Guide · 7 min read

Email Masking Explained: Masks and Aliases

Masked email, hide my email, relay, alias: four names for one mechanism. What it hides, what it does not, and how to judge any of them.

YeyMail Team ·

Someone tells you to use a masked email. A password manager offers to hide your email. A browser extension makes you a relay. A mail provider hands you an alias. Four labels, one mechanism, and a lot of people who cannot find the feature they want because they are searching for the wrong word.

The mechanism itself is dull, which is a compliment. You create a second address, you give that out instead of the one you actually read mail at, and anything sent to it is forwarded to your real inbox. The site never learns your real address. Everything else, the branding, the price, the extras on top, sits on that one idea.

What follows is a map of the vocabulary and the plumbing underneath it: who calls it what, what it genuinely protects you from, and what it does not do that people assume it does. The second half matters more, because that is where people get caught out.

One idea, several names

The feature has no agreed name because it was built independently in several places at once, and each company named it after the benefit it wanted to sell.

  • Fastmail calls them Masked Email addresses, generated inside the mailbox and creatable from password managers such as 1Password and Bitwarden.
  • Apple calls it Hide My Email and ships it with iCloud+, wired into Sign in with Apple, Safari and Mail.
  • Mozilla's service is Firefox Relay, and the addresses it generates are called email masks.
  • DuckDuckGo calls the service Email Protection and the addresses Duck Addresses: one personal address, plus any number of generated private ones.
  • Proton calls them hide-my-email aliases. SimpleLogin, which Proton acquired, has always called them aliases.
  • Almost every independent forwarding service, and every self-hosted setup, says alias.

A sixth thing gets swept into the same conversation and should not be. Plus-addressing, also called subaddressing, is where you hand out you+shop@example.com and the mail still lands in your normal inbox. It costs nothing where it is supported, but it is a convention rather than a standard. RFC 5233 is often cited as though it standardised the technique. Its abstract opens with the words "On email systems that allow for subaddressing", then defines a Sieve filtering extension for matching the user and detail parts of an address. It presupposes the convention and leaves the separator to each system.

The practical difference is that a plus tag is visible. Stripping it back to your real address takes one line of code, and plenty of signup forms reject the plus sign outright. A mask has no visible relationship to your real address at all.

What masking actually hides, and from whom

A mask hides one specific fact from one specific party: your real address, from the organisation you handed the mask to and from everyone that organisation later sells to, shares with, or is breached by. Narrow, and still worth having.

  • It breaks the join key. Your real address is a stable identifier that follows you between companies for decades, and brokers use it to stitch separate records into one profile. A different address per site removes the field they join on.
  • It gives you attribution. When spam arrives at an address you only ever gave to one shop, you know exactly who leaked, sold or lost it. No privacy policy will tell you that.
  • It makes revocation cheap. Switching off one address takes seconds. Changing the address you have used for fifteen years takes months, and you will still miss something. The value is in that asymmetry.
  • It weakens credential stuffing. Attackers replay breached username and password pairs against other sites. If the username differs everywhere, the lists do not line up.

What it does not hide, honestly

This is the part the marketing pages skip.

  • It does not hide you from the forwarding provider, which handles every message in order to route it. You have swapped a little exposure to many companies for a lot of exposure to one you chose. Reasonable, but a trade.
  • It does not hide anything else you typed. Your name, delivery address, phone number and card were in the same form. A mask on the email field does not anonymise the order.
  • It does not hide the message. Mail between servers is normally protected in transit, but the content sits readable at both ends and at the relay in the middle.
  • It does not stop cross-site linking by other means. Payment card, phone number, shipping address, device fingerprint and login IP all still work as identifiers.
  • It does not make you anonymous in any legal sense. A mask is a forwarding record held by a company that can be compelled to produce it.
  • It does not always survive a group reply. Most services rewrite the sender address on forwarded mail, so a plain reply goes back out through the mask. Reply All is the awkward case, because the other recipients were addressed directly. Test it rather than assuming, because implementations differ.

One more catches people out: forwarding adds a hop, and a hop can fail. A mask in front of a boarding pass or a bank one-time code is a fresh way to lose something that has to arrive.

Masking and encryption are different jobs

People reach for masking when they mean encryption, and for encryption when they mean masking. The two protect different parts of the same message.

Encryption protects content. Transport encryption covers a message as it moves between two servers, negotiated one hop at a time, so it is normal rather than guaranteed along the whole path. Body encryption with PGP or S/MIME protects the body, and only the body: the subject line, the sender, the recipient and the timestamps stay readable, because the servers in between need them to deliver the message.

Masking protects an identifier. It changes what appears in the From and To fields, which is precisely the part encryption cannot hide. An encrypted message sent from your real address still tells every server on the path who is talking to whom. A masked message in plain text hides who you are and nothing else.

The two compose rather than compete. Any product that sells a forwarding mask as a form of message encryption is either confused or hoping you are. If a service encrypts bodies, ask what it does with subject lines.

How the providers map onto the vocabulary

Once you know the words, the more useful question is where the feature lives, because that decides how it fails.

  • Inside a mailbox provider. Fastmail's Masked Email is part of a Fastmail account. Masks and inbox are one relationship, so there is nothing to connect up and nothing survives leaving.
  • Inside an operating system. Apple's Hide My Email comes with iCloud+ and is deepest where you already are, in Sign in with Apple and Safari autofill. It is also the hardest to take with you.
  • In front of the inbox you already have. Firefox Relay and DuckDuckGo Email Protection forward into whatever mailbox you use today: easiest to try, easiest to abandon.
  • Inside a password manager. 1Password and Bitwarden can generate masks by calling a forwarding service you hold an account with. The manager is the interface, not the mail path.
  • As a dedicated forwarding service. SimpleLogin, addy.io and similar tools do this one job, usually with the most control over rules, domains and replies.

