40 by @SwampTrainer — 2025-08-23T08:36:57Z

Of course, but the evidence of even an automated internal system that needs me to wait a few days before I use their service for a specific thing is clear when they locked the account and told me that was why. When their own website says:

> Tuta automatically encrypts all your data end-to-end, even email headers and metadata such as subject lines so that your personal and business emails stay private.

Then when a user is told “hey, what you’re doing looks like spammer behavior,” and I’m not a bot or a spammer, then it’s a bit creepy. I’m happy to hear @Tuta_official explain the technical side of how they can manage a tough balance.

I don’t blame them at all for doing that at all - I would do the same. I meant only that for OP’s purpose, they should leave poor Tuta alone.

---

## Post 41 by @anonymous409 — 2025-08-23T08:44:44Z

> [@anon57862721](#):
>
> I never claimed this is the only way to make other email accounts privately

Neither did I.

It seems that you’re currently missing the point. It is not about privacy, or whether the email service provider is trustworthy. It’s about technically valid anonymity.

Your comment on bypassing the sign up restriction only works for Proton. As I’ve said, Tuta does not allow ANY registrations on Tor, VPN, and even some residential IPs for reasons I do not fully understand (they claim it for the prevention of abuse, but then why block normal residential IPs?). It doesn’t matter whether you have any secondary privacy-friendly email providers. They just don’t allow you to register.

Changing the exit IP address of the VPN might temporarily solve the issue if the IP block is based on a blacklist. But as you know, VPNs are far from being anonymous. And obfuscation has nothing to do with either privacy and/or anonymity. It’s just a way to bypass to VPN restriction on heavily censored locations to connect to the VPN.

---

## Post 42 by @iluvprivacy — 2025-08-23T09:30:02Z

I wasn’t even talking about Tuta.

---

## Post 43 by @Catalyst2422 — 2025-08-23T09:53:53Z

Could you find somewhere with free public Wi-Fi to sign up?

This site is also quite useful for avoiding spam filters when signing up. It gives temporary gmail addresses by using plus and dot addressing. I find that not many sites are wise to dot and plus addressing.

> **[Disposable Gmail | Temp Mail](https://www.emailnator.com/)**
>
> The most advanced temporary email service on the web to keep spam out of your mail and stay safe. It offers you to use a real Gmail email address.

---

## Post 44 by @PurpleDime — 2025-08-23T14:19:14Z

> [@iluvprivacy](#):
>
> I had no idea! Does that ever reset? Say I disable the alias and then delete it. Can I create a new one afterwards or it’s once per life of the account? I can’t afford to make a mistake because I don’t want my Proton account shut down. I got emails and everything.

_ **Yes, but there’s a BUT** _

You can always delete an alias for a specific website and replace it with another. The problem that Proton doesn’t seem to appreciate is that a lot of times, when you update your email address for a certain website, your current address needs to be working until the new one is added and verified.

For many websites, if you update your email address, they will send you a confirmation code via email to your _current_ address, not your new one. Some will send to both.

That means that for many websites, if you try to update your email, but you don’t have access to your current address, you will never be able to update your email, even if you still have access to your online account.

_ **Real life example: Filen** _

This is exactly what could have happened to me with Filen. Filen is an E2EE cloud service for which I have an account. With my Filen account, I used an email address from Skiff. Skiff was an E2EE email provider that was supposed to compete with Tuta and Proton Mail, but they shut down after they got bought by Notion. When Skiff announced their shut-down, they told their users that they had 6 months to get their affairs in order before losing all their data.

As I explained, my Filen account was linked to a Skiff email address. If had tried to update my Filen email after Skiff shut down, I would have never been able to do so, because Filen doesn’t send the verification to the new email address but to the current one. I would still have been able to log into my Filen account, but updating my email would have been impossible.

_ **We need to make noise so Proton understands** _

The fact that Proton doesn’t appreciate situations like this is why it’s so disappointing. I’ve been saying for a while now that I will write a proper post about the problems with this rule, but I’ve been so distracted with other stuff. I will try to get to it before then end of September, because there are many issues that Proton doesn’t appreciate, and we need to make noise.

Complaining via customer support is not going to achieve anything. I know because I tried multiple times.

---

## Post 45 by @PurpleDime — 2025-08-23T14:29:01Z

> [@iluvprivacy](#):
>
> Interesting you got a warning after using 3 alias per site. Just like me. Is the next warning an account shut down?

