{"id":400,"date":"2026-09-21T19:09:32","date_gmt":"2026-09-21T13:39:32","guid":{"rendered":"https:\/\/emailalias.io\/blog\/?p=400"},"modified":"2026-09-21T19:09:34","modified_gmt":"2026-09-21T13:39:34","slug":"email-leak-detection","status":"publish","type":"post","link":"https:\/\/emailalias.io\/blog\/email-leak-detection\/","title":{"rendered":"Email Leak Detection: How to Know When an Alias Is Exposed"},"content":{"rendered":"<div class=\"post-tldr\">\n  <p class=\"post-tldr__title\">The short version<\/p>\n  <ul>\n    <li><strong>Email leak detection tells you which of your addresses was exposed<\/strong> \u2014 not just that you were in a breach, but which service leaked or sold your details.<\/li>\n    <li><strong>Aliases make it work.<\/strong> Each alias is used with one service, so a strange sender on it is a clear sign the address has escaped.<\/li>\n    <li><strong>EmailAlias watches this for you<\/strong> and flags odd senders and leak patterns on each alias \u2014 an early warning so you can switch off the leaked alias before the spam starts.<\/li>\n  <\/ul>\n<\/div>\n\n<p>Email leak detection tells you when an email address you use has been exposed. Most people only find out when <a href=\"https:\/\/en.wikipedia.org\/wiki\/Email_spam\" rel=\"noopener\" target=\"_blank\">spam<\/a> and scams start rolling in. The goal here is to find out sooner \u2014 and to know exactly which service leaked you. A normal inbox can&#8217;t do that, because everyone emails your one real address. EmailAlias can, because you give each service its own alias, so the mail arriving at each one is a clue. This guide explains what email leak detection is, how EmailAlias does it, and how to use it every day.<\/p>\n\n<nav class=\"post-toc\" aria-label=\"Table of contents\">\n  <h2 class=\"post-toc__title\">Table of contents<\/h2>\n  <ol class=\"post-toc__list\">\n    <li><a href=\"#what\">What email leak detection is (and what it isn&#8217;t)<\/a><\/li>\n    <li><a href=\"#why\">Why aliases make leak detection possible<\/a><\/li>\n    <li><a href=\"#how-it-works\">How EmailAlias does email leak detection<\/a><\/li>\n    <li><a href=\"#how-to-use\">How to use email leak detection in EmailAlias<\/a><\/li>\n    <li><a href=\"#risk-score\">How to read a risk score and what to do<\/a><\/li>\n    <li><a href=\"#benefits\">How you benefit<\/a><\/li>\n    <li><a href=\"#compared\">Email leak detection compared<\/a><\/li>\n    <li><a href=\"#limitations\">Honest limitations<\/a><\/li>\n    <li><a href=\"#final-thoughts\">Final thoughts<\/a><\/li>\n    <li><a href=\"#faq\">Frequently asked questions<\/a><\/li>\n  <\/ol>\n<\/nav>\n\n<h2 id=\"what\">What Email Leak Detection Is (and What It Isn&#8217;t)<\/h2>\n<p>Email leak detection is any tool that watches for signs that one of your email addresses has been exposed \u2014 leaked, scraped, sold, or caught in a <a href=\"https:\/\/en.wikipedia.org\/wiki\/Data_breach\" rel=\"noopener\" target=\"_blank\">data breach<\/a> \u2014 so you can act before it turns into spam or fraud. There are two main kinds, and it helps to know which one you&#8217;re using.<\/p>\n<ul>\n  <li><strong>Breach-database checks.<\/strong> Tools like <a href=\"https:\/\/haveibeenpwned.com\/\" rel=\"noopener\" target=\"_blank\">Have I Been Pwned<\/a> check if your address shows up in a known, published breach. This is useful, but it only works after a breach goes public \u2014 and since it watches your one real address, it can&#8217;t tell you which service leaked it.<\/li>\n  <li><strong>Per-alias detection.<\/strong> This kind watches the mail arriving at each of your addresses and flags anything odd. Because it&#8217;s tied to one alias, it can point straight at the service that leaked. This is what EmailAlias does.<\/li>\n<\/ul>\n<p>One thing to be clear about: EmailAlias&#8217;s leak detection is <strong>not<\/strong> a breach database or a dark-web scan. It doesn&#8217;t prove a company was hacked. It&#8217;s an early warning based on who is emailing your aliases \u2014 a signal to go and look, not a final verdict. EmailAlias says exactly this in its own alerts, and so does this guide.