Brave introduces disposable email alias feature for privacy-focused signups

Brave has released a new Email Aliases feature in version 1.94 of its browser, allowing users to create disposable addresses when registering for websites and online services. The feature is intended...

Brave has released a new Email Aliases feature in version 1.94 of its browser, allowing users to create disposable addresses when registering for websites and online services. The feature is intended to limit the exposure of a person’s primary email address and make it harder for services to link activity across sites.

Instead of providing a personal address directly to a website, users can generate a unique alias that forwards messages to their main inbox. This can help identify which service may have shared or exposed an address if unsolicited mail begins arriving through a particular alias.

Brave said the capability complements its existing browser privacy protections, such as storage isolation designed to reduce tracking through cookies and cached data. Email addresses can still serve as durable identifiers, however, especially when they are retained by multiple online services or exposed in a breach.

Account and privacy details

Users must create a free Brave Account and associate it with a primary email address to receive forwarded mail. Brave said this account type is separate from its Premium subscription offering.

According to the company, Brave Accounts use OPAQUE, a password-authenticated key exchange protocol standardized in RFC 9807. The approach is designed to authenticate users without sending their passwords or password hashes to Brave’s servers. While this can reduce certain risks associated with stolen authentication databases, it does not prevent phishing attacks or protect users who choose weak passwords.

  • The free tier currently supports up to five email aliases.
  • Brave plans to offer a paid tier with a higher alias limit.
  • Primary addresses and generated aliases are stored in encrypted form, the company said.
  • Forwarded messages are subject to automated spam and malware filtering and are removed from Brave’s servers shortly after delivery.
  • Alias notes remain local unless synchronized through Brave Sync, where they are end-to-end encrypted.

Brave cautioned that messages forwarded through newly created aliases may initially be routed to spam folders while its email infrastructure establishes sender reputation. The feature is aimed at reducing spam and limiting the long-term privacy impact of data leaks, but users should still use unique passwords and remain alert for phishing messages.