I have no idea, and it’s not something I want to test. But that’s definitely an option Proton has. Imagine you’re subscribed to Proton Unlimited, with Proton Mail as your default email provider you’ve been using for years. You create 3 aliases, and Proton decides to completely shut down your account.

That’s very scary to me and also completely unreasonable.

> [@anonymous409](#):
>
> Anonymous registration for Tuta was never possible in the first place. Not only do they block Tor exit nodes, but also VPNs and many residential IPs(including mine).

This is surprising because I use a VPN 24/7, and it was enabled when I created my Tuta account on Mullvad less than 6 months ago. I also paid for my Tuta account anonymously with a gift card that I bought with cash from the Proxy Store.

Have you tried changing VPN locations? And are you sure you don’t already have a free Tuta address. Because if you do, and you try to create a new account after being connected with an older account, that might be why. Tuta is stricter about reprimanding people with multiple free accounts than Proton.

It’s also possible that someone logged into their Tuta account with the VPN IP location that you used. But I would try different ones. Wait a couple of hours/days between each failed attempt.

---

## Post 46 by @thatsspirit — 2025-08-23T21:09:12Z

Hey, so which will be best in this situation (1 time registration - anonymous and they dont know muc):

1. Registering in Dmail (mail.dmail.ai)
2. Registering by onion site in protonmail but confirming with Dmail as recoverymail (needed to use to third party apps), needed to turn off ublock to register then.
3. same as nr 2. but with alias mail from simplelogin coming to protonmail

---

## Post 47 by @KasztanowyKasztan — 2025-08-24T08:20:38Z

I wonder why nobody mentioned: [https://www.aliasvault.net/](https://www.aliasvault.net/)

Such a great service.

---

## Post 48 by @anon57862721 — 2025-08-24T08:45:39Z

I did mention it way up in this thread.

---

## Post 49 by @KasztanowyKasztan — 2025-08-24T09:12:58Z

Right. Haven’t noticed it. My bad.

---

## Post 50 by @Stiffly2505 — 2025-08-24T13:30:22Z

Not a Proton user, but that policy sounds pretty shortsighted: If you use mail aliases exactly for their intended purpose, eventually one of your registered sites will experience a breach. I last had it with Internet Archive ([archive.org](http://archive.org)). To prevent future spam, what you’d want to do is create a new alias, and change over from the old one.

Personally I just use iCloud Hide My Email. I have up to 10 accounts on one service, and 2 or 3 on multiple other ones. Never received any restriction whatsoever for that.

---

## Post 51 by @Natha — 2025-08-24T18:01:00Z

About AliasVault, is there a catch? It’s free and open source, they don’t seem to have any business plan at the moment (they do mention a premium plan on their GitHub/roadmap), you can create an account and host your data on their servers at not cost, there seem to be only one dev behind it, it hasn’t been audited, etc.

I don’t know. I have the feeling that it is too good to be true. I get that it is a very young piece of software, so there’s no point in having like business expectations from it. At the same time, why paying for any other cloud based password manager if you could go with AliasVault?

I first heard about it in this thread, nowhere else so far. Thus why I am a bit suspicious.

---

## Post 52 by @win11.shading291 — 2025-08-24T18:19:37Z

> [@anon29849](#):
>
> alias services not always work or they dont allow to register with their domains

I’ve never had that happened with ProtonPass so far. I create an alias everytime I have to register somewhere. I keep it active and if it ever leaks, I disable + delete.

---

## Post 53 by @Natha — 2025-08-24T18:38:32Z

Never had the issue either. I still haven’t updated to Proton Ultimate though. So I’m limited to the few aliases available with the Mail Plus plans.

I get that Proton is trying to limit the potential abuses of these aliases. As much as I think that the ToS of SimpleLogin need to be refreshed.

If you are on Proton with a custom domain and do end up being flagged for misusing your aliases, nothing is stopping you from using [addy.io](http://addy.io). As mentioned in their [FAQ](https://addy.io/faq/#can-i-add-a-domain-if-im-already-using-it-for-email-somewhere-else), you can keep using Proton Mail (or any other mail service) by creating a subdomain that will be dedicated for [addy.io](http://addy.io). Or you can just use the aliases generated by [addy.io](http://addy.io) with their own domains. Both cases are great for generating burner aliases. And I’m pretty sure that anyone with a light usage can manage to stay on the free plan. If not, 1€ / month is nothing.

