Firefox Relay
relay.firefox.com
relay.firefox.com
It won't get banned by some services, you have complete control over the domain and account, you can send email from any address you wish, you can sign up for domain-wide haveibeenpwned alerts by verifying domain ownership via TXT records, and you don't have to worry about the service going out of business in 2 years.
After going through my password manager last year and changing as many logins and emails as I could, I've found several services that have sold my email address to third parties and one that was hacked. It's a relief to know I don't have all my proverbial email eggs in one basket.
There is the caveat of the domain getting into the wrong hands, if you look long enough down the road. What if you die, or simply can't afford to renew the domain well into the future? I know if I could look down from heaven after I die and saw someone re-registering my dropped domain, I would be furious!
Then there is the issue of even when you're alive, you could simply refuse to renew for whatever reason and the domain is suddenly someone else's.
MarkMonitor and Epik are the only companies that I know of that can safeguard against this. Epik has so called 'forever domains' and ensure the domain stays active well into the future.
But if my custom-domain email provider closes shop, I can at least take my domain with me.
You have a point though, I should just prepay for the next 10 years of my domain, and set myself a reminder to renew in 9 years :-)
There might be similar caveats with other TLDs but I only have experience with .com
I think we are at the point that a noun becomes a verb to say how good or bad (Godaddys case) something is!
I've been doing this years and I usually use the domain I'm signing up for as the address. Beware tho some people get really confused by how email works. I was requesting quotes for a home improvement project and I've had employees at these companies think I was either friends with the owner or that I hacked their email.
"My email/username for Warby Parker is 'warbyparker.com@...'"
"No, they need your email, not theirs."
"..."
Got asked that once after specifying sixt@mydomain when renting a car
I had a customer support on the phone insisting I was not giving them a valid email. “It should have something like @gmail.com or @yahoo.com”.
You'll still be able to filter on it, or know if anyone sold your address for spam, or be able to abandon the address if you need to.
Do those bots really exist? I would think the TLD I use is just not interessting enough for them, but it's from a big country.
I have never seen bots try random addresses on a subdomain.
That way, it’s super easy to know which service is actually either spamming me, or leaked my email address.
Most of this is “tech salesperson” spam or corporate newsletter type stuff. But they bought my email address, and are sending unsolicited mail, so I report it all hoping to harm their reputation with Google and Microsoft.
It would be interesting to do something like this with signatures. You could generate new addresses "on the fly" by picking a prefix and signing it. Then you can use this email and it can't be modified in a way to generate a new valid email.
For example you could have walmart-oaiua83n@yourdomain.example and they couldn't just change it to goodcompany@example.com.
(I use fastmail to host. This is the only reason I can't use Hey yet.)
wolmart.yq@example.com
w+2 = y and o+2 = q
Sort by cheapest renewal.
For example, you can register and renew a .feedback domain for $1.49 a year.
In my case I use my CC TLD. I'm in a generally stable nation that follows the rule of law and the administrator of the CC TLD has all sorts of processes in place that I have access to as far as regaining control of the domain if it's inappropriately transferred, making appeals, etc.
The extra $10 or so a year this costs is very much worth it to me as basically a form of insurance.
This is a terrible solution. Updating aliases takes a few seconds, you can even shorten this time by creating a simple script adding the new alias and updating the aliases db.
If I want to block an incoming address it's a few clicks away, I've just never needed to because spam filtering works pretty well. Perhaps that might change some day and I'll switch to a whitelist approach.
I may use the * in the future for custom emails for groups of concerns (jobs@domain or applications@domain, hn@domain, banking@domain), but I'm worried it will just add to the heaping mental overhead I already experience when working with email (what was my address I use for this again...?, etc). I can't help the feeling that it's just a matter of time before it starts to look like my original email account where even unsubscribing from things seems like a labor of Sisyphus, but this time with the added noise of it going to an email naming system I've lost control of.
They're all tucked away in your password manager anyway, so there isn't any effort or tracking needed.
I've had this system for about two years now and have yet to receive any junk mail with the new domain.
Sending email is complicated.
The IP reputation matters a lot, followed by the content itself. I don't think email recipient servers downright mark all lesser known senders as spam.
(Source, I run https://owlmail.io and this is a common question.)
This makes it harder to just randomly spam <anything>@example.com because you need the subdomain, which is what spammers do - just randomly generate local parts that might exist. info, john, sales, etc.
nvm, it's in the FAQ:
"What happens if Mozilla shuts down the Firefox Relay service?
