Case file · Email
addy.io
An open-source email aliasing relay (not a mailbox): it hands out throwaway aliases that forward to your real inbox, can PGP-encrypt the forwarded mail, takes no ID, and accepts Monero. But it holds your real destination address, logs IPs for 3 days, and will disclose your identity to law enforcement on abuse - so it is pseudonymous, not anonymous.
The systematized overview
The bureau vs the internet.
7.9/10 · No identity required (aliasing relay)
First, the shape: addy.io is an email ALIASING relay, not a mailbox. It generates alias addresses that forward to your real inbox - which still lives elsewhere (Gmail, Proton, etc.) - so it hides your real address from senders and can PGP-encrypt forwarded mail, but it is not an anonymous mailbox. It is one of the strongest openness stories in the category: fully open-source (AGPL-3.0), self-hostable, independently pen-tested by Securitum in 2023, no ID or phone to sign up, and Monero accepted. The honest limits: it holds your real destination address (a persistent identifier), logs IPs for 3 days, sits under UK/Five-Eyes jurisdiction, and will disclose your identity to law enforcement on abuse - so it is pseudonymous, not anonymous. A genuine no-KYC tool at 7.9/10; self-host to remove the operator from the trust path.
2 recurring praises · 3 recurring gripes
Most praised: open-source, self-hostable, audited; no id and monero accepted. Most cited downside: pseudonymous, not anonymous (holds your real inbox; logs ip; le disclosure).
We track our editorial score and community sentiment separately — neither moves the other. Read together, they're the systematized overview.
The facts
Jurisdiction, sign-up & encryption.
- Jurisdiction
- Will Browning (sole operator), United Kingdom (Five/Nine-Eyes); governing law England and Wales
- Sign-up needs
- Destination (real) email + password; no ID, no phone
- KYC trigger
- None - no ID ever demanded; identity it already holds (destination email + 3-day IP log) disclosed to LE on abuse
- Encryption
- Optional PGP of forwarded mail (bring your own key); database recipient fields AES-256-CBC; opportunistic DANE TLS in transit
- Provider access
- Sees forwarding metadata (which alias maps to which real address); stores mail only on failed delivery if you opt in; discloses identity to LE on abuse
- Anon. payment
- Free tier; paid tiers payable by Monero (XMR) or other crypto via NOWPayments (yearly plans, ~$10 min)
- Logging
- Nginx IP logs rotated daily, retained 3 days; no third-party trackers
- Open source
- Yes - AGPL-3.0, self-hostable (github.com/anonaddy/anonaddy)
- Audited
- Independent Securitum security/pentest audit, Sept 2023 (security, not a no-logs audit)
- Custom domain
- Custom domains on paid tiers (unlinkable aliases); free tier uses shared domains (linkable by domain)
- Free tier
- Yes - unlimited standard aliases, 1 recipient, 10MB/mo bandwidth
- Since
- 2019 (as AnonAddy)
The full read
Our analysis, in plain words.
Read the shape before the score: addy.io is an email ALIASING relay, not a mailbox. You keep your real inbox wherever it already is (Gmail, Proton, a private host) and put addy.io in front of it, handing every website a different alias like `random@addy.io` that forwards to you. If an alias leaks or starts getting spam, you kill it. You can reply through the alias so the sender never learns your real address, and you can attach your own PGP key so forwarded mail is encrypted before it reaches your mailbox. That is a genuinely useful privacy layer - and it is open-source (AGPL-3.0), self-hostable, and was independently pen-tested by Securitum in 2023.
What it is not is anonymity. addy.io holds your real destination address - the whole mechanism depends on it - logs your IP for three days, sits under UK/Five-Eyes jurisdiction, and its terms commit to disclosing your identity to law enforcement on abuse. So it is pseudonymous: it hides your real address from the people you correspond with, not from the operator or a lawful order. Its own policy text is refreshingly honest about all of this; only the "anonymous" tagline overreaches. On our scale that lands it at KYC level 1 (no ID ever, but a persistent identifier by design) and 7.9/10 - comparable to Mailbox.org and Proton, a notch below on the persistent-identifier ceiling and solo-maintainer risk. It earns Reviewed, not Verified: the Securitum audit proves the code is sound, not that a no-logs posture holds (it does log IPs), so it lacks the audited-no-data evidence that earns Posteo and Tuta their VERIFIED stamp. Self-host it and the operator leaves the trust path entirely.
The score, broken down
How the 7.9 is built.
Privacy
weight 50%What identity, data and metadata the service can demand or collect.
76 × 50% = 3.8 of 10
Trust
weight 30%Whether it can technically deliver what it claims — code, audits, age.
83 × 30% = 2.5 of 10
Reliability
weight 20%Whether the no-KYC claim holds under real-world pressure.
80 × 20% = 1.6 of 10
Weighted total 7.9 / 10 · no reliability rule triggered, so the score stands. See the rubric →
Every point, sourced
What earned the score.
Privacy
The fine print, read for you
The clause they bury.
“Free, Open-source Anonymous Email Forwarding ... Want to stay anonymous? Pick a username that is not tied to your real name.”
What it meansThe "anonymous" in the marketing overreaches: addy.io forwards to your real inbox (which it holds), logs your IP for 3 days, and its own terms commit to "disclosing your identity" to law enforcement on abuse. It is a pseudonymous relay - it hides your real address from senders, not from the operator or a lawful order. Its policy text is honest about this; the tagline is the only overreach. Self-hosting removes the operator from the path entirely.
