Email Privacy

How email addresses get exposed, what you can actually control, and how to build a setup that limits the damage.


Email privacy usually gets discussed as encryption — whether the contents of a message can be read in transit. That matters, but it is not the problem most people actually have.

The common problem is the address itself. One address, given to several hundred organisations over fifteen years, each of which may share it, sell it, lose it, or be acquired by someone with different plans for it. Once it's in circulation there is no recall.

These guides deal with that: how addresses get exposed, how to work out who leaked yours, what you can genuinely control, and what no tool can undo. Where a claim is volatile it carries the date we checked it, and where something can't be verified we say so rather than filling the gap.

If you want the practical version rather than the background, start with a unique email address for every website — it's the single habit that changes the most.

Every guide in this hub

Give every service its own address

Don't SPAM Me puts unlimited aliases on a domain you own. Any address at that domain starts working the first time mail arrives, and when spam turns up you know exactly which company leaked it. The software is free; you bring the domain, or register one during setup.

Get started — free

Keep reading