Privacy alias vs email forwarding is disposable masks versus durable domain routing. Privacy apps mint addresses you expect to burn. Business forwarding keeps support@ alive for years on a zone you own, with optional send-as and hop history. MailerZ is the second. Exclusive MX. HOLD unknown. Header From intact. Not anonymous. Not Workspace. Quote pricing. No inboxing percentage.
Quick answer for privacy alias vs email forwarding
These products share the word alias and little else.
RFC 5321 still needs one MX owner.
MailerZ: exclusive MX, SRS envelope, intact Header From, optional paid SMTP, HOLD on Free.
Privacy apps: provider domains or short-lived names. Different failure mode: disable and move on.
You can use both. Do not merge MX.
Start free on the brand zone.
Authoritative mail transport is defined in IETF RFC 5321 — Simple Mail Transfer Protocol. Product path: email alias service, custom-domain email alias, and pricing.
User problem and decision criteria
Decision criteria: lifespan, send-as, history, who owns the zone, blocklists.
HR mail on a mask is malpractice.
Throwaway on a brand catch-all is a cannon.
Agencies should sell two SKUs.
No SOC 2 as a privacy feature.
No stealth MailerZ.
Workspace is a third aisle (store).
ESP is a fourth (lists).
Technical mail flow
Brand: MailerZ hop to Gmail. Mask: provider hop or app inbox.
Bake-off dual MX lies.
History matters for brand incidents.
Masks optimize for disable.
Step-by-step setup / decision path
- Split the address inventory.
- Brand strings → MailerZ map.
- Throwaways → mask app if wanted.
- Exclusive MX on the brand.
- HOLD on the brand.
- Paid send-as only on brand identities you mean.
- Never print a mask as careers@.
- Probe the brand.
Classify the next failure before a second DNS edit.
HOLD unknown unless you wrote a FORWARD reason.
Quote live pricing before promising alias counts.
Failure modes and proof
One tool for both jobs.
Dual MX bake-off.
Careers@ on a mask.
Catch-all brand.
Stealth claim.
Invented competitor prices.
Inboxing table.
Free send-as.
Header rewrite.
Shared secrets.
No job split in SOW.
Leftover MX.
MailerZ workflow and product boundary
MailerZ is custom-domain aliasing and forwarding with optional paid send-as. Secuno LLC operates mailerz.net. The app is mail.mailerz.net. Not Workspace, not IMAP, not an open relay, not a campaign ESP.
Envelope SRS only. Header From, Subject, Date, Message-ID, body, and MIME stay intact. Exclusive MX. Hold unknown on Free. Copy SMTP host, port, and TLS or STARTTLS from the dashboard when you send.
Free: one domain, ten aliases, one seat, fourteen-day store, send-as disabled, SMTP and API disabled. Solo forty dollars a year, twenty-five aliases, ninety-day store, 2,500 outgoing, 20 send-as per hour. Starter eight or eighty. Business nineteen or one hundred ninety. Agency thirty-nine or three hundred ninety. Quote pricing. No SOC 2, ISO, HIPAA, SLA, or inboxing percentage.
Cost, alternatives, and trade-offs
Two small products beat one confused product.
A burned brand is expensive.
A blocked mask is cheap.
Agency two-SKU quoting.
Workspace if you need a store.
No fake SLA.
HOLD is cheap.
Solo can be the brand spend.
Operational depth
Kickoff question: “Will this string still matter in two years?” Yes → MailerZ. No → mask.
Blocklists are why masks fail at banks. Brand zones usually do not fail that way.
Disable path on brand is vendor updates. Disable path on mask is the product.
HOLD on brand. Infinite mint on mask.
Quote MailerZ live. Check the other vendor live. Do not scrape.
Security page for enterprise forwarding questions.
No HIPAA on either as assumed.
Offboard brand SMTP.
Probe brand after cut.
Keep ESP off both if you can.
Write the split in the brand guide.
Rehearse on Free.
Field notes for privacy alias vs email forwarding
Kickoff with one question: will this string still matter in two years. If yes, it belongs on a zone you own with a forwarding hop. If no, a privacy-alias app is a reasonable aisle—and it may get blocked at a bank. MailerZ is the keep-strings product. Do not force it to be a mask factory.
Careers@ on a mask domain is how HR mail dies when someone disables a generator. Printed addresses are contracts. Disposable philosophy does not belong on letterhead. If a founder wants both anonymity and a public jobs address, write two lines in the SOW. Two products. Two MX stories. Never one dual-publish bake-off.
