Seven Ways to Make Your Email Aliases Even More Secure

Email aliases were once a niche privacy trick. Now, though, they’re a mainstream solution offered by any number of major email service providers, including Apple, DuckDuckGo, SimpleLogin, and Firefox.  Getting a basic alias set up and running to conceal your real email address is easier than ever—but given recent data leaks and sophisticated cyber attacks, it’s increasingly clear that a basic setup only gets you so far.

That’s why cybersecurity experts now recommend having a nuanced email alias strategy that combines multiple aliases and secure authentication protocols to keep your real inbox away from prying eyes. As a journalist often working on sensitive topics involving security and compliance, I’ve been using email aliases for almost a decade. Here are some tips that have saved me a lot of privacy hassle over the years.

Why you should use email aliases

“Email aliases” refers to swapping your real email address with a stand-in that can forward emails to your primary inbox. That way, senders don’t need to know your real email to communicate with you, and you can easily decommission aliases if they are targeted by too much spam.

Email aliases have been a standard practice for users who have to communicate sensitive information and maintain a degree of privacy, like journalists, lawyers, corporate executives, and public figures who expect to be targeted by spammers and cyber attackers. However, they don’t replace real account security and won’t stop anyone from breaking into your account if they somehow find your real email address.

Moreover, recent technological developments have made email aliases harder to maintain due to deliverability issues and data leaks. It’s still fine to use email aliases to keep your inbox private, but you need an actual strategy to preserve your privacy now that spammers have grown much more sophisticated.

Why your email aliases need a strategy

Email aliases hide your real address from the recipient, but not from your email provider or anyone determined to cross-reference your details from leaked data. So if you use the same alias everywhere or route every email to the same inbox without other safeguards, your email only looks private. Determined attackers can and will find ways to exploit that single point of failure. 

Then there’s the other issue that no one warns you about. Most modern email services, including Gmail and Outlook, have built-in identity verification and will send shared alias domains straight into spam. If you want to get around this, not only do you need to set up your own custom domain for email aliases, but also properly configure your domain with authentication protocols like SPF and DKIM. 

And finally, your email alias provider itself may be compromised, revealing your forwarding address through email headers, as in the case of Apple Mail. Alias providers may also have other points of failure, like the broken sync features in ProtonMail that many have complained about. So relying entirely on a single provider without a custom domain setup is a major red flag. 

Clearly, you need to plan out your email aliasing strategy from the beginning to avoid missing important emails, being relegated to the spam folder, or leaking your private inbox through faulty technical implementation from your email service provider.

Segment aliases by service, not only by relationship

Most users prefer to maintain a bunch of aliases dedicated to different relationships, like one for personal emails, one for their work colleagues, one for scheduling meetings and appointments, one for streaming services, and so on. This works fine as a convenience hack to keep your inbox clutter-free, but it doesn’t insulate an alias if one of the services or applications associated with it experiences a data breach. 

For example, if you had a single email alias that you relied on for all your banking and financial activity, Experian’s infamous 2015 data breach could have compromised all your financial services using that single vulnerability. 

Privacy-conscious experts recommend maintaining a separate email alias for each service, such as one for Netflix and a completely different one for Apple TV, then bundling them under a single subdomain on your custom domain that’s specific to streaming services. That means your Netflix alias ends up looking something like yourname.netflix@streaming.yourdomain.com. So if one platform experiences a breach, your other aliases for similar services still remain private. 

Don’t rely on “plus addressing” if you want privacy

A common way to generate email aliases is to simply add a + sign next to your real email, such as yourname+streaming@yourdomain.com. This is fine for decluttering your inboxes, but doesn’t actually secure your email address because anyone can guess your real email address by removing everything after the + sign. 

Instead, it’s better to use a combination of randomly generated words or hashkeys. If someone sees an email alias that reads LJzcR7cHhZ9Q3sW4MTJk@yourdomain.com, that doesn’t do anything to help them figure out the other email aliases on that same domain. This is especially useful if you aren’t using a custom domain yet and relying on a shared domain from your email provider or aliasing service, because those are even easier to guess. 

Use a custom domain if you’re going all-in on aliasing

Relying on your alias provider’s shared domain, like @simplelogin.io or @gmail.com, is problematic for at least a couple of reasons. For one, it makes it near-impossible to divest from that domain if you ever want to switch to a different email or alias provider. Whereas if you use a custom domain, you can just point that domain to your new aliasing service if the old one is no longer safe or convenient. 

But aside from being locked into an email or alias service, you may also hurt your deliverability rates: A lot of these domains have poor spam scores that don’t pass most inbox filters. With a custom domain, you can set up your own domain authentication via SPF, DKIM, and DMARC. That way, inboxes assign you a separate spam score based on your own email activity, not the collective behavior of everyone else using that shared domain. 

This is why a custom domain is a worthy investment if you want to keep using email aliases as a long-term privacy tactic. You have better ownership of your data and can set up business-level security features that aren’t available to free shared domain emails. 

Pay attention to the email headers

Here’s what happened with people using the Hide My Email service in Apple Mail before July 7: Normally, Hide My Email generates a random two-word alias to conceal your real email from recipients, but due to a technical flaw, an attacker could easily uncover your real address by targeting your inbox with spam mail. They would simply spam your alias and wait for Apple Mail’s filters to respond back with a rejection notification, which would contain your real email address right there in the email header.

Whenever you receive an email forward from your aliasing service, expand the header section to make sure your real address isn’t revealed in the email metadata. (On Gmail, it’s the little dropdown next to the recipient name at the top of your mail.) If you see a “Forwarded-To” field with your real email in the message header, that means you have a leak. 

Back up your alias lists frequently

Many providers bundle their email aliases with a password manager for easy access management, but that comes with its own risks. 

Several users on the Privacy Guides forum note that they accidentally deleted all their SimpleLogin aliases when trying to clear the Proton Pass logins associated with those accounts. Apparently, Proton has an auto-sync feature connecting the two services that works both ways. It’s even worse if you’re not using a custom domain, because then those aliases are lost for good unless you can reacquire them. 

You should regularly back up your list of email aliases in a text document or spreadsheet so that in case they end up getting deleted, you can create fresh ones with identical names and prevent important emails from bouncing off. 

Poison old email aliases before decommissioning

Many email providers retain records of your deleted account data for months or even years to comply with legal regulations. This makes them a common target for data brokers who scrape these accounts for any useful information. Luckily, there’s a simple fix. 

When you’re about to delete an old email account or alias, make sure to replace any personal details associated with that account with random values before you shut it down. This includes your name, address, date of birth, and any associated payment details that could be used to single you out. 

Keep a non-aliased backup contact method 

With many popular email providers like Gmail and Outlook cracking down on email aliases, you’ll often encounter a situation where using an alias to communicate is simply not feasible. Many inboxes have spam filters that bounce emails sent from random aliases or refuse to honor forwarding requests from your alias provider. It’s a compounding effect as well, because the more that email services reject emails from an alias, the worse it is for your alias’ reputation and deliverability rates. 

For banking platforms, important package deliveries, legal communications, and other priority email messages, consider maintaining a direct inbox that does not hide behind an alias or rely on email forwarding to receive messages. This can serve as a fallback for situations where missing an email is just not an option.

Comments are closed.