Every email from an email alias includes a link. That link is used to look at the details of that email alias and gives you the option to deactivate it. You'd think there would be some login verification to prevent just anyone from using that link, but no, anyone that has this link, can now deactivate your email alias. The password itself is formatted in json, compressed with deflate, and simply tacked on to the end of the link's URL. When you click on the link, the destination webpage takes the end of the URL, decompresses the deflate, and serves a deactivate button to deactivate the email alias. When you click on that button, the email alias's address and password are sent to DDG's API and your email alias is disabled.