---

## Post 54 by @AtomicBug — 2025-08-24T21:14:00Z

Temporary address sites have already been mentioned. But I use two on the [identity generator](https://strongphrase.net/#/identity) I made:

- [Emailnator.com](http://Emailnator.com) - Because it offers real gmail addresses, which get my a lot of spam protection
- [Reusable.email](https://reusable.email/) - Because it has a really nice interface

Also, IVPN is offering a new email forwarding tool that I’m looking forward to! It’s currently in beta: [Mailx beta launch - Audited, open-source email aliasing service](https://www.ivpn.net/blog/mailx-beta-audited-open-source-email-aliasing/)

---

## Post 55 by @unseen — 2025-08-26T18:13:33Z

> About AliasVault, is there a catch? It’s free and open source, they don’t seem to have any business plan at the moment

If I remember correctly, it’s in beta currently and will eventually introduce premium plan. According to the dev, it’s also possible to self-host everything. So if you don’t trust their cloud, you could use your own server.

I agree it’s pretty new and not well-known, so it’s natural to be skeptical about it. I tested it and enjoy using it so far. I’m currently using it for all my new throwaway/test accounts. I really hope this project grows and stays for a long time (or I hope one day I will be good enough at self-hosting to host it myself if necessary).

> I first heard about it in this thread, nowhere else so far

There’s a post on reddit: [Reddit - The heart of the internet](https://www.reddit.com/r/selfhosted/comments/1hvrat0/aliasvault_opensource_password_email_alias/)

Also, check out this post: [AliasVault: Open-Source E2EE Password & (Email) Alias Manager](https://discuss.privacyguides.net/t/aliasvault-open-source-e2ee-password-email-alias-manager/24436)

---

## Post 56 by @unseen — 2025-08-26T19:04:05Z

> That’s why it’s better to go with [Addy.io](http://addy.io/) who allow you to create multiple aliases for the same website.

Unfortunately, [addy.io](http://addy.io) also doesn’t allow that. It is stated in their FAQ:  
” **Can I use aliases to create multiple accounts on other websites and services?**  
No, you must not use [addy.io](http://addy.io) to create large numbers of accounts on other websites/services as this is against the terms and conditions.”  
(link: [Frequently Asked Questions - FAQ - addy.io](https://addy.io/faq/#can-i-use-aliases-to-create-multiple-accounts-on-other-websites-and-services) )

> **It is against their ToS to create more than one alias for the same website.**

Technically, they don’t spell that out explicitly. Here are the exact wordings:

“11. Abusive registrations of email addresses (including aliases) for third-party services;” (Proton’s Terms of Service)

“Abusive usage of aliases for third-party services is prohibited. For example, you shouldn’t use email aliases for bulk signups on a third party website.” (SimpleLogin’s Terms and Conditions)

In my opinion, they use vague terms like “abusive registrations” and “bulk signups” so that they have the excuse to ban/issue warning to whoever feels suspicious to them, while also continuing serve other customers that do the same thing but somehow don’t trigger their anti-abuse algorithm. So as long as you don’t trigger the anti-abuse system, you will be fine. Many people said they had multiple aliases for the same website and didn’t receive any warning.

I understand your frustration, I’m also upset about this issue and the lack of transparency from Proton. After a lot of digging, I found out something that could be helpful if you decide to use Proton/SimpleLogin alias. One of the mods of Proton on reddit commented:

- ”This isn’t about “using several accounts” but about registering them in a very short time to trigger. I do know what the limit is, as the limit isn’t public knowledge due to security reasons (otherwise would facilitate the life of abusers).”
- “Space it out and don’t do it all at the same time”
- “Just spread them over time time and you’ll be fine. I have had 5 tidal aliases (for a family account), created over some time and didn’t have any issues (on a paid plan).”

So I think if you wait a few days or a week before using the new alias for the same website, it will be safe. How much time was there between the two account registrations when you received the warning last time?

---

## Post 57 by @arise1984 — 2025-08-26T20:10:11Z

> [@unseen](#):
>
> In my opinion, they use vague terms like “abusive registrations” and “bulk signups” so that they have the excuse to ban/issue warning to whoever feels suspicious to them, while also continuing serve other customers that do the same thing but somehow don’t trigger their anti-abuse algorithm. So as long as you don’t trigger the anti-abuse system, you will be fine. Many people said they had multiple aliases for the same website and didn’t receive any warning.

