VeridentiDocs
ChangelogFor BusinessContact
Docs End-user guide Set up masked email

Set up masked email

Why it's there

When you hand every site your real email, one breach or one data-broker sale is enough to flood your inbox and link your accounts together. Masked email gives each site a different address, so a leak at one can't reach the others — and you can see exactly who leaked it.

What it is

A masked email (or alias) is a stand-in address that quietly forwards to your real inbox. The site only ever sees the alias. Switch an alias off later and the forwarding stops.

Sites you sign up for shop.com quiet-fox73@your-alias news.com blue-lake20@your-alias sweeps.com warm-pine44@your-alias forward to Your real inbox stays private — one place Spam at one alias names the exact site that leaked it.
Each site gets its own masked address that forwards to your real inbox. Your real address stays private — and if one site leaks or sells your data, the alias it was sent to names the culprit. Kill that one alias and the spam stops.

Choose how aliases are made

Open Settings → Masked email and pick a provider. Use whichever service you already have — or none:

ProviderHow it works
NoneThe default — Veridenti fills your real email everywhere. Masked email is optional.
FastmailCreates a fresh masked address per site; can also import aliases you already made.
addy.ioCreates aliases under your addy default domain; can import existing ones.
SimpleLoginCreates aliases under your SimpleLogin domain; can import existing ones.
DuckDuckGoCreates a fresh @duck.com address per site.
Firefox RelayFresh address per site — your custom subdomain if you have one, else @mozmail.com (free plan caps at 5).
Forward EmailCreates a fresh masked@yourdomain per site (needs your own domain).
TipWhich should I pick? Already use one of these? Pick that one — Veridenti will use the aliases you already have. New to masked email? DuckDuckGo and Firefox Relay are free and the quickest to start. Want your aliases under your own domain? Choose Fastmail, addy.io, SimpleLogin, or Forward Email.

Connect a provider

Most providers need a one-time key so Veridenti can make aliases for you:

  1. In Settings → Masked email, choose your provider.
  2. Paste your provider's API key (for Fastmail it's an API token starting with fmu1-). Forward Email also asks for your domain.
  3. Click Save & use this provider. Veridenti verifies the key and, where supported, loads any aliases you already have.
NoteYour key stays on your device, encrypted at rest. Veridenti uses it only to create or fetch aliases — it never reads your mail. Find the key in your provider's own settings, usually under "API" or "Integrations".

Create an alias on a signup form

Once a provider is connected, Veridenti offers a masked address right where you need it:

  1. On a signup or newsletter form, click into the email field — a small mask icon appears inside it.
  2. Click it to open the Masked email — this site picker.
  3. Click Create a masked email (add an optional label first), or pick one you've already made. Veridenti fills the alias into the form.

To use your real address instead, open the same picker and choose Use my real email ("Always delivers").

Kill an alias later

If an alias starts getting spam, that site leaked or sold your address. Turn the alias off and the forwarding stops — your real inbox never sees another message from it. Leak Radar can point out which alias is affected, often before a breach is even public.

What if masked email isn't offered?

What's next

Last updated August 26, 2026 · Docs v1.3
Enter to open · Esc to close
Veridenti