Security

Emcognito Security and Privacy Architecture

Emcognito is an email forwarding alias service. It creates aliases that forward to your real inbox, stores account and alias metadata needed to route mail, and keeps no copy of a forwarded email body for any purpose beyond delivering it to you. It never reads them. See the privacy policy for exactly how long anything is retained.

Updated 

Forwarding path

  • A sender emails one of your Emcognito aliases.
  • The forwarding service validates the alias and account state.
  • Allowed messages are forwarded to your verified destination inbox.
  • You can suspend or delete an alias if it starts receiving unwanted mail.

What is stored

  • Account identifiers required for passwordless sign-in and billing state.
  • Alias metadata such as labels, notes, status, and routing fields.
  • Monthly forwarding counters used to enforce transparent plan limits.

What is not stored as the product model

Emcognito's public product model is forwarding, not mailbox hosting. The service keeps no copy of a forwarded message body for any purpose beyond delivering it to you, and never reads it; the privacy policy states exactly how long anything is retained. Users should still avoid sending highly sensitive secrets through any forwarding service unless it matches their threat model.

What you can verify without our cooperation

Most security pages ask you to take their word for it. These four are published in DNS or over HTTPS, so anyone can check them from a terminal without an account and without asking us.

  • Inbound mail is protected by MTA-STS in enforce mode: a sending server that supports the standard must use TLS with a certificate that validates for our mail host, so a network attacker cannot quietly downgrade the delivery to plaintext. Check it with `dig TXT _mta-sts.emcognito.com` and read the policy at https://mta-sts.emcognito.com/.well-known/mta-sts.txt — `mode: enforce` is the line that matters.
  • Mail claiming to be from emcognito.com is rejected unless it authenticates: our DMARC policy is `p=reject`, applied to subdomains as well. Check it with `dig TXT _dmarc.emcognito.com`.
  • Forwarded messages are ARC-sealed, so your mail provider can still tell that the original sender authenticated correctly even though we handled the message in between. Without this, forwarding breaks the sender's own SPF and DKIM and your provider is more likely to treat legitimate mail as spam.
  • Security reports have a published, machine-readable destination: https://emcognito.com/.well-known/security.txt names a monitored contact, in the format RFC 9116 defines.

Frequently asked questions

Is Emcognito open source?

No, and we are not going to imply otherwise. What that costs you is the ability to read the forwarding code, so the honest question is what you can check instead. The mail-transport claims above are all independently verifiable from a terminal — MTA-STS enforce, DMARC p=reject, ARC sealing and a published security.txt — because they are published in DNS and over HTTPS rather than asserted here. A third-party audit is not funded yet. This page will keep saying that until one happens.

Does Emcognito replace encrypted email?

No. Emcognito hides your real address and helps trace leaks. It is not a substitute for end-to-end encrypted mailbox services.

How do I report a security problem?

Email security@emcognito.com. It forwards to the same monitored mailbox that https://emcognito.com/.well-known/security.txt publishes as the contact of record (hello@wm.emcognito.com), in the RFC 9116 format scanners and researchers expect — so either address reaches the same place. Include enough to reproduce it: the address or endpoint involved, the request, what you saw and what you expected. A vulnerability that exposes the link between an alias and its owner is the most serious class of bug this product can have, and it is triaged first.

Unlimited aliases, free. No alias cap.

100 forwarded emails a month at no cost, no credit card, passwordless sign-in.

Create your free aliases