Using a free address for sign-ups

Is a free address good enough to sign up with?

For most sign-ups, yes. Anything that sends you a code, a download link or a newsletter works perfectly: the code appears at the top of the inbox, and the inbox is still there if you need it again. For anything holding money, identity or work data, use a real account instead.

Good fits

  • Trials and demos, where you want the product before you want the relationship.
  • Downloads behind an email wall — a whitepaper, a coupon, a file.
  • Forums and communities you are not sure you will stay in.
  • Newsletters, which you can simply stop reading without touching your main inbox.
  • Second accounts on a service that allows them.

Poor fits

  • Banking, payments, tax, health, government. These need an address only you can open, and often a phone number by law.
  • Your work. Use the address your employer gave you.
  • Anything you must be able to recover in years. If losing the inbox would lock you out of something valuable, do not put it there.
  • Anything you must reply to. This address receives only; you cannot send from it.

Why the address looks like a real name

Addresses here are built as first.last@domain — an ordinary-looking personal address. Random-character addresses are the ones forms refuse most often, because that pattern is what throwaway services produce. A name-shaped address on a real mail domain behaves like any other address in most sign-up flows.

That is not a guarantee. Some services keep their own lists of domains they will not accept, and no free service can promise to be on none of them. If one refuses, generate another address and try again.

A safety habit worth keeping

Because the address is the only key, do not reuse the same one for something sensitive later. It costs nothing to generate a fresh address per service — and it means one leaked address does not connect your accounts to each other.

What sign-up forms actually check

Three things, usually: that the address is well formed, that its domain has mail records (this one does), and sometimes that the domain is not on a list of throwaway providers. The first two always pass here. The third is out of anyone's hands — which is why the honest answer is "usually accepted", never "always".

A pattern that works well

Use one address per service, and note it next to the account in your password manager. When a service starts sending mail you do not want, you know exactly which one leaked, and you can simply stop opening that inbox — without unsubscribing, without changing your real address, and without touching your other accounts.

What to ask before you rely on an account

If the account matters at all, ask one question: if this inbox were readable by someone else tomorrow, what could they take? If the answer is more than "a newsletter subscription", use a real mail account with a password and two-factor authentication instead.

Related: where to find a verification code and what we store.

Create a free email address