Fake emails: the questions people actually ask

·

Short answers, in the order they come up. Where something is worth more than a paragraph, there is a link.

Can I receive mail at this address?

Yes — that is the whole point. The address exists on a live mail server from the moment you take it, and anything sent to it appears on the page by itself, usually in about a second. Nothing to install, no account.

Can I send mail from it?

No, and this will not change. An outbound channel is the exact thing that turns a convenience into a spam tool: within days the domains would be on every block-list in circulation, and the cost would land on everyone using the site to receive an ordinary confirmation code. Receiving stays useful precisely because sending is not on the table.

Who else can read my messages?

Anyone who knows the address. There is no password, because there is no account — the address is the key. That is a deliberate trade: it is what makes the mailbox instant.

In practice this matters less than it sounds, because addresses are not guessable in any useful way and nobody has a reason to look for yours. It matters a great deal for one thing: do not use a generated address for anything you would be sorry to lose — banking, government services, account recovery.

How long does the mailbox last?

Several days. Long enough that a confirmation sent tomorrow still finds you, short enough that an abandoned inbox does not sit around forever. If you need an address that lasts, attach a domain of your own — then it lives as long as the domain does.

A website refused my address. Why?

Almost always a block-list on their side, not a fault on ours: some services keep lists of domains known to hand out fake email addresses and reject anything arriving from them, usually with a vague error that explains nothing.

The practical answer is to pick a different domain — which is precisely why more than one is offered. If you want to know whether a domain can receive mail at all before you rely on it, the domain debugger reads its live DNS and tells you.

The full version of this answer — including the case where the form accepts the address and then nothing arrives — is on its own page: a site will not accept your fake email.

Are attachments safe to open?

They are as safe as attachments anywhere else, which is to say: it depends on the file, and you have to look. We do not strip or disinfect files — we flag them. Two levels of warning appear next to the attachment: one for file types commonly used to deliver something harmful or with a name designed to confuse, and a stronger one for types that can run programs on your computer.

⚠️
Anyone claiming to remove “100% of all possible threats” is guessing. Read the warning, and if a file you did not expect arrives with a message you did not ask for, do not open it.

Why would I add my own domain?

It is one MX record — how to attach one.

Is this a “real” address or a fake one?

Both words are right about different things. Technically it is entirely real: real domain, real MX records, ordinary SMTP delivery — no sender can tell from the protocol that it came from a generator, because at the protocol level there is nothing to tell.

What is fake is the link between the address and you. It carries no name, no phone number, no billing detail and no history anyone can follow back. The address is real; the identity behind it is not.

What do you keep about me?

The honest answer is “less than you would expect, but not nothing” — and the detail belongs in one place rather than in a summary that drifts out of date. It is written out in the privacy policy: what is stored, for how long, and what leaves the server.

Something is not answered here

Use the Feedback link in the footer of every page. Questions that come up more than once end up on this page.

All articles