Brave Rolls Out Email Aliases to Cut Off a Common Path to Phishing
Version 1.94 of the Brave browser lets users mask their real inbox behind disposable addresses, aiming to blunt data-broker resale and post-breach phishing.

Key points
- Brave browser version 1.94 introduces Email Aliases, letting users generate disposable addresses that forward to their real inbox.
- The feature is free for up to five aliases; Brave says a paid Premium tier will lift the cap later.
- Aliases require a free Brave Account, which authenticates users using OPAQUE, a password protocol standardised as RFC 9807.
- Brave stores the primary address and aliases encrypted, and deletes forwarded messages from its servers within seconds of delivery.
- The feature does not stop phishing on its own and will not shield users who reuse weak passwords.
Brave has added a built-in email alias system to its browser, giving users a way to sign up for websites without handing over their real inbox. The feature ships in Brave 1.94 and, as first reported by BleepingComputer, is aimed squarely at the phishing and spam that follow website data breaches.
Here is the idea in plain terms. When you register for a new service, Brave generates a random address for you. Mail sent to that address is forwarded to your real one. If the site is later hacked, or sells your details to a data broker (a company that buys and resells personal information), the address that leaks is the throwaway, not the inbox you actually read.
What exactly did Brave ship?
Brave 1.94 adds Email Aliases, a forwarding service tied to a free Brave Account. Users register their real address once. The browser then creates aliases on demand, up to five on the free tier, with a paid Premium option promised later.
Brave already isolates data between websites so that cookies and cached files cannot be used to link a user across sites. Email addresses were the missing piece. An address entered into a signup form sits on that company's servers indefinitely, and often ends up in breach dumps that circulate for years.
How does the login side work?
Brave Accounts authenticate using OPAQUE, a password-authenticated key exchange standardised as RFC 9807. In plain English: your password is never sent to Brave, and Brave never stores a hash of it either. That means if Brave's own servers are ever breached, there is no password database for attackers to crack in bulk.
Brave is candid about the limits. OPAQUE does not stop someone typing their password into a fake Brave login page, and it does not rescue anyone using "password123".
What happens to the forwarded mail?
Brave says the primary address and every alias are held encrypted on its servers. Forwarded messages pass through automated spam and malware filtering, then get deleted from Brave's systems within seconds of delivery. Notes users attach to an alias stay on the local device, or, if Brave Sync is turned on, are end-to-end encrypted between devices.
One practical caveat: Brave warns that forwarded mail may land in spam folders at first while its sending domain builds reputation with the big mail providers.
Feature at a glance
| Item | Detail |
|---|---|
| Browser version | Brave 1.94 |
| Free tier | Up to 5 aliases |
| Paid tier | Premium, unlimited, coming later |
| Login protocol | OPAQUE (RFC 9807) |
| Message retention | Deleted from Brave servers within seconds of delivery |
| Account required | Free Brave Account, separate from Brave Premium |
Should ordinary users care?
Yes, if you sign up for a lot of websites. Every breach headline you have read in the past year almost certainly included email addresses. Those addresses fuel targeted phishing, where criminals send fake emails designed to trick you into handing over passwords or card details.
Aliases will not fix bad passwords or stop a convincing scam email. What they do is contain the damage of any single breach. Burn the alias, keep the inbox.
Common questions
Do I need a Brave Premium subscription to use aliases?
No. The Email Aliases feature uses a free Brave Account, which is separate from Brave Premium. The free tier covers up to five aliases.
Will this stop phishing entirely?
No. Aliases reduce the volume of phishing that reaches you after a breach, but they do not detect scam messages. Brave explicitly says the system does not protect against phishing or weak passwords.



