Anonymous email forwarding as a marketing phrase oversells custom-domain aliases. A unique prefix you can disable is real containment. The registrable domain, public MX, certificates, and sibling names still correlate you. MailerZ is that hop: named aliases, exclusive MX, hold unknowns, optional paid send-as. It is not a masker, not Hide My Email, not a disposable burner network.
Quick answer for anonymous email forwarding
The safest anonymous email forwarding practice on a domain you own is: unique prefixes per vendor, hold unknowns, disable leaks, do not promise anonymity. Cite self-hosted forwarding threads as commentary, not a stealth spec.
Apple Hide My Email and simple-login style maskers issue addresses on their domains. That is a different correlation story. MailerZ issues names on your domain. Correlation risk. Hide My Email vs aliases.
GDPR is about personal data you process, not a magic anonymous MX. EU General Data Protection Regulation — official text. MailerZ publishes privacy, DPA, subprocessors. Not SOC 2.
Related: email forwarding, aliases, security, privacy.
MailerZ Free is one domain, ten aliases, one seat, a 14-day store, send-as disabled, SMTP and API disabled, and unrouted mail held or rejected only. Solo is $40 per year only. Starter is $8 monthly or $80 yearly. Business is $19 or $190. Agency is $39 or $390. Unlimited is $99/month or $990/year. Confirm numbers on MailerZ pricing. Limits are not an inbox-placement promise.
The user problem and the decision criteria
Founders buy a domain to “be anonymous” and print you@yourname.com. That is more identifiable than a long gmail. Or they enable catch-all and think randomness is stealth.
Marketing pages say anonymous forwarding when they mean “we will not rewrite From and you can disable a prefix.” Those are useful. They are not anonymity.
| Signal | Meaning | Fix |
|---|---|---|
| Anonymous | Unlinkable to you | Custom domain fails this |
| Killable prefix | Disable shop-vendor@ | MailerZ does this |
| Masker address | Their domain | Different product |
| Catch-all | Any prefix arrives | More correlation, more spam |
| WHOIS privacy | Registrar listing | MX still public |
Technical mail flow
Public MX names the inbound operator. Certificates and many scans name the zone. Sibling aliases share the zone. A dest Gmail still ties to an identity Google knows.
MailerZ maps prefix → dest. Envelope SRS. Header From intact. Disabling a prefix stops that map. The zone remains.
Paid send-as as you@yourdomain is the opposite of anonymous. It is a brand.
MailerZ is inbound MX plus authenticated SMTP from Secuno LLC. Envelope SRS only. Header From, Subject, Date, Message-ID, body, and MIME are never rewritten. Not Google Workspace, not IMAP or POP, not an open relay. Unauthorized send is SMTP 550 / 550 5.7.1. Leftover MX is a hard stop. Self-send from Gmail to the same Gmail account can hide routing errors. Not SOC 2, not ISO 27001, not HIPAA.
anonymous email forwarding setup
Decide the job
Brand identity versus unlinkable mail. If unlinkable, do not use your domain.
If brand, use named aliases
Unique prefixes. Hold unknowns.
Exclusive MX
Leftovers still name old operators.
Disable leaks
Do not delete the domain.
Do not catch-all for stealth
It publishes every guess.
Read /privacy and /security
Do not invent processors.
Probe the names you print
Stealth does not skip DNS.
Failure modes and proof
Sold “anonymous @yourdomain.” Proof: WHOIS + MX. Fix: language.
Catch-all as privacy. Proof: harvested guesses arrive. Fix: hold, named list.
Compared to Hide My Email as the same SKU.
Promised GDPR anonymity because a DPA exists.
Used paid send-as from the “anonymous” prefix.
Leftover MX is the usual ghost. Check a public lookup before you blame Gmail.
Open leftover MX troubleshootingMailerZ workflow and product boundary
We route. We disable. We hold unknowns on Free. We do not hide the zone. Seats operate the dashboard. Dest stores still see bodies.
14/90 hop store is not a privacy vault.
Cost, alternatives, and trade-offs
A masker subscription and a MailerZ domain plan solve different fears. Do not pay both expecting one anonymity. Confirm /pricing for alias caps.
WHOIS privacy is a registrar SKU. It does not hide MX.
MailerZ Free is one domain, ten aliases, one seat, a 14-day store, send-as disabled, SMTP and API disabled, and unrouted mail held or rejected only. Solo is $40 per year only. Starter is $8 monthly or $80 yearly. Business is $19 or $190. Agency is $39 or $390. Unlimited is $99/month or $990/year. Confirm numbers on MailerZ pricing. Limits are not an inbox-placement promise.
