Masked email from Fastmail and 1Password
fastmail.com
fastmail.com
For people who want to do this and care about retaining ownership, would be probably wise to run their own email servers and using different patterns of catch all addresses.
I think a lot of people have been spoiled by gmail's longevity. Unless you're using your own domain it's a wash anyways right?
I think this is an acceptable trust. I personally prefer trusting something with more longevity than fastmail (apple hide my email).
> I personally prefer trusting something with more longevity than fastmail
Fastmail launched 5 years before Gmail, in 1999. It's also a paid product with a sustainable business model. It's hard to get more longevity than that.
> I personally prefer trusting something with more longevity than fastmail (apple hide my email).
Fastmail (launched 1999) is older than Gmail (launched 2004).
> New Masked Email addresses will be created @fastmail.com. You can change this in Settings → Domains
I agree with you, and I'm looking forward to be trying this out.
Wait till 2038 so you can say "aha! I told you so!"
or have peace of mind during the prime of my life for the next two decades
One of the really nice parts of building this out with Fastmail is that you can create Masked Emails for your own domain. So, if you ever decide that Fastmail isn’t right for you, then you still receive all of those emails when you set up a wildcard alias with your new email provider.
Similarly, if you ever decide that 1Password isn’t right for you, that doesn’t stop you from receiving your emails. And the email addresses should still be part of your 1Password export.
myaccount+alias@mydomain.com
automatically?
Disclosure - I work at 1Password, though I had only tangential involvement in this effort
Settings -> Domains -> Team Settings -> Masked email domain
It will default to fastmail.com, but easy to change it.
The full "it just works" integration seems to only work between 1password and fastmail directly.
We go one step further and generate a random email address for each new service you sign up with. It'll look something like "hot.potatoes4827@mydomain.com".
You can create a new masked email anywhere you have the 1Password browser extension, including our brand new iOS Safari extension.
Unfortunately, way too many internet services don't allow the plus sign in an email address. It's weird, but it's true.
How hard is that though? Export all email addresses from 1Password (trivial), extract generated emails (trivial), and add forwarding rules for each one in your mail server (trivial to easy depending on your setup).
Maybe not easy for non-savvy users, but neither is a custom domain or even knowing about the + trick.
It still could.
> Everything is still tagged to your identity, i.e. @mydomain.com.
If your domain is tied to your identity, then yes. But to be extra clear, this should have said "Everything is still tagged to your domain" as not everyone has their domain tied to their identity. I for example have my domain setup njal.la with zero personal details attached to the domain itself, either publicly or at njal.la.
Otherwise subaddressing with + works well with most mail hosts other than Microsoft Exchange / Office365 (which have had endless problems).
The advantage of Masked Emails is that third parties won't even know about mydomain.com. The disadvantage is that you need 1Password to recall which email address you used with a particular website.
The main thing that always held me up was, how do you plan to avoid getting blacklisted at the domain level if people start abusing the ability to create random emails? A few services I use even disallow Gmail addresses.
I can't fully speak for the Fastmail folks, but I know that there are a few upper limits for how many masked email addresses that one account can create. We tried to set them unreasonably high to allow for all manner of legitimate use while still preventing bad actors. They're also monitoring usage and tuning that limit. Plus, you can always email support and ask for a increase for your specific account, if you ever bump up against it.
mailinator's been around providing this (as a recieve only) service for decades by this point.
Edit: saw someone point out this only works for one user per domain.
I suppose the advantage with a non-custom domain is you leak no info about yourself, the masked email is 'just another Fastmail email address'. But doing it for a custom domain feels like it defeats the point, isn't it just like catch-all at that point?
It’s what I do with a custom domain (though only have a handful of custom aliases currently).
Having this integrated in a first class way is a nice surprise and a really great feature imo.
It’ll make it easy to see who leaked your email and kill the alias while also not locking you into to fastmail forever as a provider.
The Masked Email integration makes that entire process automatic. It's even easier than before. It's enough to convince a few Fastmail-using friends to start doing it.