Read the source →“We will report any such breach to the relevant law enforcement authorities and we will co-operate with those authorities by disclosing your identity to them. [+] We may terminate or suspend access to our Service immediately, without prior notice or liability, for any reason whatsoever.”
What it meansTwo clauses to know: on abuse, addy.io discloses the identity it holds (your destination email + logged IP) to law enforcement; and it can suspend "for any reason whatsoever." For an aliasing service the suspension risk is not fund-loss but continuity - a termination breaks every alias at once, which can lock you out of downstream accounts. Note: it never reserves a right to demand ID, so this is a disclosure/suspension posture, not KYC-on-trigger.
Read the source →No ID or phone is ever demanded - signup takes only a destination email and a password. It is level 1 (not 0) because an aliasing relay inherently needs a real destination address, which is a persistent identifier addy.io holds and can be compelled to disclose, and it logs IPs for 3 days. It never reserves a right to request identity documents (so not level 2), unlike KYCnot.me’s reading.
Policy review — point by point
-
No ID/phone; honest policy text
Signup takes only a destination email; the privacy policy plainly discloses the 3-day IP logging and the law-enforcement cooperation rather than hiding them. ↗
-
Open-source + audited
AGPL-3.0, self-hostable, and independently pen-tested by Securitum in Sept 2023 with no significant vulnerabilities. ↗
-
LE disclosure + for-any-reason suspension
Discloses the identity it holds to law enforcement on abuse, and may "terminate or suspend access ... for any reason whatsoever" - a continuity risk (breaks all aliases), not a fund risk. ↗
-
Persistent identifier + UK jurisdiction
Holds your real destination address by design and operates under England and Wales (Five-Eyes) - so it cannot be identity-free, and a lawful order can reach what it holds. ↗
addy.io is operated by a single UK developer under the laws of England and Wales - a Five/Nine-Eyes member with an explicit law-enforcement cooperation clause. That is the opposite of the German cohort’s strong-data-protection edge: a lawful UK order can compel the identity addy.io holds (your destination email + a 3-day IP log). The mitigants are real - it is open-source and self-hostable, so a privacy-maximalist can run it themselves and remove the operator (and its jurisdiction) from the trust path entirely.
We keep watching
Incident & policy timeline.
- 2019
Launched as AnonAddy
Will Browning launched AnonAddy as an open-source email-aliasing service, later rebranded to addy.io. Solo-maintained, AGPL-licensed, self-hostable from day one.
source ↗ - Sep 2023
Independent Securitum audit + rebrand to addy.io
addy.io published an independent security audit by Securitum (web-app pentest + source review) that found no significant vulnerabilities - a real transparency move for a solo-dev project.
source ↗ - Ongoing
PrivacyGuides-recommended; clean record
addy.io is a recommended email-aliasing provider on PrivacyGuides, with no corroborated deanonymization, freeze, or mail-stranding incident. The recurring caveats are the free-tier 10MB bandwidth bounce and single-maintainer continuity risk.
source ↗
The verdict
Where it stands.
Strengths
- No ID or phone to sign up; Monero accepted
- Fully open-source (AGPL-3.0) and self-hostable
- Independently pen-tested (Securitum 2023); transparent named owner
- Optional PGP encryption of forwarded mail; kill any alias that leaks
Trade-offs
- Not a mailbox - holds your real destination address (persistent identifier)
- Logs IPs for 3 days; UK/Five-Eyes jurisdiction; discloses identity to LE on abuse
- Solo-maintainer bus factor; no transparency report / warrant canary
- Free tier 10MB/mo can bounce inbound mail; shared-domain aliases are linkable by domain
Across the internet
What reviewers report.
Consistently praised
- Open-source, self-hostable, audited; no ID and Monero accepted
- PrivacyGuides-recommended; stable forwarding, responsive solo dev
Recurring complaints
- Pseudonymous, not anonymous (holds your real inbox; logs IP; LE disclosure)
- Solo-maintainer continuity risk; no transparency report
- Free-tier 10MB bounce; shared-domain aliases linkable
Strongly positive and PrivacyGuides-endorsed, with the honest, recurring caveats being the aliasing shape (not anonymity), the free-tier bandwidth bounce, and single-maintainer sustainability. No corroborated deanonymization or mail-stranding incident. Synthesized from addy.io’s own policy/security pages, GitHub, PrivacyGuides and Trustpilot.
Keep exploring
Related lists & categories.
Ask the bureau
addy.io, common questions.
Is addy.io anonymous?
No - it is pseudonymous. It hides your real address from senders and can PGP-encrypt forwarded mail, but it forwards to your real inbox (which it holds), logs your IP for 3 days, and discloses your identity to law enforcement on abuse. The "anonymous" tagline overreaches. Self-hosting removes the operator from the trust path.
Is addy.io no-KYC?
Yes - it never asks for ID or a phone number; signup takes only a destination email and password. We rate it KYC level 1 (a persistent-identifier-by-design relay). It does not reserve any right to demand ID, so it is not level 2.
What is addy.io actually for?
Giving every website a different throwaway alias so your real address never leaks, and killing an alias if it starts getting spam. It is an aliasing layer in front of your existing inbox, open-source and self-hostable, with optional PGP so even your mailbox provider sees ciphertext. It is not a replacement for a private mailbox.
Your exact case not covered? The live Ask the bureau answers it and turns it into a public FAQ.