Email & Privacy Glossary

Plain-language definitions for the terms that come up constantly in email privacy, each linking to a fuller explanation.


Plain definitions for the terms that come up constantly in email privacy, and which are routinely used to mean two different things. Each links to a fuller explanation.

Addresses and routing

Email alias. A separate email address that delivers to an inbox you already read. Permanent, private, and switchable off individually. Full explanation.

Masked email. Another name for an alias, used by Apple, Fastmail and others. Same mechanism.

Disposable / temporary email. An address designed to expire, usually within minutes or hours, often with a public inbox anyone can read. Fine for a one-off download; useless once you need a password reset. Compared with aliases.

Burner email. Ambiguous — people use it for both a genuinely temporary address and a permanent alias they intend to discard later. Worth clarifying which is meant before following anyone's advice.

Email forwarding. The underlying mechanism: mail arriving at one address is passed on to another. An alias is forwarding plus the ability to manage each address separately.

Catch-all email. A domain configured to accept mail for any address at it, rather than only addresses created in advance. Means an alias can exist the moment you invent it; also means the domain accepts guessed addresses until you disable them.

Subaddressing (plus-addressing). you+shop@gmail.com delivering to you@gmail.com. Useful for sorting your own mail. Not a privacy measure — the real address is visible to anyone who deletes the tag.

Custom email domain. A domain you own, used for email. The reason aliases on it survive you changing provider. Why that matters.

How addresses escape

Email leak. Any event that puts your address in the hands of a party you didn't give it to — a sale, a share, a breach, or an acquisition. Broader than "breach", which is why the two aren't interchangeable.

Data breach. Unauthorised access to a system holding personal data. One cause of an email leak, not the only one.

Email harvesting / scraping. Automated collection of addresses published in plain text anywhere — forum profiles, WHOIS records, contact pages, PDFs.

Data broker. A company that compiles and sells personal information about people it has no direct relationship with. Full explanation.

People-search site. A broker that publishes profiles openly, searchable by name.

Senders and stopping them

Spam. Unsolicited bulk email. Legally, US commercial email is governed by CAN-SPAM, which is an opt-out regime — a sender does not need your consent first, only to stop when asked.

Phishing. Email designed to trick you into revealing credentials or installing malware. A subset of spam with a specific intent, and the reason not to click links in mail from senders you don't recognise.

List-Unsubscribe header. A header that lets your mail client show a one-click unsubscribe button instead of making you find the link. Honoured by legitimate senders; absent or fake on mail from operators who ignore the law.

Suppression list. A record a sender keeps of addresses that must not be mailed — people who opted out, and addresses that hard-bounced. Why a rejection at your end can do some of your unsubscribing for you.

Spam trap. An address created or repurposed specifically to catch senders using harvested or stale lists. Mail to one damages the sender's reputation.

Give every service its own address

Don't SPAM Me puts unlimited aliases on a domain you own. Any address at that domain starts working the first time mail arrives, and when spam turns up you know exactly which company leaked it. The software is free; you bring the domain, or register one during setup.

Get started — free

Keep reading