Again that is more manual effort, though I don't consider it much effort given that I'm only signing up for a limited number of sites per year. And I suppose a little extra friction in one respect isn't even that bad a thing, makes me think a bit about whether I do actually want to sign up there. Ideally I'd like to see more efforts about making such things standardized across providers so that even regular people can get the benefits from near any registrar or email provider at all with whatever tooling they like. I guess that's probably either infeasible, or if it happens it'll be out of a rise of competing centralized masking providers raising the issue high enough in the general consciousness that demand drives it. If there are any existing open efforts around that I'd be delighted to know about them though!
When I sign up for a new service, I register on the spot as e.g. amazon@mydomain.com, the mails they send are considered as a 'mistaken sender' and are sent to the catch-all mailbox (which is just my regular mailbox!)
The downside is that you (and spammers) can* send email to any random address and reach me, but in practice I have not found that to be a problem; I don't actually get spam at addresses which are not posted somewhere online. And it's in your best interest to contact me at a more specific email, because if I ever do get widespread spam, I'll swap the default rule to mark as spam, and only allow specific addresses. I recommend hn+«your handle»@«my domain».
On the off chance: I'm moving to NYC soon and am in the job market; feel free to shoot me an email if you're hiring at a company that's solving real problems for humans (not, say, selling ads).
The single other significant issue I can think of which has come up actually is when one desires to actually use email for two-way communication with a site, not just receiving stuff. Sending from aliases isn't really practical, spoofing the from address even from the same domain has a high chance of trigger all sorts of spam protection for obvious reasons. I'm sure there is probably some way to handle it from one's own server but that has its own challenges. So sending mail ends up being from a different address as the account, which most places don't seem to care about but seems to hit automated edge cases and snag things up once in a while.
This is why using a different email with each website is glorious! If example.com leaks my example.com@«my domain» address, I can enable stricter filters for that address.
> I suspect if they become popular enough it's only a matter of time before spammers add some sort of "this looks like a catch-all account type email, try sending random stuff" to their logic.
This isn't game-over, either. As I noted, if this ever starts happening, I'll change my sieve filter so that any address without a filter rule gets sent to the trash, instead of my inbox. This does mean I lose the "zero friction" benefit, but adding a new address would still be just a single line in a text file. And it's much less lock-in than using the web interface of some given email provider to set up new aliases, since I can copy my filtering config over to any provider which supports sieve filters (and wildcard addresses).
That said, I don't think this will ever be a problem. Because "this looks like a catch-all account type email, try sending random stuff" is a pattern that makes you very easy to identify as a spammer. Given the possible address space, I don't see a scenario where the chance of hitting a real mailbox is worth the risk of blowing your cover and getting your mail server blocked.
Lately I’ve been combining this with cards via privacy.com to further limit my risk in the event of another data breach, and so far it’s working quite well, though I do have a long way to go to fully convert everything.
As for longevity, Fastmail has been around since 1999 in some form or another, and even made themselves independent again after being acquired by another company through an employee buy-out. https://en.m.wikipedia.org/wiki/Fastmail
Most of it comes to two addresses which are public via git (one from commit logs, the other explicitly stored in a repo).
0: https://www.email-validator.net/blog/validating-catch-all-em... (warning: annoying marketing page)
For sure we recommend (and make it very easy) using your own domain. We want you to stay because we're providing you enough value to be worth staying, not due to lock-in.
Email can be portable, but I think it’s gotta be easier to come up with a portable email address than expecting everyone to buy a domain and set up the DNS records? Does a registrar of email only domains exist today?
[1] https://en.m.wikipedia.org/wiki/Mass_surveillance_in_Austral...
It's a legal and bureaucratic not technical puzzle. I wouldn't believe any comfort statement on the point either. This sequence isn't a bug, it's a feature of the Five Eyes configuration.
You can use your own domain.
But only if you use Fastmail for that domain.
With that it's entirely portable. You can point your mx records at any other provider.
Disclosure - I work at 1Password, though I had only tangential involvement in this effort.
Disclosure - I work at 1Password, though I had only tangential involvement in this effort
Disclosure - I run Fastmail, though also only had tangential involvement in this effort.