Exactly my thinking. On another note of proton questionable policy, they did spelled it out in their tos that multiple proton free accounts are prohibited, ie 2 is literal multiple so technically only 1 are permitted. But their staff, wearing “proton staff” reddit tag said that its fine to have multiple free accounts as long as they’re not use abusively.

Their policy on proton free account are strict, only 1 account are permitted per user but they also have their staff going around basically saying go ahead break our tos, have multiple free accounts, its fine as long as you don’t use them for abuse. “For abuse” is still very much vague so they can act on the actual abusive users while keeping a closed eye to the ones that don’t. But anyone that have multiple free proton accounts that don’t abuse them are really living dangerously since proton can ban them anytime, at any moment for literal tos breaking.

---

## Post 58 by @mangomango — 2025-08-27T06:58:22Z

I like to use AdGuard’s temporary email services because AdGuard inspires me some trust and because the service is fast and transparent. I used to use Guerillamail too. It seems that emailnator and reusable.email are quite appreciated here too.

However, be really careful with these emails as they have no security at all and you are probably better off using an email alias. Even if it triggers your mentality “omg it’s linked to my email and alias account, my privacy is ruined”:rofl:

---

## Post 59 by @U53R — 2025-08-27T14:29:31Z

> [@anon29849](#):
>
> best services to register to various platforms

See my reply on another thread

> [@What email alias do you use? And which ones would you recommend the most to use?](https://discuss.privacyguides.net/t/what-email-alias-do-you-use-and-which-ones-would-you-recommend-the-most-to-use/30512/2):
>
> [duck.com](http://duck.com) ones. And for forums forwarding feature in [dropmail.me](http://dropmail.me) as it gives unlimited subdomains (for example: test@domain.com on dropmail = test@my-random-sub.domain.com) and unlimited forwarding time. Also as I know their addresses is unique so it is unlikely that anyone will get same.

---

## Post 60 by @PurpleDime — 2025-08-28T17:07:39Z

> [@Best mail services for burner mails (registering)?](https://discuss.privacyguides.net/t/best-mail-services-for-burner-mails-registering/30345/45):
>
> ![](https://forum-cdn.privacyguides.net/user_avatar/discuss.privacyguides.net/unseen/48/11841_2.png) unseen:
> 
> > In my opinion, they use vague terms like “abusive registrations” and “bulk signups” so that they have the excuse to ban/issue warning to whoever feels suspicious to them, while also continuing serve other customers that do the same thing but somehow don’t trigger their anti-abuse algorithm. So as long as you don’t trigger the anti-abuse system, you will be fine. Many people said they had multiple aliases for the same website and didn’t receive any warning.
> 
> Exactly my thinking.

_ **Proton ToS ≠ Addy ToS** _

There might be some truth to this, but it’s still a problem. ToS should be clear. Even if you are correct, Proton and Addy do NOT interpret the word “bulk” the same way.

> [@Best mail services for burner mails (registering)?](https://discuss.privacyguides.net/t/best-mail-services-for-burner-mails-registering/30345/45):
>
> On another note of proton questionable policy, they did spelled it out in their tos that multiple proton free accounts are prohibited, ie 2 is literal multiple so technically only 1 are permitted. But their staff, wearing “proton staff” reddit tag said that its fine to have multiple free accounts as long as they’re not use abusively.

Exactly. For Proton, it’s anything more than one, which is completely contrary to what “bulk” actually means.

Also, [in a past comment about this](https://discuss.privacyguides.net/t/how-do-you-use-aliases-with-substack-do-you-use-multiple-aliases-or-just-one/27876/15), I pointed ou that Proton makes that rule very clear when they give you a warning.

> _You have tried to register multiple times to_ \*\*\*\*\*\*\*\* _and this is against the terms of service of SimpleLogin. Please don’t do that anymore._
> 
> _If you continue registering multiple accounts to a single service we will have to disable your account._

Multiple means anything more than one.

**In their FAQ Addy says:**

> _No, you must not use [addy.io](http://addy.io) to create large numbers of accounts on other websites/services as this is against the terms and conditions_

They use the term _“large”_, which like _“bulk”_ emphasizes a great order of magnitude. It suggests that having 2 or 3 aliases for the same website would be ok. And to get confirmation, I asked the owner of Addy, and he said it would be perfectly fine for me to have 3 to 4 aliases for any website. It’s only after I got his confirmation, that I signed up for a premium subscription.

That is very different from Proton who say in their warnings, and in my interactions with their support team, that only one alias per third party website is allowed.

