In early 2021 I got a Mozilla Monitor alert. An online store I'd bought from once had been breached, my email address, phone number, date of birth, home address, and a crackable password hash, all in a SQL dump that got posted on a hacking forum. Half a million users, and I was one of them.
I'd bought a few used books. That's what it cost me.
What got me wasn't the breach itself. It was that I had no idea what happened to that data afterward. That data gets traded. Re-sold. Combined with data from other breaches, cross-referenced with purchase history, packaged into profiles and sold again. Your email address is the thread that ties all of it together, and once it's out, you have no way to see where it goes.
I started using email aliasing about a month after that alert. This is what five years of it actually looks like.
Most people treat their email like a login credential. It's closer to a fingerprint. You can't rotate it the way you rotate a password. You can't get a new one without losing access to years of accounts. It follows you everywhere, every service you've ever signed up for, every breach you've been part of, every data broker who bought a list with your name on it. The data broker industry runs on this. They build profiles from your purchase history, your location patterns, your estimated income, whatever leaked from the last breach you weren't told about. Your email is what lets them tie it all together across sources. That's why it's valuable. That's why it keeps getting sold.
Every service gets its own unique forwarding address. The alias routes to your real inbox. The service never sees your actual email. When an alias starts getting spam or phishing mail, you know immediately which service it came from, and not guessing, not cross-referencing, just knowing. You disable the alias and the mail stops. That's the mechanism. What I didn't expect was how useful it would be as a detection system. Within a few months I was learning things about how data moves that I couldn't have known any other way.
When an alias leaks: I disable it immediately. No forms, no unsubscribe links. Just off.
My main tool is Firefox Relay Premium, about $48 a year. Simple, reliable, works well with Firefox, includes reply support so I can respond to emails without exposing my real address. I keep SimpleLogin (under Proton now) and addy.io as backups โ if one service goes down or raises prices, I'm not stuck. One cheap custom domain (~$12-15/year) handles portability and bypasses the rare service that blocks common forwarding addresses. Apple Hide My Email is free with iCloud+ and works well for anything Apple-connected. Firefox Relay's free tier is a reasonable starting point if you want to try this before spending anything. What I actually paid:
The free tiers cover a lot. Paid plans mainly add reply support, unlimited aliases, and convenience. You don't need the full setup to start.
Get a service and try the free tier first. Firefox Relay and Apple Hide My Email are the easiest entry points. If you're planning to stick with this long-term, buy a cheap custom domain early, it'll save you headaches if a service shuts down or changes pricing later. Then go through existing accounts. For each one: generate a unique alias, log in, update the registered email, verify it went through. I tracked everything in a spreadsheet, alias, service, date created, notes on anything that leaked. The whole migration took about two weekends, with follow-ups spread over a few more weeks after that. Banks and government services were the hardest. Some required support tickets. A few didn't allow email changes at all. For those I created dedicated monitoring aliases and accepted the limited exposure. After the migration, the rule becomes automatic: every new signup gets its own alias before I even enter the site. That part doesn't feel like effort anymore. Set inbox filters for alias-tagged mail so you can actually see which service something came from. When an alias leaks: disable it, follow up with the service if it's worth the time, and use DROP (if you're in California) or broker opt-out tools for wider cleanup.
The 2021 breach data is still out there. Disabling aliases doesn't reach it. Aliasing stops future leakage and gives you visibility into where it's happening now. It's not retroactive. Some services reject alias addresses. Usually the ones with aggressive spam filters that block forwarding domains. A custom domain fixes most of these cases. Migrating old accounts is tedious when 2FA is involved. Some services lock you out mid-change if you don't have the old verification method available. Budget more time than you think, especially for financial accounts. If one alias per service feels like too much overhead, category-based aliases is the way, one for shopping, one for newsletters, one for anything financial, give you most of the benefit. You lose some granularity on source-tracing but the system still works. None of this replaces a password manager, a VPN, or tracker blockers. This handles email specifically.
All of this is moving in the right direction. Slowly. A $48/year service and a weekend of migration is faster than waiting for any of it to land.
My inbox is quieter. That's the obvious part. The less obvious part is that I stopped guessing about where my data goes. The 2021 breach data is still somewhere, I can't reach that. But everything since then I can trace. That's the actual shift: from vague background dread to something concrete enough to act on.
That's worth a weekend.