I can't recommend using an email system like this to anyone who cares about security or privacy.
Fastmail admins can themselves read your entire email history, as well as any law enforcement fishing expedition in US or AUS.
Instead get a domain. Configure email as well as a catch all address. Example anything@yourdomain.com would reach name@yourdomain.com which you use as your primary email address.
And say, if I am signing up for Netflix, I would give the email as netflix@yourdomain.com. The email automatically reaches my single primary inbox with the catch-all behavior. And if I find a lot of spam to netflix@yourdomain.com, I know which service is leaking my email address and I can quickly block all emails sent to netflix@yourdomain.com
I can get a domain pretty easily but I hate the idea of managing my own email. Do you recommend a particular provider? Zoho or something?
If you prefer email forwarding, then: Cloudflare announced a free email-forwarding service just yesterday [0]. Not sure if they provide unlimited email forwarding rules. Other domain registrars like domains.google and namecheap.com also support email forwarding at no-cost.
If you prefer a managed mailbox, then: Zoho Mail, Fresh Mail, AWS WorkMail et al are nice if you'd also like to send emails using the address you sign up with.
Other than that, if you're technically inclined, then have SES plonk incoming emails in to S3 [1]
Be careful registering domain.tld without whois shield and/or with TLDs that require registrant to publicly reveal ownership (like .in)
See also: simplelogin.io and anonaddy.com
If you can afford $6/mo, Google Workspace isn't bad, there's generally better security and it grants you a lot of control over your account's settings (and will remove ads from the Gmail app on your phone, even when only looking at your @gmail account inbox).
Otherwize, Zoho works, but now costs $12/user/year (it used to be free) so ymmv. Great if you were planning on pure POP/IMAP usage anyways.
https://www.queryclick.com/app/uploads/2015/10/Gmail-ads-101...
If I saw an ad in my email client, my immediate action would be to find a new email client.
It is also very easy to nuke an address this way once it is a spam trap.
There has to be a name for it; the closest I've come across is a canary trap.
https://en.wikipedia.org/wiki/Canary_trap
> A canary trap is a method for exposing an information leak by giving different versions of a sensitive document to each of several suspects and seeing which version gets leaked.
If you sign up for league of legends, which email do you use? Riot? RiotGames? Lol? LeagueOfLegends?
Presumably you can always scan backwards to find your email address in your inbox, but maybe not. I guess maybe a password manager can help you remember, if you're diligent about always using it (and never end up locked out of your vault).
I recently started signing up for things with the + trick for gmail, but now I'm worried about having a bunch of email addresses I have no way of keeping track of.
And instead of having a catchall on my domain.tld I have it on a subdomain, like s.domain.tld , easy way to keep them separate.
accounts+wellsfargo@my.domain
but they accepted accounts+wellsfargosucks@my.domain
just fine. Seems like someone messed up the regex :)I have, however, run into a number of large companies where I've been talking with employees who see my email for whatever reason, and have received the "Oh, do you work here too?" question.
I've had a few people ask "That's your email?" and just briefly explained that I own the domain and get all email sent to it.
I have used aliases to catch spam and have gathered about 200 email aliases this way over the last 12 years or so, and it works well. Rather than using a catch-all, I manually create the alias with a script.
This concern has been my #1 reason for not doing the same setup. Basically a fear of a never-ending list of random addresses to blacklist, which won’t have any meaningful effect because the next spammer will just use a different random value.
1. It’s not frequent that someone hands out your address to a 3rd party and when it does, it’s usually exactly the site you would expect. I’ve had it happen 1 time in the last 3 years across 150 different aliases.
2. It doesn’t work well for apps with weird URLs (lots of subdomains, shared domains etc.). You forget how you the address and now can’t login. Yes, maybe you have a password manager, but password managers fail frequently in my experience (e.g. they record the wrong username etc)
3. You are still traceable since ultimately all your addresses are in the same domain. Sure, advertisers aren’t looking for that pattern, but it’s not like you are truly hidden.