_ **Always ask for confirmation** _

I strongly recommend anyone who wants to ask Proton a question for which the answer is not clear to demand that they triple check their information. Do not be satisfied with a simple answer, especially if it’s the answer that you want. And when they make a statement, repeat it to them in your own words, and ask them to confirm your understanding is correct.

If they say you are only allowed one alias per third party website, ask them to confirm that statement like this:

> _So what you’re saying is, if I have 2 Instagram accounts, I can use a Proton Pass alias for only one of them?_

I argued back and forth with Proton to get a clear answer on aliases. And many times since, I’ve had interactions with Proton on social media where I had to correct them because they gave the wrong information. All this is to say, there are many Proton support agents who do not know that the alias limit is one per third party website, and will tell you otherwise, unless you ask them to double check and get confirmation from colleagues or superiors.

---

## Post 61 by @PurpleDime — 2025-08-28T17:26:43Z

> [@unseen](#):
>
> So as long as you don’t trigger the anti-abuse system, you will be fine. Many people said they had multiple aliases for the same website and didn’t receive any warning.

I don’t think this is necessarily true, and I would be extremely careful if I was in anyone’s shoes. Losing access to your Proton account means losing accesses to many online accounts if you have aliases linked to them. Not to mention losing all your emails from Proton Mail.

Proton gets to interpret their rules however they want, to the point where they change the meaning of words like _“bulk”_. They can also reprimand you even if you have not broken any of their rules, which is what I believe happened to me.

_**A) I got warning despite technically not breaking their rule**_

Proton’s rule explicitly says the following:

> _you shouldn’t use email aliases for bulk signups on a third party website._

Even if I agreed with Proton’s nonsensical definition of “bulk”, which I don’t, I did no such thing.

> [@unseen](#):
>
> How much time was there between the two account registrations when you received the warning last time?

I created 3 aliases for the same website within 2 hours. But I was not _ **signing up** _ to any service, I was simply _ **updating** _ my email address for accounts I’ve had for years. Signing up to a service and updating your email for existing accounts are not the same thing.

But Proton doesn’t care. For them, it might as well be.

> [@unseen](#):
>
> So I think if you wait a few days or a week before using the new alias for the same website, it will be safe.

_**B) Sometimes you cannot afford to wait.**_

If my current email provider is shutting down (e.g.: Skiff), and I have many online accounts linked to addresses from that provider, I cannot afford to wait to update my email for those accounts. This is just one example, and there are plenty of others.

In situations like these, I have to allocate the time to update my email for those accounts, and in that time block of sometime just a couple of hours, I need to create multiple aliases for the same website.

That is the context in which I got a warning.

_**C) Bulk means I should (technically) be allowed to have 100+ aliases for the same website.**_

Acquiring something in bulk means acquiring a lot of it in a very short instant.

If I buy _ **100 pairs of socks** _ from the same shop _ **in a single day** _, you can argue that I bought them in bulk.

But if I buy _ **3 pairs of socks in a week** _, however you slice it, I did NOT buy them in bulk.

Suppose I decide to buy 3 pairs of socks a week, and I buy each pair on different days, Monday, Wednesday, and Friday.

_ **In a single week, I have acquired 3 pairs of socks. In a month, I will have 12 pairs of socks, and after a year, I will have 144 pairs of socks.** _

I now have 144 pairs of socks in my drawer.

Did I buy them in bulk?

The answer is no.

By that logic, if I create aliases at the same pace, I should be allowed to have 144 aliases for the same website, without breaking Proton’s ToS.

I am doubtful they would allow it, even if it technically didn’t infringe their ToS. [This is something that could easily occur with Substack](https://discuss.privacyguides.net/t/how-do-you-use-aliases-with-substack-do-you-use-multiple-aliases-or-just-one/27876), as subscriptions quickly rack up.

_**D) PSAs could trigger a warning**_

Even if you pace when you create your aliases, a public service announcement (PSA) could trigger a warning. Suppose you have 3 Dropbox accounts that you create a month apart with aliases.

If six months after, Dropbox sends an email announcement about a new product they’re launching, you will receive 3 emails at the same time from the same website, to your 3 aliases.

That could trigger a warning from Proton. Companies make announcements all the time, so I personally don’t want to take that risk until Proton changes and/or clarifies their ToS. I already got a warning.

---

## Post 62 by @unseen — 2025-08-28T18:17:45Z

> There might be some truth to this, but it’s still a problem. ToS should be clear.

