HaruMail does not load remote message images or execute message scripts. This reduces automatic requests caused by opening email, but it cannot make an untrusted message safe. A sender’s display name can be misleading. Check the actual domain and the message you expected before copying a link or a verification code. Never send an unexpected correspondent your password or a recovery code.

If a message asks you to sign in or pay, open the service through a bookmark or a known address instead of following the email. Do not publish screenshots containing inbox addresses, private links, or verification codes. Closing a temporary inbox cannot undo a disclosure that has already happened.

Read a domain from right to left

In the fictional address accounts.example.com, accounts is a subdomain of example.com. In example.com.attacker.test, the name example.com is only a prefix: the destination is under attacker.test. These are illustrative names, not links to visit. Check the actual host before entering a password. A familiar sender name, a verification code or HTTPS alone cannot establish who operates a website.

If you already followed a suspicious link

Stop interacting with that page. Open the service through an address or app you already trust and check account activity there. If you entered a password, change it through that official channel and review active sessions and recovery methods. Do not paste a complete sign-in or reset link into public scanners or support posts: it can contain an access token. Closing the temporary mailbox does not undo information already submitted elsewhere.

How this guide is maintained

HaruMail publishes these guides based on the service’s implemented behavior and the references below. Examples use fictional data. If a step or explanation is incorrect, send a correction through the contact page without including private email content.

Create free address