- JavaScript 70.6%
- CSS 15%
- HTML 14.4%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
| .github/images | ||
| @local | ||
| source | ||
| agmh.txt | ||
| LICENSE | ||
| README.md | ||
Email Alias Manager (Free) — Chrome edition
View, create, and delete email aliases on
Haltman.io Mail Forwarding
directly from Chrome (and any Chromium-based browser).
No account. No telemetry. No lock-in. Just aliases.
Trusted by Phrack · The Hacker's Choice · Team TESO · EuroCompton · AntiSec
No gods. No masters. No VC. No tiers.
Table of contents
- What is this?
- Features
- Screenshots
- Install
- Getting an API key
- Usage
- Supported domains
- Permissions
- Privacy
- Manifest V3 notes
- Architecture
- Development
- Trusted by
- Security & abuse reports
- Contributing
- License
- Credits
What is this?
Email Alias Manager is a Chrome extension for Haltman.io Mail Forwarding — a free, open-source, self-hostable, abuse-aware mail forwarding stack maintained by the Haltman.io collective in cooperation with The Hacker's Choice (THC).
Give every service a different address. If one leaks, burn that alias. Your real inbox stays yours.
The extension talks to one backend — https://mail.haltman.io — and nothing else. No analytics, no telemetry, no third-party SDKs. Source is public, license is Unlicense.
It is a feature-for-feature port of the Firefox edition, rebuilt on Manifest V3 (service worker background, chrome.scripting clipboard injection, new web_accessible_resources shape).
Features
- 51 domains — pick from the full domain pool, including
reads.phrack.org,smokes.thc.org,free.team-teso.net,segfault.net, and more. - Generate — random readable handles (
blue.forest), random cryptographic handles (k7p3x9m2), or fully custom handles with live validation. - Insert into email fields — a minimal, CSS-isolated overlay renders next to any
input[type="email"]. Pick Generate or Choose and the alias is inserted. - Right-click context menu —
Email Alias Manager → Generate random aliascreates an alias and copies it to the clipboard. - Browse and manage — search, copy, or delete your aliases from the popup with keyboard and pointer controls.
- Domain controls — set a default domain, mark favorites, and remember the last one used.
- Overlay scope — show the helper on all sites, only on an allowlist, or everywhere except a denylist. One-click Disable on this site.
- Password lock — optional local lock. Your API key is encrypted at rest with PBKDF2 (SHA-256) + AES-256-GCM. The password is never stored.
- Request a new key from the popup — email-based credential flow with anti-abuse confirmation (no account required).
- No tracking — no analytics, no remote scripts, no third-party hosts. Verifiable from the source.
Screenshots
Install
Load unpacked (from source)
The cleanest way to run the extension today — you verify every line of code yourself.
git clone https://github.com/haltman-io/mail-forwarding-addon-google-chrome.git
cd mail-forwarding-addon-google-chrome
Then:
- Open
chrome://extensions. - Toggle Developer mode on (top right).
- Click Load unpacked.
- Select the
source/folder.
The extension stays installed across browser restarts. Updates are as simple as git pull + Reload on the extension card.
Install a packed build (.crx / .zip)
If you prefer a single-file install:
cd source
# Package the contents of source/ into a zip that Chrome can load
zip -r ../mail-forwarding-addon-google-chrome.zip . -x "*.DS_Store"
Then drag the resulting .zip onto chrome://extensions (Developer mode must be enabled).
For a signed .crx, use chrome://extensions → Pack extension → point at source/ and keep the generated .pem in a safe place.
Chromium-based browsers
The extension works on any modern Chromium browser that supports Manifest V3:
- Brave —
brave://extensions→ same flow. - Edge —
edge://extensions→ Load unpacked. - Opera —
opera://extensions→ Load unpacked. - Vivaldi —
vivaldi://extensions→ Load unpacked. - Arc / Chromium forks — usually
chrome://extensions.
Getting an API key
You have three options. All three land on the same Haltman.io backend.
1. Directly from the extension (easiest)
Open the popup, scroll down to Request a new key, enter your email, pick a validity (1–90 days), and click Request API key. Check your inbox for a confirmation and then paste the returned token in the Paste your API key field.
2. From the web UI
Go to mail.thc.org or forward.haltman.io, pick a handle/domain/destination, confirm the 6-digit token emailed to you. Request an API key from the same UI when you want programmatic access.
3. From the terminal
# 1) Request a token
curl -s -X POST 'https://mail.haltman.io/api/credentials/create' \
-H 'Content-Type: application/json' \
-d '{"email":"[email protected]","days":30}'
# 2) Check your inbox, then confirm. The response contains your API key.
curl -s 'https://mail.haltman.io/api/credentials/confirm?token=123456'
The API key is 64 lowercase hex characters. It is shown once and stored server-side as a SHA-256 hash — write it down somewhere safe (a password manager is ideal).