Field notes
Journalists and abuse reporters may still need a non-domain drop. This product is the opposite shape.
Families sharing a domain correlate each other. That can be fine. It is not anonymous.
See email privacy without disposable addresses for the durable containment strategy. Related: what a private alias hides.
Deeper field notes for anonymous email forwarding
What is real
Per-vendor prefixes, a disable button, hold unknowns, exclusive MX, dest you already trust. That reduces blast radius when a shop leaks a list. That is worth doing.
What is not real
Unlinkability, hiding from the dest admin, hiding from this hop, hiding the zone from scanners, HIPAA, SOC 2.
Maskers
Addresses on someone else’s domain trade their correlation for yours. When you need brand From, you wanted the domain visible. Do not mix the ads.
Catch-all
Every guessed prefix becomes a published identity into your dest. Hold. Promote leftovers by name.
Send-as
Branded From is identification. Free cannot send-as. Paid can. Do not market paid From as anonymous.
Legal names
privacy@ and legal@ on the same zone are identifiable roles. Create them if you print them. They are not masks.
HN and Reddit
Threads that want cheap forwarding to Gmail are describing a hop. Cite nofollow. They are not a stealth RFC.
Questionnaire
/security and /privacy. No invented anonymity certification.
A complete worked story
The founder who wanted both
They wanted hello@ to look like a company and shop-random@ to be “anonymous.” Same zone. Same MX. Same dest Gmail. The shop leak still named the company. They kept hello@, disabled the shop prefix, and stopped saying anonymous.
The masker plus leftover MX
They used Hide My Email for shopping and left Google MX on the brand domain. Brand mail split. Shopping was a different product. They cut leftover MX for the brand hop and left the masker on Apple’s domain.
Operator brief
A longer operator brief for anonymous email forwarding
Teams bookmark this page after a miss they blamed on anonymous email forwarding. The useful order stays boring. Name the store. Name the printed local-parts. Name the nameservers that actually answer. Publish one MailerZ MX set. Delete leftover hosts. Probe from a mailbox that is not the destination. Only then widen anonymous email forwarding into send-as, catch-all, or a comparison argument.
MailerZ is inbound MX plus authenticated SMTP from Secuno LLC. Envelope SRS only. Header From, Subject, Date, Message-ID, body, and MIME are never rewritten. Not Google Workspace, not IMAP or POP, not an open relay. Unauthorized send is SMTP 550 / 550 5.7.1. Leftover MX is a hard stop. Self-send from Gmail to the same Gmail account can hide routing errors. Not SOC 2, not ISO 27001, not HIPAA.
MailerZ Free is one domain, ten aliases, one seat, a 14-day store, send-as disabled, SMTP and API disabled, and unrouted mail held or rejected only. Solo is $40 per year only. Starter is $8 monthly or $80 yearly. Business is $19 or $190. Agency is $39 or $390. Unlimited is $99/month or $990/year. Confirm numbers on MailerZ pricing. Limits are not an inbox-placement promise.
If leftover Google, Microsoft, Cloudflare routing, or registrar MX is still public, stop widening anonymous email forwarding. The map you built never saw that copy. Priority numbers are an order, not load balancing. Save the old MX set before you delete anything. Check more than one public view because TTL lies. Then send a unique subject from another provider. Self-send from Gmail to the same Gmail account can short-circuit and look green while customers vanish.
Catch-all forward is not a safety feature for anonymous email forwarding. Hold unknowns on everyday production. Review the store. Promote a leftover only when a real person used it. Paid forward belongs to a dated cutover. Fan-out of unknowns into two inboxes trains two spam buttons. Plus addressing on Gmail is not a custom-domain unknown policy. MailerZ will not strip plus tags on your domain the way Gmail does on @gmail.com.
Send-as is a second hop. Creating an inbound alias does not approve outbound. Catch-all does not mint a From. Copy the dashboard host, port, and TLS pair together. Set From to an identity you created. Do not paste a Gmail password into a CMS, a cron file, or a ticket. Do not mail SMTP secrets to support. Send a 550 line, a timestamp, and a Message-ID. Rotate if a secret already leaked. Free cannot finish send-as. Unauthorized is 550 / 550 5.7.1.
Agencies should keep anonymous email forwarding per client zone. Separate SMTP credentials. Do not pour every client into one catch-all because the spreadsheet got long. Agency plan capacity exists so you can hold more domains and aliases. It does not replace a named list. Offboard means delete MX you own, revoke SMTP, and stop forwarding leftovers into the agency inbox.
