Welcome to the Email Alias Manager. Yeah, another browser extension. No, it’s not spyware. No, it’s not “freemium”. No, we’re not here to upsell you shit. You can view, create, and delete mail aliases using your own API key. Generate it yourself at: https://forward.haltman.io/
  • JavaScript 70.6%
  • CSS 15%
  • HTML 14.4%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
2026-06-16 01:13:51 -03:00
.github/images Release 🔥 :) 2026-01-29 14:03:59 -03:00
@local Add documentation and onboarding materials for Email Alias Manager extension 2026-04-18 12:37:22 -03:00
source Add documentation and onboarding materials for Email Alias Manager extension 2026-04-18 12:37:22 -03:00
agmh.txt Mirroring with AGMH v0.4.1 2026-06-16 01:13:51 -03:00
LICENSE Initial commit 2026-01-29 13:25:09 -03:00
README.md Revise README for clarity and structure; enhance descriptions and add new sections 2026-04-18 12:48:19 -03:00

Email Alias Manager (Free) — Chrome edition

View, create, and delete email aliases on Haltman.io Mail Forwarding directly from Chrome (and any Chromium-based browser).
No account. No telemetry. No lock-in. Just aliases.

Manifest V3 Chromium compatible License: Unlicense 51 domains

Trusted by Phrack · The Hacker's Choice · Team TESO · EuroCompton · AntiSec

No gods. No masters. No VC. No tiers.


Table of contents


What is this?

Email Alias Manager is a Chrome extension for Haltman.io Mail Forwarding — a free, open-source, self-hostable, abuse-aware mail forwarding stack maintained by the Haltman.io collective in cooperation with The Hacker's Choice (THC).

Give every service a different address. If one leaks, burn that alias. Your real inbox stays yours.

The extension talks to one backend — https://mail.haltman.io — and nothing else. No analytics, no telemetry, no third-party SDKs. Source is public, license is Unlicense.

It is a feature-for-feature port of the Firefox edition, rebuilt on Manifest V3 (service worker background, chrome.scripting clipboard injection, new web_accessible_resources shape).

Features

  • 51 domains — pick from the full domain pool, including reads.phrack.org, smokes.thc.org, free.team-teso.net, segfault.net, and more.
  • Generate — random readable handles (blue.forest), random cryptographic handles (k7p3x9m2), or fully custom handles with live validation.
  • Insert into email fields — a minimal, CSS-isolated overlay renders next to any input[type="email"]. Pick Generate or Choose and the alias is inserted.
  • Right-click context menu — Email Alias Manager → Generate random alias creates an alias and copies it to the clipboard.
  • Browse and manage — search, copy, or delete your aliases from the popup with keyboard and pointer controls.
  • Domain controls — set a default domain, mark favorites, and remember the last one used.
  • Overlay scope — show the helper on all sites, only on an allowlist, or everywhere except a denylist. One-click Disable on this site.
  • Password lock — optional local lock. Your API key is encrypted at rest with PBKDF2 (SHA-256) + AES-256-GCM. The password is never stored.
  • Request a new key from the popup — email-based credential flow with anti-abuse confirmation (no account required).
  • No tracking — no analytics, no remote scripts, no third-party hosts. Verifiable from the source.

Screenshots

Popup Domain picker

Choose & search aliases

In-page overlay next to email fields In-page overlay menu opened

Install

Load unpacked (from source)

The cleanest way to run the extension today — you verify every line of code yourself.

git clone https://github.com/haltman-io/mail-forwarding-addon-google-chrome.git
cd mail-forwarding-addon-google-chrome

Then:

  1. Open chrome://extensions.
  2. Toggle Developer mode on (top right).
  3. Click Load unpacked.
  4. Select the source/ folder.

The extension stays installed across browser restarts. Updates are as simple as git pull + Reload on the extension card.

Install a packed build (.crx / .zip)

If you prefer a single-file install:

cd source
# Package the contents of source/ into a zip that Chrome can load
zip -r ../mail-forwarding-addon-google-chrome.zip . -x "*.DS_Store"

Then drag the resulting .zip onto chrome://extensions (Developer mode must be enabled).

For a signed .crx, use chrome://extensions → Pack extension → point at source/ and keep the generated .pem in a safe place.

Chromium-based browsers

The extension works on any modern Chromium browser that supports Manifest V3:

  • Brave — brave://extensions → same flow.
  • Edge — edge://extensions → Load unpacked.
  • Opera — opera://extensions → Load unpacked.
  • Vivaldi — vivaldi://extensions → Load unpacked.
  • Arc / Chromium forks — usually chrome://extensions.

Getting an API key

You have three options. All three land on the same Haltman.io backend.

1. Directly from the extension (easiest)

Open the popup, scroll down to Request a new key, enter your email, pick a validity (1–90 days), and click Request API key. Check your inbox for a confirmation and then paste the returned token in the Paste your API key field.

2. From the web UI

Go to mail.thc.org or forward.haltman.io, pick a handle/domain/destination, confirm the 6-digit token emailed to you. Request an API key from the same UI when you want programmatic access.