<\/p>\n<aside class=\"post-keytakeaway\"><strong>Key takeaway:<\/strong> There are two kinds of leak detection: breach-database checks (which watch your real address, after the fact) and per-alias detection (which watches mail as it arrives and names the service). EmailAlias does the second \u2014 its flags are early warnings to check, not proof of a breach.<\/aside>\n\n<h2 id=\"why\">Why Aliases Make Leak Detection Possible<\/h2>\n<p>The whole idea rests on one simple fact about aliases. When you sign up somewhere with a dedicated alias, only that one service should ever email that address. So a stranger showing up on it is a real clue: the address has ended up somewhere it shouldn&#8217;t have.<\/p>\n<p>Your real inbox can&#8217;t give you that clue. Everyone emails your real address, so an unknown sender there means nothing. An <a href=\"https:\/\/emailalias.io\/blog\/what-is-an-email-alias\/\" rel=\"noopener\" target=\"_blank\">email alias<\/a> has just one expected sender, which turns it into a quiet tripwire \u2014 the moment the wrong mail arrives, you learn something about the service you gave it to. For the basics of how the forwarding works, see <a href=\"https:\/\/emailalias.io\/blog\/how-email-aliases-work\/\" rel=\"noopener\" target=\"_blank\">how email aliases work<\/a>.<\/p>\n<aside class=\"post-keytakeaway\"><strong>Key takeaway:<\/strong> An alias has one expected sender, so an unexpected one is a real signal. Your real address hears from everyone, so a stranger there tells you nothing \u2014 which is why per-alias detection works where inbox monitoring can&#8217;t.<\/aside>\n\n<h2 id=\"how-it-works\">How EmailAlias Does Email Leak Detection<\/h2>\n<p>EmailAlias checks every message as it arrives, and it looks for two things. Both run automatically, in real time, on the alias the mail was sent to.<\/p>\n<p><strong>1. Suspicious senders.<\/strong> For each message, EmailAlias gives the sender&#8217;s domain a risk score from 0 to 100. Well-known senders like the big mail providers score near zero. The score goes up when a domain looks dodgy: a risky <a href=\"https:\/\/en.wikipedia.org\/wiki\/Top-level_domain\" rel=\"noopener\" target=\"_blank\">top-level domain<\/a> like <em>.xyz<\/em>, <em>.top<\/em>, or <em>.tk<\/em>; long or random-looking subdomains; scam words in the name; or a domain stuffed with digits and hyphens. A high enough score is logged as an exposure event on that alias.<\/p>\n<p><strong>2. Leak detection.<\/strong> EmailAlias also counts how many <em>different<\/em> senders hit one alias in a short time. An alias should only hear from one service, so if a dozen or more strangers suddenly email the same alias within about an hour, that&#8217;s what a leaked or sold address looks like. EmailAlias flags that alias as compromised so it stands out.<\/p>\n\n<figure class=\"wp-block-image size-large\">\n  <img data-recalc-dims=\"1\" src=\"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/email-leak-detection-example.jpg?resize=1080%2C608&#038;ssl=1\"\n       alt=\"email leak detection: a magnifying glass over a row of envelopes, inspecting which alias leaked\"\n       width=\"1080\" height=\"608\" loading=\"lazy\" decoding=\"async\" \/>\n  <figcaption>Email leak detection inspects the mail arriving at each alias \u2014 a suspicious sender, or a burst of strangers on one address, is the tell that it leaked.<\/figcaption>\n<\/figure>\n\n<p>Both checks feed the same exposure log, and repeat mail from the same sender on the same alias is grouped for a day so one noisy sender doesn&#8217;t flood your view. And remember: a flag is a prompt to look, not proof. EmailAlias says so in its own alerts \u2014 &#8220;a heuristic signal, not a confirmed breach \u2014 review the sender before acting.&#8221; It shows you something worth a quick look, fast, without pretending to be certain.<\/p>\n<aside class=\"post-keytakeaway\"><strong>Key takeaway:<\/strong> Two checks run in real time \u2014 a 0\u2013100 risk score on each sender, and a leak flag when lots of unknown senders hit one alias fast. Both are early warnings on a specific alias, not proof of a breach.<\/aside>\n\n<h2 id=\"how-to-use\">How to Use Email Leak Detection in EmailAlias<\/h2>\n<p>The best part is how little you have to do. Leak detection is on for every alias by default \u2014 nothing to set up. You just read what it shows and act when something looks wrong. Here&#8217;s the routine:<\/p>\n<ol>\n  <li><strong>Let it run.