The Email Privacy Checklist

Ordered by what actually moves the needle, not by what's easy to write.


Fourteen checks, ordered by how much difference each one makes โ€” not by how easy it is to write about. The top four are worth more than everything below them combined: use a different address per service, never publish your address in plain text, use unique passwords, and turn on two-factor authentication where it matters. Two widely-repeated pieces of advice are on the list too, marked as ineffective, because knowing what not to bother with is also useful.

High impact

1. A different email address for each organisation

The only measure that changes what a leak costs rather than trying to prevent one. Attribution becomes automatic, and any single company's route to you becomes revocable. How

2. Never publish your address in plain text

Check the places people forget: personal sites, forum profiles, public code repositories and commit metadata, CVs on job boards, PDFs, community directories, and WHOIS records for any domain you own.

3. Unique passwords, stored in a password manager

Not strictly email privacy, but it decides whether a leaked address is an annoyance or an account takeover. Credential-stuffing is the standard follow-up to any breach.

4. Two-factor authentication on your email account first

Your inbox is the reset route for everything else. Secure it before anything downstream.

Worth doing

5. WHOIS privacy on any domain you own

Otherwise you've traded an email exposure for a name-and-postal-address one.

6. Give less away at signup

Required fields only. Optional ones are how a bare address becomes a profile. The signup routine

7. Un-tick "share with partners"

The sender's own marketing you can unsubscribe from. Onward sharing you largely can't.

8. Block remote images by default

Stops most open-tracking pixels reporting back. How tracking works

9. Check your breach exposure once

Then let a free alerting service tell you about new appearances. Repeated manual checking achieves nothing. Reading the result correctly

10. Unsubscribe from senders you recognise

Legally backed and effective for compliant companies. Don't click anything in mail from senders you've never dealt with. Telling them apart

11. Keep the spam filter trained

Report rather than delete, and check the junk folder occasionally in both directions.

12. Search your own name once

If people-search sites list your address and relatives, that's a removal problem and a different fix entirely. Whether you need a service

Skip these

13. Obfuscating your address as "name [at] example [dot] com"

Mildly effective around 2005. Parsed trivially now. All it reliably does is inconvenience the humans trying to contact you.

14. Using a VPN for email privacy

A VPN protects your network traffic. Your email address travels inside the message and the recipient reads it either way. No effect whatsoever on who holds your address. Good tool, different job. Why

What none of it achieves

Nothing here makes you anonymous, and nothing recalls data already in circulation. The realistic outcome is that unwanted mail becomes rare, attributable, and individually switchable โ€” not that it disappears. Anyone promising more is selling something.

More: the complete guide to email privacy ยท how to protect your email address

Part of the Email Privacy guides.

The full picture: The Complete Guide to Email Privacy

Give every service its own address

Don't SPAM Me puts unlimited aliases on a domain you own. Any address at that domain starts working the first time mail arrives, and when spam turns up you know exactly which company leaked it. The software is free; you bring the domain, or register one during setup.

Get started โ€” free

Keep reading