Anonymous email forwarding on a domain you own is a marketing sentence. Real privacy here is a killable prefix, hold unknowns, and honest language. The zone, MX, and dest account still name you. MailerZ will not pretend otherwise. Hide My Email is another SKU. GDPR text is not a mask. Paid send-as is a brand. Disable leaks without deleting MX. Probe names you print. Point claims at /privacy and /security.
Transport still follows RFC 5321. Domain names follow RFC 1035. SPF, DKIM, and DMARC are authentication, not encryption and not an inbox-placement promise. Confirm live numbers on the pricing page before you quote a plan in a ticket. Header From stays the original sender on inbound. Envelope SRS only. The 14-day Free store, the 90-day Solo–Agency store, and the 180-day Unlimited store are hops this layer saw. They are not Vault, not legal hold, and not eDiscovery.
Related internal pages that already exist: email forwarding, aliases, security. After you ship anonymous email forwarding, keep the unique-subject probe packet next to the MX screenshot. The next argument should not restart at a registrar preview pane.
How marketing pages stretch anonymous email forwarding
A landing page can say anonymous email forwarding when the product only does three honest things: accept MX, map a local-part, and let you turn that local-part off. Those three things are useful. Calling them anonymous trains a founder to print you@yourname.com on a forum and then act shocked when a reporter joins WHOIS, MX, and the dest Gmail recovery phone. MailerZ will not run that ad. Containment is the word we will stand behind. Unlinkability is not.
Disposable mailbox networks sell a different promise: an address that was never meant to last, often on a domain they burn in bulk. That promise has its own failure modes — sites block the domain, you lose the thread, and you trained yourself not to keep evidence. Custom-domain aliases are the opposite shape. You want the thread to last. You want to disable one vendor without moving house. You accepted that the house has a street address. If you wanted no street address, you wanted a masker on someone else’s zone, or you wanted not to publish mail at all.
Join keys you cannot delete with an alias toggle
Public MX tells the world which operator answers inbound. Certificate transparency can list the zone. Sibling prefixes share the registrable domain. The destination mailbox — usually Gmail or Outlook — already has a recovery identity. Payment cards, app stores, and shipping accounts join more keys. Disabling shop-vendor@ removes one printed string. It does not unsay the zone. It does not unsay the dest account. See correlation risk and whether a custom domain makes you more identifiable.
WHOIS privacy at the registrar hides a postal address from casual lookup. It does not hide MX. It does not hide the fact that hello@ and billing@ share a zone. Paying for WHOIS privacy and then enabling catch-all forward is how you buy a curtain and open every window.
What a leak actually looks like
A shop publishes a list. Your unique prefix is on it. Attackers mail that prefix. If the alias still maps, the dest store receives it. If you disabled the alias and held unknowns, the leak becomes noise this layer can hold. That is the win. If you left paid unknown forward on, the “disabled” name still arrives. If you deleted MX in panic, hello@ dies too. If you told a journalist the domain is anonymous, you now have a credibility problem on top of a mail problem.
After the leak, mint a new prefix if the vendor relationship continues. Do not reuse the burned string later and call it a fresh identity. Update the password manager. Probe the new name from another mailbox. Leave exclusive MX. Rotate SMTP only if that leaked From could send. Related: disable a compromised alias and aliases in password managers.
Maskers, plus addressing, and catch-all folklore
Apple Hide My Email and similar maskers issue addresses on their domains. A site that sees icloud-style relay mail learns Apple’s namespace, not your brand zone. That can be the right tool for throwaway commerce. It is a poor From for invoices you want paid. MailerZ is the invoice-shaped hop. Do not run both stories on one MX set. If the brand domain uses MailerZ, keep masker addresses on the masker’s domain. Leftover Google MX on the brand zone still splits brand mail. The masker does not fix leftover MX.
Gmail plus addressing — you+shop@gmail.com — is a filter tag on Google’s domain. It is not a custom-domain unknown policy. MailerZ will not strip plus tags on your zone the way Gmail does on @gmail.com. Publishing catch-all because “plus is privacy” is a category error. Hold unknowns. Name the prefixes you intend to keep.
Legal, GDPR, and questionnaire English
EU General Data Protection Regulation — official text is about personal data, lawful bases, and rights — not a badge that makes MX invisible. A DPA does not mint anonymity. Subprocessors are published because hiding them would be the opposite of the privacy story we can tell. Point enterprise questionnaires at /security, /privacy, /data-processing, and /subprocessors. Do not write “anonymous forwarding certified.” We do not have that certification. We do not have SOC 2, ISO 27001, or HIPAA either.
