Our approach
We apply layered operational and technical safeguards appropriate to the service and review controls as the product changes. No internet system is risk-free, so we combine prevention with monitoring, recovery, and responsible reporting.
Account access
The service supports email one-time-code sign-in and Google sign-in. Login codes are time-limited. Users should secure their destination inbox and Google account, review account access, and never share login codes.
Domain and routing controls
DNS verification demonstrates control before forwarding is activated. Account authorization checks restrict domain, alias, and recipient changes. Routing records and operational logs are limited to what is needed to operate, troubleshoot, and protect the service.
Payments and providers
Checkout is handled by configured payment providers such as Stripe and PayPal. The application stores provider references and billing status, not complete payment card numbers.
What users can do
Use a protected destination inbox, keep DNS accounts secure, remove recipients that no longer need mail, verify unexpected forwarding changes, and contact us quickly if a domain or account may be compromised.
Report a security issue
Send a clear description and reproducible steps to support@easymailforward.com. Do not access other users' data, disrupt production, use automated destructive testing, or publicly disclose an unresolved issue. We will acknowledge and prioritize valid reports based on risk.