What TempMail stores
We store your generated address, provider session information, and received messages on this server for a one-hour session. A random HTTP-only cookie reconnects your browser to the session. That cookie is needed for the inbox to work; it does not contain the provider’s credentials.
Expired local sessions and their message cache are removed automatically within one minute. Creating a new address removes the old local session. Your browser may keep a cookie until its expiry, but it cannot reopen a deleted session.
Website analytics
We use Google Analytics to understand visits to our public pages and improve the website. Google Analytics may use cookies and process browser, device, and usage information. Our analytics integration does not send inbox addresses, message contents, verification codes, or provider credentials as event data.
What the provider receives
TempMail is powered by BLOCIFY LLC. The selected email provider receives the mail addressed to your disposable mailbox. Guerrilla Mail also receives your IP address and browser user agent as required by its API. Maildrop and Guerrilla Mail apply their own storage, delivery, and public-access rules, independently of TempMail.
For sources that support individual deletion, Delete requests removal at the selected provider. TempMailPortal and TempMail.lol instead offer Hide message, which removes it only from the current local session; the provider keeps it until its own expiry. Ending a local session does not guarantee deletion of upstream mail or copies held by the sender. Read the Guerrilla Mail website and Maildrop website for the provider’s current policies.
Public inboxes are not confidential
Anyone who knows a public address may be able to read its messages at the provider. TempMail’s session isolation does not turn a public mailbox into a private account. Do not use it for banking, identity documents, important account recovery, customer information, or production credentials.
Safer previews
We remove scripts, forms, remote images, and other disallowed email markup. Messages appear in an isolated frame. Opening an email does not load its tracking images through this interface. Clicking an external link can connect your browser to another website with its own policies.
Public pages and search engines
Search engines may index our homepage, guides, and provider information. Inbox API responses are marked noindex and are not included in the sitemap. Server-rendered public pages never contain your mailbox address, messages, or session credentials.
Cookies, fonts, and analytics
This version uses an essential inbox cookie. Fonts are served from this site. Public production pages use Google Analytics as described above. No advertising scripts are included. Hosting infrastructure can process connection information as needed to serve requests.