Known mask domains appear on deny lists. That is expected. Your company zone usually does not fail that check because it looks like any other domain. That is not stealth. Anyone can look up MX. IETF RFC 5321 — Simple Mail Transfer Protocol still delivers to whoever answers. MailerZ hosts in public MX are visible to people who look. Most signup forms do not look. Abuse desks can.
HOLD unknown on the brand zone. Privacy apps train people to mint infinite local-parts. That habit on a brand MX is a spam cannon. Named aliases for hello, billing, and a shop you might disable. Leave guesses held. Catch-all FORWARD is the opposite of a privacy strategy on a durable domain.
Send-as as the brand is a MailerZ paid path. Copy host, port, and TLS or STARTTLS from the dashboard. Free cannot send-as. Do not quote a blog memory of another vendor’s SMTP. Check their live docs the day you care. Do not invent their prices here either.
Header From intact is the forwarding identity contract. MailerZ rewrites envelope MAIL FROM with SRS and leaves From, Subject, Date, Message-ID, body, and MIME alone. A mask that shows a provider domain in From is a different identity job. Read original headers in any bake-off. If From was rewritten, you are not comparing the same religion.
Exclusive MX still applies. A “comparison month” with two owners splits senders. You will blame the wrong product. Pick one inbound owner for the brand zone. Keep a mask app on provider domains if you still want throwaways. Do not point lastname.com at both.
Disable paths differ. On a mask, disable is the product. On a brand, disable is a vendor-update list plus a replacement string if invoices still arrive. Do not disable billing@ on Friday without a replacement. That is an accounts incident, not a privacy win.
Enterprise buyers will ask for SOC 2. MailerZ does not claim it. Send them security. Do not mint a badge in the comparison deck. Inboxing percentages are the other fiction. Filters live at the receiver. Neither aisle owns Gmail’s folder.
Agencies should quote two SKUs: brand routing on MailerZ, optional masks elsewhere. Mixing them in one line item creates tickets that cannot be classified. The human who wanted stealth will hate HOLD. The human who wanted careers@ will hate a burned mask.
If the user already lives in Gmail, MailerZ keeps that tab. A privacy app may keep mail in its own view on a timer. That is a store decision. MailerZ is not IMAP. Do not sell a second webmail as a feature of forwarding.
Rehearse the brand on Free: one domain, ten aliases, HOLD, no send-as. Prove exclusive MX and a third-mailbox probe. Then decide whether Solo or a larger plan is the brand spend. Keep the mask app on the side if throwaways remain a real job.
Write the split in the brand guide. Public strings live on the zone. Throwaways do not. Future staff should not invent a third aisle at 11 p.m. because a signup form rejected a famous mask domain.
Price from live pages the day you buy. Comparison blogs go stale. This article will not scrape Addy.io or anyone else. MailerZ numbers live on pricing. Trust those. Walk from any vendor who sells a folder guarantee on a forwarder.
Worked scenarios for privacy alias vs forwarding
A founder uses a famous mask domain for careers@ because it felt private. Candidates mail it. An intern disables the mask. Jobs vanish. The site still prints the string. This is the wrong aisle. Careers@ belongs on the company zone with MailerZ, remapped when HR changes. The mask app can stay for the founder’s personal SaaS trials.
A bank signup rejects SimpleLogin-style domains. The founder thinks custom-domain forwarding is broken. Their lastname.com on MailerZ is accepted because it is just a domain. MX is still public. The bank did not grant stealth. They granted a normal address. Explain that in the ticket so nobody dual-publishes Google MX to “look real.”
An agency writes one SOW line: “email aliases.” The client wanted stealth and a public billing@. Tickets cannot be classified. Rewrite as two SKUs. Brand routing on MailerZ. Optional masks elsewhere. HOLD on the brand. Infinite mint on the mask. Exclusive MX only on the brand.
A bake-off dual-publishes MailerZ and a mask provider on one zone. Senders split. Each vendor looks flaky. Delete one owner. Comparisons that need two MX sets are not comparisons. They are leftover MX.
Header From on a received forward through MailerZ is the applicant. Envelope may show SRS. A mask that rewrites visible From is a different identity. If the bake-off did not open original, it did not compare. Read headers.
Free MailerZ rehearsal: hello@, billing@, personal@. HOLD a fake. Probe a third mailbox. Then buy Solo if send-as or more names are required. Keep the mask app for throwaways. Do not move careers@ to the mask to “save a row.”