<\/strong> Every message to every alias is scored the moment it arrives. You don&#8217;t tag senders or train anything.<\/li>\n  <li><strong>Check your dashboard.<\/strong> It shows a running count of exposure alerts across all your aliases \u2014 a quick sense of how much has been flagged.<\/li>\n  <li><strong>Open the exposure list.<\/strong> On the <a href=\"https:\/\/emailalias.io\/monitoring-analytics\" rel=\"noopener\" target=\"_blank\">monitoring &amp; analytics<\/a> page, each event shows four things: the alias, the sender&#8217;s domain, a 0\u2013100 risk score, and the time. That&#8217;s enough to see which service and how serious.<\/li>\n  <li><strong>Watch for email alerts.<\/strong> Higher-risk events also email you, so you don&#8217;t have to watch the dashboard. Alerts are rate-limited so a bad day doesn&#8217;t bury you.<\/li>\n  <li><strong>Act on the serious ones.<\/strong> If an alias is flagged for a service that shouldn&#8217;t be drawing strange mail, treat it as exposed and switch it off (how to, just below).<\/li>\n<\/ol>\n<p>What you see depends on your plan. The <a href=\"https:\/\/emailalias.io\/pricing\/\" rel=\"noopener\" target=\"_blank\">free plan<\/a> gives you basic leak detection: your most recent events and alerts for the highest-risk flags. Premium ($4\/month) adds the full history, alerts for every event, and faster notifications. The detection runs the same on both \u2014 the difference is how much you can see and how often it emails you.<\/p>\n<aside class=\"post-keytakeaway\"><strong>Key takeaway:<\/strong> Nothing to switch on. Read the exposure list (alias, sender, score, time) on the monitoring page, watch for email alerts, and act on the serious ones. Free shows recent events; Premium shows the full history.<\/aside>\n\n<h2 id=\"risk-score\">How to Read a Risk Score and What to Do<\/h2>\n<p>The 0\u2013100 score is meant to be easy to read:<\/p>\n<ul>\n  <li><strong>Low (near zero).<\/strong> A known, trusted sender. The alias is fine \u2014 nothing to do.<\/li>\n  <li><strong>Moderate.<\/strong> Something&#8217;s slightly off about the sender. It may be harmless, but it&#8217;s worth a glance \u2014 especially if you didn&#8217;t expect a new sender on that alias.<\/li>\n  <li><strong>High, or a leak flag.<\/strong> A clearly suspicious sender, or lots of unknown senders on one alias. This is the one to act on.<\/li>\n<\/ul>\n<p>When an alias is flagged high, acting is quick \u2014 because it&#8217;s an alias:<\/p>\n<ol>\n  <li><strong>Remember which service it belongs to.<\/strong> If you labelled the alias when you made it (always do), the source is obvious.<\/li>\n  <li><strong>Treat that service as having leaked your address.<\/strong> Breached, careless, or selling data \u2014 the result is the same for you.<\/li>\n  <li><strong>Switch off or replace the alias.<\/strong> Flip the kill switch and the problem stops at that one address, without touching your real inbox or your other aliases. Our guide on <a href=\"https:\/\/emailalias.io\/blog\/how-to-stop-spam-emails\/\" rel=\"noopener\" target=\"_blank\">how to stop spam emails<\/a> covers the switch-and-replace routine.<\/li>\n  <li><strong>Check anything you reused.<\/strong> If you reused a password or shared other details with that service, change them too. For the full checklist, see what to do after an <a href=\"https:\/\/emailalias.io\/blog\/email-data-breach-what-to-do\/\" rel=\"noopener\" target=\"_blank\">email data breach<\/a>.<\/li>\n<\/ol>\n<p>Keep it simple: a flag means &#8220;go look,&#8221; not &#8220;you&#8217;ve been breached.&#8221; Check the sender first \u2014 a new but legitimate partner of the service can score moderate. The win is that you&#8217;re looking at all, at the right address, at the right time.<\/p>\n<aside class=\"post-keytakeaway\"><strong>Key takeaway:<\/strong> Low is normal, moderate is worth a glance, high or a leak flag is your cue to act \u2014 find the service, treat it as exposed, and switch off that one alias. Because it&#8217;s an alias, the fix is a single switch.