Can an anonymous email be traced?

A recipient sees the sending infrastructure rather than you, and cannot identify a person from an ordinary message on its own. Anonymity here is practical rather than absolute, so treat it as real protection from the person reading the message rather than as protection from everything and everyone.

On this page
  1. What does the recipient actually see?
  2. Can a recipient work out who you are?
  3. Who can see more than the recipient?
  4. How do people usually deidentify themselves?
  5. What is anonymous sending good for, then?

This is the question everybody asks before sending an anonymous message and almost nobody gets a straight answer to. The honest version has three parts, because who is looking changes what can be seen.

What does the recipient actually see?

The sending address and the infrastructure it came from, and whatever you chose to write. They do not see your personal address, your name or your organisation unless you put one of them in the message.

They also see headers, which describe the route the message travelled rather than the person who composed it. Those headers point at the sending service, which is the point of using one.

Can a recipient work out who you are?

Not from the message itself. What identifies people in practice is the content: a detail only three people knew, a writing habit, a time of day, an attachment carrying its own metadata.

Anonymity is almost always lost through what was written, not through what was technically exposed. If the message describes something only you could have seen, no sending service can protect you from that.

Who can see more than the recipient?

Any provider involved keeps operational records, as every service that carries mail does, and a formal legal process can reach a provider. That is true of every email service that has ever existed and any page claiming otherwise is not describing reality.

The practical meaning is simple. Anonymous sending protects you from the person receiving the message, and it is not a shield against a court.

Who is lookingWhat they can seeWhat they cannot
The recipientthe sending infrastructureyour identity
The recipient’s administratorthe same, plus filtering logsyour identity
The sending provideroperational recordswhat you meant by it
A formal legal processwhat a provider holdsanything nobody recorded
Anyone elsethe message, if forwardedeverything else

How do people usually deidentify themselves?

By replying from their own mailbox afterwards. The anonymous message goes out cleanly and then the conversation continues from an address with their name on it, which undoes the whole exercise in one click.

The other common route is attaching a document that carries author metadata. Paste the text instead, and read it back for the details that only you would know.

What is anonymous sending good for, then?

A first approach to a source, a report about something you saw, a survey that would be biased by your name, or a joke. In each case the protection you need is from the person reading it, and that is exactly the protection this provides.

Sender privacy here is a product feature rather than a side effect, and there is no domain, no configuration and no account history to build first. The detail is on anonymous sending, the journalist case is on anonymous sending for journalists, and the reporting case is on identity free sending for a report.

One limit worth repeating: we do not send phishing, credential harvesting, malware or anything designed to deceive a recipient into handing something over. Everything else we answer is on the answers hub.

By Raze, Founder. Updated .

Tell us what you need to send