Getting started

What is temp mail? Temporary email addresses, explained

Temp mail is an email address you use once and walk away from. It exists so that a sign-up, a download or a free trial does not cost you your real inbox. Here is what it actually is, how it works underneath, where it stops working, and how it differs from the other things it gets confused with.

  • Beginner
  • 12 min read
A blue envelope with a perforated edge and a torn-off corner drifting away as small squares, on a grey pedestal beside a small grey bin

What temp mail is, in one paragraph

A temporary email address — temp mail, disposable email, throwaway email, the names are interchangeable — is an address on a domain that somebody else runs, that you can start using without creating anything, and that you intend to abandon. It receives mail like any other address. What makes it temporary is not a timer in the address; it is that nothing connects it to you, nothing has to be maintained, and the messages are deleted after a fixed window whether you read them or not.

The reason it exists is simple: most of the internet asks for an email address before it gives you anything, and most of what it then sends is mail you did not want. A temporary address absorbs that. The confirmation code goes where you can read it; the newsletter that follows goes into a mailbox that will not exist next week.

How it works underneath

There is no magic in it, only a decision most mail providers do not make. Ordinary email works like this:

  1. The sender’s server looks up the domain’s MX record. Every domain that receives mail publishes one; it names the server that accepts mail for that domain. For grabmail.io it points at smtp.grabmail.io.
  2. It hands the message over by SMTP. The receiving server can accept or refuse it. A normal provider refuses anything addressed to a mailbox that does not exist.
  3. A temporary-mail server accepts every address on the domain. That is the whole difference. anything@grabmail.io is valid before anyone has typed it, because the server does not keep a list of mailboxes — the mailbox comes into existence when the first message is delivered to it.
  4. A retention job deletes the message later. Here that is 5 days after arrival, enforced by a scheduled job, not by a policy page.

Because nothing is created, nothing has to be registered: there is no account, no password and no “generate address” step that reserves anything. Pick a name, put it in front of a public domain, and it works. The same mechanism is what lets you point a domain of your own at the service with one DNS record — every address on it then behaves the same way, on a name nobody else is using.

A sendermail for your domainYour DNSMX 10 smtp.grabmail.ioGrabMailchecks the MX itselfThe only thing you publishand keeps the messageNo account, no token, no verification page. The record is the proof.
One MX record is the entire setup. The sending server asks DNS where mail for the domain goes, and the answer is a server that accepts every address on it.

Temp mail, disposable, burner, throwaway, alias: the same thing?

Four of those words mean the same thing. Two of them do not, and mixing them up is how people end up with the wrong tool.

NameWhat it isWho reads the mailLives for
Temp mail / disposable / throwaway / fake emailAn address on a shared public domain, nothing created, nothing owned.Whoever knows the address, on the service’s own site or API.Minutes to days, then the messages are deleted.
Burner emailUsually a real second mailbox, opened for one purpose and closed afterwards — or a disposable address used the same way.You, until you close it.As long as you keep it.
Email alias (SimpleLogin, addy.io, Firefox Relay, Apple’s Hide My Email)A forwarding address that delivers into your real inbox and can be switched off.You, in your real mailbox.As long as you keep it.
Plus-addressing (you+shop@gmail.com)Your real address with a tag; every provider that supports it delivers it to you.You. The sender can trivially remove the tag.Forever — it is your real address.
10 minute mailTemp mail with a very short window. A brand, and then a category.Whoever knows the address, for ten minutes.Ten minutes, sometimes extendable.

The distinction that matters is the third column. With temp mail the mail stays on somebody else’s server and anyone who knows the address can read it; with an alias the mail lands in your own inbox and only you can. Burner, alias or temp mail goes through when each one is the right choice.

What it is good for

Anything where the address is a formality and the mail that follows is noise:

  • Sign-ups you do not care about. A forum you will read once, a tool you want to try, a site that gates a download behind an address.
  • Free trials. The trial works; the “we miss you” sequence afterwards lands in a mailbox that will not exist next week.
  • Downloads and whitepapers. The link arrives; the sales follow-up does not reach you.
  • Testing your own sign-up flow. A developer can open a hundred addresses in a hundred test runs without creating a hundred accounts anywhere. This is the case the API exists for.
  • Automation and AI agents. A script or an agent that has to get past “check your email for the code” can read the code itself, over HTTP.
  • Keeping the noise out. The address you give to a shop, a Wi-Fi portal or a competition entry is not the address your bank writes to.

The practical version of this — how to open one, what name to pick, what to do when a form refuses it — is in signing up without your real address.

Where it is the wrong tool

A temporary address is defined by what it lacks: an owner and a future. Four situations need exactly those two things.

An account you might need to recover
Password resets go to the address on file. If that address is a temporary one, the reset lands in a mailbox that has expired or that anyone can open. Use your real address, or an alias you control.
Anything involving money
Receipts, invoices, payment confirmations and anything a bank or a marketplace sends are things you may need in a year, and things nobody else should be able to read. Never a temporary address.
Work, and anything under a contract
A message you are obliged to keep, or to be reachable at, needs a mailbox that exists next month. Retention here is 5 days, and it is not extendable.
Anything you would mind a stranger reading
On a shared public domain the address is the only thing protecting the mailbox. It is not private, and it is not designed to be — see below.

