Skip to content

Email Anonymity Guide

Email was never designed for privacy. Even with an encrypted provider, the protocol leaks metadata (who emailed whom, when, subject lines on external mail), and any message to a normal Gmail user lands in plaintext on Google’s servers. “Anonymous email” is therefore about reducing exposure and separating identities, not achieving perfect secrecy. Pick tools by what you’re actually defending against.

ProviderJurisdictionNotes
Proton MailSwitzerlandE2EE at rest, large ecosystem (VPN, Drive), open-source clients, audited
Tuta (formerly Tutanota)GermanyE2EE at rest incl. subject lines; encrypts the whole mailbox; no IMAP (custom protocol)
Mailbox.orgGermanyStandards-based (IMAP/SMTP) with PGP support; less “walled garden”

These encrypt stored mail and mail between their own users; none can encrypt what an external sender delivers in cleartext. Note Skiff shut down in 2024 after its acquisition — don’t adopt it.

Alias services give every signup its own address that forwards to your real inbox, so a breach or spammer only learns a throwaway alias, and you can cut one off without changing your real address:

  • SimpleLogin (Proton-owned) and addy.io (formerly AnonAddy) — per-service aliases, reply support, and catch-all custom domains so you can mint service@yourdomain on the fly.

Aliasing layers on top of any inbox and is the single highest-leverage email-privacy habit for everyday use.

You are…PriorityFit
General privacyLess tracking, convenienceProton/Tuta + aliasing
ActivistJurisdiction, metadata, account separationProton/Tuta + aliases + Tor access
Journalist protecting sourcesStrongest separation; don’t rely on email aloneDedicated compartmented account + Signal/SecureDrop for the sensitive channel

For source protection, email is rarely the right primary channel — see OPSEC for Activists and Journalists.

Mail headers can expose the sending IP, client (User-Agent/X-Mailer), and timing. Reputable privacy providers strip the originating IP from outgoing headers, but subject lines and envelope sender/recipient are visible to external mail servers regardless. Assume the fact and timing of an email are observable even when the body isn’t; see Metadata Hygiene for attachments.

  • Sign up without a phone number — some providers require one for “abuse prevention”; choose ones that don’t, or register over Tor.
  • Pay without identity — use providers that accept cash/crypto, or a free tier; see Cryptocurrency Privacy.
  • Compartmentalize — never cross an anonymous account with a real-name one (shared recovery address, same browser session, same device). See Burner Devices Guide and Sock Puppet Accounts.
  • Access consistently — reach the account the same anonymized way every time (e.g. always via Tor); a single direct login deanonymizes it.