About TempMailGenerator

TempMailGenerator is a small independent operation. We own the domains, we run the servers, and the people writing these pages are the same ones who decide which name comes out of rotation this month and which one replaces it. There is no support department and nobody's money to answer to, which is why the guides read like notes taken next to the machine rather than like a brochure.

What the click assembles

Pressing the button builds a string and writes one row. The string is a name and a domain joined by an at sign; the row says that this inbox exists and names the minute it stops existing. Nothing is provisioned, nothing is registered anywhere outside this service, and the whole operation finishes before the button has finished animating.

The name comes out in one of two shapes. Either two ordinary words run together, as in quietriver2841, or a first name and a surname joined by a dot, as in mia.reid7395. Both end in four digits, and that tail is the one piece of arithmetic in the generator worth explaining. A guest inbox opens to anybody holding its address, so guessing has to be uneconomic. Four digits put about 35 million combinations behind each domain: forty eight adjectives crossed with forty eight nouns, or forty first names crossed with forty surnames, multiplied by nine thousand endings. Shorten the tail to two digits and the same vocabulary collapses to roughly 351 thousand, a space small enough to enumerate between lunch and dinner while reading whatever turns up along the way. Pronounceability survives at either size, and it matters the moment somebody has to read an address down a telephone.

The digits come from the operating system's cryptographic source rather than from a clock or a counter. A name built from the time of day looks scrambled and is not: anyone who knows within a few minutes when an address was created can regenerate the candidates and try them in order.

Type your own name instead and the rules tighten slightly. Three to thirty two characters, lowercase letters, digits, dot, underscore and hyphen, starting and ending on a letter or a digit. Twenty six names are refused outright, among them abuse, postmaster, security and hello, because this website's own domain also carries inboxes: without that list a stranger could take the address printed on our contact page and read mail that people sent to us.

What happens between the mail server and your screen

There is no mail server here in the traditional sense, and no open port 25. Cloudflare's MX records accept the message and hand it to a small worker, which parses the MIME structure, discards anything over ten megabytes, files attachments into object storage and passes a compact summary to the application over a signed request. A message addressed to an inbox that does not exist is accepted and dropped without comment, so probing addresses at random teaches the prober nothing.

The body is cleaned once, on arrival, rather than every time you open it. Tags are matched against a list of the roughly forty that a normal message needs, and everything else goes. Inline styles are removed in their entirety, because that is how an email lays a decorative rectangle over the page it is displayed on. Links may only point at http, https or mailto, so a data: address cannot smuggle executable content in through an image tag. And the contents of script, style and iframe are thrown away with the tags rather than surviving as loose text. Whatever survives that pass is drawn inside a frame sealed off from everything around it, and that frame is the second of the two layers.

Delivery to your browser costs one connection, held open from the moment the address appears, with a keepalive every twenty five seconds so nothing in the middle closes it. Nothing on the page asks the server for news. Then a sweep runs every ten minutes, deletes the rows that have expired, removes their attachments from storage, and that is the end of the mailbox.

Why the site explains the rest of the route

Handing out an address is the easy half. The twenty guides in this section cover the other half: what a form does with the string after you submit it, which of the four checks decides your case, how many separate systems end up holding a copy, and why a perfectly legal address gets refused by code written from memory in five minutes.

We are placed unusually well to describe some of that. We watch our own domains get sampled, turn up on public lists and start failing at particular signup forms, and we know roughly how many weeks each stage takes. None of that came from a keyword tool.

Two things it will not do, and one it now does

It does not send. Every address issued here receives and nothing else. A service that lets anonymous visitors send becomes a spam relay inside a week and loses its domains shortly after, which kills the receiving side along with them.

It does not pre-clear anything. The generator has no idea whether the site you are about to visit will accept the domain it just gave you. A refusal further down the road is information nobody held at the moment of the click, and the answer is almost always another address rather than an argument.

It does have an API now, and for years this site argued that it never would. The argument was about domains being a shared and finite supply that a script drains faster than any crowd of people. What was wrong was the conclusion: the interface simply had to spend a different supply. It hands out addresses on a pool of its own that no visitor is ever offered, with ceilings on how fast a key may draw from it. The full reversal is written out here, including what we got wrong the first time.

What it costs

Nothing, and advertising pays for it. There is no paid tier, no upgrade page and nothing deliberately crippled so that a better version exists to sell. An account is free too, and it buys ten inboxes at once, unlisted domains, attachments, and an inbox that strangers cannot open by knowing the string.

Advertising sits in slots whose height is fixed before anything loads, so the text you are reading does not jump. No advert is permitted to imitate a button that belongs to the site. Formats that only earn when they are mistaken for something else get turned down.

Where it is the wrong tool

Anything you might one day need to get back into. A bank, a tax office, an employer, a courier, a registrar, a drive holding your files: the address that receives a recovery link has to be alive on the day you need it, and every address issued here is built to have expired long before. No request to us undoes that, because the deletion removes the record rather than disabling it.

Guest inboxes carry a second limit worth stating plainly: there is no password anywhere in the design, which leaves the string itself doing the entire job of a lock. The disclaimer draws both of those lines properly. Corrections, abuse reports and bug reports go through the contact page, and corrections in particular are welcome. Repairing a wrong sentence is cheaper than defending it.

Read next

All guides