Security
Responsible disclosure
If you find a security vulnerability in tempy.email, please tell us before going public. We'll respond quickly and credit your work.
Report a vulnerability →Email security@agdir.no with a description of the vulnerability, steps to reproduce, and the potential impact. Plain text is fine — no need for a formal report format.
We aim to acknowledge within 48 hours and give you a fix timeline within 7 days.
- tempy.email web application
- Developer API —
api.tempy.email - Developer portal —
tempy.email/developers - Email infrastructure (SMTP receive, webhook delivery)
- Denial-of-service and volumetric attacks
- Social engineering or phishing
- Issues in third-party providers (AWS, Cloudflare)
- Rate limiting — by design, some limits are intentionally relaxed for a public anonymous service
tempy.email is a public, anonymous service. Any email delivered to a tempy.email address is accessible to anyone who knows the address — this is intentional and documented. Do not send sensitive information to tempy.email addresses.
Emails are stored in memory only and deleted automatically when the address expires. There is no persistent email storage, no user accounts, and no IP logging.
- We won't take legal action against researchers acting in good faith
- We'll acknowledge your report within 48 hours
- We'll provide a fix timeline within 7 days of confirmation
- We'll credit you in our changelog if you'd like
tempy.email is a free public service with no commercial revenue. We don't offer monetary rewards, but we'll credit your find publicly and share a genuine thank-you.