<\/aside>\n\n<h2 id=\"benefits\">How You Benefit<\/h2>\n<p>Per-alias leak detection gives you four things a normal inbox can&#8217;t:<\/p>\n<ul>\n  <li><strong>Early warning.<\/strong> You often catch the odd sender or the burst of strangers <em>before<\/em> the full spam and <a href=\"https:\/\/en.wikipedia.org\/wiki\/Phishing\" rel=\"noopener\" target=\"_blank\">phishing<\/a> wave hits \u2014 time to shut the address first.<\/li>\n  <li><strong>You learn who leaked you.<\/strong> Over time you see which services respect your data and which don&#8217;t \u2014 and you can stop trusting the leakers with anything sensitive.<\/li>\n  <li><strong>An easy fix.<\/strong> The exposed address is just an alias, so reacting costs nothing: switch it off and move on. A leak of your real address, you can&#8217;t switch off.<\/li>\n  <li><strong>No effort.<\/strong> It runs on its own, on every alias, with no lists to keep. You get monitoring without doing any.<\/li>\n<\/ul>\n<p>It also works well next to a breach-database check. Use EmailAlias to catch exposure as it happens and to know <em>which<\/em> service to blame, and keep something like Have I Been Pwned for confirmed public breaches. Between them you cover &#8220;which address is acting exposed right now&#8221; and &#8220;did my details show up in a known breach.&#8221; If you&#8217;re cleaning up existing exposure too, our guide to <a href=\"https:\/\/emailalias.io\/blog\/remove-yourself-from-data-brokers\/\" rel=\"noopener\" target=\"_blank\">removing yourself from data brokers<\/a> is a good next step.<\/p>\n<aside class=\"post-keytakeaway\"><strong>Key takeaway:<\/strong> You get early warning, you learn who leaked you, the fix is one switch, and it needs no effort \u2014 and it works alongside breach-database checks, not instead of them.<\/aside>\n\n<h2 id=\"compared\">Email Leak Detection Compared<\/h2>\n<p>Here&#8217;s how the common ways to spot an exposed address stack up.<\/p>\n\n<figure class=\"wp-block-table\"><table><caption>How different email leak detection approaches compare on what they watch and what they can tell you<\/caption>\n  <thead>\n    <tr><th>Approach<\/th><th>What it watches<\/th><th>Tells you which address leaked?<\/th><th>Real-time?<\/th><th>Needs the breach to be public?<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td>Breach-database monitoring (e.g. HIBP)<\/td><td>Published breach dumps vs your real address<\/td><td>No<\/td><td>No \u2014 after the fact<\/td><td>Yes<\/td><\/tr>\n    <tr><td>Watching your own inbox for spam<\/td><td>Spam that reaches you<\/td><td>Rarely<\/td><td>No<\/td><td>No<\/td><\/tr>\n    <tr><td>Per-alias exposure intelligence (EmailAlias)<\/td><td>Senders arriving at each alias<\/td><td>Yes \u2014 the alias names the service<\/td><td>Yes<\/td><td>No<\/td><\/tr>\n  <\/tbody>\n<\/table><\/figure>\n\n<p>None of these is simply &#8220;better&#8221; \u2014 they answer different questions. Breach-database checks are the go-to for confirmed public breaches. Per-alias detection is the only one that&#8217;s real-time and can name the exact service that leaked. The best setup uses both, which is why leak detection lives inside EmailAlias rather than trying to replace a breach scanner.<\/p>\n\n<h2 id=\"limitations\">Honest Limitations<\/h2>\n<p>Email leak detection is worth having, but it&#8217;s fair to be straight about the edges:<\/p>\n<ul>\n  <li><strong>It&#8217;s a warning, not a verdict.<\/strong> A high score is a reason to look, and it can be a false alarm \u2014 a new but legitimate sender can score moderate. Always check before you act.<\/li>\n  <li><strong>It only sees mail that arrives.<\/strong> If a service leaks your address to a list that hasn&#8217;t emailed you yet, there&#8217;s nothing to detect until someone does. It catches exposure as it turns into mail.<\/li>\n  <li><strong>It&#8217;s not a breach database.<\/strong> It won&#8217;t tell you your details showed up in a specific public dump \u2014 that&#8217;s what a tool like Have I Been Pwned is for. Use both.<\/li>\n  <li><strong>Free plans see less.<\/strong> The free plan shows recent events and the worst alerts; the full history and alerts for every event are Premium.