How It Works
Open the page, get an address
The moment you arrive, the service generates a random address on one of its domains and shows it to you. There is no form to fill in and nothing to confirm.
Messages arrive on their own
The page holds a live connection to the server. When a message is delivered, it appears in your inbox without a refresh. If your network or a corporate proxy cuts that connection, the page quietly falls back to checking every few seconds, and the connection indicator tells you which mode it is in.
Your inbox is not open to anyone who guesses the address
Knowing the address is never sufficient. Your browser holds a private authorisation created with the inbox. To open the same inbox from a different browser you need the separate recovery code shown when it was created — which is why the service asks you to save it.
Everything expires
The header above your inbox shows two times: when the address stops receiving mail, and when the stored messages are deleted. Background jobs enforce both. You can also delete a message, or the whole inbox, immediately.
Messages are treated as hostile
Every message is stripped of scripts, embedded frames, forms and unsafe links before it is stored. Remote images are blocked so that opening a message does not report back to the sender. The message itself is displayed inside an isolated frame that cannot run code or reach the rest of the page.