We use cookies to enhance your experience. By continuing to visit this site you agree to our use of cookies.Privacy Policy

EvilMailEvilMail
FeaturesEverything EvilMail can doTemp Mail for…Temp mail for Discord, ChatGPT & moreNetwork ToolsDNS, WHOIS, port & network toolsCompareEvilMail vs other temp mail services
APIREST API reference & guidesTemp Mail APICopy-paste code in every language
AppsPricingBlog
About UsWho we are & what we buildTrust & SecurityHow we protect your dataFAQAnswers to common questionsContactGet in touch with the team
LoginRegister
EvilMailEvilMail
AppsPricingBlog
LoginRegister

Guides, tutorials, and updates

Expert insights on email security, disposable email services, API integrations, and DNS management.

Featured

Anti-Abuse Controls That Keep an Alias Service Off the Blocklists
SecurityAugust 4, 2026

Anti-Abuse Controls That Keep an Alias Service Off the Blocklists

The moment you let users receive mail at throwaway addresses and forward it anywhere, you are running an open-ish relay whose reputation is only as good as your worst 100 users. Here is the boundary-first playbook — SRS, ARC, Rspamd rejection thresholds, FBLs, and auto-ejection — that keeps your forwarding IPs out of Spamhaus.

13 min readRead More
The DPA and Subprocessor List You Actually Need Before You Outsource Email
PrivacyAugust 3, 2026

The DPA and Subprocessor List You Actually Need Before You Outsource Email

Wiring up SES or Postmark takes an afternoon. Being able to answer a DPO's "list every subprocessor that touches our data" request takes a DPA and a subprocessor list you treat as versioned config — not a PDF in a drive. Here is what Article 28 actually requires, mapped to the email stack, with the commands to test it.

10 min readRead More

All Posts

Encrypting Dovecot Mailboxes at Rest with mail_crypt: Global vs Per-User Keys
Security

Encrypting Dovecot Mailboxes at Rest with mail_crypt: Global vs Per-User Keys

LUKS protects nothing on a running mail server — the volume is unlocked 24/7. Dovecot's mail_crypt plugin encrypts the message payloads themselves so the bytes on disk stay ciphertext through backups, snapshots, and RMA'd drives. Here's how to pick between global and per-user keys, wire it without losing data, and migrate a live mailbox with no maintenance window.

August 3, 202612 min read
Redacting PII From Mail-Server Logs Without Going Blind
Privacy

Redacting PII From Mail-Server Logs Without Going Blind

Your mail.log is the largest un-audited PII store you run. Here is how to strip identity at the rsyslog layer, pseudonymize with a keyed HMAC, and still debug every delivery — because Postfix already hands you a PII-free correlation key.

August 3, 202612 min read
KVKK Compliance for Mail Systems Serving Turkish Users
Privacy

KVKK Compliance for Mail Systems Serving Turkish Users

The email address a user types in, and the IPs in your Received: headers and Postfix logs, are personal data under KVKK. That makes any mail operator serving Turkish users a data controller. Here are the three engineering controls — consent, retention, and a 72-hour breach runbook — that actually make you compliant.

August 3, 202612 min read
Forward and Forget: Architecting a Zero-Retention Email Alias Relay
Privacy

Forward and Forget: Architecting a Zero-Retention Email Alias Relay

Most "private" forwarders quietly spool deferred mail to disk and log your subjects, Message-IDs, and recipients for days. Here's how to build an alias relay that provably can't — content transits RAM only, SRS and ARC keep forwarded mail in the inbox, and the only thing on disk is an opaque alias-to-destination row.

August 2, 202612 min read
Detecting and Blocking Disposable Email at Signup Without Rejecting Real Users
Developers

Detecting and Blocking Disposable Email at Signup Without Rejecting Real Users

We run a temp-mail service, so here is the uncomfortable truth from the other side: static blocklists lose. Here is a layered, scored pipeline that catches throwaways without torching real customers on Apple Hide My Email or Firefox Relay.

August 2, 202611 min read
One Unsubscribe Flow That Satisfies CAN-SPAM, GDPR, and Gmail's One-Click at Once
Privacy

One Unsubscribe Flow That Satisfies CAN-SPAM, GDPR, and Gmail's One-Click at Once

The naive "single unsubscribe link" fails in three silent ways — Gmail ignores an unsigned header, link scanners drain your list on GET, and a row-delete can't prove withdrawal under GDPR. Here's how to build one flow to the strictest common denominator, with the headers, the handler, and the curl tests.

August 2, 202611 min read
Aliases vs Forwarding vs Full Masking: What Each One Actually Hides
Privacy

Aliases vs Forwarding vs Full Masking: What Each One Actually Hides

Privacy blogs use "alias", "forwarding", and "masking" interchangeably — but they defend against three completely different adversaries. Here's what leaks at the SMTP, DNS, and header level in each case, and how to pick by the threat you actually face.

August 2, 202611 min read
GDPR Retention and Deletion Policies for Mail Logs, Queues, and Delivery Events
Privacy

GDPR Retention and Deletion Policies for Mail Logs, Queues, and Delivery Events

Every line in your Postfix maillog ties an IP, an envelope sender, and a recipient to a timestamp — that is personal data under GDPR. Here is how to build a per-data-class retention clock, make expiry automatic and provable, and honor erasure without blinding your anti-abuse forensics.

August 1, 202612 min read
Idempotent, Replay-Safe Webhook Handlers for Delivery, Bounce, and Complaint Events
Developers

Idempotent, Replay-Safe Webhook Handlers for Delivery, Bounce, and Complaint Events

Mail providers send delivery events at-least-once, out of order, and from anyone who can find your URL. Here's how to build a handler that authenticates, dedupes at the database level, and never lets a late "delivered" resurrect an address that already hit "spam."

August 1, 202612 min read
XOAUTH2 for IMAP and SMTP: authenticating after app passwords die
Developers

XOAUTH2 for IMAP and SMTP: authenticating after app passwords die

App passwords are being retired on a per-provider schedule, and most mail code still authenticates with a static string. Here is the working migration playbook: the exact SASL wire format, the two OAuth flows you actually need, copy-paste token-minting and IMAP/SMTP snippets, and the failure modes nobody documents.

August 1, 202612 min read
…
EvilMailEvilMail

EvilMail — free temp mail and disposable email service. No registration required.

Product

FeaturesPricingAPITools

Resources

BlogFAQGlossaryRegisterAbout Us

Legal

Privacy PolicyTerms of ServiceTrust & SecurityContact
© 2026 EvilMail. All rights reserved.