4. Domain hijacking can happen. So now you have to be mindful of your domain since it’s a juicy target; Someone hijacker’s your domain, redirects your banking email for a password reset.
2. Again, not a problem. Everyone should be using a pass manager.
3. If you use the same domain/email for your banks (or any other financial/important service) as you do for social media/gaming/whatever, then that's on you. It's basic security practice to separate the important things so basic hacks like the one you mention are useless.
4. The purpose of this is basic privacy and security, not to be truly hidden.
So you can sign up for new companies with random@someservice.mydomain.com and have it still route into our inbox.
https://www.fastmail.help/hc/en-us/articles/360060591053-Plu...
I've done this a bunch in past, but wish it was easier to go back and change existing services.
Also found a couple that reject sign-ups when their name is in the username part.
As a user of both 1Pass and Fastmail for years, this is a really neat addition.
Next I'd love 1Pass to generate random phone numbers to use that I can recall quickly for things like supermarket checkout where I need to enter a number to get their discounts, and I don't want to use my real one. Doesn't even need to be a genuine phone line, just a 10 digit code.
* register a pseudonymous domain and use Fastmail to forward it in to my real email
* use Twilio + a little TwiML to register a real phone number in my area code & have all messages/calls forward to my cell
This let me establish trust domains: when I share my email with an untrusted entity they get companyname@mypseudonym.com & the phone number I registered before. I always have the ability to know where the communications come from & can quickly cut off junk/spam at either source[1]. And if a company is trustworthy I could always move them to my real domain/phone if I so wanted.
[1]: Phone is obviously harder as there's only one number, but legitimate companies seldom if ever call – their junk is from a consistent text source that's easier to block. My burner & my clean numbers get about the same amount of autodialer calls, sadly.
This is how you know not to use that company.
Makes it easy when I receive spam to see who sold my email address.
There’s also zero overhead to “create” a new one. It works for any address.
I actually don't accept *@domain.tld even though I have a custom domain because I got too many fishing emails that weren't caught in spam. I didn't have the patience to deal with it. That might have changed over the decade+, though.
I haven't found this to be a problem. Usually it's in my password manager. Otherwise they've sent me an email, which I can quickly search my inbox for.
Does one need to keep records? I just do service@domain.tld, for example: ycombinator@example.net.
I started receiving a lot of sexually-explicit spam addressed to recruiting@mydomain.tld, so now I know that one of the recruiters to which I gave this email address had their inbox/contact-list compromised.
a.ccountname@gmail.com is the same as
ac.countname@gmail.com
acco.untname@gmail.com
and so on.
Other vendors and companies like FB are surely doing this too, as companies send FB emails for matching / ad targeting.
https://twitter.com/WolfieChristl/status/1288428611100454912
For example: jdoe+netflix@example.org would be the address used on a netflix account.
However I do appreciate the additional anonymity a randomized or hashed user part provides
["MaskedEmail/set", { "create" : { "k1" : { "state" : "enabled", "description" : "Hacker News", "url" : "https://news.ycombinator.com" } } }, "R1"]
returns:
["MaskedEmail/set", { "created" : { "k1" : { "id" : "masked-123456", "email" : "flighty.emu5803@mydomain.example", "createdAt" : "2021-09-28T14:19:19Z" } } }, "R1"]
Very simple to work with.
I knew fastmail was building JMAP but I didn't think to look at JMAP when I was trying to find fastmail's API that can be used to integrate this in other services. This is really nice compared to the SOAP/XML monstrosity I stumbled upon, heh.
edit because of downvote: I'm referencing the new data control laws (it is even beyond surveillance at this point), which makes it impossible to anyone who cares to use any autralia based products. I should have made that more clear.
Fastmail wasn't end-to-end encrypted to begin with, so laws requiring backdoors have no relevance to Fastmail. And every civilized country has some legal method to compel information from companies relating to significant criminal activity.
I am not trying to tell you to use Fastmail, just that fear of doing so explicitly because of Australian law is silly. ;)
[0] https://www.iflscience.com/policy/australias-new-police-powe... [1]
https://www.spreadprivacy.com/introducing-email-protection-b... (beta only)
I know there are plenty of others, but I use all the above and found them reliable and intuitive.
