Featured
At a glance
Pros
- +Zero identity requirements, no ID, phone, or real name needed to register.
- +Tor and VPN friendly, operator explicitly recommends both for anonymous signup.
- +Cryptocurrency donations, accepts Monero and Bitcoin to support operations without financial surveillance.
- +Transparent logging policy, plainly discloses what data is retained and for how long.
- +Custom domain variety, accounts available across ~12 alternative domains.
- +No password resets, eliminates a common account recovery vector that deanonymizes users.
Cons
- −Major security incident, alleged 2025 breach via Roundcube zero-day, though operator disputes successful exploitation.
- −No functional webmail, Roundcube removed in 2025; replacement 'Cock-mail' is in development as of 2026-05-30.
- −Informal support, no guaranteed response; support page jokes about 'intoxicated aliens' handling requests.
- −Blacklist flags, detected by security providers with low trust scores on some third-party scanners.
Full review
What is Cock.li
Cock.li is a free email hosting service that has been operational since 2013, offering user accounts across roughly a dozen alternative domains including cock.li, airmail.cc, 420blaze.it, horsefucker.org, and others. The service explicitly markets itself as professional email with an irreverent tone, emphasizing open access to email without surveillance-state requirements. As of 2026-05-30, the site claims over one million users and is actively developing a new webmail client called "Cock-mail" after discontinuing its previous Roundcube instance in 2025.
How no-KYC is it?
Cock.li is among the most permissive email providers for anonymous registration. The service does not require any personally identifiable information-no photo ID, no phone number, no real name. The registration page asks only for a desired email address, password, and CAPTCHA completion. The privacy policy, last modified 2025-04-03, states: "Cock.li does not require personally identifiable information to register for the service." The operator explicitly recommends using Tor or a VPN and following basic OPSEC to avoid linking personal information to accounts. There are no password resets, meaning account recovery is impossible-an intentional friction that preserves anonymity.
Privacy & security
The privacy posture is transparent but not absolute. Cock.li discloses that it may retain registration details (email, hashed password, IP, user agent, timestamps), mail storage, filters, XMPP data, and 48-72 hours of IMAP/SMTP logs. HTTP access logs are also kept. The operator candidly states: "You can't" fully trust them-any email provider can read mail in plaintext before storage, and the service does not offer server-side encryption. Users are urged to use X.509 or GPG with correspondents and to download and delete mail regularly.
A significant incident occurred in June 2025 when a threat actor allegedly exploited a Roundcube zero-day (CVE-2025-49113) to breach the service. Cock.li denied finding "signs of intrusion or successful exploitation" but announced it would stop using Roundcube regardless. The service now directs users to desktop email clients while its custom webmail is in development. Third-party security scanners flag the domain with mixed signals: ScamAdviser rates it "likely safe" while Gridinsoft assigns a 35/100 trust score citing blacklist detections.
Payments, fees & limits
The core service is free. Cock.li operates on donations via two funds: TEAMSAFU (supporting the development team) and SERVICESAFU (operating expenses). Donations are accepted in Monero and Bitcoin. The Monero address is published on the donation page. There is no paid tier or premium feature set-every functionality is available without payment. New accounts face a proof-of-work challenge to unblock SMTP sending, requiring several minutes of CPU time to prevent spam abuse.
User experience & support
The interface is deliberately crude and functional. Webmail has been absent for extended periods; the current "Cock-mail" project represents an effort to rebuild this capability after abandoning Roundcube. Support is informal and community-oriented, with contact addresses for admin, support, development, and security listed on the contact page. The operator warns that "support may be provided by aliens, intoxicated aliens, or wild animals walking around on DDR mats." There is no ticket system or guaranteed response time. The service maintains a public update log, warrant canary, and transparency page.
Who it's for
Cock.li suits privacy-conscious users who prioritize anonymity over polish, and who can self-support their email workflow. It fits those comfortable with desktop clients, GPG encryption, and accepting provider trust as a limitation. The service is less appropriate for users needing reliable webmail, professional support, or guaranteed uptime. Alternatives like ProtonMail or Tutanota offer more infrastructure but require more identifying information; Cock.li occupies a niche for maximal registration anonymity with minimal service guarantees.
KYC & privacy
Pseudonymous access, no personal data.
Cock.li collects no mandatory PII at registration but may retain IP addresses, user agents, and 48-72 hours of SMTP/IMAP logs. The operator does not sell or share personal data per the privacy policy. Users should note the 2025 Roundcube security incident and the inherent limitation that any email provider can read plaintext mail before storage.
No
Custodial
No
Requires email
No
Logs IP
Verdict
Cock.li is a viable option for users who need a no-KYC email address immediately and can tolerate rough edges, security uncertainty, and self-managed client software. It outperforms mainstream providers on anonymity at signup but trails them on infrastructure reliability and professional support. Use GPG and download mail regularly.
Frequently asked questions
Is Cock.li no-KYC?
Does Cock.li require an email or phone to sign up?
What payment methods does Cock.li accept?
Is Cock.li safe?
Is Cock.li still operating in 2026?
Does Cock.li work with Tor?
Update history
This review is monitored and refreshed regularly.
-
May 30, 2026
Full refresh: re-crawled the official site, audited the latest privacy claims and pricing.
-
April 20, 2026
Added Cock-mail webmail development note; Roundcube deprecated after 2025 incident.
-
March 24, 2026
Updated donation methods: TEAMSAFU and SERVICESAFU funds now active for Monero/Bitcoin.
-
January 1, 2026
Flagged 2025 security incident and operator's disputed post-mortem.
-
November 26, 2025
Noted proof-of-work SMTP unblocking for new accounts.
-
August 2, 2025
Confirmed privacy policy last modified 2025-04-03 with updated deletion links.
-
April 30, 2025
Recorded blacklist warnings from third-party security scanners.
-
March 27, 2025
Initial review published.
Community reviews
5 user reviews
moneromaxi
been using cock.li for years with thunderbird and gpg. never had to give a name or anything. the xmr donation option is clutch.
anon_trader
signup is truly anonymous but the lack of webmail is annoying. had to set up claws mail to get anything done. worth it for no kyc though.
privacyfirst
the 2025 breach news spooked me. operator says no signs of intrusion but i moved my sensitive stuff elsewhere. still use it for burner accounts.
xmr_only
only email provider i know that takes monero donations and actually tells you to use tor. based. the proof of work spam block is clever too.
cypher_punk
support is a joke literally. webmail down for months. the 'cock-mail' thing better work or this service is finished.