16 ms·
Show HN: An ad free temporary mail service
Made this privacy conscious temporary mail extension as a hobby a few years ago as I found a cool domain.
I've now revamped the UI, added more domains and created an extension that shows your inbox in your browser (it only asks for permission to read from TemporaryMail.com and not all sites like the other extensions), it's also free from ads (paying the service out of pocket and perhaps adding an upgrade feature later on).
What makes this site a bit more unique is that I wrote the email parser from scratch following the RFC (took me 2 months and tons of testing) so it should display all incoming emails exactly as they are displayed in your favorite email client.
The site itself: https://TemporaryMail.com https://TemporaryMail.com
Firefox Extension: https://addons.mozilla.org/en-US/firefox/addon/temporary-email/ https://addons.mozilla.org/en-US/firefox/addon/temporary-ema...
Chrome Extension: https://chromewebstore.google.com/detail/temporarymailcom-a-simple/aigcbpaaeflggbfikokmkkfecnlcodoh https://chromewebstore.google.com/detail/temporarymailcom-a-...
Edge Extension: https://microsoftedge.microsoft.com/addons/detail/temporarymailcom-dispo/ckkkdpnddlnoaiclialbhlcplpokhhka https://microsoftedge.microsoft.com/addons/detail/temporarym...
Opera Extension: https://addons.opera.com/en/extensions/details/temporarymailcom-disposable-email/ https://addons.opera.com/en/extensions/details/temporarymail...
Please give me your worst and criticize it to oblivion as I want to improve it. Also thinking about adding an API for it so let me know your thoughts on that too.
PS
I launched this back at the end of December 2020 and posted here on HN and it didn't get much traction.
- singron 2y agoDo you have a commercial interest or is this just for fun or a kind of public service?
- TemporaryMail 2y agoJust for fun. It started with me getting annoyed with SHEIN as they sent out spam to me and their unsubscribe link was set to localhost (127.0.0.1 - they are still using this last I checked) and in the same time period I found a suitable domain at an auction so I thought I'd give this a go.
- WiF3cap7ShUth4 2y agoI was wondering whether you had ever considered developing an alias email service instead of temporary email? Many users who use temporary email services may soon be blacklisted. Personally, I believe that an open-source service such as Addy (previously AnonAddy) has a brighter future. I am not a technological specialist, therefore I can just mention on the user side. Regardless, I appreciate your efforts to help the community. I wish you good health and success.
- TemporaryMail 2y agoIf I'm not misunderstanding you, the same should go for aliases as they will be flagged as disposable addresses as well. I also noticed that Addy allows users to send emails through it, which is a risky process as it requires close monitoring so spam isn't sent out through the service. I will take a closer look at this and see if it's possible to improve it in some way. Thanks for the kind words also and the same to you! =)
- WiF3cap7ShUth4 2y agoSimple Login (SL), Addy (AD), and DuckDuckGo Email Protection (DDG) are the 3 alias email services I use. Both SL and AD can send and receive. DDG only receives. You can disable the sending direction and simply allow the forward service to run. I believe you will be able to handle this technological challenge. SL and AD are free for 10 aliases, but AD also includes PGP in the free tier. DDG allows for unlimited aliases but does not support PGP; nonetheless, it is free. How great would it be if you could combine the benefits of such services? I appreciate your time. SL: https://simplelogin.io/ https://simplelogin.io/ AD: https://addy.io/ https://addy.io/ DDG: https://duckduckgo.com/email/ https://duckduckgo.com/email/
- TemporaryMail 2y agoThanks for the advice and I'll look into supporting email forwarding, but I'm not sure why users would need PGP.
- xlinux 2y agoThe only feature temp mail service should focus on having tons of domains. Many temp mail domains are blacklisted. only way to get around is rotating the domain name everyday. I will give it a try.
- TemporaryMail 2y agoYou're right about that and I'm doing my best at rotating, but it's very easy to detect these addresses as the "detectors" can simply just set a cron to grab the latest domains once an hour. I'm however thinking about creating a paid service with a low price (maybe like $2/month) just to filter out the majority of the bots and then using that money to get a lot of domains.
