A Short History of Email Privacy and Disposable Services
How we went from polite SMTP and trust-based delivery to a world where most signups are a privacy negotiation.
Email predates the modern web by more than a decade — the core protocol still in use today traces back to RFC 821, published in 1982, when the network connecting its users was small, mostly academic, and built on an assumption of mutual trust. Its earliest design assumed every sender was, plausibly, a known colleague at another institution. Privacy was not a designed-in feature so much as an unstated assumption of the environment the protocol was born into — nobody needed to protect an address from a network with a few thousand trusted participants.
The commercial shift of the 1990s
When commercial internet access opened up through that decade, two things changed at almost the same moment. The volume of unsolicited mail exploded — a shift significant enough that the term "spam" entered mainstream vocabulary specifically to describe it — and the value of a captured email address as a durable marketing asset became obvious to anyone running a signup form. The first disposable email services appeared almost immediately afterward, as a direct, defensive reflex to that shift: if giving out your address meant permanent unsolicited contact, the obvious fix was an address you could give out and then discard.
The rise of the inbox as identity
By the mid-2000s, email had quietly become the de facto login credential for the internet at large. Every signup form, every password-recovery flow, and eventually every passwordless "magic link" assumed a working, monitored inbox behind it. That shift entrenched email far beyond its original role as a messaging protocol — it became a global identity anchor that dozens of unrelated services all keyed their records to. It also raised the stakes of address hygiene considerably: leaking the wrong address no longer meant a burst of unwanted mail, it meant a durable link into your account recovery chain across every service that had ever seen it.
Breach disclosure becomes normal
The 2010s brought a parallel shift: large-scale data breaches went from rare news events to a routine, almost weekly occurrence, and breach-notification laws in many jurisdictions began requiring companies to disclose them. Services like Have I Been Pwned emerged specifically to help ordinary users track which of their addresses had been exposed where — a tool that would have made little sense in the 1990s internet, when breaches of this scale and this public visibility simply were not part of anyone’s mental model of email risk.
Standardised authentication catches up
For most of email’s history, the protocol had no built-in way to verify a message actually came from who it claimed to be from — a gap that made spoofing and phishing trivially easy. SPF, DKIM, and later DMARC were layered on top of the original protocol over roughly two decades to close that gap, and are only now, in the 2020s, approaching baseline-expected status rather than optional configuration. Our explainer on email spoofing covers how those specific mechanisms work.
Where we are now
Regulation catches up to the data economy
For most of email’s commercial history, there was no significant legal constraint on what a company could do with an address once it had been collected. That began changing meaningfully with the EU’s GDPR taking effect in 2018, followed by comparable regimes like the CCPA in California — the first time, in most jurisdictions, that ordinary users gained a formal, enforceable right to demand deletion of data a company held about them. Our dedicated article on GDPR covers what those rights actually mean in practice and where disposable email fits alongside them.
Disposable email as a mainstream, not fringe, response
It is worth noting how quickly disposable and throwaway email went from an obscure technique known mainly to early internet users to a widely recognized, casually-used category — largely because the underlying problem it addresses (an email address as a permanent, correlatable identifier) went from a niche concern to something almost every internet user has directly experienced, whether through spam volume, a breach notification, or simply noticing how targeted their advertising has become. The tool followed the problem’s visibility, not the other way around.
Modern privacy practice looks less like a single tool and more like a portfolio: real, permanent addresses reserved for trust relationships you intend to keep; aliasing services for ongoing relationships you want to compartmentalise; and disposable addresses for the growing category of low-stakes, one-shot signups that never needed a durable address in the first place. The genuinely interesting development of the last several years is that all three of those choices are now normal, mainstream defaults rather than the fringe behaviour of privacy specialists — see our look at where this is heading next for what is likely to keep changing from here.