Email Privacy Basics
position: 28
Email was designed in an era that assumed everyone involved was trustworthy. A few of its properties follow from that assumption and surprise people who have never had reason to look.
Your address is an identifier, not a contact detail
To a marketing system, your address is a primary key. It is stable, unique, and you carry it between services, which makes it ideal for joining records that would otherwise stay separate.
Data brokers rely on this. A purchase from one shop, a signup at one site and a survey answered years ago can be combined into a single profile because the same address appears in all three. Nothing in the process required your consent beyond the terms you accepted at each individual step.
Using different addresses for different services breaks that join. This is the single largest practical improvement available, and it costs nothing.
Opening a message reveals more than you expect
Most marketing mail contains a tracking pixel: a tiny image with an address unique to you. When your client loads it, the sender learns that you opened the message, roughly when, roughly where you were, and what kind of device you used.
Links are usually tracked too. The link you see and the link you follow differ: the visible one points at a redirect service that logs the click before sending you on.
Blocking remote images stops the pixel. Most clients can do this, and it is the one setting worth changing. On this site messages are shown with remote images enabled, because otherwise most legitimate mail looks broken. If that matters for a particular message, do not open it here.
Mail is not private in transit or at rest
Transport between servers is usually encrypted now, but the message sits readable at each end. Your provider can read your mail, and the recipient's provider can read it too. Anyone who compromises either account can read everything in it.
For most correspondence this is acceptable. For anything genuinely confidential, email is the wrong medium, and no service, this one included, changes that.
The habits that matter
A different address per service. Aliases for the things you keep, disposable addresses for the things you do not.
Block remote images by default. Kills the tracking pixel in one setting.
Never publish an address in public text. Scrapers find it within days.
Check where a link goes before following it. Long redirect addresses in a message you did not expect deserve suspicion.
Do not use unsubscribe links from senders you do not recognise. For a legitimate company they work. For a spammer they confirm that a human reads the address, which makes it worth more.
Keep a real address for the small number of things that need one, and give it out rarely.
What a disposable address does and does not do
It removes one specific risk completely: the address you handed over cannot follow you, because it stops existing. Whatever a company planned to do with it, it can no longer do.
It does nothing about the message content, about tracking pixels in messages you open, or about anything else you typed into the same form. If you filled in your name, your name is still on the form.
Think of it as one tool that solves one problem thoroughly, rather than a privacy measure in general. Used that way it is genuinely useful, and it takes no effort at all.