Email Masking: Your Guide to Protecting Privacy With Decoy Addresses

Your password can be changed. Your email address cannot.
Why email addresses are more valuable to attackers and data brokers than passwords after a breach.
Mark

Why does an email address matter more than a password after a breach?

Mimi

Because you can change a password in minutes. Changing your email address is nearly impossible—it's tied to every account you have. Once it's out there, it stays out there. That's why attackers prioritize it.

Mark

So masking is basically a way to give companies a fake address that still works?

Mimi

Exactly. The mask forwards everything to your real inbox, but the company never sees your real address. If they get hacked, they only have the fake one.

Mark

What's the catch? Why would these masking services do this for free?

Mimi

The free versions are limited—maybe you can't reply, or you get fewer masks. The paid tiers have more features. It's a freemium model. And some services, like Apple's, are bundled into subscriptions you're already paying for.

Mark

If I use a mask to buy something, can the seller still contact me if there's a problem?

Mimi

Only if the masking service lets you reply through the mask. That's why reply capability is crucial. Some free services don't offer it, which is a real limitation for anything transactional.

Mark

How do I know the masking service itself isn't reading my emails?

Mimi

You check their privacy policy and terms of service. Look for companies in jurisdictions where they can be held legally accountable. Apple, Mozilla, and Proton all explicitly state they don't read or store messages—they just relay them.

Mark

Is there a scenario where masking wouldn't help?

Mimi

If you're using the same mask for multiple services and one gets breached, that mask is compromised. But that's why most services let you create unlimited masks. You use a different one for each service.

  • Every app download and newsletter signup extracts an email address that, once exposed in a breach, cannot be easily reclaimed — unlike a password, it becomes a permanent vulnerability.
  • Data brokers, hackers, and marketers treat email addresses as durable commodities, making the inbox a front line in an ongoing war over personal identity.
  • Masking services respond by generating randomized decoy addresses that forward messages silently, letting users burn and replace any address the moment it becomes compromised.
  • The technology is maturing fast — Apple, Mozilla, DuckDuckGo, and Proton Mail all offer versions, though free tiers often lack reply capability, limiting usefulness for transactional exchanges.
  • The remaining tension is trust: masking providers sit between sender and recipient, and only transparent privacy policies and legal accountability distinguish a genuine shield from another middleman.

In an era when an email address has become more difficult to change than a password — and more valuable to those who would exploit it — a quiet technological countermeasure is gaining ground. Email masking services offer a kind of digital pseudonymity, generating disposable addresses that shield the real one from the inevitable failures of companies entrusted with our data. Providers like Apple, Mozilla, DuckDuckGo, and Proton Mail have made this protection increasingly accessible, reflecting a broader reckoning with how thoroughly the modern internet has monetized identity.

Every time you sign up for an app or newsletter, someone wants your email address — and increasingly, people are giving them a fake one instead.

Email masking services generate randomized decoy addresses that automatically forward messages to your real inbox, keeping your identity hidden. The concept is simple: if a masked address starts attracting spam or gets caught in a breach, you disable it and create another. Your real address stays untouched. Apple offers this through Hide My Email for iCloud+ subscribers, Mozilla through Firefox Relay, DuckDuckGo through its Email Protection service, and Proton Mail through both its password manager and a standalone product called SimpleLogin.

The stakes are higher than they might appear. When a company is hacked, a password can be changed in minutes. An email address cannot — and it's often the master key attackers want most, since it unlocks password resets across dozens of accounts. It's also what data brokers trade in. A masked address, by contrast, is disposable by design.

Not all services are equal, however. Some free tiers only receive messages and cannot reply — workable for newsletters, but a problem when a retailer needs to reach you about an order. Mozilla product manager Santiago Andrigo recommends masking whenever you're uncertain what a site will do with your data, or when your association with a service — a medical forum, a minority community — could expose something sensitive if breached.

Workarounds like Gmail's plus-sign trick offer filtering but no real privacy; anyone can strip the suffix and recover your actual address. A dedicated throwaway account is more private but doesn't scale.

The one genuine concern is that masking providers sit in the relay path between sender and your inbox. Trust, then, becomes the product. Apple says it deletes relayed messages within seconds. Firefox Relay says it neither reads nor stores them. Proton Mail states it keeps no copies at all. These commitments are the only meaningful guarantee — which is why choosing a provider with clear, legally accountable privacy policies matters as much as choosing the service itself.

Every time you download an app or sign up for a newsletter, someone wants your email address. It's become the price of entry to almost everything online. But there's a growing alternative: instead of handing over the real thing, you can give them a fake one.

Email masking services work like this. You get a randomized address—maybe something like "purple-mountain-847@relay.com" or a string of letters and numbers—that looks nothing like your actual email. When someone sends a message to that decoy address, the service automatically forwards it to your real inbox without revealing your identity. It's the digital equivalent of a burner phone, except for your email.

The services doing this work are becoming mainstream. Apple offers it to iCloud+ subscribers through a feature called Hide My Email, available on Safari across iPhones and Macs. Mozilla's Firefox Relay provides the same function for browser users. DuckDuckGo has an Email Protection service. Proton Mail, the encrypted email company, offers masking through its password manager and a standalone service called SimpleLogin. There are dozens of others—Addy.io, FastMail, and more—each with free and paid tiers.

Why does this matter? Consider what happens when a company gets hacked. Your password can be changed. Your email address cannot, at least not easily. Yet that address is often the most valuable thing attackers steal, because it's the key to resetting passwords across all your accounts. It's also the thing marketers and data brokers most want to buy. An email address, once exposed, becomes a permanent liability. A masked address, by contrast, can simply be turned off. If one starts collecting spam, you disable it and create another. The original stays clean.

But not all masking services are equal. Some free versions can only receive emails, not reply to them. That's fine if you're just signing up for a newsletter you'll never interact with. It's a problem if you buy something online and the seller needs to contact you about your order. Andy Yen, the CEO of Proton Mail, emphasizes this point: the ability to reply through your mask is essential for anything transactional. Most services offer a dashboard where you can see all your active masks and toggle them on or off.

When should you use one? Santiago Andrigo, a product manager at Mozilla, suggests two scenarios. First, when you're unsure what a website will do with your information—masking gives you control, and if unwanted messages arrive, you can simply block that mask. Second, when your association with a service could expose something sensitive. Joining an online community for a medical condition or a minority group, for instance. A data breach there could reveal something you didn't want public. A mask protects that.

There are other tricks people try. Some Gmail users add a plus sign and extra characters to their address—"yourname+newsletter@gmail.com"—which helps filter messages and track who's sharing your address. But Yen points out this does nothing for privacy. Anyone can strip away the plus sign and get your real address. Setting up a throwaway Gmail account is another option, but it's tedious and doesn't scale.

The one legitimate concern with masking services is trust. They sit in the middle, relaying messages between senders and your real inbox. How do you know they're not reading your mail? Look for providers with clear privacy policies, transparent terms of service, and legal accountability. Apple says it deletes all messages from its relay servers within seconds and doesn't read content except for spam filtering. Firefox Relay says it doesn't read or store messages, and keeps undelivered ones for no more than three days. Proton Mail states clearly it keeps no copies of anything passing through its servers. These commitments matter because they're the only thing standing between your privacy and the company running the service.

The real pain point for any user is actually not the password getting leaked, but the email getting leaked.
— Andy Yen, CEO of Proton Mail
Masking your email gives you control—if you start receiving unwanted messages, you can easily block any emails coming to that email mask.
— Santiago Andrigo, principal product manager at Mozilla
Contattaci Domande frequenti