alias.mom

Why bother with any of this

Three people who are not real, in situations that are. If you already know why you want an alias, you can skip this and go make one.

Maria bought a sofa

In 2019 Maria bought a second-hand sofa from a marketplace listing. The seller wanted an email address to arrange the pickup, so she gave the one she has used since she was nineteen. The sofa was fine. It is still in her living room.

Somewhere between then and now, that address left the marketplace. Maybe the seller sold their contacts. Maybe the marketplace was breached. Maybe a third party they shared data with was breached. Maria has no way to find out and nobody to ask.

She now gets about forty pieces of junk a day. Not the kind a spam filter catches cleanly, because a lot of it is technically legitimate: companies that bought a list, are complying with the letter of the law, and include an unsubscribe link that either does nothing or confirms the address is live.

Here is the part that traps her. That address is the login for her bank. It is on file with her doctor, her landlord, her employer, her children's school, and roughly two hundred accounts she has forgotten about. Abandoning it means finding all of them first.

So she does not abandon it. She keeps deleting. The cost of the sofa was eighty euros and six years of noise.

If she had handed over an alias, she could have deleted it in 2020 and everything else would have carried on exactly as before.

Tom is in a breach and does not know which one

Tom gets the notification everyone gets eventually: his address appears in a dump, alongside a password hash from a service that was using an algorithm nobody should have been using in 2014.

The notification names the company. Fine. But Tom, like most people, has some variation of the same handful of passwords across a couple of hundred accounts, and the interesting question is not "was this company breached". It is which of my accounts are now reachable by someone with this list.

He cannot answer it. His address is the same everywhere, so the leaked pair is a key that someone will now try in every lock they can find. That is credential stuffing, it is automated, and it is cheap.

The address is doing two jobs at once, and they are in conflict. It is how services reach him, and it is the thread that ties every one of those services to every other one.

With a separate address per service, a leaked pair opens exactly one door. And Tom would have known which company leaked it on the day the first junk arrived, without waiting years for a notification.

Priya wants one conversation to end

Priya shared a flat with someone for two years. It ended badly. He has her phone number, which she changed, and her email address, which she has not, because it is fifteen years deep into her life.

He is not doing anything a court would find interesting. He mails her every few months. Nothing threatening, nothing actionable, just the fact of him still being able to reach her whenever he decides to.

She can filter it. Filtering means the mail still arrives, is still delivered to her, and is moved into a folder by a rule she has to maintain. It also means she knows it is there.

What she wants is not a folder. She wants the channel to stop existing, and she wants that without telling two hundred other people her new address.

An alias would have let her delete the one route he had, in about four seconds, with no announcement to anyone and no effect on anything else.

The pattern underneath all three

One address for everything is a single point of failure that you cannot replace, cannot revoke in part, and cannot audit. Every relationship you have ever entered runs through it, so it becomes more expensive to change with every year that passes, which is precisely backwards: the longer it has been exposed, the harder it is to do anything about.

An alias is not clever. It is one address per relationship. That is the whole idea, and the reason it works is boring: when each relationship has its own door, you can close one without closing the rest, and you always know who gave your address away, because only one person had it.

What this does not fix

A page like this normally stops at the paragraph above. Here is the rest, because you will find it out anyway and we would rather it came from us.

It does not make you anonymous. The shop still has your name, your address and your card. An alias covers one identifier out of several, and it is the one most easily traded, but it is one.

It does not protect mail from us. For a forwarding alias, your mail passes through our servers in plaintext. We do not store it, but it exists here for the moment it takes to send it on, and we could in principle be compelled to capture it going forward. If that is your threat model, use an inbox-only alias with the private inbox on, where the mail is sealed to a key we do not hold. That mode has its own costs and the page says what they are.

Aliases on our domains depend on us existing. If we disappear, so do they, and so does access to whatever you registered with them. Aliases on a domain you own do not: you repoint one DNS record and every address keeps working, whoever runs the service. That is the strongest argument on this entire page and it is an argument for owning a domain, not for using us.

We are young. Nobody has audited us. Our sending reputation is still being built. If you want a service with a decade of history, that is a fair thing to want and we are not it yet.

These people are made up

Maria, Tom and Priya do not exist. The situations are ordinary to the point of being boring, which is the point: this is not a tool for people with dramatic threat models. It is for anyone who has ever given an address to a company and then wished they had not.

Start with one

You do not have to migrate anything. Make one alias, use it for the next thing that asks, and see whether you like knowing where your mail comes from. Signup takes no email address and no password.

Create an account Read the docs first