I couldn’t agree more. We are discussing this issue and putting this much effort into deducing Proton’s behavior because Proton’s ToS is not clear. To be clear, I’m not defending Proton. I’m one of the users who are usually censored on Proton’s subreddits due to calling them out. In the previous comment, I was trying to be as objective as possible by using all the information I have, including their official public documents, what their mods say, and what users report, to deduce how Proton behaves.

> _You have tried to register multiple times to_ \*\*\*\*\*\*\*\* _and this is against the terms of service of SimpleLogin. Please don’t do that anymore._
> 
> _If you continue registering multiple accounts to a single service we will have to disable your account._

I forgot how this warning is worded, thanks for reminding me. Based on that, it’s clear that Proton’s behavior and statement are inconsistent.

> They use the term _“large”_, which like _“bulk”_ emphasizes a great order of magnitude. It suggests that having 2 or 3 aliases for the same website would be ok. And to get confirmation, I asked the owner of Addy, and he said it would be perfectly fine for me to have 3 to 4 aliases for any website.

It’s great to hear that Addy really does allow having multiple aliases for the same website!

I got the impression that Addy doesn’t allow that because they answered “No” directly to the “Can I use aliases to create multiple accounts on other websites and services?” question, and “multiple” means more than one. They probably should adjust this part to avoid such misunderstanding.

> It’s only after I got his confirmation, that I signed up for a premium subscription.

I just want to confirm again, you tested it (signing up or updating multiple accounts on the same website using different Addy aliases) and there was no problem?

> unless you ask them to double check and get confirmation from colleagues or superiors

Did the mentioned Proton support get back to you after getting confirmation from superiors and confirm the one alias per third party website rule? I only have had a few interactions with Proton support, but half of the interactions I had, they ignored my questions and just gave me “copy-and-paste” answers that didn’t actually answer my questions.

Sorry if there is any unclear wording, English is not my first language.

---

## Post 63 by @unseen — 2025-08-28T18:56:12Z

> _**D) PSAs could trigger a warning**_
> 
> Even if you pace when you create your aliases, a public service announcement (PSA) could trigger a warning. Suppose you have 3 Dropbox accounts that you create a month apart with aliases.
> 
> If six months after, Dropbox sends an email announcement about a new product they’re launching, you will receive 3 emails at the same time from the same website, to your 3 aliases.
> 
> That could trigger a warning from Proton. Companies make announcements all the time, so I personally don’t want to take that risk until Proton changes and clarifies thei their ToS. I already got a warning.

Is this something you have experienced first hand?

I’m aware that they scan SMTP headers (sender, recipient, subject) to detect abuse, so I’m just wondering whether the subject matters. Do only emails with keywords like ‘sign up’, ‘welcome’, ‘confirmation’, ‘registration,’ etc., in the subject trigger warnings, or will a warning be triggered as long as there are multiple emails from one sender to multiple recipients under one Proton account?

> But I was not _ **signing up** _ to any service, I was simply _ **updating** _ my email address for accounts I’ve had for years.

I’m aware of this issue as well, really frustrating. The common explanation I heard from other users is Proton’s anti-abuse system cannot distinguish between an email address update confirmation email and a new account registration email, both types of email are treated equally and trigger the abuse detection.

---

## Post 64 by @PurpleDime — 2025-08-29T17:29:33Z

> [@unseen](#):
>
> I just want to confirm again, you tested it (signing up or updating multiple accounts on the same website using different Addy aliases) and there was no problem?

Yes, I have created multiple aliases for the same website with Addy and didn’t have any issues. That said, I have probably less than 20 Addy aliases in total (not for the same website).

> [@unseen](#):
>
> Did the mentioned Proton support get back to you after getting confirmation from superiors and confirm the one alias per third party website rule?

Yes, they have. The Proton agents I have corrected verified the information with their colleagues and superiors, and admitted that I was right.

> [@unseen](#):
>
> I only have had a few interactions with Proton support, but half of the interactions I had, they ignored my questions and just gave me “copy-and-paste” answers that didn’t actually answer my questions.

From my experience, it’s common for Proton Support to copy and paste their ToS. This is something I don’t mind, as long as it’s accompanied by commentary. If it has no commentary explaining, I will ask for clarifications.

I personally don’t like it when they tell me to just check their ToS, and are incapable of quoting me the specific part that applies to my question. That has happened to me before with Proton’s support team, but also other services.

> [@Best mail services for burner mails (registering)?](https://discuss.privacyguides.net/t/best-mail-services-for-burner-mails-registering/30345/51):
>
> Is this something you have experienced first hand?

