📧 Anonymous Email Guide

🌐 Email Providers

Not every market conversation happens inside the market itself, and when it doesn't, the email provider you pick matters — look for one that operates a Tor hidden service and doesn't demand identity documents to register. ProtonMail runs a proper onion site and offers real encryption, though it occasionally asks for phone or secondary verification depending on the signup flow, which is worth knowing going in. Tutanota provides end-to-end encryption by default with a comparable trade-off. For the least friction, services like Cock.li or Guerrilla Mail skip verification entirely, at the cost of the operational maturity and feature set the bigger providers offer. Whichever you pick, create the account through Tor Browser from the start — an account created from your regular browser has already tied your real IP to it before you've sent a single message.

💡 Tip: Create the account through Tor Browser from the very first step — an account registered from your regular browser already has your real IP attached to it.

🧅 Tor-only Email

Tor-native email services, reachable only through their onion address, take this a step further: they never see a clearnet IP for any user, ever, because there's no clearnet path to reach them in the first place. That's a structurally different guarantee than a clearnet provider that happens to also offer a Tor mirror. Run a separate account per market or identity rather than one account you reuse everywhere — cross-linking accounts defeats the entire point of compartmentalizing identities, since one linked account exposes the pattern connecting all of them. Access this email exclusively through Tor Browser set to Safest mode, and never, under any circumstance, log into it from a regular browser or your home network — doing that even once permanently ties the account to an identifiable connection, and there's no way to undo that single mistake after the fact.

💡 Tip: Logging into an anonymous email account from your regular network even once permanently ties it to that connection — there's no undoing that single mistake.

🔐 PGP with Email

Use PGP on top of an already-encrypted email provider, not instead of one or in place of caution — end-to-end encryption protects a message in transit and at rest on the provider's servers, but the provider itself is still a party that could be compromised, subpoenaed, or legally compelled to hand over what it holds. PGP closes that remaining gap, since it means only you and your intended recipient can ever decrypt the content, regardless of what happens to the provider. Compose and encrypt locally in your PGP client before the text ever touches the email composer — the same discipline covered in the secure communication guide for in-market messages applies here identically. Never send a shipping address or transaction detail in plaintext over email, even to a provider you otherwise trust; that's exactly the kind of information a subpoena or breach turns into a permanent, readable record.

💡 Tip: An E2EE email provider protects your message from outsiders — PGP on top protects it from the provider itself being compromised or subpoenaed.

⚠️ Important Warnings

  • 🌐 Create and always access anonymous email accounts through Tor Browser — never from a regular browser, not even once
  • 🔗 Use a separate email account per identity or market — cross-linking accounts defeats the point of compartmentalizing
  • 🔒 PGP on top of E2EE covers the provider itself being compromised or compelled — E2EE alone doesn't
  • 📍 Never send a shipping address or transaction detail over email in plaintext, regardless of the provider