Usage
Popup
- Generate — pick a domain, press Generate & Copy. The alias is created on the server and copied to your clipboard.
- More options — choose Readable words or Random, or enter a fully custom handle with live validation.
- Choose — browse, search, copy, or delete your existing aliases.
- Password lock — if enabled, click the 🔒 icon to lock the session immediately.
In-page overlay
On any page with an <input type="email">, a small helper appears next to the field (icon mode) or a pill group (buttons mode). Click it to open a card:
- Generate & insert — creates a new alias and inserts it into the field.
- Choose existing — search and insert one of your aliases.
- Disable on this site — adds the current site to your denylist.
The overlay:
- renders inside a Shadow DOM so site CSS can't leak in and vice versa,
- never reads the field's existing value,
- never transmits the current URL or page content to the backend.
Context menu
Right-click anywhere → Email Alias Manager → Generate random alias.
Creates a word1.word2@<random-domain> alias, copies it to the clipboard via a brief chrome.scripting.executeScript injection into the active tab, and shows a desktop notification.
Options
Open with the ⚙️ button in the popup, or via chrome://extensions → Email Alias Manager → Details → Extension options.
- API key — view, replace, or remove the stored key.
- Default domain — preselect your favorite domain in the popup.
- Input overlay — toggle globally, or restrict to an allowlist / denylist of sites (hosts, URLs, or
file://). - Password lock — enable, lock now, or disable. Uses PBKDF2 (310k iterations, SHA-256) + AES-256-GCM.
- Disconnect extension — wipes all local extension data (aliases on the server are unaffected).
Supported domains
51 domains available at the time of writing. Highlights from the Phrack / THC / TESO / AntiSec / EuroCompton constellation:
| Domain | Scene note |
|---|---|
reads.phrack.org |
Phrack Magazine — the original hacking e-zine |
smokes.thc.org |
The Hacker's Choice — since 1995 |
free.team-teso.net |
Team TESO — early-2000s exploit research |
segfault.net |
general-purpose, disposable |
ghetto.eurocompton.net |
oldest IDS enemy |
lulz.antisec.net |
AntiSec — you know what it is |
Other entries (metasploit.io, polkit.org, cobaltstrike.org, johntheripper.org, …) were publicly available for registration and added to the shared pool; they are not affiliated with the original projects.
The full list is discovered at runtime via GET /api/domains, cached locally for 24 hours, and shown in the popup's domain picker.
Permissions
The extension requests the minimum set that makes it work. Every permission maps to a feature you can see:
| Permission | Purpose |
|---|---|
storage |
Persist API key, domain cache, and user preferences (chrome.storage.local). |
contextMenus |
Register Email Alias Manager → Generate random alias. |
activeTab |
Act on the tab where you invoked the extension (context menu, clipboard). |
scripting |
Inject a tiny local function into the active tab solely to write the alias to its clipboard. |
notifications |
Status notifications after Generate random alias (success / failure). |
clipboardWrite |
Copy newly generated aliases to the clipboard. |
<all_urls> content script |
Render the overlay next to <input type="email"> fields only. |
host_permissions: https://mail.haltman.io/* |
Talk to the Haltman.io backend. The only host the extension ever talks to. |
The extension does not request tabs, cookies, webRequest, webNavigation, history, bookmarks, downloads, or any broad host permission beyond mail.haltman.io. This is intentional — see chrome-issues.md (Purple Potassium).
Privacy
- Privacy policy · Anti-abuse policy · Security policy
- The extension talks to one host only:
https://mail.haltman.io(always over TLS). - API keys ride in the
X-API-Keyheader, never in URLs or query strings. - The extension never reads the value of the email field, transmits browsing history, page content, or any telemetry.
- When the password lock is on, the API key is encrypted at rest with PBKDF2 + AES-256-GCM and only decrypted in memory for the duration of your unlocked session.
See privacy-policy.md (the file that mirrors the policy at mail.haltman.io/privacy) for the full text.
Manifest V3 notes
This build complies with the MV3 policies that are most commonly flagged on review (Chrome Web Store Purple Potassium, Blue Argon, Red Titanium):
- No remotely hosted code. No
<script src>pointing at a remote origin, noeval, no dynamicFunction, no runtime imports from URLs. Every byte executed lives inside the package. - Clipboard injection uses
chrome.scripting.executeScriptwith afunc+argspayload — not stringified user data. The injected function is the same one you can read insource/background/background.js. - Narrowest permission set. See the table above.
tabswas intentionally removed; we only needactiveTab+scripting. - No obfuscation, no minification. The code in
source/is the code that runs. - Data, not logic, from the backend. API responses are strictly parsed as JSON; nothing is ever executed as code.
