Lifecycle and risk·Updated Sep 4, 2026

How Long Does a Temporary Email Last? Plan Before It Expires

Understand Once Email lifetime choices, deletion and replacement, then decide what to save and when an account needs a permanent recovery address.

Reviewed by Once Email product review

What this guide helps you do
Readers can plan what to save, when to migrate recovery information and why a displayed lifetime should never be treated as a storage guarantee.

Article guide

Why this article is worth your time

Original analysis
We separate three clocks that users often confuse: mailbox lifetime, message retention and the sender-defined validity period of a code or link.
Trend context
Passwordless and magic-link flows make expiry more visible, but providers still set independent validity windows that do not follow a temporary mailbox countdown.
Practical value
Readers can plan what to save, when to migrate recovery information and why a displayed lifetime should never be treated as a storage guarantee.

A temporary inbox is designed to disappear. That is useful when a message has a short purpose, but it creates a serious risk if the address later becomes the only way to recover an account, retrieve a receipt or contact support.

Once Email currently offers 10-minute, one-hour and one-day lifetime choices. Mailbox data is scheduled for deletion within the selected lifetime, with one day as the longest lifetime shown by the service. You can replace or delete the address sooner. An expired or deleted address and its messages cannot be restored.

This is a product limit, not a promise that every message will remain available for every second of the selected period. Delivery delays, browser state, maintenance and sender-side problems can still affect what you see. Treat every useful message as temporary from the moment it arrives.

What the countdown means

The selected lifetime controls how long the temporary mailbox is intended to remain available. It is not the validity period of a verification code or link. The sender decides how long its code, invitation or reset link remains valid, and that period may be shorter than the mailbox countdown.

Three different clocks may therefore be running:

  • the Once Email mailbox lifetime;
  • the sender's message or code validity period;
  • the lifetime of the account or transaction created with the address.

A message can remain visible after its code has expired. The reverse can also happen: a code may still be valid in theory after the temporary mailbox is no longer available. Do not assume these clocks are coordinated.

OWASP guidance recommends single-use password-reset tokens that expire after an appropriate period.

What replacement and deletion change

Replacing an address creates a different temporary mailbox. Deleting an address ends access to the current mailbox. Neither action migrates messages, forwards future mail or creates a recovery path.

Before selecting either action, check whether you still need:

  • a verification code that has not been entered;
  • an order reference or support identifier;
  • an attachment you are authorised to retain;
  • the sender's official domain or contact instructions;
  • evidence for an authorised software test.

Save only what you genuinely need and are allowed to keep. Verification links, reset links, session tokens and one-time codes are secrets. Do not place them in public screenshots, shared issue trackers or analytics systems.

Why temporary email is poor account recovery

Account recovery depends on a channel that remains under your control. A temporary address is deliberately short-lived, so it is a poor recovery address even when an initial sign-up succeeds.

Current NIST digital identity guidance treats account recovery as a distinct process involving recovery codes, recovery contacts or repeated identity proofing. It also describes notifications and multiple contact methods as important protections. Once Email does not provide those long-term identity and recovery functions.

Use a permanent address for any account involving money, personal records, saved work, purchases, employment, education, healthcare, government services or an ongoing subscription. Also use one whenever support may require a reply from the registered address: Once Email is receive-only and cannot send, reply or forward.

Move important accounts while access still works

Sometimes a low-risk trial becomes valuable. If the service permits changing the registered address, move it to a permanent mailbox while you can still sign in. Confirm the new address before deleting or replacing the temporary inbox.

A practical migration sequence is:

  1. Sign in through the service's known official site.
  2. Add a permanent address you control.
  3. Complete the service's confirmation process.
  4. Add another recovery method or save recovery codes if offered.
  5. Verify that security notifications reach the new destination.
  6. Only then remove dependence on the temporary address.

Do not use an email link from an unexpected message to start this change. Open the known service directly, especially when the message creates urgency or asks for credentials.

A checklist before the mailbox expires

Ask these questions while time remains:

  • Have I completed the one short-lived task for which I created the address?
  • Does any resulting account need future access or support?
  • Have I moved an important account to a permanent recovery address?
  • Have I recorded a non-secret reference that I am authorised to keep?
  • Have I removed codes and links from screenshots or test reports?
  • Am I ready for the address and messages to become unrecoverable?

If any answer is uncertain, do not build more activity on the temporary address. Finish the authorised task or move to a durable mailbox.

The safe rule

Choose a temporary inbox only when the task is permitted, short-lived and reversible. Assume the address will not be available later. If the relationship, record or account must survive, start with—or promptly move to—a permanent address that supports recovery and replies.

Expiration is not a defect to work around; it is the defining boundary of the product. Planning for that boundary prevents a convenient one-time inbox from becoming an avoidable lockout.

Temporary Email Threat Model: What It Protects and What It Does Not
Model the assets, adversaries, protections and limits of a receive-only temporary inbox without confusing address separation with anonymity or message safety.
Email Verification Codes: A Safer Way to Copy, Check and Use Them
Treat an email verification code as a short-lived secret: confirm the request, inspect the destination, copy only the code and clear it when the task is finished.
Verification Email Not Arriving? A Safe Troubleshooting Checklist
Work through address mistakes, sender delays, retries, filtering and mailbox limits without repeatedly requesting codes or weakening account security.