Four layers, and they do different jobs: where mail is hosted, which address each organisation gets, what you disclose alongside it, and what you do about records already circulating. Most people buy one layer โ usually an encrypted provider โ and assume it covers the others. It doesn't. The layer that changes the most for the least money is the second one.
Layer 1 โ Where mail is hosted
What it decides: who can read your messages, and what a breach of your provider exposes.
An encrypted provider means the host can't read stored mail. That's a genuine benefit with a real limit: mail from people not using encryption arrives as ordinary email, and metadata is largely unprotected either way.
What it does not decide: anything about who has your address. Move to the most privacy-respecting host available and hand the new address to three hundred organisations, and your inbox looks identical. The distinction
Good enough: your current provider, if the contents aren't your concern. This layer is optional for most people.
Layer 2 โ Which address each organisation gets
What it decides: whether a leak is contained, whether you can identify the source, and whether you can revoke it.
This is the highest-value layer and the cheapest. One address per organisation means a breach at one company exposes something nobody else holds, spam names its own source, and you can cut off any single company without asking them.
Options run from free (DuckDuckGo, Relay's free tier) to a few dollars a year (your own domain). The trade-off is convenience versus owning the namespace. Which to pick ยท How to run it
If you do one thing, do this.
Layer 3 โ What you disclose alongside the address
What it decides: whether your record is a cheap bulk entry or a valuable segmented profile.
- Required fields only. Birthday, phone and postcode are what turn an address into a profile.
- Un-tick "share with partners" โ the sender's own marketing you can unsubscribe from; onward sharing you largely can't.
- Don't publish your address in plain text anywhere. Forum profiles, commit metadata, CVs, PDFs, WHOIS.
- WHOIS privacy if you register a domain, or you've solved an email exposure by publishing your home address. Details
Layer 4 โ Records already circulating
What it decides: your existing exposure, which the other three layers can't touch.
Search your own name. If people-search sites list your address and relatives, that's a removal problem: free via California's DROP if you're eligible, GDPR erasure in the EU and UK, manual opt-outs otherwise, or a paid service for breadth. The free routes
Removal is a treadmill by construction โ brokers re-ingest from sources you can't be deleted from โ so treat it as maintenance rather than a fix. Why
The order to build it
- Layer 2 first. Start giving each new signup its own address today. Free or nearly free, immediate effect, stops the problem growing.
- Layer 3 alongside it. Costs nothing, it's just a habit at the form.
- Layer 4 once, to see where you stand. Then decide whether it's worth ongoing effort.
- Layer 1 only if contents matter to you. It's the most disruptive change and the least connected to the usual complaint.
That order is deliberately the reverse of how these get sold.
What the finished thing doesn't do
- Not anonymity. You gave your real name to most of these organisations. The boundary
- Not retroactive. Layers 2 and 3 change what happens next; they don't unshare anything.
- Not permanent, for layer 4. Removal doesn't stay done.
- Not zero spam. The realistic outcome is rare, attributable and individually switchable.
More: the checklist, ordered by impact ยท the complete guide