We will give you advance notice that you need to change the email address of any accounts that are using Relay aliases."
Note that one cannot reply using this service (yet). So the whole anonymity is gone as soon as one wants to contact some service without disclosing the real address (?)
The same thing if any other company did it. That said, I do hope they'll offer an option to pay for more email relays which could also ensure its viability. Having 5 relays for free is nice, but I'd personally use a unique address per service.
[3] https://gitlab.com/timvisee/ffsend/-/issues/100#note_3763163...
Yeah, the instance is available at: https://send.vis.ee/
The only thing I'm worried is that this domain will soon be blacklisted by services (especially those I don't want to give my email address to).
Services usually just verify you control the new email address.
As a token of confidence, I've moved all ~150 of my online accounts (including all banking, financial, and healthcare accounts) to Owl Mail – it needs to exist for my life to operate smoothly.
Does your system track which online service gets which email, or do you track that yourself in a password manager?
2. An upcoming feature will enable the creation of sender 'allow' and 'deny' lists for each Owl Mail address (With default sender 'allow' lists for top sites). Currently I track my account credentials in a password manager. A browser extension is also on Owl Mail's roadmap.
Big name websites generally have enough users that email "just works". Smaller websites are more likely to use misguided measures such as a bad email validating regex (hello to anyone with a non-standard TLD!), only allowing gmail, or blacklisting domains like these.
The only correct to validate email addresses is to just send a message there and see if the user can click the confirmation link.
Chances are that would be the next step in any signup flow anyway, so why introduce this artificial middle step of "validating the email address"?
From my personal experience it is best to have a secondary email account on a provider that is usually not blocked (like gmail), to keep your primary email account clean.
Ever heard of Magento? They have that built in, at least in version 1. But it's a fixed list with "valid TLDs", anything not on that is not accepted when registering.
Feels strange, when you can't register on your own shop...
People can have more than one email address, so if your goal is "one account/offer/trial membership per real person", email ain't the way to achieve that, period.
Even worse are sites that disallow registering via "freemail providers" and require you to "use your ISPs or employer's". (Haven't seen this one in a while, but it definitely used to be a thing.)
My sites and apps have a blacklist and we don't allow email accounts from those. It's just me running this thing. If I had the security and engineering workforce of even a mid-sized tech company, I wouldn't have to do this. Alas.
I use owlmail.io for hundreds of accounts (major sites included) and haven't had an issue.
You can use unlimited custom domains and create disposable aliases on the fly as well!
(I'm the creator, lmk any questions!)
So how do you prevent abuse?
I've discovered some cool new products in this thread and Forward Email looks great. I'm glad there are other people out there working on solving this problem!
I store aliases in DB along with a short description of to whom they were issued, and some extra flags. My mail client then highlights emails sent to these aliases in green color and shows their description instead of the alias itself in the "From" column of the message list.
I always give random aliases to online services, eshops, shipping companies, etc. These private aliases will never receive SPAM, or phishing, unless leaked by the company.
Anything that looks like a transactional email from some service, and is not sent to private alias, just gets deleted right away. It's not even worth opening, no matter how good it looks.
And I can keep my phishing guard up on much lower volume of green emails. It also makes whitelisting transactional email easier, without allowing random SPAM to the Inbox, because filtering based on the "shared secret" per company delivery address will allow in all important email from the company, regardless of how or from what address it was sent.
What a letdown to see this service so quickly retired.
- Access your data for all web sites
If even the browser vendor can't do better than requesting access to everything I'm not surprised that we end up with extensions being sold and abused (for their permissions).
Most extensions I could consider are only needed for few pages.
Yeah, the all_urls add-ons are always concerning. We have an issue filed to move that to optional_permissions instead, but need to get the UX right:
> Any emails larger than 150KB will not be forwarded.
I'm not sure what to think of the size limitation. I wonder what percentage of emails are under that.
[0] https://anonaddy.com/blog/sending-email-from-an-alias-and-up...
One of the best things about AnonAddy is that it allows you to create aliases on the fly. So, I hardly even need to visit their website, browser extension or anything.
Unfortunately HackMD rejects the anonaddy.com TLD, so I've had to use my "real" address there, but so far everywhere else it works fine. A clever friend realized you can register a new github account with an anonaddy address and use that to connect to HackMD. Smart.
