Safety boundaries
Is MyraMail Safe to Use?
Safe depends on the job. A temporary inbox can reduce exposure of your regular address, but short retention and ordinary email transport create strict limits.
Reviewed by Dynamic Foundries · 10 September 2026
MyraMail is appropriate for authorized, low-risk, short-lived receiving tasks. It is not appropriate for secrets, important accounts, identity checks, recovery addresses, illegal activity, or circumventing another service's rules.
Appropriate uses
- Testing a confirmation message from software you own or are authorized to test
- Previewing a legitimate newsletter or sample message
- Receiving a non-sensitive, one-time link expected within minutes
- Keeping a brief experiment separate from a personal inbox
Do not use MyraMail for
- Banking, payments, tax, government, health, legal, work, or school accounts
- Password resets, account recovery, or multi-factor authentication
- Identity documents, credentials, confidential files, or private correspondence
- Fraud, impersonation, harassment, spam, malware, or illegal material
- Evading KYC, age gates, sanctions checks, platform bans, or disposable-email restrictions
- Automated or bulk address generation
Message-content controls
Incoming HTML is untrusted. MyraMail removes scripts, browser event handlers, embedded frames, forms, actionable links, remote image sources, and unsafe CSS URL patterns before display. It then renders the result in a sandboxed frame that cannot run scripts or access the parent page.
These are defense-in-depth controls, not a warranty that every malicious message can be rendered harmless. The OWASP XSS Prevention Cheat Sheet explains why HTML sanitization must be maintained as browsers and bypass techniques evolve.
Transport and confidentiality
HTTPS protects traffic between the browser and MyraMail. Mail transport and IMAP use TLS where configured, but ordinary email passes through sender and recipient infrastructure and is not end-to-end encrypted by this service. MyraMail's operator can technically process the mailbox as part of providing it.
Privacy boundary
The sender does not receive your usual email address. That separation can reduce future spam to your primary inbox. It does not hide your source IP from infrastructure, prevent the third-party website from identifying you through other data, or erase operational records when the mailbox expires.
Availability boundary
Delivery can be delayed, rejected, filtered, or blocked. Some websites reject known disposable domains. The timer cannot be extended and the address cannot be recovered. Use a normal mailbox whenever a missed or late message would matter.
Reporting
Report abuse, security concerns, or an inadvertently sent message through the contact page. Security researchers can use the published security contact.