Brave has introduced a new Email Aliases feature in desktop browser version 1.94, allowing users to sign up for websites without sharing their real email address.
The privacy-focused feature generates unique forwarding addresses that deliver messages to a user’s primary inbox while keeping that primary address hidden from online services.
The release is the 39th entry in Brave’s ongoing privacy-update series. It was developed by Brave engineers Pavel Beloborodov, Tarik Demirović, Harold Spencer Jr., and DesignOps Lead Agustín Ruiz, with contributions from former Brave privacy engineer Arthur Edelstein.
Email addresses have become valuable identifiers for advertisers, websites, and data brokers. Unlike browser cookies, an email address can follow a person across devices, browsers, and online services.
Companies can use customer email lists to match users with profiles held by advertising platforms, including Google, Meta, and LinkedIn.
Brave Unveils New Email Aliases
For example, a customer may provide an email address while purchasing running shoes from an online store. The store could then upload that address to an advertising platform’s server-side matching system.

If the platform already has the same email linked to a social-media account, it can associate the customer’s purchase with their advertising profile.
This type of data sharing can occur outside the browser, meaning traditional tracker blocking may not stop it. Brave said Email Aliases are designed to reduce this exposure by giving each website a separate address rather than the user’s permanent email identity.
Users can create an alias directly inside an email field on a website. The generated address forwards incoming messages to the email linked with the user’s Brave Account.
If an alias begins receiving spam or is connected to a service the user no longer uses, it can be deactivated and replaced with a new address.

The feature is managed through Settings > Autofill & Passwords > Email Aliases, or through the internal browser page brave://settings/email-aliases.
Users must first create a Brave Account using an email address and password, which is separate from a Brave Premium subscription account.
Brave said its account system uses OPAQUE, a password-authenticated key exchange protocol standardized in RFC 9807. The protocol is intended to ensure that a user’s password is not sent directly to Brave’s servers during authentication.

According to Brave, it stores the primary account address and generated aliases encrypted at rest. The company said it does not read email content, but processes incoming mail for spam and malware filtering before forwarding it. Messages are deleted from Brave’s servers within seconds after delivery.
Alias notes are stored locally on the user’s device. When Brave Sync is enabled, those notes are encrypted end-to-end between devices in the same Sync chain.
Brave is initially offering five free email aliases per user. The company said it plans to expand the capability to mobile devices and introduce a Premium version later. It also warned that some forwarded messages may initially reach spam folders while the service establishes its email-sending reputation.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC
The post Brave Unveils New Email Aliases to Keep Your Personal Email Address Private appeared first on Cyber Security News.