For now I'm using Firefox Relay, but the 5-email limit (without a plan for more) is a showstopper.
https://www.fastmail.help/hc/en-us/articles/1500000277942-Ca...
When I get spam to a particular alias, I blacklist it to my spam folder. Naturally this might get a little difficult if a spam bot ever figures this out where I'd need to move to a whitelist rather than blacklist process. But it's worked flawlessly for years so far.
At least with my method I don't need to create the alias in advance.
They seamlessly integrate with the sender identity feature in Fastmail making it very clear that you are replying from the Masked Email.
From a quick analysis on the headers, I don't see anything that leaks who your real identity is, but of course Fastmail knows and could reveal that if legal reasons exist.
Overall smooth feature along with the ability to use a custom domain for portability (to a less sophisticated wildcard setup, or another provider).
I have registered a domain just for the purpose which doesn't have my name in it or host any websites or anything else which can be used to leak my identity with a whois privacy guard service.
It has the dual advantages of being guessable by me if something goes tits up with my self-hosted bitwarden, and I can eyeball who has leaked my email address on incoming spam.
Being locked in to a provider domain means you can never easily switch from them. It's a form of vendor lock-in. (Fastmail supports using your own domain, of course, but they also don't encrypt at rest in a way not readable to Fastmail, so you should avoid them.)
I wrote up a step by step howto for switching over to your own domain name:
And this "generate a Masked Email right there in the form where you're using it" pattern means that the friction is so low that it's a viable choice - it's EASIER to do the safe thing, and that's the real game changer.
Anyway, keep up the good work!
Other than thinning my online identity to make any assumed attempts at correlation harder, in a couple of cases over the years I had the pleasure to "Gotcha!" companies selling (or losing) their users' email addresses. In other cases I also received unrelated spam on addresses as a result of undisclosed or less-publicised security breaches.
I just tried it with my own domain via the Fastmail iOS app. There doesn’t seem to be a way to delete things.
I do like that I can attach notes and have an easy block button. I might start using it instead of my existing wildcard setup, but need delete.
Using unique email per service is really great. I detected Zenni Optical either had a security breach or sold my information because of the unique email I used.
Update: looks like deletion only works when using the website, though.
This is a great feature. I’m glad this will bring it to more people.
For example, I opened up Agoda once in firefox private tab, and searched for 2 specific hotels to get an idea of pricing. As I had signed into Agoda, less than 5 minutes after searching both those hotels were listed on facebook with discounts. So with ad's and social media blocked, the only way they could link me was via email.
If everyone starts using fastmail to hide their email, then companies cannot do this targeted advertising and will block it.
They also have a pretty big library of email domains to choose from that I can create normal alias for, so I'd be surprised to not see those come as an option in the future.
I can't find anything in the 1Password interface to change a login for current accounts.
All the language makes it sound like it's only upon login/account creation.
I guess the fallback is just manually creating one in Fastmail, but it's a bummer if you can't just do it from one place in 1Password.
I wish the block option for masked aliases was bouncing the emails and not sending them to trash.
As someone who uses Fastmail and 1Password, thank you for posting this. Currently really impressed with both services, the prospect of linking the two and obtaining unique email addresses is even better!
I end up in a situation where if I don't pay close attention I leak my "main" email address.
Instead of “some.thing1234@”, I’d rather just have “thing1234@“.
Update: hmmm… looks like I can’t initiate an email with masked email though. I can set up my wildcard to do that in the more rare case when I need to initiate email.
You can create an arbitrary number of disposable email addresses, keeping up to 50 of them active at a time.
You choose a prefix, and then your disposables have the form prefix-<whatever you want>@yahoo.com.
I've just registered a new random domain to use for these aliases to further separate my identity from email leaks.
With this feature, I can stop using my gmail account for general junk.
It seems Masked Email is useful primarily if you have 1Password account as a deeper integration to auto-fil email addresses during sign-up.
I’d love this feature with Bitwarden.