Most of what is written about email aliases, including most of what is on this blog, explains why you would want them: the leak you can trace to a single site, the spam you can switch off at the source, the address that no data broker can join to the rest of your life. Very little of it tells you what to actually do on a Tuesday evening with a fresh account and a password manager holding a hundred and forty logins. This post is that.
The plan below takes about an hour. It does not move everything. It moves the accounts where an alias helps and costs you nothing, sets up the habit that keeps future signups on aliases without you thinking about it, and leaves a small set of accounts deliberately alone. Anyone with a forwarding-alias service can follow it; the steps are the same everywhere and only the buttons differ.
If you have not settled on a service yet, the comparison of alias services is the place to start; come back when you have a login. The hour starts there.
Five minutes: decide how aliases will be named
Do this before you create a single address, because otherwise you will end up with three naming rules and forty aliases nobody can read. There are two schools. Site-named aliases (shop-example@ your domain) can be understood at a glance, in your inbox and in a leak: when mail arrives at an alias called after a newsletter, you know who has your address without opening anything. Random aliases (k4x9q2@) give away nothing to anyone, but you rely entirely on your service's list or your password manager to remember which is which.
The trade-off is recognisability against guessability. A purely site-named alias is easy for you to read and easy for someone else to guess: if a spammer sees one retailer's name at your domain, another retailer's name is a good bet. Random aliases have no pattern to enumerate but hand all the memory work to tooling.
A sensible default is a readable label with a short random tail, something like shop-name.7f2k@. You still know what it is when it turns up in a breach dump, nobody can work out your other addresses from it, and most alias services will generate that shape for you if you type the label and let them add the suffix. Pick one rule now, write it in the notes of your password manager, and stop thinking about it. Consistency matters far more than which rule you chose.
One further choice belongs here: the service's shared domain, or a domain you own. Shared-domain aliases are quicker to set up. Aliases on your own domain can move with you if you ever leave the service, and are less often refused by sites that block known alias domains. If you are undecided, start on the shared domain today and look at your own domain later. Nothing in the rest of this plan changes.
Five minutes: pick the destination and prove it forwards
Every alias forwards somewhere. Decide where before you create any, because changing it later means checking every alias again. The destination should be an inbox you actually read, that has two-step verification switched on, and that you are not planning to abandon. The NCSC's guidance on recovering a hacked account explains why the choice matters: an attacker who gets into a mailbox will commonly set up a forwarding rule and use it to reset the passwords on everything else. The inbox at the end of your aliases is now the inbox at the end of your accounts. Treat it accordingly.
Then test. Create one alias, send it a message from any other account you have, and wait for it to appear at the destination. Look in the spam folder as well. If it does not arrive, stop and fix that now, whether the cause is a domain that has not finished verifying or a destination provider filing forwarded mail as junk. Nothing else in the hour is worth doing until a test message has landed where you expect it, because every step from here depends on verification emails getting through.
Ten minutes: sort your accounts, lowest stakes first
Open your password manager and look at the list. You are going to work from the least consequential accounts to the most, and you will not reach the top of the list today, and possibly not ever. The tiering rule from the post on aliases for bank accounts applies here in full:
- First: newsletters, shops, loyalty schemes, apps you tried once, anything that only ever sends you marketing and receipts. This is where leaks come from and where an alias costs you nothing.
- Next: forums, community sites, software subscriptions, streaming, anything with a login you would mind losing but that does not hold your money or your identity.
- Last, and for now not at all: banks, government services, your employer, insurers, and anything that checked a document to confirm who you are. Leave these on the real address unless you have read the bank accounts post and consciously accepted the recovery risk it describes.
Make a rough count of the first two tiers. If it is under about thirty, you will finish today. If it is over a hundred, take the thirty you use most, leave the rest for another session, and rely on the extension habit described below to catch new signups. That habit will do more for you over a year than one heroic evening will.
