See what's coming through your aliases
Real-time exposure intelligence and forwarding analytics. See who's sending to which alias, spot suspicious senders before they reach your inbox, and watch leak signals develop over time.
Every alias, every sender, every event
Four built-in views give you complete visibility into what's happening behind your aliases.
Live exposure events
Every inbound sender is scored against risky TLDs, typosquat patterns, and known leak signals — flagged in your dashboard the moment a match appears.
Forwarding activity timeline
See exactly which aliases are getting traffic, how much is being forwarded, and how much is being filtered out as spam — broken down by direction and status.
Risk score by alias
Each alias gets an overall risk rating based on the senders hitting it. Aliases with concerning patterns surface first — disable the leaky ones with one click.
Sender intelligence
Drill into any flagged event to see the sender domain, risk score, and the matched signals — full transparency on why we flagged it.
From inbound email to dashboard event
Detection runs on the same async pipeline as forwarding — sub-second latency, no blocking.
- 1
Inbound email arrives
A sender hits one of your aliases. The message is queued for analysis before any forwarding decision is made.
- 2
Multi-signal scoring
We score the sender domain on risky TLDs, typosquatting patterns, digit-stuffed subdomains, and other phishing-adjacent signals — combined into a 0–100 risk score.
- 3
Event recorded
If the score crosses the threshold, an ExposureEvent row is written to your dashboard with the sender, score, and timestamp.
- 4
Email sent to forward queue
Premium aliases jump the queue via priority routing; the forward worker handles the message with the appropriate spam threshold for your plan.
- 5
Alert delivered (if warranted)
High-risk events trigger an email alert — instantly for Premium, weekly digest for Free. You decide what to do next: keep, disable, or rotate the alias.
What's in each plan
Detection runs identically for everyone. The differences are in alert frequency and dashboard depth.
| Capability | Free | Premium |
|---|---|---|
| Exposure events tracked | Yes | Yes |
| Forwarding activity counts | Yes | Yes |
| Email alert threshold | High-risk only (≥ 50) | Any risk (≥ 15) |
| Alert email frequency | Once per week | Up to 24h |
| Event history visible | Last 7 days, top 5 | Full history |
| Overall risk score widget | — | Yes |
| Risk distribution chart | — | Yes |
| API access to events | — | Yes |
Common questions
What counts as an exposure event?
Any inbound sender whose domain crosses the configured risk threshold. We look at TLD reputation (free/cheap TLDs commonly used for spam), typosquat patterns (digit substitutions, hyphen-stuffed brand names), subdomain entropy, and other heuristics. A score of 50+ generally means the sender is suspicious.
Do you read the contents of my emails to do this?
No. Risk scoring runs on metadata only — sender domain, alias hit, timestamp. The message body is forwarded to your real inbox without inspection or storage. See our zero-knowledge architecture for details.
How fast does an event show up in the dashboard?
Within seconds of the message arriving. Detection runs in the same async worker pipeline as forwarding, so by the time the email lands in your inbox the event is already in your dashboard.
Can I disable an alias from the analytics view?
Yes. Each alias surfaces with a one-click disable button when its risk score crosses the warning level. Disabling stops forwarding immediately — no further senders reach your inbox via that alias.
Are alerts plan-aware?
Yes. Free plan only sends an email alert for high-risk events (score ≥ 50) at most once per week. Premium gets alerts for any flagged event (score ≥ 15) at the standard 24h cooldown. Detection itself runs identically for both — only the inbox-frequency differs.
Dig deeper into how we protect your inbox
Security & Compliance→
TLS 1.3, AES-256, zero-knowledge architecture, and the controls behind every alias.
Do you read my email?→
Exactly what we can and can't see — the metadata that powers the analytics, and what stays private.
API documentation→
Premium users can pull exposure events, email logs, and dashboard stats programmatically.
Frequently asked questions→
Plans, limits, custom domains, and the rest of the things people ask before signing up.
Start monitoring in two minutes
Generate your first alias, forward it to a few signups, and watch the analytics dashboard fill up in real time.