How Long Does a Temporary Email Last? Plan Before It Expires
Reviewed by Once Email product review
Article guide
Why this article is worth your time
- Original analysis
- We separate three clocks that users often confuse: mailbox lifetime, message retention and the sender-defined validity period of a code or link.
- Trend context
- Passwordless and magic-link flows make expiry more visible, but providers still set independent validity windows that do not follow a temporary mailbox countdown.
- Practical value
- Readers can plan what to save, when to migrate recovery information and why a displayed lifetime should never be treated as a storage guarantee.
On this page
A temporary inbox is designed to disappear. That is useful when a message has a short purpose, but it creates a serious risk if the address later becomes the only way to recover an account, retrieve a receipt or contact support.
Once Email currently offers 10-minute, one-hour and one-day lifetime choices. Mailbox data is scheduled for deletion within the selected lifetime, with one day as the longest lifetime shown by the service. You can replace or delete the address sooner. An expired or deleted address and its messages cannot be restored.
This is a product limit, not a promise that every message will remain available for every second of the selected period. Delivery delays, browser state, maintenance and sender-side problems can still affect what you see. Treat every useful message as temporary from the moment it arrives.
What the countdown means
The selected lifetime controls how long the temporary mailbox is intended to remain available. It is not the validity period of a verification code or link. The sender decides how long its code, invitation or reset link remains valid, and that period may be shorter than the mailbox countdown.
Three different clocks may therefore be running:
- the Once Email mailbox lifetime;
- the sender's message or code validity period;
- the lifetime of the account or transaction created with the address.
A message can remain visible after its code has expired. The reverse can also happen: a code may still be valid in theory after the temporary mailbox is no longer available. Do not assume these clocks are coordinated.
OWASP guidance recommends single-use password-reset tokens that expire after an appropriate period.
What replacement and deletion change
Replacing an address creates a different temporary mailbox. Deleting an address ends access to the current mailbox. Neither action migrates messages, forwards future mail or creates a recovery path.
Before selecting either action, check whether you still need:
- a verification code that has not been entered;
- an order reference or support identifier;
- an attachment you are authorised to retain;
- the sender's official domain or contact instructions;
- evidence for an authorised software test.
Save only what you genuinely need and are allowed to keep. Verification links, reset links, session tokens and one-time codes are secrets. Do not place them in public screenshots, shared issue trackers or analytics systems.
Why temporary email is poor account recovery
Account recovery depends on a channel that remains under your control. A temporary address is deliberately short-lived, so it is a poor recovery address even when an initial sign-up succeeds.
Current NIST digital identity guidance treats account recovery as a distinct process involving recovery codes, recovery contacts or repeated identity proofing. It also describes notifications and multiple contact methods as important protections. Once Email does not provide those long-term identity and recovery functions.
Use a permanent address for any account involving money, personal records, saved work, purchases, employment, education, healthcare, government services or an ongoing subscription. Also use one whenever support may require a reply from the registered address: Once Email is receive-only and cannot send, reply or forward.
Move important accounts while access still works
Sometimes a low-risk trial becomes valuable. If the service permits changing the registered address, move it to a permanent mailbox while you can still sign in. Confirm the new address before deleting or replacing the temporary inbox.
A practical migration sequence is:
- Sign in through the service's known official site.
- Add a permanent address you control.
- Complete the service's confirmation process.
- Add another recovery method or save recovery codes if offered.
- Verify that security notifications reach the new destination.
- Only then remove dependence on the temporary address.
Do not use an email link from an unexpected message to start this change. Open the known service directly, especially when the message creates urgency or asks for credentials.
A checklist before the mailbox expires
Ask these questions while time remains:
- Have I completed the one short-lived task for which I created the address?
- Does any resulting account need future access or support?
- Have I moved an important account to a permanent recovery address?
- Have I recorded a non-secret reference that I am authorised to keep?
- Have I removed codes and links from screenshots or test reports?
- Am I ready for the address and messages to become unrecoverable?
If any answer is uncertain, do not build more activity on the temporary address. Finish the authorised task or move to a durable mailbox.
The safe rule
Choose a temporary inbox only when the task is permitted, short-lived and reversible. Assume the address will not be available later. If the relationship, record or account must survive, start with—or promptly move to—a permanent address that supports recovery and replies.
Expiration is not a defect to work around; it is the defining boundary of the product. Planning for that boundary prevents a convenient one-time inbox from becoming an avoidable lockout.
Related guides
Postfix vs Dovecot: Different Roles in a Receiving Email Server
See where Postfix and Dovecot sit in the inbound mail path, what each service owns, how LMTP connects them, and which evidence to check when delivery fails.
How to Inspect Email Links and Tracking Pixels Without Opening Them
Review email HTML locally for dangerous schemes, nested redirects, misleading domains, remote images and tracking-pixel clues without rendering the message.