Proton didn’t allow me to create multiple aliases for the same website, so no, I have not experienced this. But that doesn’t mean it couldn’t happen. Proton’s abuse trigger may not be promted with simulaneous emails from the same website if it happens a couple of times. But after a while, it could.

There’s a forum I belong to, on which I am subcribed to a dozen plus threads that have constant activity, every single day. I get notified via email every time there’s an update on those threads. Within a week I can easily receive 30 to 50 email notifications from a single thread. And remember I am subcribed to at least a dozen. I only have one account on that forum, but imagine if I had 3, and that I used a Proton Pass alias for each.

That means that I would get 100+ email notification on _each_ alias at the same time, _every week_. That could easily ring Proton’s alarm.

> [@Best mail services for burner mails (registering)?](https://discuss.privacyguides.net/t/best-mail-services-for-burner-mails-registering/30345/51):
>
> I’m aware that they scan SMTP headers (sender, recipient, subject) to detect abuse, so I’m just wondering whether the subject matters. Do only emails with keywords like ‘sign up’, ‘welcome’, ‘confirmation’, ‘registration,’ etc., in the subject trigger warnings, or will a warning be triggered as long as there are multiple emails from one sender to multiple recipients under one Proton account?

I have no idea, and I’m sure we’ll never know because I’ve asked Proton, and they told me they couldn’t tell me because they don’t want people to game their system, which makes sense.

The context in which I asked how their system works is by asking how they could tell the different between aliases that are used just for emailing, and aliases that are used to manage accounts.

Because, as I’ve explained in my [Substack post](https://discuss.privacyguides.net/t/how-do-you-use-aliases-with-substack-do-you-use-multiple-aliases-or-just-one/27876/3), you’re allowed to create 10 different aliases to email 10 different Gmail addresses (same domain). But you’re not allowed to create 10 aliases to manage 10 Google accounts (also same domain).

How can Proton tell the difference? I don’t know, but they can. I know because I have created multiple aliases to email Gmail addresses, and it didn’t trigger anything because it’s allowed. Those aliases are still active.

---

## Post 65 by @unseen — 2025-08-29T23:55:24Z

> Because, as I’ve explained in my [Substack post](https://discuss.privacyguides.net/t/how-do-you-use-aliases-with-substack-do-you-use-multiple-aliases-or-just-one/27876/3), you’re allowed to create 10 different aliases to email 10 different Gmail addresses (same domain). But you’re not allowed to create 10 aliases to manage 10 Google accounts (also same domain).
> 
> How can Proton tell the difference? I don’t know, but they can. I know because I have created multiple aliases to email Gmail addresses, and it didn’t trigger anything because it’s allowed. Those aliases are still active.

Interesting discovery. Sorry to ask again but when you said “to email 10 different Gmail addresses”, it means you sent emails to 10 different Gmail addresses, but do you also receive emails from those 10 different Gmail addresses? Because I think it’s trivial for them to detect the difference between sending and receiving emails. And I believe it’s also trivial for them to store a list of “official addresses” of those services like Google and Facebook that are used to send email confirmation to users. I also believe they have enough data to build a filter/algorithm to detect that, since they operate a service that receive a huge amount of emails from third-party services everyday.

> Proton didn’t allow me to create multiple aliases for the same website, so no, I have not experience this. But that doesn’t mean it couldn’t happen.

I see, I will test that with my throwaway SimpleLogin account when I have time. I will let you know the result. What you said makes sense, but I still think there are chances PSA emails won’t trigger an warning, because Proton can detect the difference, just like how you mentioned they can tell the difference in your 10 Gmail addresses case. The fact that there are people out there still maintain multiple aliases for the same website suggest that is a possibility. They must’ve also receive PSA emails from the same website during the time they have those aliases.

Thanks for replying!

---

## Post 66 by @PurpleDime — 2025-08-30T10:54:20Z

> [@unseen](#):
>
> when you said “to email 10 different Gmail addresses”, it means you sent emails to 10 different Gmail addresses, but do you also receive emails from those 10 different Gmail addresses?

Yes. If I create an alias to email someone, it’s because I expect a response.

One of the reasons I have found myself in this situation is because I’ve encountered quite a lot of businesses, including medical practices (yikes!), that don’t have their own domains and use Gmail addresses. I’m not going to email my doctor and my plumber with the same alias.

