We've been building web tools and digital products for years, and if there's one habit I'm strict about, it's never using a real email address on a site I don't completely trust. We've watched firsthand what happens to email addresses once they enter the marketing ecosystem — and it's not pretty.

This isn't a theoretical warning. It's based on what I've seen building tools like temp-mails.org, running STEAM education programs, and dealing with the aftermath of letting my email end up in the wrong places.

What websites actually do with your email

When you sign up for a service, your email address goes into their CRM — Customer Relationship Management software. From there, it may be used for the service you signed up for, but it's also frequently passed to third-party marketing platforms, ad networks, and "partners."

The word "partners" in a privacy policy can mean almost anything. In practice, it often means data brokers — companies whose entire business model is collecting and reselling personal data. Your email address gets bundled with data from other sources: your browsing behavior, purchase history, demographic estimates, and more. The resulting profile gets sold to advertisers, insurers, employers, and anyone else willing to pay.

We've personally signed up to test various services using unique email addresses we tracked. Within days, several of those addresses started receiving marketing emails from companies I'd never interacted with. The connection was the signup form I'd filled in.

73%
of data breaches expose email addresses as part of the stolen data
4B+
email addresses exposed in breaches tracked by Have I Been Pwned
45s
average time before a new email address receives its first spam message after exposure

The compounding effect nobody warns you about

The problem with using your real email everywhere isn't a single incident — it's the compounding effect over time. Each signup adds your address to one more database. Each database is one more breach risk, one more potential resale to a data broker, one more source of marketing email.

After five years of casual signups, a typical email address might exist in dozens or hundreds of databases. Any one of them getting breached means your address joins the underground market. Once it's there, it stays there indefinitely — breach data doesn't expire.

This is why people who've had the same email for ten years often describe their inbox as "impossible to manage." It's not a spam filter problem. It's the result of years of accumulated data exposure.

Email hashing: the tracking mechanism most people have never heard of

Here's something most people don't know about. When you give your email to a website, many of them convert it into a hash — a fixed-length string of characters generated from your address — and share that hash with advertising platforms like Meta and Google.

These platforms match the hash against their user databases. If they find a match (and they almost always do), they link your behavior on that website to your advertising profile on their platform. This is how you can browse a product on a website you've never connected to Facebook, and then see ads for it on Instagram within hours.

Your email address is the link. Using a disposable address breaks that link entirely.

What I actually do

Our approach, developed after years of building and testing these tools: I keep a real email address for genuine relationships — banking, healthcare, services I pay for and actively use, people I know. For everything else, I use a disposable address.

For services I'm evaluating, this is especially important. We want to see how the product works without being locked into their marketing list for the next three years. If I decide I like the product and want to commit to it, I can always update my email in the account settings.

This habit takes about three seconds longer than using your real address. The benefit is an inbox that stays manageable and a data footprint that stays small.

The practical rule we follow: If I'm not ready to receive marketing emails from this company for the next five years, I don't give them my real address. A disposable address handles the signup without the long-term consequence.

When it's fine to use your real email

This isn't about never giving out your email. It's about being deliberate. Services you pay for and actively use, your bank, your doctor's office, services where the ongoing email relationship has real value to you — these are appropriate places for your real address. You're in a genuine relationship with these entities and the communication serves you.

The problem is the indiscriminate handing-out of your address to every site that asks. That's what fills your inbox and grows your data exposure. Being selective — using a disposable address for low-trust signups and your real address only for high-trust relationships — is the most practical privacy habit most people can adopt.