Privacy-First Disposable Email
Everything you need to protect your inbox, automate email workflows, and keep your identity safe — all in one platform.
Instant Disposable Email
Generate a fully working email address in under 2 seconds. No sign-up, no personal information, no traces. Your temporary inbox is ready the moment you visit.
Zero-Knowledge Privacy
We don't track you, sell your data, or store anything beyond your session. No analytics cookies, no advertising pixels, no third-party trackers. Your privacy is not a feature — it's our foundation.
Auto-Expiring Inboxes
Choose how long your inbox lives — from 10 minutes to 24 hours. When time's up, every email, attachment, and trace is permanently wiped. Nothing lingers.
Your Domain, Your Brand
Connect your own domain and create unlimited email accounts under it. Full DNS management with automated MX, NS, and TXT record configuration included.
Developer-Ready API
Integrate disposable email into your apps, CI/CD pipelines, and test suites. Create inboxes, read messages, and manage domains programmatically with our RESTful API.
Desktop & Mobile Client Support
Access your mailbox from Thunderbird, Outlook, Apple Mail, or any email client. Full POP3 and IMAP protocol support means you're never locked into a web interface.
12 Languages, Multiple Domains
Available in English, Turkish, Russian, Ukrainian, Polish, Persian, Filipino, French, German, Azerbaijani, Hausa, and Akan. Choose from system domains or bring your own.
Smart Verification Code Extraction
Automatically parse incoming emails and extract verification codes from popular services. Perfect for automated testing, account creation, and signup flows.
Built-In DNS Management
Manage A, AAAA, CNAME, MX, TXT, NS, SRV, and CAA records directly from your dashboard. Four geographically distributed nameservers ensure maximum uptime.
End-to-End Email Encryption
Every email is transmitted over SSL/TLS encrypted channels with STARTTLS enforcement. Full DKIM signing, SPF records, and DMARC policies ensure your messages are authenticated and tamper-proof.
Why EvilMail?
No Sign-Up Required
Generate a temp email instantly. Zero friction.
99.9% Uptime
Redundant infrastructure. Always online.
Self-Destructing
Emails vanish automatically. No cleanup needed.
Global Infrastructure
4 nameservers across multiple regions.
Ready to Take Control of Your Inbox?
Create your first disposable email in seconds. No credit card, no commitment.
Privacy & Security Insights
Practical guides to help you stay safe, anonymous, and in control of your digital footprint.
TLS 1.3 on Postfix and Dovecot Without Breaking Inbound Mail
Cranking the cipher floor everywhere quietly makes inbound mail less secure. The correct 2026 posture: lock TLS 1.3 hard on submission and IMAP, keep port 25 deliberately permissive, and get inbound guarantees from MTA-STS, DANE and TLS-RPT instead.
Catching Bulk Spam With rspamd Fuzzy Hashing and Your Own Shared Storage
Bayes trains on words and RBLs blocklist IPs — a coordinated blast that rotates sending IPs and mutates two words per copy walks through both. What survives the mutation is the message skeleton. Here's how rspamd fingerprints that skeleton with min-hash shingles, and how running your own shared fuzzy_storage turns one spam-trap hit into a fleet-wide reject.
Backscatter and Joe-Jobs: Reject Bad Recipients at SMTP Time, Never Bounce Later
A joe-job spammer forges your domain in a million MAIL FROMs, and every receiver that accepts-then-bounces mails the failure report to you. That flood is backscatter, and the cure isn't a better spam filter — it's rejecting unknown recipients with a 5xx during the SMTP transaction. Here is the Postfix, Rspamd, and DNS configuration that keeps your MTA from becoming a secondary spam emitter.
SpamAssassin Custom Rules and Meta Scoring: Catch the Pattern, Not the Word
Individual spam signals are deliberately weak, and SpamAssassin's additive engine sums them blindly. Meta rules let you score the combination instead — here's how to build component tests scored at zero, wire them into boolean and N-of-M metas, and tune one high-confidence score without spraying false positives.
Catching Compromised Mailboxes: Outbound Spam Detection with rspamd and Volume Baselines
Your inbound rspamd stack is airtight, and that is exactly why you still get blocklisted. When an attacker logs into port 587 with valid SASL credentials, their spam run is authenticated, trusted, and completely unfiltered. Here is how to put rspamd on the submission path and catch the breach in the first 200 messages.
Rspamd + Postfix over Milter: the Proxy Worker Done Right
Most guides bolt rspamd onto Postfix and stop at "it works." The correct 2026 default is the milter path through the rspamd proxy worker in self-scan mode: one ingress that scans inbound and DKIM-signs outbound. Here's the exact wiring, the macros that silently kill scoring, and how to read the verdict from headers instead of guessing.

