email privacy how to keep your email private email aliases encrypted email zero-access encryption two-factor authentication

How to keep your email private: the complete checklist

Adrian Maverick · · 9 min read

Most advice on email privacy fixes one thing. Alias guides hide your address and stop there. Security guides tell you to turn on two-factor and call it privacy. Encryption guides skip the inbox you already have. This checklist covers all of it, starting with a quick audit most people have never done.

The short version: to keep your email private, protect three things. Keep your real address out of signup forms by using aliases. Lock the account with a unique password and app-based two-factor, then remove apps and forwarding rules that can read your mail. And keep message contents readable only by you and your recipient, with a provider that can't open your stored mail.

Start with a 10-minute audit of the inbox you have

Before changing anything, find out who can already see your mail. This is the part nearly every guide skips, and it is where real leaks hide.

1. Check where your address has already leaked

Enter your address at Have I Been Pwned, a free breach-lookup service. It lists the data breaches your address appears in and what leaked alongside it, such as passwords, phone numbers or home addresses. Any service on that list with a password you reused elsewhere is your first job: change that password everywhere it appears.

2. Find the apps that can read your inbox

Every "sign in with Google" and every email add-on you ever approved may still have access. In a Google account, open myaccount.google.com/linkedapps, filter to apps with access to your account, select each one, click See details, and remove anything you don't use. Watch for any app that can "read, compose, send and permanently delete" your mail. Microsoft accounts have the same list under Privacy, app access.

This is not a theoretical risk. In 2018 the Wall Street Journal reported that employees at Return Path, an email-marketing company, had read about 8,000 unredacted Gmail messages through access users had granted to an app, as Engadget summarized.

3. Look for hidden forwarding rules and filters

An attacker who gets into an email account once often sets up a forwarding rule so they keep receiving copies after you change the password. In Gmail, open See all settings and check Forwarding and POP/IMAP and Filters and Blocked Addresses. In Outlook, check Rules and Forwarding. Delete anything you didn't create.

4. Sign out devices you don't recognize

Your account security page lists every phone, laptop and browser signed in. Sign out old devices and anything unfamiliar. If you find something you can't explain, change your password first, then sign everything out.

Protect your address

Your main address is the thread that ties your accounts, your purchases and your data-broker profile together. Expose it less and there is less to link.

5. Use an alias for every signup

An alias is a separate address that forwards to your real inbox. Give each shop, newsletter or app its own, and when one starts getting spam, you know who leaked it and can switch it off without touching your real address.

Options you may already have:

  • Apple Hide My Email creates random forwarding addresses, through Sign in with Apple and, with iCloud+, anywhere, per Apple's documentation.
  • Alias services such as SimpleLogin and Firefox Relay work with any inbox.
  • A private email provider with aliases built in. In Secria Mail, the free plan includes 2 aliases, Mail Plus 15, and Pro unlimited.

Gmail's plus trick is not a real alias. Google ignores anything after a plus sign and any dots in your username, per Google's help page, so you+shop@gmail.com reaches you@gmail.com. It is great for filtering, but your real address is sitting right there in the string, and some sites reject the plus. Use it to sort mail, not to hide.

6. Keep one address just for money and recovery

Use a separate address, known to nobody, for your bank, your password manager and account recovery. It never appears on a signup form, so it is much harder to target with phishing, and a breach at some shop can't lead anyone to it.

Lock the account

A private inbox that someone else can log into is not private. This is the security layer, and it is short.

7. Use a unique password and app-based two-factor

Use a long password from a password manager, never reused. Then turn on two-factor authentication with an authenticator app or a passkey rather than text-message codes. SMS codes can be stolen through SIM swapping, where an attacker moves your phone number to their own SIM. NIST's digital identity guidelines (SP 800-63B-4) classify SMS as a "restricted" authenticator, and CISA's mobile guidance says plainly not to use SMS as a second factor.

Protect what's inside

8. Choose a provider that can't read your stored mail

This is the step that decides who can read your mail in the long run. Most mainstream providers encrypt your mailbox but keep the keys themselves. That is how they search, sort and scan it, and it means their access depends on their policy, their security and the legal requests they receive. We go through what that looks like at Google in is Gmail private?

What you want is zero-access encryption: your private key is created on your device and the provider only ever stores mail it cannot open. Then "we can't read your email" is a property of the system, not a promise.

This is the layer we built Secria for. Your keys are created on your device and only ever reach our servers encrypted, so your stored mail is sealed with keys we never hold. Every plan, including free, uses hybrid ML-KEM-1024 and X25519 encryption, a post-quantum design built on the NIST standard FIPS 203, designed so mail captured today stays sealed after quantum computers arrive. If you want to compare providers side by side, we list the criteria that matter in the most private email service.

9. Stop your inbox reporting back on you

Many marketing emails carry a tracking pixel, a tiny invisible image that tells the sender when you opened the message, from what device and roughly where. Opening the email is enough to trigger it. You can block it with your mail app's remote-image setting or use a provider that deals with it for you. Secria removes tracking pixels automatically and hides your IP address from senders. The per-app steps for Gmail, Outlook and Apple Mail are in how to stop email tracking.

10. Leak less without the message being opened

Some of what your email reveals never requires reading the message itself.

  • Lock-screen previews. Turn off message previews on your phone's lock screen so a subject line or first sentence isn't visible to anyone near it.
  • Subject lines. Put the sensitive detail in the body, not the subject. Subjects show up in notifications, search results and previews everywhere.
  • Old mail. Delete what you don't need, especially attachments with ID documents, tax forms or medical records. What isn't stored can't leak in a breach.
  • Read receipts. Decline read-receipt requests when your mail app asks.

Does using Gmail's confidential mode make email private?

Not in the way the name suggests. Confidential mode stops recipients forwarding or downloading a message and can make it expire, but Google itself can still read it, and Google notes recipients can still take screenshots. It is access control, not privacy. For what real encryption looks like when you send, see how to send an encrypted email.

FAQ

How do I make my email address private?

Stop giving out your real address. Use an alias for signups, whether from Apple Hide My Email, an alias service or your email provider, and keep your main address for people you know. Aliases can be switched off one by one when they start attracting spam.

How do I keep my Gmail private?

Run the audit above: remove third-party apps with Gmail access, check forwarding and filters, and sign out unknown devices. Then decide whether you want Gmail's smart features on, since they let Google's systems process your messages. For mail Google can't read at all, you need a zero-access provider.

Is it safe to use SMS for two-factor on my email?

It is better than no two-factor, but it is the weakest option, because a SIM-swap attacker can intercept the codes. NIST and CISA both steer away from SMS. Use an authenticator app or a passkey.

Can my employer or school read my email?

On an account they provide, generally yes: the organization administers the account and can usually access it under its own policies. Keep personal mail on a personal account.


Want an inbox that does most of this checklist for you? Start with Secria's free plan.

Secria fact-checks every post against primary sources. Spotted something wrong or out of date? Email hq@secria.me and we will correct it.