Skip to content

← All writing

Privacy

Most disposable email is not private at all

31 July 2026 · 2 min read · TMailr

A disposable inbox hides your address from one sender. That is a real and useful thing, and it is a much smaller thing than privacy, which is why using one as though it were privacy goes wrong in predictable ways.

What it actually hides

The sender learns a string that is not yours and will stop working. They cannot join it to anything else they hold, cannot sell it usefully, and cannot reach you next year. For a one-off signup, a download link or a forum you will never revisit, that is the entire requirement and a throwaway meets it exactly.

What it does not hide

  • The message itself. Mail arrives over the public internet and sits on a server that can read it. Encryption in transit and at rest is not end-to-end encryption.
  • Anything else in the message. If you put your name, your order number or your phone number into a form, the throwaway address protected none of it.
  • Who you are to the service. They still have your card, your delivery address and your device.
  • Your other addresses. Replying from your real mailbox puts your real address in the thread, which undoes the whole exercise in one click.

The address is guessable, so the link has to not be

Most disposable services hand out short, memorable local parts, and some let anybody open an inbox by typing its name. That means the address is not a credential and must never be treated as one. If knowing the address is enough to read the mail, then every code sent to it is public.

This is worth checking before you trust one. Ours will not open an inbox from the address alone: the secret is in the link, and knowing where mail was sent gets you nothing. A service that lets you type any address and read its contents is a public noticeboard, which is fine for a download link and disqualifying for anything else.

Where people get burnt

The recurring mistake is using a throwaway for an account that matters and then needing it. Password resets go to the address on file. If that address expired an hour after you signed up, the account is gone, and no support desk can help because the only proof of ownership was the mailbox.

The second mistake is assuming the mail is gone because the inbox is. Deletion has to be something the service does rather than something it implies. Ask what is deleted, when, and whether the stored copy goes with the record.

Choose by the question you are answering

  • Never need this again, and nothing sensitive: a disposable inbox is exactly right.
  • Want to keep the relationship but not give out my address: an alias, which forwards and can be switched off.
  • Something I will need to recover, or that carries money: your real mailbox, with a password manager and two-factor authentication.

The honest summary is that a disposable address is a burner for a conversation you do not intend to continue. It is not anonymity, not encryption, and not a place to keep anything. Treat it as the paper cup it is and it works very well.

More on privacy