Architecture
source/
├── manifest.json Manifest V3
├── background/
│ └── background.js service worker: messages, context menu, API, clipboard inject
├── content/
│ ├── content.js shadow-DOM overlay next to email inputs
│ └── content.css minimal host-side reset
├── popup/
│ ├── popup.html onboarding, Generate tab, Choose tab (loads polyfill + ES module)
│ ├── popup.css
│ └── popup.js ES module, imports from ../lib
├── options/
│ ├── options.html settings: key, lock, overlay, default domain
│ ├── options.css
│ └── options.js ES module, imports from ../lib
├── lib/
│ ├── browser-polyfill.js classic script: exposes browser.* over chrome.*
│ ├── api.js typed API wrapper
│ ├── crypto.js PBKDF2 + AES-GCM helpers
│ └── storage.js storage.local accessors
├── data/
│ └── dictionary.json readable handle word list
├── icons/
└── image/
- Service worker background. Registered as
background.service_worker, loaded as a classic script so it can callimportScripts("../lib/browser-polyfill.js")at top level. - Thin polyfill.
lib/browser-polyfill.jswraps thechrome.*callback-style APIs into promise-returningbrowser.*equivalents for the handful of namespaces we use (runtime,storage,notifications,contextMenus,tabs.sendMessage). This is what lets us keep a singlebrowser.*codebase across Firefox and Chrome. - One backend. Every outbound request is
fetch(\https://mail.haltman.io/api/...`)`. - Endpoints used —
GET /api/domains,GET /api/alias/list,POST /api/alias/create,POST /api/alias/delete,POST /api/credentials/create. - Shadow DOM everywhere UI touches the page — site CSS never hits the overlay, and the overlay never inherits from the page.
Development
Prerequisites
- Chrome ≥ 109 (or any Chromium-based browser with MV3 support).
- Optional:
web-ext(npm i -g web-ext) for a nicer dev loop — it works with Chromium viaweb-ext run --target chromium.
Run
git clone https://github.com/haltman-io/mail-forwarding-addon-google-chrome.git
cd mail-forwarding-addon-google-chrome
# Either:
# chrome://extensions → Developer mode → Load unpacked → select source/
# or:
cd source && web-ext run --target chromium
Service-worker logs live under chrome://extensions → Email Alias Manager → Inspect views: service worker.
Lint / package
cd source
web-ext lint # static checks (manifest, CSP, etc.)
web-ext build --overwrite-dest # produces a web-ext-artifacts/*.zip
Coding notes
- The source uses
browser.*everywhere.chrome.*is only used insidebackground.jsfor MV3-only APIs (chrome.scripting.executeScript,chrome.contextMenus.*,chrome.runtime.onInstalled). - The MV3 service worker registers all event listeners synchronously at the top of the script — listeners must be visible before the first
await, otherwise they are missed on cold start. - The content script is preceded by
lib/browser-polyfill.jsincontent_scripts[].js, so by the timecontent.jsruns,browser.*is already defined. popup.htmlandoptions.htmlload../lib/browser-polyfill.jsas a classic script before the ES module, so modules can import fromlib/storage.js(which usesbrowser.*) without a race.- No bundler, no transpile step, no build artifact in tree. Edits to
source/are live.
Trusted by
This extension ships the Haltman.io / THC shared domain pool that is used by — and in some cases hosted by — people you probably already read.
- Phrack Magazine —
reads.phrack.org - The Hacker's Choice (THC) —
smokes.thc.org - Team TESO —
free.team-teso.net - EuroCompton —
ghetto.eurocompton.net - AntiSec —
lulz.antisec.net - …and 45+ more.
Huge respect to THC for running mail.thc.org on top of the same stack — no middlemen, no SaaS leashes, no corporate clownery.
Security & abuse reports
- Security / VDP — mail.haltman.io/security (there is a Hall of Fame).
- Abuse — mail.haltman.io/abuse.
- Direct contact —
[email protected]and[email protected].
We do not tolerate abuse of the forwarding service — no ransomware, botnets, DDoS, fraud, or harassment infrastructure. If you see abuse, write to us; we will neutralize it.
Contributing
Issues, PRs, and pull-request conversations are welcome at the GitHub repository.
Before submitting a PR:
- Keep it scoped — small, focused changes land fastest.
- No build steps, no dependencies, no transpilers — if you need to add one, open an issue first.
- Follow the existing style (2-space indent, double quotes, semicolons, strict equality).
web-ext lintmust pass.- Do not add analytics, telemetry, remote hosts, or third-party scripts. Ever.
- Keep the MV3 surface tight — any new permission needs a justification that would survive a Chrome Web Store review (see
chrome-issues.md).
License
Released under the Unlicense — public domain, no restrictions, no copyleft, no strings. Fork it, sell it, rebrand it. We don't care.
Credits
Built by the Haltman.io collective — an independent crew of Brazilian hackers — in cooperation with The Hacker's Choice (THC).
Foundations we stand on: the original Perl alias API by Lou-Cipher (RIP the service, long live the idea), Postfix, Dovecot, PostSRSd, MariaDB, OpenDKIM, and everyone who kept the mail stack boring enough to still work in 2026.
Made in Brazil. 🇧🇷