Cutting across all of that is the difference that decides whether the vocabulary still matters to you in five years: whose domain is the mask on? An address on a provider's shared domain is borrowed, and if you leave, every mask you gave out goes dead. An address on a domain you own is yours: change provider, repoint the MX records, and every mask still lands. Small technical difference, very large consequence, and almost never what the product page leads with.

When a masking service is the wrong answer

Plenty of people do not need to pay anyone for this.

  • If all you want is to know who leaked your address, plus-addressing already does that free, provided your provider supports it and the site accepts the plus sign.
  • If you own a domain and run a catch-all, you can invent addresses forever with nothing in the middle. The cost is the spam a catch-all attracts, and the maintenance.
  • Free tiers are real. DuckDuckGo Email Protection is free. Firefox Relay has a free tier. If you already pay for iCloud+, Hide My Email is included.
  • For high-stakes accounts, use your real address. Banks, government services, medical providers, employers, your domain registrar and anything involving identity checks or travel documents are places where an extra hop is a liability. Mozilla's own guidance for Relay makes much the same point.

A paid service earns its keep when you have a lot of low-trust signups, want per-address rules, or want the addresses to outlive the provider. Otherwise the free options are the honest answer.

What to look for, whatever it is called

  • Replying. Can you reply from the mask without configuring anything? Does the reply reveal your real address? What happens on Reply All? Test it before you rely on it.
  • Domain ownership. Shared domain or one you own? Only one of those is portable.
  • What happens when you stop paying. Do the masks keep forwarding, go read-only, or bounce on day one? Ask before you sign up, because afterwards the answer is whatever they decide.
  • Deletion and counting. Does a deleted address free up your quota or count against it forever? Can it be recreated?
  • The off switch. Can you refuse mail at the SMTP level, so the sender is told, rather than having it quietly discarded? A rejection is honest breakage. A silent drop looks like working software.
  • Retention. What is stored, and for how long? Message bodies, or only delivery metadata? A provider that cannot answer in one sentence has not thought about it.
  • Deliverability. Forwarded mail complicates SPF and DKIM checks. Ask how the service handles that, and whose sending reputation your mail inherits.
  • Claims you can check. A certification claim should name the scheme and the date. Absence of a formal audit is not damning for a small provider; a vague claim is worse than an honest gap.

The naming will keep drifting, because every new entrant renames the thing after whatever it most wants to sell. Mask, alias, relay, hidden address, protected address: judge the mechanism, not the noun.

The YeyMail takeaway
One more name for it, with the limits written down

YeyMail's word for it is alias. The mechanism is the one described above: mail to the alias forwards to your real inbox, and the reply address is rewritten on every forwarded message, so replying needs no setup at all. Reply All is the honest exception, and per-alias SMTP is only needed to start a new conversation. Aliases are unlimited on domains you own; on the shared yeymail.com domain there is a ceiling, and it counts every address ever created there, deleted ones included. The kill switch refuses mail at SMTP time, is never paywalled, and keeps working after you cancel, alongside shared-domain forwarding at 20 messages a day with no end date. Starter is $0.99 a month or $9.48 a year, and the 7-day trial takes no card. No SOC 2, no ISO 27001, no penetration test, no bug bounty.

Start free — one alias per signup7-day trial · No credit card

Sources

Common questions

What is email masking?

Email masking means handing out a generated address instead of your real one. Mail sent to the mask is forwarded to the inbox you actually read, so the site you signed up with never learns your real address, and you can switch that one address off later without changing the address everyone else uses.

Is a masked email the same as an alias?

In practice, yes. Masked email, hide my email, email mask, relay and alias all describe the same mechanism: a second address that forwards to your real inbox. The words differ by vendor rather than by technique. Fastmail says Masked Email, Apple says Hide My Email, Mozilla's Firefox Relay says email mask, DuckDuckGo says Duck Address, and most other services say alias.

Does email masking encrypt my email?

No. Masking changes the address in the From and To fields; it does nothing to the content of the message. Even body encryption such as PGP leaves the subject line, the sender and the recipient readable, because mail servers need those to deliver the message. Masking and encryption are separate jobs and neither replaces the other.

Can I reply from a masked email address?

Usually yes. Most forwarding services rewrite the sender address on forwarded mail, so a plain reply goes back out through the mask and your real address stays hidden. Reply All is the awkward case, because other recipients were addressed directly. Behaviour differs between services, so send yourself a test message before relying on it.

Does RFC 5233 standardise plus-addressing?

No. RFC 5233 defines a Sieve filtering extension for matching the user and detail parts of an address on systems that already allow subaddressing. It presupposes the convention and leaves the separator character to each system. Plus-addressing is a widely supported convention, not a standard.

When should I not use a masked email address?

Use your real address wherever a failed delivery would be costly or where your identity is verified: banks, government services, medical providers, employers, domain registrars and travel bookings. A mask adds a forwarding hop, and every extra hop is another way for a message you need to go missing.

Keep reading

Guide
What Is an Email Alias? A Plain-English Guide
Guide
How to Stop Spam Emails (Filters Aren't Enough)