4 ms·
Hi all, creator here. I've been working on AnonAddy (short for anonymous email address) for the past few months with the vision of creating a privacy friendly,
by willbrowning 7y ago
Hi all, creator here. I've been working on AnonAddy (short for anonymous email address) for the past few months with the vision of creating a privacy friendly, transparent and easy to use email forwarding service.
The web app is built using Laravel, Vue.js and Tailwind CSS. Source code is available on GitHub[1], also mirrored on Gitlab[2]. The server is running Postfix, MariaDB, Nginx and Redis.
I know that there are already a number of other services available that do a similar thing, but I wanted to address a few issues with them, such as:
- Proprietary source code
- Adverts, analytics and trackers used on the sites
- No option to encrypt emails using a GPG/OpenPGP key
- No option for multiple recipients
- No API
AnonAddy protects your real email address from spam and allows you to identify who has sold your data by using a different unique email address for every website.
Here's a highlight of some of the features so far:
- Add your own GPG/OpenPGP key per recipient to encrypt all forwarded emails
- Custom domains
- Anonymous email replies
- UUID aliases that look like - 94960540-f914-42e0-9c50-6faa7a385384@anonaddy.me
- Add multiple recipients per alias
- Add additional usernames to compartmentalise your aliases
- Browser extension for Firefox and Chrome
- API
New features are added regularly, here are some potential future features:
- Tags/folders to help organise aliases
- Random word aliases e.g. yellow.biker54@anonaddy.me
- More brower extension functionality to manage existing aliases etc.
- Send from aliases e.g. initiate email conversation
- Send replies from custom domains as opposed to from an AnonAddy domain
One of the most frustrating challenges was sorting out CORS issues with the API whilst building the browser extension. I noticed that only Firefox seemed to be enforcing the policy and not Chrome (Brave) which caused some confusion. In the end I looked at this awesome package by Spatie - laravel-cors[3] and was able to solve the issue. An important thing to note is that the Cors middleware needs to be included in Laravel's global middleware stack for it to work.
I've learnt a lot about Postfix, DAME, DNSSEC etc. whilst building this but I'm always looking to improve things so I'd love to hear if you have any suggestions or feedback at all.
Thanks,
Will
[1] https://github.com/anonaddy https://github.com/anonaddy
[2] https://gitlab.com/anonaddy https://gitlab.com/anonaddy
[3] https://github.com/spatie/laravel-cors https://github.com/spatie/laravel-cors
- itake 7y agoI am not a huge fan of the name just because it stands out too much. Companies will see that in their db and think its a fake temporary email.
- willbrowning 7y agoThat's a fair point. I've already added an additional domain to the site and will add more that look "generic" soon too.
- ppadron 7y agoAnd custom domains already cover that. This looks really great and thorough, congratulations!
- seanph 7y agoThat did occur to me too, but if they demand an email address, there it is. You can also set it up with your own domain. It just takes some effort.
- itake 7y agoIf you setup your own domain, then its a lot less anonymous :)
- altShiftDev 7y agoNice, looks good. Can you comment on what logs you keep and how much of users communications you're privy to? Is everything e2e encrypted?
- willbrowning 7y agoCheers! Nginx access and error logs are kept which do record IP addresses. Default log settings are used for Postfix. The logs are rotated daily using logrotate and retained for 7 days, old log files are deleted. Log files are only ever used to diagnose any errors/bugs. Emails received are not e2e encrypted unless they have already been encrypted before arriving to the server. Users can add their own PGP key to the site for each of their recipients and then the server will encrypt all forwarded emails with it. Emails received are immediately piped through to the Laravel application by Postfix.