Brave browser adds email aliases to help users avoid tracking

brave

The latest version of the Brave browser, 1.94, introduces a feature called “Email Aliases” that allows users to generate disposable email addresses when they sign up for a new service.

Using an alias address keeps the user’s real email address hidden from the website while forwarding messages from the service.

Brave already uses data isolation to prevent websites from inferring user identities based on cookie- or cache-based correlations; however, email addresses are still stored on website servers, creating a privacy gap.

image

Brave’s new feature addresses this risk by blocking cross-site identity matching, reducing spam and protecting users from threats like phishing attacks that can follow data breaches.

“If a website you signed up for gets hacked, your information could be leaked and end up with data brokers or worse,” Brave explains in the announcement.

“Your email address is then circulated far beyond the company you originally trusted, and may show up in phishing campaigns years later.”

To generate and use email aliases, users must create a free Brave account and register their primary email address with that account so that message forwarding can take place. This is separate from a Brave Premium account.

Manage aliases from the Brave Account page
Manage email address aliases
Source: Brave

In a separate messageBrave explains that Brave Accounts uses OPAQUE, a password-authenticated key exchange standardized as RFC 9807, to authenticate users without transmitting their passwords or hashes to Brave’s servers.

According to Brave, this reduces exposure to password logging, memory erasure attacks and mass cracking of leaked password databases, although it does not protect users from phishing or weak passwords.

The new alias system is free for up to five email aliases, while Brave says it plans to introduce a paid Premium version later, which will remove that limitation.

To preserve users’ privacy when forwarding messages, Brave stores the primary address and generated aliases in an encrypted state. At the same time, forwarded messages are not checked beyond automatic spam and malware filtering.

Messages are deleted from Brave’s servers within seconds of delivery, while notes attached to aliases remain local or, if synced via Brave Sync, end-to-end encrypted.

Brave has warned that forwarded messages may initially end up in spam folders while it establishes its reputation as an email provider, so users testing this new feature should keep that in mind.


article image

Generic prevention scores can hide what happens after initial access. Once attackers use valid credentials, prevention plummets.

The 2026 Blue Report measures security techniques by techniques in 338 million simulations run in customer production environments.

Get the report

Leave a Reply

Your email address will not be published. Required fields are marked *