Brave has rolled out version 1.94 of its browser with a new privacy feature called Email Aliases, designed to let users sign up for services without exposing their real email address.

When creating an account on a website, users can generate a disposable alias that forwards messages to their actual inbox while keeping the true address hidden from the site. Brave says this closes a privacy gap left by its existing anti-tracking protections. The browser already isolates cookies and cache data to stop cross-site identity correlation, but email addresses collected during account signups remain stored on individual website servers, where they can be exposed in breaches.

According to Brave’s announcement, aliases prevent cross-site identity matching, reduce spam, and lower the risk of phishing campaigns that often follow leaked credential dumps. The company noted that once an email address is compromised, it can circulate among data brokers or attackers for years.

How It Works

To use the feature, users must create a free Brave Account and register a primary email address so forwarding can function. This account tier is separate from Brave Premium. Up to five aliases are available for free, with Brave planning a paid Premium tier later that removes the cap.

Primary addresses and aliases are stored in encrypted form. Forwarded messages pass through automated spam and malware filtering but are not otherwise inspected, and Brave says it deletes forwarded messages from its servers within seconds of delivery. Notes attached to aliases stay local unless synced through Brave Sync, in which case they are end-to-end encrypted. Brave warned that forwarded mail may initially land in spam folders while it builds sender reputation as a new email provider.

Authentication Without Password Exposure

In a related announcement, Brave detailed that Brave Accounts use OPAQUE, a password-authenticated key exchange protocol standardized as RFC 9807, to verify user logins without transmitting passwords or password hashes to Brave’s servers. The company says this reduces exposure to password logging, memory-scraping attacks, and bulk cracking attempts against leaked password databases. Brave was clear that OPAQUE does not protect against phishing or weak password choices, since those risks exist independent of how credentials are transmitted.

For security teams tracking browser-level privacy tooling, the alias feature adds another mitigation against the long tail of phishing and credential-stuffing campaigns that follow third-party data breaches, though its effectiveness will depend on adoption and how well Brave’s mail infrastructure avoids spam filter friction in practice.