- tredre3 2y agoYou could allow users to use their own domains, like https://yopmail.com/add-domain https://yopmail.com/add-domain does.
- TemporaryMail 2y agoI'm not sure that's a great solution though, because all the domains would use the same mail server which would basically instantly flag your domain and all your addresses as disposable.
- KomoD 2y agoThis is what the top sites do, e.g. temp-mail.org And they also don't allow you to view all the active domains which helps against getting blacklisted quickly
- omoikane 2y agoI find it amusing that a .org site (temp-mail.org) has ads all over it while a .com site (temporarymail.com) does not, given that .org was mostly used by non-profits while .com is intended for commercial use.
- KomoD 2y agoWhy generate the random names on the server? That could just be done on the client, reduces load and is faster.
- TemporaryMail 2y agoIt's a pretty big list of names that I've scraped together. There's barely and load on the server to generate the names and it only happens once for the new users so it wouldn't be worth putting that load on the client just for that one time, especially not with the traffic it's currently getting (currently around 1k users/day).
- 8organicbits 2y agoI'm always a little suspicious of these services. People use them to create throw-away accounts, which they abandon after one use. Those accounts remain active and are useful for botting (vote manipulation, comment spam, etc). Whoever owns the email domain can do a password reset to do an account take over. I'm curious about the privacy policy. The title says that you don't have ads, but there's tons of discussion about sharing information with ad partners.
- TemporaryMail 2y agoYes, just like all other email providers nothing is encrypted and you could totally look at the emails. The difference here is though that there's nothing of value. If I wanted to use this for malicious intent, then I think the most valuable thing I could get away with would be a 5% discount coupon. I like that you bring this stuff up though as it could perhaps be good to mention this on the site down at the FAQ so people don't think I'm doing something shady with the service since there are no ads.
- bastawhiz 2y ago> If I wanted to use this for malicious intent, then I think the most valuable thing I could get away with would be a 5% discount coupon Or spinning up hundreds of accounts on a website so you can perform card testing. Or creating accounts so you can put all of the inventory for an e-commerce site into carts to reserve it for yourself. Or running sneakerbots. Or any other malicious intent where the victim is the website operator.
- TemporaryMail 2y agoAgain, wouldn't it be easier for the attacker to just buy a domain and use that completely undetected instead of having to use a rate-limited disposable email service?
- bastawhiz 2y agoYou're assuming they're doing it hundreds of times a minute. Often they're signing up for the accounts by hand to get through the captchas. The rest of it can be automated
- asimpletune 2y agoIs there a link to the mail parser itself?
- TemporaryMail 2y agoNo, I wrote it in PHP and I didn't want to get an angry mob after me. I've been thinking about open sourcing it if anyone would want it, but right now the site has way too little attention for it to get any traction. It's a really neat script though and it's also just one file and supports all the different kind of emails (with/without boundaries, base64 emails, attachments and some other stuff).
- ranger_danger 2y agohow do you know you're following "the" RFC correctly? And which one is that? There are several different standards just for email addresses themselves, which almost everyone gets wrong. Did you know addresses can have quotes and parentheses in them?
- TemporaryMail 2y agoI didn't know at first and it was hell as when I first delved into this I thought it would be a simple task as it would be some agreed upon standard like JSON behind the scenes, but from what I understood emails were created a long time ago and some providers did things differently. The majority of the work was done through testing lots of emails and I must have sent at least a thousands emails to myself from different providers and sites. I've deleted the bookmarks in an attempt to reduce the PTSD it caused, but I think the main one I visited was RFC 1341 as I had some difficulties understanding the boundaries and encoding. What was really tricky is getting it to work with all the different types as some emails didn't have boundaries while others had them, some were encoded entirely in base64, some partially, some of them were just plaintext, others were HTML while some were mixed or even offered multiple versions depending on what the email client supported. Best thing is honestly to try it out and just pick a random address and send a really tricky email to it, would love to see you break the parser and telling me so I can improve it.