<\/li>\n<\/ul>\n<p>None of this changes the core value. Per-alias detection is the only signal that&#8217;s both real-time and able to point at one service \u2014 and since the flagged address is an alias you can switch off (never your real inbox), acting on it is nearly free. For more on when to give out your real address at all, see <a href=\"https:\/\/emailalias.io\/blog\/should-you-use-your-real-email\/\" rel=\"noopener\" target=\"_blank\">whether you should use your real email online<\/a>, and for the scams that follow a leak, <a href=\"https:\/\/emailalias.io\/blog\/types-of-phishing-attacks\/\" rel=\"noopener\" target=\"_blank\">the common types of phishing attacks<\/a>.<\/p>\n\n<h2 id=\"final-thoughts\">Final Thoughts<\/h2>\n<p>Most people learn an address leaked only once the spam is already rolling in. Email leak detection moves that moment earlier and makes it specific: instead of &#8220;my email gets spam,&#8221; you get a real-time signal that names the service and lets you shut it off at a single address. EmailAlias builds this into every plan \u2014 automatically, with no setup \u2014 and keeps it honest: it&#8217;s an early warning, a nudge to look and act, not a claim that a breach happened. Give each new service its own alias, check your exposure view now and then, and when an alias lights up, switch it off. That&#8217;s the whole habit \u2014 and it makes your inbox the first place you hear about a leak instead of the last.<\/p>\n\n<h2 id=\"faq\">Frequently Asked Questions<\/h2>\n<div id=\"rank-math-faq\" class=\"rank-math-block\">\n<div class=\"rank-math-list \">\n<div id=\"faq-q-1\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">What is email leak detection?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Email leak detection is any system that watches for signs an address you use has been exposed \u2014 leaked, scraped, sold, or breached \u2014 so you can react before it turns into spam or fraud. It comes in two forms: breach-database monitoring, which checks whether your real address appears in published breach dumps, and behavioural per-alias detection, which watches the mail arriving at each of your addresses and flags anomalies. EmailAlias does the second: it scores senders and spots leak patterns on each individual alias.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-q-2\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">Does EmailAlias check breach databases like Have I Been Pwned?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>No. EmailAlias&#8217;s exposure intelligence is not a breach database or a dark-web scan, and it doesn&#8217;t claim to confirm that a company was hacked. It&#8217;s a heuristic signal built from who is emailing your aliases \u2014 it scores sender domains for risk and flags when many unknown senders hit one alias. For confirmed public breaches, use a breach-database service like Have I Been Pwned alongside it; the two answer different questions and work well together.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-q-3\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">How does EmailAlias know an alias has leaked?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Two ways. First, it scores the domain of every sender that reaches an alias from 0 to 100, raising the score for high-risk top-level domains, scam-like keywords, and machine-generated-looking domain names. Second, it watches how many different senders hit a single alias in a short window \u2014 if a dozen or more distinct, unfamiliar senders arrive within about an hour, that burst looks like a leaked or sold address, and the alias is flagged as compromised. Both run automatically as mail arrives.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-q-4\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">What is a risk score?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>It&#8217;s a 0\u2013100 number EmailAlias assigns to the sender of each message that reaches an alias, based on heuristics about the sender&#8217;s domain. Known, reputable senders score near zero. The score rises for suspicious signals like risky top-level domains (.xyz, .top, .tk), deeply nested or randomised subdomains, scam-associated words in the domain, or names stuffed with digits and hyphens. A low score is normal, a moderate score is worth a glance, and a high score is a prompt to investigate that alias.