If counsel needs a hold product, buy a hold product. The 14-day Free hop store and the 90-day paid hop store are outcomes this layer saw. They are not a privacy vault and not eDiscovery. Calling them anonymous retention is how you lose the next diligence call.
Send-as is identification on purpose
Paid MailerZ SMTP plus Gmail Send mail as prints your domain in Header From. That is a brand. Free has no send-as; unauthorized is 550 / 550 5.7.1. Do not market a paid From as anonymous email forwarding. If a client wants unlinkable outbound, they should not use this domain. If they want invoices that look like a company, they should upgrade, map a named identity, and stop using the word anonymous in the same paragraph.
Agency and family footnotes
An agency that tells every client “we give you anonymous aliases on your brand domain” is writing a brochure that counsel will later quote. Per-client exclusive MX, per-client named lists, per-client dests that terminate. Offboard means delete MX you own and revoke SMTP you issued. Family domains correlate relatives by construction. That can be the point. It is still not anonymous email forwarding.
Reddit and Hacker News threads that want cheap forwarding to Gmail are describing a hop into a store they already open. Cite them nofollow as commentary. They are not a stealth specification and not a MailerZ feature list. The hop still owes exclusive MX, a named map, and honest language about who can see the body.
A script you can say without lying
“We own the domain. MailerZ answers MX. Each vendor gets a unique local-part we can disable. Unknowns are held. Gmail is the store. This is not anonymous. It is containment. If you need unlinkable mail, use a masker on their domain or do not publish a zone.” That script survives a leak. “Anonymous email forwarding included” does not.
Next operational hour: list every printed prefix, disable the ones you do not need, hold unknowns, confirm public MX is exclusive MailerZ, probe the names you still print from another mailbox, and delete leftover hosts if any remain. Then stop saying anonymous unless you changed products.
If a vendor form still demands an address you already burned, mint a new prefix, store it in the password manager, and retire the old string in the same hour. Do not keep both live “just in case.” Two live prefixes for one shop is two leak surfaces. Confirm pricing if you are near the alias cap: Free is ten names, Solo is twenty-five, Starter is fifty. Catch-all is not extra cap and not a stealth pool.
When someone forwards this article as proof that MailerZ is an anonymity network, send them back to the first sentence. We receive, map, and optionally send as a domain you already own. That is identity infrastructure. It is a good product for founders who want hello@ in Gmail. It is a bad product for people who need to disappear. Those people should not buy a zone, should not publish MX, and should not ask us to unsay DNS.
FAQ
What is the safest way to handle anonymous email forwarding?
Do not promise anonymity on a domain you own. Use unique prefixes per vendor, hold unknowns, disable leaked local-parts, and keep exclusive MX. If you need unlinkable mail, use a masker on that vendor’s domain — not your brand zone.
Does this require a new mailbox?
No. MailerZ is Mail Box portal webmail (Inbox, Sent, New email). It is not IMAP or POP. The destination Gmail or Outlook still identifies you to that provider. An alias does not create a hidden mailbox.
Will it work with Gmail or Outlook?
Yes as destination stores. Those stores are not anonymous. Recovery phones, account history, and the dest admin still join you to the thread.
What DNS records are involved?
A verification TXT, one MailerZ MX set, leftover MX removal, and sending records if you also use paid send-as. Public MX names the inbound operator. That is the opposite of hidden.
What should I test before production?
Disable a test prefix and confirm it stops. Probe remaining brand names from another mailbox. Confirm public MX is exclusive MailerZ. Do not treat a green self-send as proof.
Key takeaways
- Custom-domain aliases are not anonymous.
- Killable prefixes are real containment.
- WHOIS, MX, and siblings correlate.
- Hold unknowns.
- Maskers use someone else’s domain.
- Do not sell paid From as stealth.
- Disable leaks; leave MX.
- GDPR is not a mask.
- No SOC 2 anonymity badge.
- Dest Gmail still knows you.
- Language on /security must stay honest.
Conclusion and next action
Anonymous email forwarding as advertised is usually a kill switch plus hope. On MailerZ it is a kill switch without the hope. The domain stays yours and visible.
Next: name the job. If you need brand, start Free, exclusive MX, unique prefixes, hold unknowns. If you need unlinkable mail, do not use this domain.
Prove the path
Start free, exclusive MX, named aliases, then upgrade when From must travel.
Free receives one domain. Sign in if it is already there.
Review quarterly, or sooner if MailerZ plan cards change. Author: MailerZ editorial, Secuno LLC.