Help center
FAQ: Is disposable email safe, and what if mail never arrives?
Most questions about burner inboxes have short answers. Below, fourteen of the most common ones are grouped into four topics — jump in through a topic card or read straight through. If nothing here fits, write to us at the bottom of the page.
Using disposable email
Basics like claiming and extending an address live in the how-it-works guide; this section covers snags you hit mid-use.
Tap "Get a new address" and try again — some sites block individual addresses, and a fresh one often clears the hurdle. If several swaps still fail, the site is probably blocking the entire disposable domain. Do not keep forcing it: decide whether the site is worth your real email. If yes, register with your real address; if not, move on.
No. Inbox access lives only in your page URL parameter and this browser's local storage — without the full link, nobody can see your mail. When an address expires, its messages are deleted with no server copy. Even if someone later gets a similar prefix, they cannot reach any past mail.
No. Expiry wipes the address and every message at once, with no recovery path — that is the point of a burn-after-reading inbox. Handle receipts and download links before time runs out, or use a forwarding alias from the start: mail relays to your real inbox and stays in a 30-day online archive.
One page manages one address at a time; tapping "Get a new address" destroys the old one immediately. To run two in parallel, open a private window or use another device — each gets its own address. For many long-term identities, forwarding aliases fit better: up to 100 per account, each pausable or deletable on its own.
Safety & privacy
How anonymous a burner really is, and when your data disappears — covered here in one place.
For everyday sign-ups, a disposable address is safer than handing over your real inbox: no registration, no profile tied to you, and everything is destroyed on expiry. The catch is that anyone with your full inbox link can read the mail inside — never post that URL publicly. Banking, government, and similarly sensitive mail belongs on your real address, not a burner.
No. Reset links go to the address on file, and a temp address is gone within 24 hours at most. Burners suit throwaway accounts you will never revisit. For anything you might keep, register with your real email or a forwarding alias — aliases stay active and reset mail reaches your real inbox normally.
Mail exists only to show you and, for aliases, to forward to you. Temp inbox messages are deleted when the address expires (24 hours max); relay archive entries auto-clear after 30 days, and you can delete anything sooner. The service is free, receive-only, and needs no personal profile — see the Privacy Policy for the full breakdown.
Forwarding aliases & archive
Alias creation rules and quotas are in the limits reference; here we focus on delivery status issues.
Open the message detail to see the block reason and score, then tap "Not spam". The message is restored immediately and future mail from that sender will not be blocked again. Every archived message is visible to you, including blocked ones — nothing disappears silently.
Delivery to your real inbox hit a snag — often a full mailbox or a temporary rejection from the receiving server. Tap "Retry forward" on the detail page; you will see progress and the result. Confirm your real inbox can receive mail before retrying. The message body remains in the 30-day archive either way.
It is dropped outright — no forward, no archive, and nothing is delivered later when you resume. Pause only after you are sure nothing important is in transit. If you want less noise but fear missing something, leave the alias active for a few days, then pause or delete once you are confident.
It runs on the server without you. Once an alias exists, forwarding continues whether you are logged in or not. You only need to sign in to manage aliases (create, pause, delete) or browse the 30-day archive. Sessions last 7 days; after that, request a fresh login code.
Login & two-factor auth
The relay console uses email codes instead of passwords — this section covers sign-in friction.
Work through this order: check your real inbox spam folder first — codes sometimes land there; wait out the 60-second resend cooldown, then tap "Resend"; double-check you typed the email correctly. Too many rapid requests trigger a protective limit — the page will tell you; wait a bit and try again.
Every login requires a one-time 6-digit code sent to your real email, so whoever controls that inbox controls the account — there is no fixed password to leak or brute-force. Sessions expire after 7 days. For an extra lock, enable two-factor authentication in Security settings and confirm a TOTP code at login.
To enable: generate a QR code in Security settings, scan it with an authenticator app (or enter the key manually), then confirm with a 6-digit code from the app. Disabling requires the current code too. Before switching phones, turn 2FA off while the old device still works, then re-enable on the new one. If the old device is gone and you cannot produce a code, email support@onceemail.com.
Did not find your answer? Ask us directly
Describe what happened in an email and we will reply as soon as we can. Step-by-step walkthroughs and hard limits live on the guide and limits pages too.