- paravirtualized 2y ago> Made this privacy conscious temporary mail extension > Enable JavaScript and cookies to continue It's not privacy conscious. Privacy conscious would mean A) does not use Cloudflare as a CDN B) does not require JavaScript C) does not discriminate against Tor users. There are a few services like this already, which I'm not going to spoil for cred on HN, but my rating of this site as of now is 0/10, unusable in the literal sense.
- TemporaryMail 2y agoA) The connection is fully encrypted. B) That would make the UX horrible. C) I had Tor enabled in the beginning, but when I got complaints from people on Tor doing really shady stuff with it I had to disable it.
- paravirtualized 2y agoThe woes of supporting an "I don't want to leave any crumbs" threat model. There are countless of pro-privacy projects who call themselves that simply because their service can be used to increase privacy, but they do not actually do much to protect privacy beyond that. Many even use Google Analytics. For B, simply support both. This site is popular enough for there to be no risk sharing: Guerrilla Mail.
- TemporaryMail 2y agoTake a look at your network requests though, there isn't a single third-party script running on the site. I understand what you mean, but it has to apply to the use-case. If the service I was running was to support journalists, then I would agree with you, but taking these measures would help promote spam as users would be able to get around the rate-limiting that I've set.
- kukkeliskuu 2y agoHow about redefining the problem a little bit so that it is something else than what others are doing? For example, the platform approach? Allow people to easily set up a temporary email service with their own domain. That would go around the problem needing changing domains all the time. You could make it easy for people to search and buy their temp email domain through you. Or if that is too much, work, allow people to self-host your service by open sourcing it and creating Docker compose configurations etc. I would personally also write a spec for one-click account delete link that can be recognized automatically, sent with the email. If that takes traction, then it would benefit everybody. It just might, as it benefits the service provider the most.
- TemporaryMail 2y agoThat's great advice and although there's already an open source solution available, there's some hassle involved in setting it up. I will definitely look into these solutions and although I've seen some of them around, there could maybe be a way to implement a better alternative that's both easy to use and safe so it doesn't get abused.
- kukkeliskuu 2y agoI don't think I would pay for temp email service, or be bothered to set up open source one by myself. But if I could buy a throwaway domain name from company that specializes in temp emails as a package deal, then I would be tempted.
- TemporaryMail 2y agoRight, that actually sounds like a decent idea and since the users would then have verified themselves with their payment details, it would reduce the risk of abuse.
- kukkeliskuu 2y agoYup. And I don't think I would care too much about the actual domain, because, well, it would be a throwaway domain. It could be some random characters even. Which means you could possibly buy very cheap domain names in bulk, and re-sell them with low retail price, and profit the difference. The temp email service that you would provide "for free" would be the reason to buy from you.
- terrycody 2y agoMost such services are blacklisted, or very soon to be blacklisted. You can use Gmails and rotate them, and use "." "+" "number" tricks though, but typically, use Gmails is the way to do.
- TemporaryMail 2y agoThat's another way yes and I've actually seen another site do this, but I wasn't able to find it in my browser history.
- terrycody 2y agoMaybe you are referring to https://www.emailnator.com/ https://www.emailnator.com/, it utilized that trick
- TemporaryMail 2y agoExactly, that's the site I had in mind although I'm pretty sure it had another name before (could perhaps also be the reason to why I didn't find it in the first place).
- pneumonic 2y agoThe problem with using gmail variants is it's easy to transform terr.yc.ody+abc@gmail.com into terrycody@gmail.com, and spammers or spammer suppliers can do that automatically.
- borissk 2y agoThanks for providing a valuable service to the Internet community and good luck :)
- TemporaryMail 2y agoThanks for that comment, refreshing to read amidst this war zone of a comment section, ha ha! :)
- alam2000 2y ago[dead]
- kukkeliskuu 2y agoI remember using spamgourmet service back in the day, and it had a feature for forwarding emails with an implicit counter. So foo.c@spamgourmet.com would be forwarded three times (c=3), and the rest would be eaten.
- TemporaryMail 2y agoIt's a great service that I used myself many years ago and I was sad to see them shut down, but it seems as though they are back now.
- dr_dimitru 2y agoCan I receive email with attachment?