Brave browser adds email aliases to help users evade tracking
The latest version of the Brave browser, 1.94, introduces a feature called ‘Email Aliases’ that allows users to generate disposable email addresses when signing up to a new service.
Using an alias address keeps the user’s real email address hidden from the website while still forwarding messages from the service.
Brave already uses data isolation to prevent websites from inferring user identities based on cookie-based or cache correlations; however, email addresses are still stored on website servers, creating a privacy gap.
Brave’s new feature addresses this risk by blocking cross-site identity matching, reducing spam, and protecting users from threats such as phishing attacks that can follow data breaches.
“If a website you signed up for is hacked, your information can be leaked and end up with data brokers or worse,” explains Brave in the announcement.
“Your email address then circulates far beyond the company you originally trusted with it, and can show up in phishing campaigns for years afterward.”
To generate and use email aliases, users need to create a free Brave Account and register their primary email address with that account, so message forwarding can occur. This is separate from a Brave Premium account.

Source: Brave
In a separate announcement, Brave explains that Brave Accounts uses OPAQUE, a password-authenticated key exchange standardized as RFC 9807, to authenticate users without transmitting their passwords or hashes to Brave’s servers.
According to Brave, this reduces exposure to password logging, memory-scraping attacks, and bulk cracking of leaked password databases, although it does not protect users from phishing or weak passwords.
The new alias system is free for up to five email aliases, while Brave says it plans to introduce a paid Premium version later, which will lift this restriction.
To preserve users’ privacy when forwarding the messages, Brave stores the primary address and generated aliases in an encrypted state. At the same time, the forwarded messages are not checked beyond automated spam and malware filtering.
Messages are deleted from Brave’s servers within seconds after delivery, while notes attached to the aliases remain local or, if synced via Brave Sync, end-to-end encrypted.
Brave cautioned that forwarded messages may initially land in spam folders while it establishes its reputation as an email provider, so users testing out this new feature should keep that in mind.
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.



