Email Exposure Audit

Find where your main email address doesn’t belong

Email exposure is rarely a single event. It builds up across forms, downloads, and public information. Review your existing entry points across five dimensions and create clearer address tiers for new sign-ups.

High-risk entry points

Public websites, unfamiliar download sites, and short-term promotions are more likely to bring spam after an address is exposed.

Medium-risk relationships

Shopping, communities, and subscriptions need ongoing email access, but not necessarily your main address.

Keep protected

Banking, work, healthcare, and recovery addresses should be long-term accounts under your control with security protections enabled.

Start by listing where your email appears

Check your password manager, saved browser logins, email subscriptions, and public profiles for services using your main address. Don’t look only at platforms that still email you; old, inactive accounts may still retain the address.

Group them into core accounts, ongoing services, one-time activities, and public contacts. The goal isn’t to change every address immediately, but to find the entry points most worth isolating.

Assess exposure with five questions

  1. 1. Is the page publicly visible?
    Emails in portfolios, forum signatures, and public documents should be replaced first with a revocable alias.
  2. 2. Does the service deserve long-term trust?
    Unfamiliar downloads, short-term promotions, and one-off surveys shouldn’t automatically get your main email.
  3. 3. Will you need to recover the account later?
    Keep long-term control if recovery may be needed; otherwise, consider a disposable email.
  4. 4. Can you shut it down separately after a leak?
    When one address is used everywhere, it’s hard to trace the source—and impossible to shut down just one channel.
  5. 5. Does it carry a sensitive identity?
    Use work, healthcare, and banking addresses less often for ordinary sign-ups to reduce linkability.

Choose an action based on risk

Risk level Typical situations Recommended action
Act now Public pages, suspected leaks, ongoing spam Remove the public address, switch to a dedicated alias, and update your password
Migrate gradually Shopping, communities, news subscriptions Move them to a secondary email or assign an alias per service
Isolate next time Surveys, trials, one-time downloads Use a disposable email when starting a new task
Keep stable Banking, work, healthcare, recovery accounts Keep a long-term email and enable two-step verification

If you receive a suspected phishing email, don’t just unsubscribe or change your address. Check your account login history and update the relevant passwords. Separating addresses reduces future exposure, but it can’t replace account security measures.

Make email separation a default habit

When opening a new form, first consider how long the relationship will last, then choose an address instead of automatically filling in your usual email saved in the browser. Use a disposable email for short tasks, a pausable alias for public entry points, and a stable email for important accounts.

Do a quick quarterly review of public pages, active subscriptions, and accounts you no longer use. Removing unnecessary entry points is more effective than handling spam one message at a time after it arrives.

Start your next short-term sign-up with a separate address

You don’t need to redo every account. Start by reducing the links created by your next exposure.

Create a temporary address