What to do when an alias gets compromised
One of the biggest advantages of using aliases is that when one gets compromised, you can take action immediately — without your real email address ever being exposed. This guide walks you through exactly what to do.
Signs your alias is compromised
Before taking action, make sure you’re actually dealing with a compromised alias. Common signs include:
- A sudden increase in spam to one specific alias
- Emails arriving from senders you’ve never interacted with
- The alias appears in a data breach notification (e.g., HaveIBeenPwned)
- Phishing attempts targeting information associated with that alias
If you notice any of these, follow the steps below.
Step 1: Check the damage
Start by understanding the scope of the problem.
- Go to Aliases and click on the affected alias to open its detail page.
- Review recent messages — pay attention to spam scores and sender patterns.
- Determine whether the spam is coming from many different senders (a widespread leak) or just one or two sources (a single leak).
This helps you decide how aggressively you need to respond.
Step 2: Tighten protection immediately
While you decide on a long-term plan, lock things down right away:
- Lower the spam threshold on this alias so more spam gets caught automatically.
- Block the worst offenders — go to their contact page and set the state to “blocked.”
- If you have Shield, enable rate limiting on this alias to slow down the flood of incoming messages.
- Consider enabling Gatekeeper if you know exactly who should be emailing this alias — everyone else will need your approval before their messages come through.
Step 3: Decide whether to keep or replace the alias
This is the key decision. Both options are perfectly valid.
Keep the alias if:
- The spam is manageable with tighter thresholds
- You can’t easily change the address everywhere it’s used
- It’s tied to important services you can’t update quickly
Replace the alias if:
- The spam volume is overwhelming even with tighter settings
- The alias was only used for a few services
- You suspect targeted phishing attempts
Step 4: Replacing the alias
If you’ve decided to replace it, follow this process:
- Create a new alias for the same purpose.
- Update your email address with each service that used the old alias. Go through them one by one.
- Disable the old alias once everything is migrated — but don’t delete it immediately. You might have forgotten a service, and you’ll want to catch any stragglers.
- After a few weeks with no important mail arriving at the old alias, go ahead and delete it.
Tip: keep a quick list of which services use which alias. It makes migration much faster if you ever need to do this again.
Step 5: Prevent future compromises
A few simple habits go a long way:
- Use a unique alias for every service. If one leaks, only that one is affected.
- Avoid reusing the same alias for multiple unrelated services.
- Monitor your dashboard regularly for unusual activity on any alias.
The advantage of aliases
This scenario is exactly why aliases exist. When a regular email address gets compromised, you’re stuck with it — you can’t just change your email address everywhere overnight. With Cleanbox, you simply disable the compromised alias, create a new one, and move on. Your real email address was never exposed in the first place.