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-q-5\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">What should I do when an alias is flagged?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Recall which service the alias belongs to (labelling aliases at creation makes this instant), treat that service as having leaked or sold your address, and disable or rotate the alias. Because it&#8217;s an alias, that single switch stops the exposure at that address without affecting your real inbox or any other alias. If you reused a password or shared other details with that service, rotate them too. Remember the flag is a heuristic prompt to look \u2014 review the sender before acting.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-q-6\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">Does email leak detection cost extra?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>No \u2014 it&#8217;s built into every plan, including the free tier, and runs automatically with no setup. The difference is visibility: the free plan gives you basic leak detection with your most recent exposure events and alerts for the highest-risk flags, while Premium ($4\/month) unlocks the full exposure history, email alerts for every recorded event, and tighter notification timing. The detection engine itself is the same on both plans.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-q-7\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">Can email leak detection give false alarms?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>Yes, and the product is upfront about it. The signals are heuristics, not confirmations, so a brand-new but legitimate sender on an alias can score moderate and a flag doesn&#8217;t prove a breach occurred. That&#8217;s why EmailAlias frames each alert as a heuristic signal to review rather than a verdict. In practice false alarms are cheap to handle: you glance at the sender, and if it&#8217;s fine you ignore it \u2014 no harm done, and the genuine signals still surface early.<\/p>\n\n<\/div>\n<\/div>\n<div id=\"faq-q-8\" class=\"rank-math-list-item\">\n<h3 class=\"rank-math-question \">Is email leak detection the same as spam filtering?<\/h3>\n<div class=\"rank-math-answer \">\n\n<p>No. Spam filtering decides whether an individual message is junk and where to put it. Email leak detection asks a different question: has this address been exposed, and which service is responsible? It looks at patterns across the senders reaching each alias \u2014 sender reputation and sudden volume from unknown senders \u2014 to warn you that an address has leaked, so you can shut it down. The two are complementary: filtering handles individual junk mail, leak detection handles the exposure behind it.<\/p>\n\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>The short version Email leak detection tells you which of your addresses was exposed \u2014 not just that you were in a breach, but which service leaked or sold your&#8230;<\/p>\n","protected":false},"author":3,"featured_media":398,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"rank_math_focus_keyword":"email leak detection","rank_math_title":"Email Leak Detection: Spot an Exposed Alias Early","rank_math_description":"Email leak detection watches every alias for suspicious senders and leak signals, so you learn which address was exposed \u2014 before the spam and scams start.","_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[13],"tags":[],"class_list":{"0":"post-400","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-features"},"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/email-leak-detection.jpg?fit=1200%2C630&ssl=1","jetpack_sharing_enabled":true,"jetpack-related-posts":[{"id":437,"url":"https:\/\/emailalias.io\/blog\/block-an-email-sender\/","url_meta":{"origin":400,"position":0},"title":"How to Block an Email Sender (and Allow Trusted Ones)","author":"Troy Hunt","date":"September 22, 2026","format":false,"excerpt":"The short version Blocking a sender drops their mail silently \u2014 it never reaches your inbox and they get no bounce or error to tell them. One click does it. On any forwarded message you can block that sender, or add an address or whole domain to your blocklist directly.