Disclaimer

A generated address has one job and a short life. This page is about the places people reach for it anyway, and what it costs when the tool turns out to be the wrong shape for the job.

Everything here follows from the expiry

The address you were just handed carries a deletion time from its first second. Nothing you do keeps it alive indefinitely. A guest inbox survives one day past the last time you looked at it, and it goes instantly if you ask the generator for a replacement. An account stretches those numbers upward; it does not remove them.

So before pasting an address into a form, look at what the form is guarding. If the account behind it holds money, files, a domain name, a job, a parcel or a government record, the address is wrong for it, and no amount of care changes that.

The failure is undramatic and it arrives months later. A password needs resetting, the reset link goes to the address on file, that address was removed by a cleanup pass weeks earlier, and nobody at the other company can now confirm the account belonged to you in the first place. Nothing has been locked. The account is orphaned, and we cannot help, because deleting an inbox here removes the record instead of disabling it.

Refusal by a form is normal, and it is not a fault

Identifying disposable domains is a small industry with its own vendors and its own subscription lists, refreshed continuously. A domain that becomes popular becomes recognised. When a signup form tells you the address is not acceptable, the check on the other side did exactly what it was built to do.

Generate again and you get a different domain. Sign in and you get domains that are never displayed on this website, which is why they stay unrecognised much longer. What will not help is waiting, retrying the same string, or writing to us: another company's list is not something we can edit, and an appeal from us carries negative weight.

The message may never arrive, and the silence explains nothing

This is the quieter half of the same problem. A sender that rejects disposable domains usually says nothing at all. No bounce comes back to you, nothing shows up on our side, and the code you are sitting there waiting for was never issued in the first place rather than lost in transit.

From where you stand that looks the same as a service having a slow afternoon, which is how ten minutes disappear into pressing refresh. We cannot promise that a given site will write to a given address. Two minutes of nothing is the point where generating again beats waiting longer.

A guest address is not a secret

Guest inboxes have no password. Whoever knows the address reads what is inside, by design, since there is no account behind it and therefore no identity to check.

The random names produced here are hard to guess, which is a real protection but a statistical one rather than a lock: about 35 million possibilities on a domain makes a search uneconomic, not impossible. A name you type in yourself is weaker by a wide margin, because short memorable words are precisely what somebody sweeping a domain tries first. Treat anything landing at a guest address as visible to strangers. Anything you would mind being read belongs behind an account, where the inbox answers to its owner alone.

Even then this remains a free service funded by advertising, not a confidential channel, and no page on this site has ever described it as one.

An expired name does not stay yours

Deletion returns the string to circulation. There is no permanent register of names that have ever been used, because keeping one would mean holding a record of every address forever, which is the opposite of what this service is for.

The consequence is worth stating: a name you generated today may be issued to somebody else next month, and mail still addressed to it will land in their inbox rather than yours. Old newsletters, forgotten receipts and stale reset links all follow the name, not the person. That is one more reason not to leave a generated address on file anywhere you care about, and it is set out in full in what happens when the same address comes back.

We do not vet what arrives

The contents of an inbox are the work of the people who mailed it. Nothing there passes across a desk of ours, nothing is moderated, and we stand behind none of the links, offers or files inside.

Scripts, stylesheets and frames are removed before display, and known executable file types never reach storage at all. That defeats the ordinary attack. It does not defeat the tracking pixel: images load from the sender's server, so opening a message tells the sender the address is read. It does not make a hostile document harmless or a fraudulent link honest. A message arriving at an address that did not exist a minute ago came from a stranger, and no amount of filtering changes what that implies about its contents.

The API is a tool, and the responsibility travels with it

Addresses issued through the interface come from a pool that is recognisably disposable, and the limits on a key are not a suggestion. Point it at your own test suite, your own staging environment, your own signup flow. Pointed at somebody else's service to open accounts in bulk or slip past their rules, it becomes an incident in their logs and then in ours, and the key stops working. The reasoning behind each ceiling is in why the API has the limits it has.

The guides describe systems we do not run

Those twenty pages cover the far side of a signup form: how validation runs, the route an address takes through a company, what a breach does with it afterwards. All of that is somebody else's software and somebody else's policy, revised whenever they feel like it and announced to nobody.

Text that was correct on the day of writing therefore rots on its own. Verify how a thing behaves today before you build anything on it, and when a page here has fallen behind reality, say so on the contact page. Nothing written here is tailored to your situation, and nothing written here is legal advice. Where real consequences are on the table, put the question to a qualified person in your own country instead of to a free mail service.

What the tool is actually for

None of the above is an argument against generated addresses. It is an argument for using them where the mail stops mattering quickly, which covers most of the mail a person receives.

For a signup wall, a download gate, a trial, a forum you will visit twice, a discount code: generate, paste, read the message, walk away. For anything with a balance, a renewal, a name on a document or a key to something else: use a real mailbox, and if you would rather not hand over your main one, take an alias from your own provider, which lasts until you decide otherwise instead of until a timer runs out.

One rule covers both cases. Copy what you need out of the message before you leave the page: the order reference, the licence key, the confirmation number. This is a delivery point and not storage, and it is built to forget on a schedule.

The service, finally

Costs nothing, warrants nothing. Availability is not promised, the behaviour described on these pages can change, and the whole thing may stop one day and take every open inbox down at the same instant. What is left of the small print sits in the terms.

Read next

All guides