> [@unseen](#):
>
> Because I think it’s trivial for them to detect the difference between sending and receiving emails.

I agree. But when you sign up for a new service or update your email for an existing account, you receive a confirmation email. I believe it’s that confirmation that triggers Proton’s alarm. It’s _one_ element of their trigger system. They just choose not to show you the confirmation email when they decide to strike you, and hence you are unable to create your account.

> [@unseen](#):
>
> And I believe it’s also trivial for them to store a list of “official addresses” of those services like Google and Facebook that are used to send email confirmation to users.

I wouldn’t put it past them to do that. Like I said, Proton wouldn’t explain to me how their system works, which I can understand. But even though there are parts we don’t know, I think it’s fair to assume that the confirmation emails are part of what triggers the alarm.

Also, it’s not uncommon for websites to change their newsletter / confirmation email addresses and domains. I know because I have experienced it multiple times. I use filters for many of my emails. I set rules so that if I receive an email from _@facebook.com_, it goes straight to my Facebook folder. But then one day, I see a Facebook email in my main inbox, which doesn’t make sense. That’s because it’s from a different domain _@fb.com_, which Facebook also owns.

All this is to say, I wouldn’t be surprised if Proton had a list of all the confirmation email domains and addresses from websites people use. I’m sure that’s not the only string to their bow, though. They could also check email titles to differentiate confirmation emails from regular emails.

> [@unseen](#):
>
> I also believe they have enough data to build a filter/algorithm to detect that, since they operate a service that receive a huge amount of emails from third-party services everyday.

I believe so, too.

---

## Post 68 by @unseen — 2025-09-21T18:48:53Z

> [@PurpleDime](#):
>
> They use the term _“large”_, which like _“bulk”_ emphasizes a great order of magnitude. It suggests that having 2 or 3 aliases for the same website would be ok. And to get confirmation, I asked the owner of Addy, and he said it would be perfectly fine for me to have 3 to 4 aliases for any website. It’s only after I got his confirmation, that I signed up for a premium subscription.

I have just seen a post on reddit saying that their Addy account is being disabled for having 2 aliases: [Please help! ‘Account disabled for breaking terms and conditions’](https://www.reddit.com/r/addy_io/comments/1nmugjw/please_help_account_disabled_for_breaking_terms/)  
Just want to share it because I think you might be interested.

---

## Post 69 by @PurpleDime — 2025-09-22T05:31:50Z

Thank you for this very valuable info. I saw in the last comment that Addy responded. They asked OP to contact them via email, and it looks like they will have their account re-enabled. It seems to be a mistake, but it also appears that new accounts have stricter restrictions. I intend to ask Addy about this.

---

## Post 70 by @daniellebro444 — 2025-11-05T15:47:31Z

Hey folks, jumping into this thread since I’ve been tinkering with temp email options lately for all sorts of sign-ups and tests without clogging my main inbox. I’ve tried a bunch of the ones mentioned—DuckDuckGo’s aliases are solid if you’re already in their ecosystem, and SimpleLogin works okay but yeah, that free limit hits quick. Anonaddy’s username flexibility is nice too, though I always forget I can’t reply for free.

Lately, though, I’ve been using Boomlify for most of my needs, and it’s handled things in a way that just fits better for what I do. It’s one of those [temp mail](https://boomlify.com/) services where you can whip up a disposable address on the spot for privacy or dodging spam, no account required to get started. What caught my eye is how you can pick a custom username instead of dealing with some random string, and it pulls from a bunch of domains that they keep fresh—I’ve seen new ones pop up when others get blacklisted. The emails stick around longer than your average 10-minute burner too, which is handy if a verification takes a day or so to land.

I mostly use it for quick website testing or grabbing trial accounts without committing my real email, and the cloud sync means I can check the same inbox from my phone or laptop without any hassle. There’s even a little built-in viewer for 2FA codes that pops them up right there, saving me from switching apps. If you’re into dev stuff, they’ve got an API that lets you pull emails straight into scripts or apps—docs are pretty straightforward with examples in a few languages, and you get some free credits daily to play around.

Anyway, it’s not perfect—still figuring out the forwarding quirks—but for infinite aliases without the short expiry nonsense, it’s been reliable in my book. Curious what others think if you’ve given it a spin.

---

## Post 71 by @anon57862721 — 2025-11-05T16:01:13Z

I recommend you give [AliasVault](https://www.aliasvault.net/) a try. Its brand new, still in beta but developing fast by @lanedirt and is a solid option for what it does.