Thirty minutes: migrate a few at a time
Now the actual work, which is repetitive by design. For each account in the first tier: create the alias according to your naming rule, sign in to the site, change the contact email to the alias, and wait for the verification message. Do not start the next account until it has arrived. Most sites send a confirmation to the new address, some to the old one, some to both, and a few switch silently; for those, request a password reset once you have changed the address so that you know it is live.
Work in batches of about five rather than in one long sweep. If five verify cleanly you have learned that your forwarding is fine and can speed up. If one fails you have one thing to debug rather than twenty. And every time an address changes, update the entry in your password manager: the login now uses the alias, and the notes or a custom field records which alias belongs to which site. That mapping is what makes labelled-with-a-tail or fully random aliases workable at all. The companion post on aliases and password managers goes into how to lay this out; the short version is that the password manager is the source of truth for which alias goes where, and the alias service is the source of truth for what each alias is doing.
If you do not yet use a password manager, this is the moment to start, and the browser's built-in one is fine for it. The NCSC's answer to whether you should use one is a plain yes.
Expect a few older accounts to be awkward: a shop that will only change your email through support, a forum where the setting is three menus deep. Skip them and make a note. The point of the hour is coverage, not completeness.
What not to migrate
Say it plainly, so there is no ambiguity later. Do not move your bank, your government logins, your employer, or anything where the email address is part of how they confirm your identity. Do not move the account for your password manager or for the alias service itself; both need to sit on an address that keeps working if either of them has a bad day. Do not use an alias as the recovery address for your main mailbox. In every one of these cases the failure mode is the same: the one time you urgently need the message, it goes to an address that a lapsed subscription, a mistaken kill switch or a service closure has quietly stopped delivering. If in doubt, leave it on the real address. Aliases are for the wide, low-stakes surface, and that is where nearly all the leaks happen anyway.
Five minutes: install the extension so new signups default to an alias
The migration covers the past. What covers the future is a habit, and habits form fastest when the alias is the path of least resistance. Most services publish a browser extension that notices an email field and offers to fill it with a fresh alias; Firefox Relay's, to take one example, puts a button in the field that generates an alias on click. Install the extension for your service in every browser you use, sign in to it, and try it on the next form you meet. From that point the decision at signup is no longer "shall I make an alias" but "shall I use the one being offered", and the answer is nearly always yes.
If your service has a phone app or keyboard, set that up in the same five minutes; signups on a phone are the ones that slip through.
When a site rejects the alias
It will happen. Some sites refuse addresses on any domain they recognise as an alias service; Firefox Relay's own FAQ notes that some sites have gone as far as accepting only Gmail, Hotmail and Yahoo. Your options, in order: try an alias on your own domain if you have one, since those are rarely on anyone's blocklist; decide whether the account is worth your real address, and if it is low-stakes and you need it today, use the real address and put the site on your list to revisit; or walk away, which is often the right answer for a site that has decided how you may be contacted. The post on what to do when a site rejects your alias works through the cases in more detail.
The plan on one page
| Step | Time | Done when |
|---|---|---|
| Naming rule | 5 min | One rule, written down |
| Destination and test | 5 min | Test message arrived |
| Sort accounts | 10 min | Tiers listed, first thirty picked |
| Migrate tier one | 30 min | Every verification received, mapping saved |
| Extension | 5 min | Alias offered on the next form |
| Rejections and stragglers | 5 min | Noted, not fought |
| Activity view | 1 week | First leak found and switched off |
After the hour: read the activity view for a week
You are done with the hour. Now let the setup work. Most alias services show a per-alias log of what was delivered and from whom. For the next week, glance at it once a day. What you are looking for is an alias receiving mail from a sender you never gave it to: a shop alias hearing from a "partner", a newsletter alias getting a security warning from a company you have no account with. That is a leak, or a sale, and for the first time you know exactly where it came from. Turn the alias off, note the site against the date, and read who leaked my email address for what to do next.
Then, in a few weeks, come back for the second tier. By that point the extension will have made aliases the default for anything new, the first tier will be quietly absorbing whatever the shops sell on, and the second session will be shorter than the first.