Security
tempail.co is designed around a simple idea: the less we hold, the less there is to protect.
What we do not store
- No database. We do not store email addresses, messages, tokens or passwords on our servers.
- No accounts. There is nothing to sign up for and no profile to compromise.
- No tracking. We use no advertising cookies, no analytics scripts and no third-party trackers.
Transport security
The site is served over HTTPS, and all canonical and social URLs use HTTPS. We enforce strict transport security and modern, restrictive HTTP headers, including a Content Security Policy, X-Content-Type-Options: nosniff, X-Frame-Options: SAMEORIGIN, a Referrer Policy, and a Permissions Policy that blocks camera, microphone and geolocation access.
Your session
Your JWT token, temporary address and password exist only in your browser’s LocalStorage. They are sent only to the Mail.tm service when fetching your inbox, and they never leave through us. Clearing your browser data removes them permanently.
Dependencies and limitations
Mail delivery and the storage of received messages are handled by Mail.tm, a third-party provider. This means your messages pass through and are held by that service. A temporary email is a convenience tool — it is not a secure channel for sensitive or legally binding information. Read our Transparency page for the full picture.
Reporting a vulnerability
Found a security issue? We take reports seriously. Please contact us through the contact page and include as much detail as you can.