\u2026","rel":"","context":"In &quot;Features&quot;","block_context":{"text":"Features","link":"https:\/\/emailalias.io\/blog\/category\/features\/"},"img":{"alt_text":"block an email sender, shown as a letter stamped and set aside into a blocked tray","src":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/block-an-email-sender.jpg?fit=1200%2C630&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/block-an-email-sender.jpg?fit=1200%2C630&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/block-an-email-sender.jpg?fit=1200%2C630&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/block-an-email-sender.jpg?fit=1200%2C630&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/block-an-email-sender.jpg?fit=1200%2C630&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":369,"url":"https:\/\/emailalias.io\/blog\/email-data-breach-what-to-do\/","url_meta":{"origin":400,"position":1},"title":"Email Security 101 (Part 2): What to Do After an Email Data Breach","author":"Troy Hunt","date":"September 15, 2026","format":false,"excerpt":"Email Security 101 \u2014 a 4-part series. \u2190 Part 1: How to Remove Yourself From Data Brokers. You're on Part 2. Part 3: Types of Phishing Attacks is now live. The short version Move fast, in order: confirm the breach, change the password on the breached account, then change that\u2026","rel":"","context":"In &quot;Security&quot;","block_context":{"text":"Security","link":"https:\/\/emailalias.io\/blog\/category\/security\/"},"img":{"alt_text":"what to do after an email data breach, shown as a forced-open mailbox with mail spilling out and a broken padlock","src":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/email-data-breach-what-to-do.jpg?fit=1200%2C630&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/email-data-breach-what-to-do.jpg?fit=1200%2C630&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/email-data-breach-what-to-do.jpg?fit=1200%2C630&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/email-data-breach-what-to-do.jpg?fit=1200%2C630&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/email-data-breach-what-to-do.jpg?fit=1200%2C630&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":364,"url":"https:\/\/emailalias.io\/blog\/simplelogin-vs-addy-io-vs-emailalias\/","url_meta":{"origin":400,"position":2},"title":"SimpleLogin vs addy.io vs EmailAlias: 2026 Comparison","author":"Troy Hunt","date":"September 14, 2026","format":false,"excerpt":"The short version All three hide your real inbox behind forwarding aliases \u2014 the differences are price, free-tier generosity, open-source, and each one's standout feature. SimpleLogin is the pick for Proton users and open-source fans; addy.io is the most flexible and cheapest for tinkerers and self-hosters; EmailAlias focuses on a\u2026","rel":"","context":"In &quot;Comparisons&quot;","block_context":{"text":"Comparisons","link":"https:\/\/emailalias.io\/blog\/category\/comparisons\/"},"img":{"alt_text":"SimpleLogin vs addy.io vs EmailAlias compared, shown as three keyed mailboxes","src":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/simplelogin-vs-addy-vs-emailalias.jpg?fit=1200%2C630&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/simplelogin-vs-addy-vs-emailalias.jpg?fit=1200%2C630&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/simplelogin-vs-addy-vs-emailalias.jpg?fit=1200%2C630&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/simplelogin-vs-addy-vs-emailalias.jpg?fit=1200%2C630&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/09\/simplelogin-vs-addy-vs-emailalias.jpg?fit=1200%2C630&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":241,"url":"https:\/\/emailalias.io\/blog\/improvmx-alternative\/","url_meta":{"origin":400,"position":3},"title":"ImprovMX Alternative: An Honest Review","author":"Troy Hunt","date":"July 7, 2026","format":false,"excerpt":"If you're hunting for an ImprovMX alternative, you're probably in one of two camps: you love the idea of email forwarding on your own domain but want stronger privacy, or you've hit a limit ImprovMX simply isn't built to solve. ImprovMX is a genuinely