How long a temporary address lasts

There are two clocks, and the services differ mainly in the second one. The address exists as long as the domain does — you can come back to anything@grabmail.io next year and it will still receive. The messages are the part with a deadline:

Service styleMessages kept forWhat that means in practice
Ten-minute services10 minutes, often extendable a few timesFine for a code that arrives in seconds. Useless for a confirmation link you open tomorrow.
Most temp-mail sitesAround an hour to a dayCovers a sign-up and its follow-up. Not a trial that emails you on day three.
GrabMail5 days after each message arrivesLong enough for a trial, a shipping notice or a weekend. Then it is gone, and nothing extends it — not a tier, not a setting.

Retention is per message, not per mailbox: a message that arrives today has its own 5-day clock regardless of what else is in the inbox. Attachments, up to 5 MB per message, expire with the message they came in. How long a disposable inbox lasts has the exact rules and how to read the deadline off the API.

Who can read a temporary inbox

Anyone who knows the address. There is no account, so there is nothing a mailbox could be locked to; the address is the key. On a public domain that means a short, guessable name — test@grabmail.io, hello@grabmail.io — is a shared mailbox in practice, because other people think of the same names.

This is not a flaw to be fixed later; it is what makes the service free, instant and account-less. The right response is to treat it accordingly: an address that is long and unguessable for anything you would rather not share, and nothing confidential at all. What a domain of your own changes is the guessing — its addresses are on a name nobody else is using — not the rule.

Why some sites refuse a temporary address

Because the domain is on a list. The public disposable domains are known, published in open blocklists, and a fair share of sign-up forms check the domain against them and refuse it outright. Changing the part before the @ does not help; it is the domain being refused. When that happens there are three honest ways round it:

  • Use a domain of your own. One MX record pointing at smtp.grabmail.io and every address on it works, on a name no list has ever seen. Free, no account.
  • Use a domain that is kept off the lists. There is a paid pool of ordinary-looking .com domains, checked against the public blocklists, for people who need a disposable address that forms accept — see pricing.
  • Use an alias instead. If the site matters enough to insist, it may matter enough to deserve an address that reaches you.

Why sign-up forms block disposable email explains how the lists are built, how sites use them, and what each way round costs.

For developers: an API and an MCP server

Everything above is also reachable over HTTP, with no key and no account on the public domains. Three endpoints — list a mailbox, read a message, delete a message — and that is the whole surface. This is what turns a temporary address from a convenience into a tool: a test suite can open an address per run and read the code the application sent, and an AI agent can do the same through an MCP server that waits for the message to land.

list a mailbox, from a shell
$ curl -sG https://grabmail.io/api/v1/mailbox --data-urlencode "address=anything@grabmail.io"

The API reference has the request and response shapes; automating an inbox from a script and an inbox an AI agent can read are the two guides that build on it.

Questions

Is temp mail free?

Here, yes: the public addresses, the API and connecting your own domain are free, with no account and no card. The only paid option is a pool of domains kept off the disposable-mail blocklists, for people whose sign-up forms refuse the public ones.

Is it legal to use a temporary email address?

Using one is legal in the same way that giving a shop a second phone number is. What a particular site allows is a matter of its own terms: some forbid disposable addresses and enforce it with blocklists, and using one there can get the account closed. Nothing here helps you break a site’s rules — it helps you not hand your real address to sites you do not trust with it.

Is temp mail safe?

Safe for what it is for. The message never touches your real inbox, there is no account to leak, and remote images are blocked so a tracking pixel learns nothing. What it is not is private: anyone who knows the address can read the mailbox. Do not send anything confidential to one, and treat every attachment as an untrusted file.

Can I send email from a temporary address?

Not from this one. It receives only, by design — a free service with no account that could send mail would be a spam relay within a day. Some other services allow replies; check theirs.

Can I choose the address, or is it random?

Either. Type any name in front of a public domain, or take the random one the front page offers. A random one is harder for anyone else to guess, which on a shared domain is worth having.

What happens when the messages expire?

They are deleted, with their attachments, 5 days after they arrived. The address keeps working — a new message to the same name starts a new mailbox — but nothing that expired can be recovered, by you or by anyone else.

How is this different from a Gmail “+” address?

A plus address is your real address with a tag on it; the mail still lands in your inbox and the sender can strip the tag in one line of code. A temporary address is on a different domain entirely, tied to nobody, and gone in 5 days.

Can I use temp mail for testing my own application?

That is one of the best uses for it. A test opens a fresh address per run, submits the sign-up form, and reads the confirmation code back over the API — no mailbox to provision, no credential to store. If your application refuses disposable domains, point a domain you own at the service and test on that.

Try it while it is fresh

An address takes one click, no account and no card. Everything in this guide works on it straight away.

Welcome back

Your inboxes and your domains, in one place.