Security
Knowing a generated address is not enough to read its inbox. Sessions use an independently generated 256-bit opaque token and the server stores only its SHA-256 hash.
Hostile email
Messages are size-limited and parsed as untrusted input. Scripts, event handlers, forms, frames, SVG, remote images, unsafe URLs, and active attributes are removed. Plain text remains available.
Isolation
Email contents and access secrets are excluded from analytics, ads, affiliate attribution, and public URLs. Private endpoints are no-store and noindex.
Reporting
Security reports can be initiated through support@gettemp.email. Do not include passwords, access tokens, OTPs, private correspondence, or exploit data in the first message. We will establish a safer exchange method when sensitive evidence is necessary.