Email Anonymity Guide
Email Anonymity Guide
Section titled “Email Anonymity Guide”Email was never designed for privacy. Even with an encrypted provider, the protocol leaks metadata (who emailed whom, when, subject lines on external mail), and any message to a normal Gmail user lands in plaintext on Google’s servers. “Anonymous email” is therefore about reducing exposure and separating identities, not achieving perfect secrecy. Pick tools by what you’re actually defending against.
Privacy-respecting providers
Section titled “Privacy-respecting providers”| Provider | Jurisdiction | Notes |
|---|---|---|
| Proton Mail | Switzerland | E2EE at rest, large ecosystem (VPN, Drive), open-source clients, audited |
| Tuta (formerly Tutanota) | Germany | E2EE at rest incl. subject lines; encrypts the whole mailbox; no IMAP (custom protocol) |
| Mailbox.org | Germany | Standards-based (IMAP/SMTP) with PGP support; less “walled garden” |
These encrypt stored mail and mail between their own users; none can encrypt what an external sender delivers in cleartext. Note Skiff shut down in 2024 after its acquisition — don’t adopt it.
Aliasing
Section titled “Aliasing”Alias services give every signup its own address that forwards to your real inbox, so a breach or spammer only learns a throwaway alias, and you can cut one off without changing your real address:
- SimpleLogin (Proton-owned) and
addy.io (formerly AnonAddy) — per-service aliases, reply support,
and catch-all custom domains so you can mint
service@yourdomainon the fly.
Aliasing layers on top of any inbox and is the single highest-leverage email-privacy habit for everyday use.
Match the provider to your threat model
Section titled “Match the provider to your threat model”| You are… | Priority | Fit |
|---|---|---|
| General privacy | Less tracking, convenience | Proton/Tuta + aliasing |
| Activist | Jurisdiction, metadata, account separation | Proton/Tuta + aliases + Tor access |
| Journalist protecting sources | Strongest separation; don’t rely on email alone | Dedicated compartmented account + Signal/SecureDrop for the sensitive channel |
For source protection, email is rarely the right primary channel — see OPSEC for Activists and Journalists.
Metadata leakage in headers
Section titled “Metadata leakage in headers”Mail headers can expose the sending IP, client (User-Agent/X-Mailer), and timing.
Reputable privacy providers strip the originating IP from outgoing headers, but
subject lines and envelope sender/recipient are visible to external mail servers
regardless. Assume the fact and timing of an email are observable even when the body
isn’t; see Metadata Hygiene for attachments.
OPSEC for anonymous accounts
Section titled “OPSEC for anonymous accounts”- Sign up without a phone number — some providers require one for “abuse prevention”; choose ones that don’t, or register over Tor.
- Pay without identity — use providers that accept cash/crypto, or a free tier; see Cryptocurrency Privacy.
- Compartmentalize — never cross an anonymous account with a real-name one (shared recovery address, same browser session, same device). See Burner Devices Guide and Sock Puppet Accounts.
- Access consistently — reach the account the same anonymized way every time (e.g. always via Tor); a single direct login deanonymizes it.
Related
Section titled “Related”- OPSEC for Activists and Journalists — when email is part of a larger threat model
- Secure Messaging Comparison — often a better channel than email
- Cryptocurrency Privacy — paying for accounts anonymously
- Metadata Hygiene — scrubbing what you attach