3. From the terminal

# 1) Request a token
curl -s -X POST 'https://mail.haltman.io/api/credentials/create' \
     -H 'Content-Type: application/json' \
     -d '{"email":"[email protected]","days":30}'

# 2) Check your inbox, then confirm. The response contains your API key.
curl -s 'https://mail.haltman.io/api/credentials/confirm?token=123456'

The API key is 64 lowercase hex characters. It is shown once and stored server-side as a SHA-256 hash — write it down somewhere safe (a password manager is ideal).

Usage

Popup

  • Generate — pick a domain, press Generate & Copy. The alias is created on the server and copied to your clipboard.
  • More options — choose Readable words or Random, or enter a fully custom handle with live validation.
  • Choose — browse, search, copy, or delete your existing aliases.
  • Password lock — if enabled, click the 🔒 icon to lock the session immediately.

In-page overlay

On any page with an <input type="email">, a small helper appears next to the field (icon mode) or a pill group (buttons mode). Click it to open a card:

  • Generate & insert — creates a new alias and inserts it into the field.
  • Choose existing — search and insert one of your aliases.
  • Disable on this site — adds the current site to your denylist.

The overlay:

  • renders inside a Shadow DOM so site CSS can't leak in and vice versa,
  • never reads the field's existing value,
  • never transmits the current URL or page content to the backend.

Context menu

Right-click anywhere → Email Alias Manager → Generate random alias.

Creates a word1.word2@<random-domain> alias, copies it to the clipboard via a brief chrome.scripting.executeScript injection into the active tab, and shows a desktop notification.

Options

Open with the ⚙️ button in the popup, or via chrome://extensions → Email Alias Manager → Details → Extension options.

  • API key — view, replace, or remove the stored key.
  • Default domain — preselect your favorite domain in the popup.
  • Input overlay — toggle globally, or restrict to an allowlist / denylist of sites (hosts, URLs, or file://).
  • Password lock — enable, lock now, or disable. Uses PBKDF2 (310k iterations, SHA-256) + AES-256-GCM.
  • Disconnect extension — wipes all local extension data (aliases on the server are unaffected).

Supported domains

51 domains available at the time of writing. Highlights from the Phrack / THC / TESO / AntiSec / EuroCompton constellation:

Domain Scene note
reads.phrack.org Phrack Magazine — the original hacking e-zine
smokes.thc.org The Hacker's Choice — since 1995
free.team-teso.net Team TESO — early-2000s exploit research
segfault.net general-purpose, disposable
ghetto.eurocompton.net oldest IDS enemy
lulz.antisec.net AntiSec — you know what it is

Other entries (metasploit.io, polkit.org, cobaltstrike.org, johntheripper.org, …) were publicly available for registration and added to the shared pool; they are not affiliated with the original projects.

The full list is discovered at runtime via GET /api/domains, cached locally for 24 hours, and shown in the popup's domain picker.

Permissions

The extension requests the minimum set that makes it work. Every permission maps to a feature you can see:

Permission Purpose
storage Persist API key, domain cache, and user preferences (chrome.storage.local).
contextMenus Register Email Alias Manager → Generate random alias.
activeTab Act on the tab where you invoked the extension (context menu, clipboard).
scripting Inject a tiny local function into the active tab solely to write the alias to its clipboard.
notifications Status notifications after Generate random alias (success / failure).
clipboardWrite Copy newly generated aliases to the clipboard.
<all_urls> content script Render the overlay next to <input type="email"> fields only.
host_permissions: https://mail.haltman.io/* Talk to the Haltman.io backend. The only host the extension ever talks to.

The extension does not request tabs, cookies, webRequest, webNavigation, history, bookmarks, downloads, or any broad host permission beyond mail.haltman.io. This is intentional — see chrome-issues.md (Purple Potassium).

Privacy

  • Privacy policy · Anti-abuse policy · Security policy
  • The extension talks to one host only: https://mail.haltman.io (always over TLS).
  • API keys ride in the X-API-Key header, never in URLs or query strings.
  • The extension never reads the value of the email field, transmits browsing history, page content, or any telemetry.
  • When the password lock is on, the API key is encrypted at rest with PBKDF2 + AES-256-GCM and only decrypted in memory for the duration of your unlocked session.

See privacy-policy.md (the file that mirrors the policy at mail.haltman.io/privacy) for the full text.

Manifest V3 notes

This build complies with the MV3 policies that are most commonly flagged on review (Chrome Web Store Purple Potassium, Blue Argon, Red Titanium):

  • No remotely hosted code. No <script src> pointing at a remote origin, no eval, no dynamic Function, no runtime imports from URLs. Every byte executed lives inside the package.
  • Clipboard injection uses chrome.scripting.executeScript with a func + args payload — not stringified user data. The injected function is the same one you can read in source/background/background.js.
  • Narrowest permission set. See the table above. tabs was intentionally removed; we only need activeTab + scripting.
  • No obfuscation, no minification. The code in source/ is the code that runs.
  • Data, not logic, from the backend. API responses are strictly parsed as JSON; nothing is ever executed as code.