good custom-domain forwarder \u2014 but it's\u2026","rel":"","context":"In &quot;Comparisons&quot;","block_context":{"text":"Comparisons","link":"https:\/\/emailalias.io\/blog\/category\/comparisons\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/07\/og-improvmx-alternative.jpg?fit=1200%2C630&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/07\/og-improvmx-alternative.jpg?fit=1200%2C630&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/07\/og-improvmx-alternative.jpg?fit=1200%2C630&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/07\/og-improvmx-alternative.jpg?fit=1200%2C630&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/07\/og-improvmx-alternative.jpg?fit=1200%2C630&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":80,"url":"https:\/\/emailalias.io\/blog\/how-to-stop-spam-emails\/","url_meta":{"origin":400,"position":4},"title":"How to Stop Spam Emails for Good: A 2026 Guide","author":"Troy Hunt","date":"May 27, 2026","format":false,"excerpt":"Wondering how to stop spam emails without spending another Saturday clicking \"unsubscribe\" on a hundred newsletters? The honest answer is that traditional filters are losing the arms race \u2014 spammers buy leaked lists faster than Gmail can update its rules. The reliable fix is structural: stop giving every site your\u2026","rel":"","context":"In &quot;Spam Protection&quot;","block_context":{"text":"Spam Protection","link":"https:\/\/emailalias.io\/blog\/category\/spam-protection\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/05\/og-how-to-stop-spam-emails.jpg?fit=1200%2C630&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/05\/og-how-to-stop-spam-emails.jpg?fit=1200%2C630&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/05\/og-how-to-stop-spam-emails.jpg?fit=1200%2C630&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/05\/og-how-to-stop-spam-emails.jpg?fit=1200%2C630&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/05\/og-how-to-stop-spam-emails.jpg?fit=1200%2C630&ssl=1&resize=1050%2C600 3x"},"classes":[]},{"id":176,"url":"https:\/\/emailalias.io\/blog\/private-email-forwarding\/","url_meta":{"origin":400,"position":5},"title":"Private Email Forwarding: How It Actually Works","author":"Troy Hunt","date":"June 16, 2026","format":false,"excerpt":"Private email forwarding lets you hand out an address that points at your real inbox without revealing what that real inbox is. Every message gets routed through a forwarding alias, so the sender only ever sees the alias \u2014 and if that alias starts attracting spam or shows up in\u2026","rel":"","context":"In &quot;Email Alias Basics&quot;","block_context":{"text":"Email Alias Basics","link":"https:\/\/emailalias.io\/blog\/category\/email-alias\/"},"img":{"alt_text":"","src":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-private-email-forwarding.jpg?fit=1200%2C630&ssl=1&resize=350%2C200","width":350,"height":200,"srcset":"https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-private-email-forwarding.jpg?fit=1200%2C630&ssl=1&resize=350%2C200 1x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-private-email-forwarding.jpg?fit=1200%2C630&ssl=1&resize=525%2C300 1.5x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-private-email-forwarding.jpg?fit=1200%2C630&ssl=1&resize=700%2C400 2x, https:\/\/i0.wp.com\/emailalias.io\/blog\/wp-content\/uploads\/2026\/06\/og-private-email-forwarding.jpg?fit=1200%2C630&ssl=1&resize=1050%2C600 3x"},"classes":[]}],"_links":{"self":[{"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/posts\/400","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/comments?post=400"}],"version-history":[{"count":1,"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/posts\/400\/revisions"}],"predecessor-version":[{"id":401,"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/posts\/400\/revisions\/401"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/media\/398"}],"wp:attachment":[{"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/media?parent=400"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/categories?post=400"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/emailalias.io\/blog\/wp-json\/wp\/v2\/tags?post=400"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}