Changelog
What shipped, month by month. An aliasing service holds your logins, so "is this project alive?" is a fair question. This page is the answer. See also the roadmap.
August 2026
- Privacy level: one setting that moves everything. Pick Balanced, High or Maximum and every alias follows, with a dropdown per level showing exactly what it does to each address you own and what it costs you. On Maximum we cannot read anything of yours, and the page says so in those words — or admits it cannot, if you excluded an alias to keep it forwarding.
- Choose how long we keep your stored mail. One day, a week, a month, per account or per alias. Shorter is one click. Longer is capped and asks you to acknowledge what it costs, because the cap is what keeps "at most this much of anyone's mail exists here" true for everyone. The page also admits the awkward part: our nightly backups can outlive a short window, and how long for.
- Lock an alias so a leak stops being worth anything. An alias can now refuse senders it has never heard from. The ones it already knows keep working, so locking breaks nothing you rely on. There is also a switch to do it automatically the moment an alias starts hearing from a second company, which is the point at which knowing about a leak stops being enough.
- Badges on every alias. A small mark on each row of your alias list showing which level applies and whether it is inbox-only, so you can see the shape of your account at a glance instead of opening ninety pages.
- Review your aliases. A spring-clean page grouping your aliases by what you might want to do: never heard from anyone, hearing from more than one company, expiring this week. It is honest about the one thing it cannot show you, which is when mail last arrived, because we delete that within days.
- Change your account number, or lock the account down. If your number leaks you can now replace it yourself, keeping every alias and everything stored. If somebody already has it, one button turns off every alias and revokes every credential, deleting nothing, so it is survivable if you turn out to have panicked over nothing.
- Documentation, a light theme, and a security page. Proper docs at /docs, a FAQ, a light mode that is not an afterthought, a press kit, and a security page that says how to report something to us, including our PGP key and the promise that we will not threaten you for it.
July 2026
- ARC sealing on forwarded mail. Forwards now carry an ARC seal, so strict receivers like Gmail and Outlook can verify the original sender's authentication even though the message passed through us. Fewer forwards land in spam.
- Rules engine: regex, more actions, dry-run. Rules can now match with regular expressions and tag an alias, notify you, or expire an alias automatically — and you can dry-run a rule against recent activity before turning it on.
- Scoped API keys and sudo mode. API keys can be limited to exactly what an integration needs, each with its own rate limit, and destructive account operations now require a fresh re-authentication (sudo mode).
- Spam handling without content scanning. A metadata-only spam policy: suspicious forwards can be quarantined per alias and released with one click. We still never read message bodies or subjects.
- Install alias as an app. The dashboard is now installable on your phone or desktop (PWA) — served entirely first-party, no app store, no third-party requests.
- MTA-STS enforce mode is live. Mail to alias is protected by an enforce-mode MTA-STS policy — downgrade attacks on delivery encryption are refused, not just reported. Check any provider on the public security scorecard.
- Trust & safety runbooks published. Our procedures for abuse reports, law-enforcement requests, and shared-domain rotation are now written down in the repository, so you can read exactly how we handle them.
Everything above is in the open-source repository, where the full history is public if you want more detail than a summary.