Simplelogin security/privacy settings best practices

I am specifically curious about the implications of these settings:

Sender Address Format

Reverse Alias Replacement

Include sender address in reverse-alias

Include original sender in email headers

You’re going to have to explain more. What about these? How do you mean?

:green_circle: [not important] Sender address format is not that important, it’s for your own quality of life.

It’s pretty much how you want to see the email while receiving in your private email box (after it’s gone through SL).


:green_circle: [not important[1]] Reverse Alias replacement

This one, I don’t really know what it does but I guess it is kinda related to the one above and makes it friendly to understand what is the email you’re sending an email from.

Meaning that if you have for example:
[me@gmail.com] → [SL: hellothere@simplelogin.io] → [coolbusiness@fancy.com]

Rather than seeing an answer in the format of coolbusiness_at_fancy_[random hash]@simplelogin.co in your email client, it might directly try to directly forward coolbusiness@fancy.com in the From in your email client. :+1:t2:

Again, it’s experimental and doesn’t really add any value in terms of privacy so you can probably skip it too.


:green_circle: [not important] Include sender address in reverse-alias

Same here, I don’t feel like this one is adding anything from the “outside” in terms of privacy. It’s mostly how you want to have it displayed in your email client. I do have it enabled (hence why it does format the way it does in the previous part of this answer :backhand_index_pointing_up:t2:).

Very subjective of a toggle, you can play around with a few of those settings and see which one you prefer. :+1:t2:


:yellow_circle: [I honestly don’t know] Include original sender in email headers

I am not really sure on what this even means. I mean, I do understand the words one at a time :joy: but I don’t really do anything special with email headers and if you don’t either, I would probably skip it.

Especially since it’s disabled by default and because headers are known for not being encrypted so overall, skip it too I’d say. :+1:t2:


Honestly I think that other options are more important/critical. The ones you mentioned are not that much of a big deal overall. :hugs:

This one is quite cool in comparison. :+1:t2:


Like this one, I usually leave it blank or input a _ for it.


Some of those settings can probably be expanded/explained more in details in their official docs: SimpleLogin Docs

There is definitely not a lot of activity down there but I guess it’s better than nothing, the project/product is still kinda alive. :+1:t2:


  1. at least from what I do understand ↩︎

I don’t even see the default display name setting. Is this for a custom domain?

Oh sorry, yes it is. :+1:t2: