alias.mom
On this page
The four settings Turning a lock on does not break anything Letting a held sender through Doing it automatically What we can see

Locking an alias

An alias you gave to one shop should only ever hear from that shop. When mail turns up from somebody else, the address was sold, passed on, or lost in a breach.

Knowing that is useful. Ending it is better. Locking an alias means the senders it already knows keep working and anyone new does not, which turns a leaked address into a worthless one.

The four settings

On any alias page, under Who can write to this alias:

Open. Anyone can write. This is how every alias starts, and it is the right setting for most of them. The cost is that a leaked address keeps working for whoever leaked it.

Locked, held for review. Senders it already knows keep arriving. Anyone new is held for you to look at, and one click lets them through. This is the one to pick if you are not sure, because a wrong guess costs a click rather than a delivery. The cost is that you have to check, and the sender is not told their mail is waiting.

Locked, forwarded with a warning. Everything still reaches you; mail from a sender the alias has never heard from arrives marked as unknown. Nothing is actually stopped, so this tells you about a leak rather than ending it.

Locked, new senders dropped. Only known senders get through. Everyone else is dropped on arrival, with no bounce. If the address was on a form you filled in last week, that reply never reaches you and you never find out.

Turning a lock on does not break anything

The moment you lock an alias, every sender it has already heard from is approved. Somebody locking their bank alias after a leak scare should not stop hearing from their bank.

A lock is about what happens next. It has no effect on the correspondence the alias exists for.

Letting a held sender through

Held senders appear at the top of the alias page. Approving one lets their mail through from now on. It does not release anything already held: that is sitting in the alias's held mail, where you can read it and decide.

Doing it automatically

Settings has a switch: lock an alias automatically when a second company writes to it. With it on, we lock the alias the moment we notice, and the email telling you about the leak says we already did.

It is off by default, and that is deliberate. It acts while you are not there, on a rule of thumb that is right most of the time but not always. A payment processor, a ticketing system, or a receipt forwarded on your behalf all look exactly like a leak from the outside. So it holds mail rather than dropping it, and it never overrides a setting you chose yourself.

What we can see

The same thing as always: who wrote and when, never what they said. A lock is decided entirely from the sender's address. See what we store.


Something here wrong or missing? Tell us. These pages live in the same repository as the code, so a correction is a one-line change.