Enterprise security asks if MailerZ is anonymous. You say no. You send the security page. You do not claim SOC 2. You do not claim an inboxing rate. You describe exclusive MX, SRS, intact From, HOLD, store clocks. That is the fit. If they needed a mask vendor questionnaire, they are in the other aisle.
A public figure enables catch-all FORWARD on the brand to “see hate mail.” Gmail dies. HOLD was the control. Named aliases for press@ and booking@. Guessed slurs stay held. That is privacy-adjacent hygiene, not anonymity.
Send-as as the brand through a mask SMTP the intern found on a blog fails AUTH or sends as the wrong domain. Copy MailerZ dashboard values on paid. Free cannot send-as. Do not invent ports.
Offboard: client keeps the brand on MailerZ under their login, or they move MX. Mask accounts are theirs. Do not leave your MX on their zone unpaid. Do not keep a shared mask login in your password manager after exit without a written transfer.
A comparison deck lists invented Addy.io prices from 2023. The live page differs. You lose trust. Quote MailerZ from /pricing the morning you present. Tell them to check the other vendor the same morning. This page will not scrape.
Someone wants IMAP folders on the domain. Neither aisle is a mailbox host. Buy a host or keep Gmail. Forwarding plus a mask app will not grow folders on your zone.
Lists and newsletters: neither aisle is an ESP. Caps and filters punish reply SMTP. Split the stream. The comparison stays clean when campaigns are not in the ticket.
Two-year test in a spreadsheet: every printed URL address is MailerZ. Every “I will never need this shop” is a mask. Re-run yearly. Strings move aisles when a shop becomes a vendor you must keep. Create a named brand alias then. Do not FORWARD the whole zone to avoid the decision.
Practice and anti-patterns for privacy vs forwarding
Anti-pattern: careers@ on a mask domain. HR mail dies when a mask is disabled. Printed strings are contracts. Brand zone plus remap when people change.
Anti-pattern: dual-MX bake-off. Senders split. Each vendor looks flaky. One inbound owner. Masks stay on provider domains if you still want throwaways.
Anti-pattern: catch-all FORWARD on the brand to imitate infinite masks. Junk cannon. HOLD on the brand. Infinite mint on the mask app.
Anti-pattern: stealth marketing for MailerZ. MX is public. Known mask domains get lists. Your zone looks like a domain. That is not invisibility. Do not fake Google MX to look real.
Anti-pattern: invented competitor prices in a deck. Check live pages the morning you present. Quote MailerZ from /pricing. Do not scrape this page either.
Anti-pattern: inboxing table in the comparison. Walk from anyone who sells a folder on a forwarder. Filters live at the receiver.
Anti-pattern: SOC 2 as a privacy feature. Send /security. No badges. No HIPAA assumed.
Anti-pattern: IMAP expectation. Neither aisle is a mailbox host. Keep Gmail or buy a host.
Anti-pattern: lists on either SMTP. ESP for campaigns. Caps exist on MailerZ send-as. Free cannot send-as.
Anti-pattern: Header From rewrite in the bake-off to make SPF pretty. If From changed, you are not comparing MailerZ’s religion. Read original headers. Envelope may show SRS.
Practice: two-year test in a sheet. Printed URLs are MailerZ. True throwaways are a mask. Re-run yearly. When a shop becomes a keeper, create a named brand alias. Do not FORWARD the zone to avoid the decision.
Practice: Free rehearsal on the brand. hello, billing, one personal. HOLD a fake. Third-mailbox probe. Then Solo if you need send-as or more names.
Practice: write two SKUs in every agency SOW. Brand routing. Optional masks. Tickets become classifiable.
Practice: disable path drill. Brand billing@ needs a replacement window. A mask disable is the product. Do not mix those motions.
Practice: enterprise call. “Not anonymous. Exclusive MX. Intact From. HOLD. Store clocks. No inboxing percentage.” That script is the fit test.
Practice: offboard brand MX and mask logins separately. Do not leave unpaid MailerZ MX. Do not keep a shared mask password after exit without a transfer note.
Operator closeout for privacy alias vs forwarding
The two-year test is the whole product split. If the string will still matter, it lives on a zone you own with MailerZ. If it is a one-off signup you will burn, a privacy app is the aisle—and it may be blocked. Do not merge those MX stories. Dual-publish bake-offs are leftover MX with a comparison slide.
