Why Blocking Burner Emails Hurts Privacy and Fails to Stop Spammers

My burner email blocklist blocked me

After my own Burnex blocklist rejected my Proton Mail alias, I realized we must stop treating privacy tools like spam. While public burner inboxes pose risks, personal aliases from Firefox Relay or Apple Hide My Email protect users from tracking and breaches. Blocking these services only punishes privacy-conscious individuals, as determined spammers easily bypass domain lists using Gmail aliases or custom domains.

You are optimizing for the attacker who gives up easily and punishing the user who takes privacy seriously.
  1. xena

    I think this post was written by an AI model.

  2. thenewnewguy

    The article author attemps to make a distintion between "burners" and "aliases" but I don't believe one exists for this usecase. Let's say for the sake of argument that you think blocking burner emails provides meaningful protection (I don't, but services using such a list obviously do). From your perspective, an "alias" is the same as a "burner". Both can be easily generated in bulk by a human or bots, cannot be resolved to an identity, and cannot be compared to determine if two emails are the same person.

  3. is_true

    Haha. I run a service that compiles IP addresses used by proxy services and a few months ago my own IP got there.

    Turned out to be a friend that installed an app to watch soccer matches for free and in return he became a node of one of those services.

  4. jeroenhd

    The people who want privacy and the people you want to block are using the same services and techniques. That's why web firewalls block privacy focused browsers, why TOR exit nodes are blocked from bald the internet, why email providers block new domains, and why sign-up forms block burners ("aliases" as you might also call them).

    You can accept privacy enhancing measures but doing so hurts your ability to filter spam and other abuse.

    I use these burner email services all the time because nobody on the internet can be trusted. Especially not the ones that try to lure you in and pop up an email registration box at the very last minute.

  5. jambalaya8

    The easiest and best way is to rate limit the number of signups from a domain per day. You might still get people trying to bulk signup but as the article states, most large spam operators do not really use those domains anyway. Of course there are plenty of small time scammers to make up for that lack, so to speak.

    I personally use burner emails when I want an account somewhere but would prefer not linking all of my personal interests and necessities to the same few email addresses. It just seems smart.

    It is frustrating to try to make it clear you are not attempting to bypass authenticity controls, especially when AI can so frustratingly create text posts that can seem realistically 'human'.

    Maybe someone will come up with a better way to attempt to add privacy back without ripping it away in the name of attempting to add it.

    Though, I mean, that's been the issue since the 1990s: security or privacy, hard to have both, and yet difficult to have either without the other.

More from this day

2026-07-10