Acceptable Use Policy

Most people will never need this page. It exists so that the few who would misuse a fake email address know exactly where the line is, and so everyone else can see the line is drawn.
If a case is not listed below, apply the test the whole policy is built on: does this protect my privacy without deceiving, impersonating or harming anyone else?
What the tool is for
- One-off sign-ups, gated downloads and trials you have no intention of keeping.
- Keeping marketing — and the next database leak — away from an address you actually use.
- A single verification code for a site you will not return to. The FAQ covers what to do when a code does not arrive.
- Testing your own sign-up and password-reset flows against a real mailbox instead of a mock.
- Running a domain of your own through here so that block-lists stop being your problem — see add a new domain.
These have one thing in common: they protect you, and the only thing the other side loses is a permanent address you were never obliged to give.
What is not allowed
- Fraud and deception for gain — scams, phishing follow-through, fake reviews, payment fraud.
- Impersonation and harassment — accounts made to pose as someone else, to stalk or threaten, or to get around a block someone placed on you.
- Ban evasion to keep harming a platform or its community after being removed for cause.
- Reaching inboxes that are not yours. Addresses here are guessable by design; deliberately guessing usernames to read other people's mail, or to take over their accounts, is prohibited.
- Getting past identity checks that exist for a legal reason — banking, government services, age-restricted services.
- Illegal content — child sexual abuse material first and foremost. Zero tolerance, reported where the law requires it.
- Mass automated abuse — scripted bulk account creation, fake engagement, vote manipulation, credential-stuffing support.
The list is not exhaustive. The thread running through it is harm to someone else.
Extra rules if you point your own domain here
A domain of yours in our mail flow is your property inside our infrastructure, so two conditions come with it:
- It has to be yours. Pointing a domain you do not control, or one obtained by deception, at our server is a breach of this policy on its own — before anything is sent to it.
- It carries your reputation and ours. A domain used for fraud or bulk abuse will be refused, and that decision is not open to negotiation. Everything else in this policy applies to mail on your domain exactly as it applies to ours.
Why spam cannot be sent through this service
Worth stating plainly: the service is receive-only. No compose button, no outbound path, no SMTP credentials for sending — the capability does not exist. Nothing ever leaves an inbox, so no generated address can be used to send anything. That is a structural fact, not a promise. What this policy adds is the part architecture cannot cover: using a received code to stand up an account whose purpose is to harm.
Public inboxes are your responsibility
There is no password, so anyone who knows or guesses an address reads the same mail. For anything even slightly sensitive, leave the random username as generated rather than choosing something obvious — a guessable name is the difference between an address nobody finds and one anybody can. The settings that control what the browser remembers between visits are described in settings.
How abuse is handled
Operator access to inboxes is kept to a minimum and used only to investigate suspected abuse, answer a valid legal request, or keep the service running. On finding misuse we may purge an inbox, block an address, drop a domain from rotation, or restrict access — without notice where the situation calls for it. Access to inboxes is never sold. What is stored and for how long is in the privacy policy.
Reporting abuse
If someone is using the service against you or others, tell us through the Feedback link in the footer of every page. Include the address or username involved and what happened — without those two we usually cannot act.
Changes
This page is updated as new forms of abuse appear. Continuing to use the service after a change means accepting the current version.
What the service does and what it deliberately does not do is described on the front page; what is stored and for how long — in the privacy policy.