Acceptable use and abuse reports
These inboxes receive mail and nothing else. There is no send path, no reply path and no relay, which removes most of the ways a service like this gets abused.
Receive-only, structurally
No part of this service can transmit mail. The receiving domains publish
v=spf1 -all — an explicit declaration that they never send — and
p=reject DMARC policies, so any message claiming to come from them is rejected by
the recipient. If you have received spam that appears to originate from one of our domains, it
was forged, and your mail provider should already be discarding it.
Not permitted
Using a temporary address to evade a ban or suspension, to register accounts for fraud, to impersonate another person, to bypass age or identity verification, or to bulk-register accounts against a service's terms. Automated scraping of inboxes you did not generate. Attempting to enumerate addresses.
Permitted and expected
One-off signups, downloads, trials, forum registrations and Wi-Fi portals. Testing your own application's signup, verification and password-reset flows — the inbox is also available as a plain JSON endpoint for exactly this purpose. Keeping marketing lists and data brokers away from your real mailbox.
Reporting abuse
If a specific address here is being used against you, include the full address and the approximate time. Note that inboxes and their contents are deleted automatically within an hour, so there is usually nothing left for us to inspect after the fact; what we can do is retire a receiving domain or block a local part from being issued again.
Reach us through the contact form on the Webmail site.
If you run a site that does not want disposable signups
That is a legitimate position and we do not fight it. Our receiving domains appear on the public disposable-domain lists, and blocking them at signup is a normal thing to do. Please block domains rather than blanket-rejecting unfamiliar TLDs, which catches a lot of innocent people.