Architecture

source/
├── manifest.json           Manifest V3
├── background/
│   └── background.js       service worker: messages, context menu, API, clipboard inject
├── content/
│   ├── content.js          shadow-DOM overlay next to email inputs
│   └── content.css         minimal host-side reset
├── popup/
│   ├── popup.html          onboarding, Generate tab, Choose tab (loads polyfill + ES module)
│   ├── popup.css
│   └── popup.js            ES module, imports from ../lib
├── options/
│   ├── options.html        settings: key, lock, overlay, default domain
│   ├── options.css
│   └── options.js          ES module, imports from ../lib
├── lib/
│   ├── browser-polyfill.js classic script: exposes browser.* over chrome.*
│   ├── api.js              typed API wrapper
│   ├── crypto.js           PBKDF2 + AES-GCM helpers
│   └── storage.js          storage.local accessors
├── data/
│   └── dictionary.json     readable handle word list
├── icons/
└── image/
  • Service worker background. Registered as background.service_worker, loaded as a classic script so it can call importScripts("../lib/browser-polyfill.js") at top level.
  • Thin polyfill. lib/browser-polyfill.js wraps the chrome.* callback-style APIs into promise-returning browser.* equivalents for the handful of namespaces we use (runtime, storage, notifications, contextMenus, tabs.sendMessage). This is what lets us keep a single browser.* codebase across Firefox and Chrome.
  • One backend. Every outbound request is fetch(\https://mail.haltman.io/api/...`)`.
  • Endpoints used — GET /api/domains, GET /api/alias/list, POST /api/alias/create, POST /api/alias/delete, POST /api/credentials/create.
  • Shadow DOM everywhere UI touches the page — site CSS never hits the overlay, and the overlay never inherits from the page.

Development

Prerequisites

  • Chrome ≥ 109 (or any Chromium-based browser with MV3 support).
  • Optional: web-ext (npm i -g web-ext) for a nicer dev loop — it works with Chromium via web-ext run --target chromium.

Run

git clone https://github.com/haltman-io/mail-forwarding-addon-google-chrome.git
cd mail-forwarding-addon-google-chrome
# Either:
#   chrome://extensions → Developer mode → Load unpacked → select source/
# or:
cd source && web-ext run --target chromium

Service-worker logs live under chrome://extensions → Email Alias Manager → Inspect views: service worker.

Lint / package

cd source
web-ext lint              # static checks (manifest, CSP, etc.)
web-ext build --overwrite-dest  # produces a web-ext-artifacts/*.zip

Coding notes

  • The source uses browser.* everywhere. chrome.* is only used inside background.js for MV3-only APIs (chrome.scripting.executeScript, chrome.contextMenus.*, chrome.runtime.onInstalled).
  • The MV3 service worker registers all event listeners synchronously at the top of the script — listeners must be visible before the first await, otherwise they are missed on cold start.
  • The content script is preceded by lib/browser-polyfill.js in content_scripts[].js, so by the time content.js runs, browser.* is already defined.
  • popup.html and options.html load ../lib/browser-polyfill.js as a classic script before the ES module, so modules can import from lib/storage.js (which uses browser.*) without a race.
  • No bundler, no transpile step, no build artifact in tree. Edits to source/ are live.

Trusted by

This extension ships the Haltman.io / THC shared domain pool that is used by — and in some cases hosted by — people you probably already read.

  • Phrack Magazine — reads.phrack.org
  • The Hacker's Choice (THC) — smokes.thc.org
  • Team TESO — free.team-teso.net
  • EuroCompton — ghetto.eurocompton.net
  • AntiSec — lulz.antisec.net
  • …and 45+ more.

Huge respect to THC for running mail.thc.org on top of the same stack — no middlemen, no SaaS leashes, no corporate clownery.

Security & abuse reports

We do not tolerate abuse of the forwarding service — no ransomware, botnets, DDoS, fraud, or harassment infrastructure. If you see abuse, write to us; we will neutralize it.

Contributing

Issues, PRs, and pull-request conversations are welcome at the GitHub repository.

Before submitting a PR:

  • Keep it scoped — small, focused changes land fastest.
  • No build steps, no dependencies, no transpilers — if you need to add one, open an issue first.
  • Follow the existing style (2-space indent, double quotes, semicolons, strict equality).
  • web-ext lint must pass.
  • Do not add analytics, telemetry, remote hosts, or third-party scripts. Ever.
  • Keep the MV3 surface tight — any new permission needs a justification that would survive a Chrome Web Store review (see chrome-issues.md).

License

Released under the Unlicense — public domain, no restrictions, no copyleft, no strings. Fork it, sell it, rebrand it. We don't care.

Credits

Built by the Haltman.io collective — an independent crew of Brazilian hackers — in cooperation with The Hacker's Choice (THC).

Foundations we stand on: the original Perl alias API by Lou-Cipher (RIP the service, long live the idea), Postfix, Dovecot, PostSRSd, MariaDB, OpenDKIM, and everyone who kept the mail stack boring enough to still work in 2026.

Made in Brazil. 🇧🇷