Careers@, billing@, and hello@ are contracts. They do not belong on a mask you can disable in a tap. Remap destinations when people change. Disable paths on a brand need vendor lists and replacement windows. Disable paths on a mask are the product. Mixing them is how invoices vanish on a Friday.
MailerZ identity contract stays: SRS on the envelope, Header From intact, Subject Date Message-ID body MIME untouched. If a bake-off rewrote visible From, you compared a different religion. Open original. Envelope may show SRS. That is expected. A rewritten From is not.
HOLD unknown on the brand. Infinite mint belongs on the mask app. Catch-all FORWARD on a durable domain is a spam cannon and the opposite of privacy. Named aliases for printed strings. Guessed slurs and dictionary names stay held.
MX is public. Anyone can look up who receives. Known mask domains get deny lists. Your company zone usually looks like a normal domain. That is not stealth. Do not fake Google MX to look real. That is leftover MX and a lie.
Send-as as the brand is paid MailerZ SMTP. Copy host, port, TLS or STARTTLS from the dashboard. Free cannot send-as. Do not invent ports. Do not quote stale competitor SMTP blogs. Lists still need an ESP. Caps exist. Solo is 20 send-as per hour and 2,500 outgoing a month.
Quote live prices the morning you present. MailerZ numbers live on /pricing. Do not scrape Addy.io or anyone else into a 2028 contract. Do not invent SOC 2 or an inboxing rate. Send /security. Filters live at the receiver.
You can keep both products. Brand MX exclusive to MailerZ. Throwaways on provider domains. Two SKUs in the agency SOW. Tickets become classifiable. Humans who wanted stealth will hate HOLD. Humans who wanted careers@ will hate a burned mask. Write both lines.
IMAP and suites are a third aisle. If they need a store, buy a host. If they need calendars, buy a suite. See the Workspace comparison when that is the real triangle. Forwarding plus a mask app will not grow folders on the zone.
Rehearse the brand on Free: ten aliases, HOLD a fake, third-mailbox probe. Then decide Solo or larger. Offboard brand MX and mask logins separately. Do not leave unpaid MailerZ MX. Qualification is not loyalty. Run the same questions on MailerZ that you run on everyone else.
Handoff memo for the next operator
Privacy and forwarding look similar in a spreadsheet and diverge in an incident. Write a memo that states which product you bought, why, and what you refused. If you chose MailerZ because you needed send-as and a catch-all HOLD, say that. If you kept a privacy alias for newsletter signups, say that too. The next operator should not have to reverse-engineer intent from a pile of forwarding rules.
Include the list of addresses that must remain reachable after a staff change: billing, legal, support, and the founder. Note which of those are aliases versus mailboxes. Note where replies are sent from. A privacy alias that cannot send as the domain will surprise a lawyer who expects to answer a vendor from the same identity that received the contract.
Add the rejection you already measured. If a bank blocked a privacy-domain From, write the date and the bank. If a catch-all HOLD saved you from a typo flood, write that. Evidence beats ideology when someone later argues to collapse everything into one cheap alias product.
Finish the memo with the renewal dates and the person who owns the card. Privacy tools vanish when a personal card expires. Business forwarding vanishes when a contractor leaves with the only login. Name both risks so the next operator can prevent them.
FAQ
- What is the safest way to handle privacy alias vs email forwarding?
- Write the job. If the address is printed on a site, you want business forwarding on your zone. If the address is a one-off signup, a privacy alias app is fine—and may get blocked. Do not point brand MX at a mask philosophy.
- Does this require a new mailbox?
- No. MailerZ is not IMAP. Keep Gmail or Outlook unless you need a suite for other reasons.
- Will it work with Gmail or Outlook?
- Yes as destinations. Self-send is not proof. Use a third mailbox and open original.
- What DNS records are involved?
- Exclusive MX, verification TXT, one SPF if you send-as. Leftover MX is a hard stop. Dashboard values only for sending.
- What should I test before production?
- A uniquely titled probe from an unrelated provider to each public alias. Confirm Header From and hop history.
Key takeaways
- Lifespan decides the aisle.
- Brand MX exclusive.
- Masks for throwaways.
- No stealth.
- HOLD on brand.
- Send-as is brand-paid.
- Quote live prices.
- Do not merge MX.
Conclusion
Use a privacy alias service to burn strings. Use business forwarding to keep strings. MailerZ is the keep-strings hop.
Start free on the domain you are willing to put on a business card.