The Rise of Phishing Attacks and How Temp Emails Help
Phishing thrives on guessing your real inbox. Disposable addresses make the guess worthless.
Phishing has matured considerably from the crude "Nigerian prince" emails of the early 2000s into precisely-targeted, professionally branded campaigns that imitate real services down to the logo, color scheme, and footer legal text. The cheapest defensive layer an ordinary user can deploy against this is one most people overlook entirely: do not give phishers a target address to aim at in the first place.
Why your real inbox is the target
Phishing campaigns overwhelmingly work from lists — breach dumps, scraped directories, purchased marketing lists — rather than guessing addresses at random. The more services that have ever known your real address, the more of those lists it ends up on over time, and the more credible-looking, well-targeted phishing eventually reaches you as a result. Reducing how many sites ever see your real address in the first place directly shrinks that surface area; it is not a guarantee against phishing, but it measurably reduces how much of it reaches an address you actually monitor.
Disposable addresses double as an early warning system
A phishing email arriving at a disposable address you used six months ago for a single newsletter signup is, in itself, useful information: it is a strong tell that the newsletter provider’s list was breached or sold, since that address was never given to anyone else and the inbox has likely already expired. You can ignore the message and mentally flag that provider as untrustworthy going forward — all without any concern that your real, permanent accounts were ever the actual target, because the disposable address was never connected to them.
What a well-crafted phishing attempt actually looks like now
Modern phishing rarely announces itself with obvious grammatical errors anymore. Expect correct branding, a plausible sender name, and a specific, believable pretext — a shipping notification, a shared document, a security alert about "unusual sign-in activity." The tell is almost never in how the message looks; it is in what it is asking you to do under time pressure, and where the link actually points if you hover over it without clicking.
Combine with other habits
- A password manager, so there are no reused passwords available for a phisher to stuff into other accounts if one does leak
- Hardware-backed or app-based multi-factor authentication on any account that matters, per NIST’s authentication guidance
- Never click "verify" or "confirm" from within an email — open the service directly in a new tab instead
- Disposable addresses for any signup where you do not need or want ongoing contact, covered in more depth in how disposable email protects your privacy
Spear phishing versus bulk phishing
It is worth distinguishing two different scales of attack, since they call for slightly different defenses. Bulk phishing sends the same generic message to millions of addresses harvested from breach lists, betting that a small percentage will fall for it purely on volume — this is the category disposable email most directly defends against, by keeping your real address out of the harvested lists in the first place. Spear phishing is targeted at a specific individual, using personal details gathered from social media or previous breaches to make the message far more convincing — no email-hygiene habit fully defends against a well-researched spear-phishing attempt aimed specifically at you, which is why habits like never clicking through from an unexpected email, and verifying requests through a second channel for anything involving money, matter more as the attack gets more targeted rather than less.
What to do if you already clicked
If you realize after the fact that you clicked a phishing link and entered credentials, the immediate priorities are: change the password for that specific account right away, from a device you trust, not from the same session; check whether you reused that password anywhere else and change it there too, since credential-stuffing attacks specifically bet on password reuse; and enable multi-factor authentication on the affected account if it was not already on. Acting within minutes meaningfully reduces the window an attacker has to act on stolen credentials before you lock them out.
None of these habits is individually a complete defence, but layered together they remove most of what makes phishing profitable at scale: a large, correlated, easily-targeted list of real addresses to aim at.