LiveMonitoring & Analytics

See what's coming through your aliases

Real-time exposure intelligence and forwarding analytics. See who's sending to which alias, spot suspicious senders before they reach your inbox, and watch leak signals develop over time.

What you get

Every alias, every sender, every event

Four built-in views give you complete visibility into what's happening behind your aliases.

Live exposure events

Every inbound sender is scored against risky TLDs, typosquat patterns, and known leak signals — flagged in your dashboard the moment a match appears.

Forwarding activity timeline

See exactly which aliases are getting traffic, how much is being forwarded, and how much is being filtered out as spam — broken down by direction and status.

Overall risk score

An account-wide risk rating computed from every flagged sender across your aliases, plus a low-to-critical distribution chart so you can see at a glance how many high-risk events you're seeing — and disable any alias in one click.

Sender intelligence

Drill into any flagged event to see the sender domain, risk score, and the matched signals — full transparency on why we flagged it.

How it works

From inbound email to dashboard event

Detection runs on the same async pipeline as forwarding — sub-second latency, no blocking.

  1. 1

    Inbound email arrives

    A sender hits one of your aliases. The message is queued for analysis before any forwarding decision is made.

  2. 2

    Multi-signal scoring

    We score the sender domain on risky TLDs, suspicious keywords (phish/scam/etc.), deep subdomain nesting, and digit-heavy or hyphen-stuffed domain labels — combined into a 0–100 risk score.

  3. 3

    Event recorded

    If the score crosses the threshold, an ExposureEvent row is written to your dashboard with the sender, score, and timestamp.

  4. 4

    Email sent to forward queue

    Premium aliases jump the queue via priority routing; the forward worker handles the message with the appropriate spam threshold for your plan.

  5. 5

    Alert delivered (if warranted)

    If the score crosses the alert threshold, an email is sent to your real inbox, throttled by a per-user cooldown — up to 24h apart on Premium, once per week on Free (high-risk only). You decide what to do next: keep, disable, or rotate the alias.

Free vs Premium

What's in each plan

Detection runs identically for everyone. The differences are in alert frequency and dashboard depth.

CapabilityFreePremium
Exposure events trackedYesYes
Forwarding activity countsYesYes
Email alert thresholdHigh-risk only (≥ 50)Any risk (≥ 15)
Alert email frequencyOnce per weekUp to once per 24h
Event history visibleLast 7 days, top 5Full history
Overall risk score widgetYes
Risk distribution chartYes
API access to eventsYes
FAQ

Common questions

What counts as an exposure event?

Any inbound sender whose domain crosses the configured risk threshold (≥ 15 to be logged). We score on TLD reputation (free/cheap TLDs like .xyz, .top, .gq), suspicious keywords in the domain (phish, scam, lottery, verify-account, etc.), deep subdomain nesting, and digit-heavy or hyphen-stuffed labels. A score of 50+ generally means the sender is suspicious.

Do you read the contents of my emails to do this?

No. Risk scoring runs on metadata only — sender domain, alias hit, timestamp. The message body is forwarded to your real inbox without inspection or storage. See our zero-knowledge architecture for details.

How fast does an event show up in the dashboard?

Within seconds of the message arriving. Detection runs in the same async worker pipeline as forwarding, so by the time the email lands in your inbox the event is already in your dashboard.

Can I disable an alias from the analytics view?

Each event in the analytics view tells you which alias was hit. Head to the Aliases page to deactivate it — that stops forwarding immediately, and no further senders reach your inbox via that alias.

Are alerts plan-aware?

Yes. Free plan only sends an email alert for high-risk events (score ≥ 50) at most once per week. Premium gets alerts for any flagged event (score ≥ 15) at the standard 24h cooldown. Detection itself runs identically for both — only the inbox-frequency differs.

Start monitoring in two minutes

Generate your first alias, forward it to a few signups, and watch the analytics dashboard fill up in real time.