Why bother with any of this
Three people who are not real, in situations that are. If you already know why you want an alias, you can skip this and go make one.
Maria bought a sofa
In 2019 Maria bought a second-hand sofa from a marketplace listing. The seller wanted an email address to arrange the pickup, so she gave the one she has used since she was nineteen. The sofa was fine. It is still in her living room.
Somewhere between then and now, that address left the marketplace. Maybe the seller sold their contacts. Maybe the marketplace was breached. Maybe a third party they shared data with was breached. Maria has no way to find out and nobody to ask.
She now gets about forty pieces of junk a day. Not the kind a spam filter catches cleanly, because a lot of it is technically legitimate: companies that bought a list, are complying with the letter of the law, and include an unsubscribe link that either does nothing or confirms the address is live.
So she does not abandon it. She keeps deleting. The cost of the sofa was eighty euros and six years of noise.
If she had handed over an alias, she could have deleted it in 2020 and everything else would have carried on exactly as before.
Tom is in a breach and does not know which one
Tom gets the notification everyone gets eventually: his address appears in a dump, alongside a password hash from a service that was using an algorithm nobody should have been using in 2014.
The notification names the company. Fine. But Tom, like most people, has some variation of the same handful of passwords across a couple of hundred accounts, and the interesting question is not "was this company breached". It is which of my accounts are now reachable by someone with this list.
He cannot answer it. His address is the same everywhere, so the leaked pair is a key that someone will now try in every lock they can find. That is credential stuffing, it is automated, and it is cheap.
With a separate address per service, a leaked pair opens exactly one door. And Tom would have known which company leaked it on the day the first junk arrived, without waiting years for a notification.
Priya wants one conversation to end
Priya shared a flat with someone for two years. It ended badly. He has her phone number, which she changed, and her email address, which she has not, because it is fifteen years deep into her life.
He is not doing anything a court would find interesting. He mails her every few months. Nothing threatening, nothing actionable, just the fact of him still being able to reach her whenever he decides to.
She can filter it. Filtering means the mail still arrives, is still delivered to her, and is moved into a folder by a rule she has to maintain. It also means she knows it is there.
An alias would have let her delete the one route he had, in about four seconds, with no announcement to anyone and no effect on anything else.
The pattern underneath all three
One address for everything is a single point of failure that you cannot replace, cannot revoke in part, and cannot audit. Every relationship you have ever entered runs through it, so it becomes more expensive to change with every year that passes, which is precisely backwards: the longer it has been exposed, the harder it is to do anything about.
An alias is not clever. It is one address per relationship. That is the whole idea, and the reason it works is boring: when each relationship has its own door, you can close one without closing the rest, and you always know who gave your address away, because only one person had it.
What this does not fix
A page like this normally stops at the paragraph above. Here is the rest, because you will find it out anyway and we would rather it came from us.
It does not make you anonymous. The shop still has your name, your address and your card. An alias covers one identifier out of several, and it is the one most easily traded, but it is one.
It does not protect mail from us. For a forwarding alias, your mail passes through our servers in plaintext. We do not store it, but it exists here for the moment it takes to send it on, and we could in principle be compelled to capture it going forward. If that is your threat model, use an inbox-only alias with the private inbox on, where the mail is sealed to a key we do not hold. That mode has its own costs and the page says what they are.
Aliases on our domains depend on us existing. If we disappear, so do they, and so does access to whatever you registered with them. Aliases on a domain you own do not: you repoint one DNS record and every address keeps working, whoever runs the service. That is the strongest argument on this entire page and it is an argument for owning a domain, not for using us.
We are young. Nobody has audited us. Our sending reputation is still being built. If you want a service with a decade of history, that is a fair thing to want and we are not it yet.
These people are made up
Maria, Tom and Priya do not exist. The situations are ordinary to the point of being boring, which is the point: this is not a tool for people with dramatic threat models. It is for anyone who has ever given an address to a company and then wished they had not.
Start with one
You do not have to migrate anything. Make one alias, use it for the next thing that asks, and see whether you like knowing where your mail comes from. Signup takes no email address and no password.