Great service. Free tier is great. Will probably end up paying and adding my own domain for the odd site that rejects theirs.
The only feature I'd like is greater bandwidth allowance per month on the lite plan. Current limits are 10MB per month free tier, 50MB on $1/mo lite tier, and unlimited on Pro. But fair enough.
Later I had my own domain, and did the address-per-site thing. Which was an absolute nightmare to undo when I sold the domain (grepping thru the raw self-hosted mbox and logging into and changing my email on hundreds of sites), although it was a great excuse to get going on using a password manager.
At this point I could use "plus addressing" at Fastmail (e.g. amazon+me@domain.com), but I find the endeavor pretty pointless. My spam is low, and I never once found it especially valuable to be able to identify or isolate an offending domain.
I don't expect that Firefox will go "full Bigfoot" on this one in terms of ads and fees but shutdown is a PITA risk. I would personally only use this kind of stuff for genuine one-offs where anonymity is paramount (read: probably not at all).
There are plusses and minuses to SG, but it's free as in beer and if your Perl and ops chops are in good shape the code is available for self-hosting. The hosted service does not support bringing your own domain but has other nifty features that might appeal to HN power users. Worth a look if you're in the market for this kind of thing.
It's in the privacy policy (https://www.mozilla.org/en-US/privacy/firefox-relay/), but yes - the emails are sent thru Amazon SES in plaintext.
We have kicked around the idea of enabling + preserving E2EE emails thru Relay, but ... it's tricky.
I was able to set up alias emails in my gmail & have all emails from a particular domain forward to my domain as well.
Then went with a password manager & changed all my email addresses to my own domain with specific relays (amazon@ netflix@ etc etc)
Works really well for ~12/year!
(Source, I'm the creator of Owl Mail [https://owlmail.io] and this is a common question.)
By using Owl Mail (or Firefox Relay, etc.) addresses everywhere, you reduce your attack surface to one security fastidious company.
And, even if Owl Mail (or Firefox Relay, etc.) were to experience a data breach, at least it would greatly increase the effort required to match emails to your identity.
To really protect yourself, use a double relay!
External -> Relay 1 -> Relay 2 -> Your Inbox
Then you will have some serious resilience :DAlso, I think one thing you should look into as a natural evolution is promoting the use of auto-generated, secure passwords unique to each relay address.
Also, it seems to forward to the address associated with your firefox account (which could end up at a mailprovider you don't want the relayed emails to go to)
I'll stick with my own *@sub.example.com forwarding setup in stead.
Edit: I've previously claimed it to be open source. But there's no License currently that would indicate that.
Edit: if I am going blind, I am not the only one [1]
[0] https://www.mozilla.org/en-US/about/legal/terms/firefox-rela... [1] https://github.com/mozilla/fx-private-relay/issues/773
Hopefully they make it clearer
Oops, thanks for catching that. We'll add a LICENSE file.
Congrats to FF Relay – more products in this space will be a win for better privacy online :)
Free email with Firefox domain. Paid with custom domain.
> In 2006, the Mozilla Corporation generated $66.8 million in revenue and $19.8 million in expenses, with 85% of that revenue coming from Google for "assigning [Google] as the browser's default search engine, and for click-throughs on ads placed on the ensuing search results pages."
I don't think Google would like it.
All the solutions that exist "rent" you numbers temporarily so that prices are reasonable.
I'm happy to donate to Mozilla. If the money is spent on FF.
That's not what I'm donating to an NGO for, but if doing so nets them more donations usable for their causes in the end, that's something I can get behind.
If Mozilla can find ways to generate additional income that also align with their values and don't put them into conflicts of interest, I can get behind that. (The management isn't exactly known for frugality and excellence in resource allocation though, so I'm taking it with a grain of salt.)
Questions:
1. Is this new?
2. Why just 5 relays? How can I get more?
3. Is something like that available from 1Password? Would be a great addition.
2. That may be a good questions for developers at #firefox-relay:mozilla.org (Matrix room)
3. It has come up in a few tweets in the past, but 1Password does not seem to have any plans for now. I use SimpleLogin browser extensions, and 1Password neatly picks up that alias address from my signup form.
A few bonuses:
• Larger attachments, 5MB + some wiggle room depending on the message size.
• Replies (single and multi-party) in beta.
• More addresses (a generous free tier, paid plans on the way).
• Fast and simple UI.
(happy user for like 12 years?)
Your comment made me think of that.