12 Email Privacy Tips to Take Back Control of Your Inbox
Your email address is the master key to your online life — it's how you log in, reset passwords, and get found by marketers and data brokers. A few deliberate habits dramatically shrink your exposure. Here are twelve, from easy to advanced.
Quick wins
- 1. Keep a private address for people, not services. Share it only with humans you trust.
- 2. Use a disposable address for low-risk, one-off sign-ups. Public downloads, newsletters, and communities where it's allowed don't need your real one.
- 3. Tag your aliases.
you+store@gmail.comstill reaches you but reveals who leaked your address. - 4. Never post your address in plain text on public pages — bots scrape them.
Account hygiene
- 5. Turn on two-factor authentication on your primary mailbox — it's the account that can reset all the others.
- 6. Use a unique, strong password for email, stored in a password manager.
- 7. Review connected apps and revoke anything you no longer use.
- 8. Check your address at a breach-notification service and rotate passwords where it appears.
Advanced moves
- 9. Block tracking pixels. Many newsletters embed invisible images that report when and where you opened them; turn off automatic image loading or use a client that blocks trackers.
- 10. Compartmentalize. Separate addresses for personal, shopping, and throwaway use limit how far any single leak spreads.
- 11. Be wary of “log in with email” link emails — they're a common phishing vector. See how to spot a phishing email.
- 12. Have an exit plan. Know how you'd recover your account if your address were compromised tomorrow.
If you do just two things: enable 2FA on your main inbox, and stop typing your real address into sites you don't trust. A disposable inbox makes the second one effortless.
For the bigger picture on limiting breach damage, read how to protect your email from data breaches.
A quick-start privacy checklist, step by step
Twelve tips is a lot at once. If you're starting from scratch, work through them in this order — each step makes the next easier, and you can stop whenever you've had enough for one sitting.
- Set up a password manager and give every account a unique password. This is the foundation. Once a manager is generating and storing passwords, you never reuse one again — so a leak at one site can't unlock the others.
- Turn on two-factor authentication for your email and important accounts. Start with the mailbox itself, since it can reset everything else, then add it to banking, work, and anything tied to money.
- Keep one guarded primary address, and use throwaway or alias addresses for signups. Reserve your real address for people and accounts that matter; for trials, downloads, and forums, a disposable inbox keeps the noise — and the next breach — away from it.
- Review and revoke old app permissions and unused accounts. Every connected app and dormant login is a door someone else might walk through. Close the ones you've forgotten about.
- Periodically unsubscribe and clean out your lists. A smaller footprint is a quieter, safer one — make it a recurring habit, not a one-time purge.
You don't have to do all five in an afternoon. Steps one and two are the ones that actually stop break-ins — get those done first, and treat the rest as gradual cleanup you return to over weeks.
Tools worth using
You don't need a shelf of software to do this well — a small, boring toolkit covers most of it. We're keeping these generic on purpose; pick reputable options and read their privacy terms.
- A password manager. Generates and remembers a unique password per account, so a single leak stays contained. This is the one tool that quietly fixes the most.
- An authenticator app. Produces 2FA codes on your device. It's sturdier than SMS codes, which can be intercepted or redirected.
- An alias or temporary email. Aliases let you create per-service addresses you can mute or kill; a temporary inbox like this one handles the truly one-off signups you'll never log into again. For the spam angle specifically, see how to stop email spam.
- A breach-notification service such as Have I Been Pwned. Tells you when your address surfaces in a known leak, so you can change that password before anyone tries it. Pair it with protecting your email from data breaches.
Frequently asked questions
What's the single most important step? Unique passwords stored in a manager, with 2FA on your email. That pairing closes off the most common way accounts actually fall — a password reused from some other site that was breached. Everything else on this page is worthwhile, but those two do the heavy lifting.
Is a temporary email enough on its own? No — and it's worth being honest about that. A temporary inbox handles exactly one slice of the problem: keeping your real address off sites you don't trust. It does nothing for your password habits, your 2FA, or the accounts you already own. Remember too that our inboxes are public and receive-only, and messages auto-delete within about 24 hours, so they're for throwaway signups, never for anything you need to keep or for sensitive accounts. Treat it as one layer among several, not the whole defense.