noKYCme

Case file · Email

cock.li

The most no-KYC mailbox there is - no information at all, Tor-reachable - and the clearest reason no-KYC is not the same as safe. It has no default encryption, had a server disk seized in 2015, and in 2025 a webmail SQL-injection breach exposed more than a million user records. A throwaway inbox, not a secure one.

Never KYC
Based
Vincent Canfield (sole operator); hosting jurisdiction has shifted
Price
Free; donation-funded (crypto donations)
Reviewed
2026-07-21
Audited by
The noKYCme Bureau

The systematized overview

The bureau vs the internet.

What the bureau found

3.0/10 · No information required

cock.li is as no-KYC as email gets: it asks for no information at all and is reachable over Tor. But it is the category’s sharpest lesson that no-KYC is not the same as secure. It runs Roundcube webmail with no default end-to-end encryption, had a server disk seized in 2015 after an address was used in bomb hoaxes, and in 2025 a SQL-injection breach exposed more than a million user records. Treat it as a disposable, secondary inbox - never for anything sensitive. The breach caps our score.

What the internet says

2 recurring praises · 2 recurring gripes

Most praised: unbeatable signup anonymity. Most cited downside: 2025 breach of over a million records.

We track our editorial score and community sentiment separately — neither moves the other. Read together, they're the systematized overview.


The facts

Jurisdiction, sign-up & encryption.

Jurisdiction
Sole operator (Vincent Canfield); hosting jurisdiction has shifted
Sign-up needs
No information at all; Tor-reachable
KYC trigger
None
Encryption
Roundcube webmail; no default end-to-end encryption
Provider access
Server can read mail; data proven exposable (2025 breach)
Anon. payment
Free; crypto donations
Logging
Operator states data disclosed only under binding legal orders
Open source
No
Audited
No
Custom domain
Multiple novelty domains offered
Free tier
Yes (free)
Since
2013

The full read

Our analysis, in plain words.

cock.li occupies the far end of the no-KYC spectrum: it asks for absolutely no information, works over Tor, and has run for over a decade on donations. If the only thing you measured were signup anonymity, it would score at the top. But signup anonymity is not the same as security, and cock.li is the clearest illustration of the gap.

Its record is a catalogue of the risks that no-KYC does not address. In 2015, after one of its addresses was used to send bomb hoaxes to schools, a host received a confiscation order and a server disk was seized. In 2025, a SQL-injection vulnerability in its Roundcube webmail was exploited to steal more than a million account records - email addresses, timestamps and webmail settings, though message contents, passwords and IPs were reported as not included that time. There is no default end-to-end encryption, so the mail the service holds is readable in principle, whether to a court order or to a worse breach than 2025’s.

So we rate cock.li exactly as it should be used: a disposable, secondary inbox for throwaway signups where you would not care if the address leaked. The 2025 breach is an unreimbursed loss of user data on a large scale, which caps the overall score at 3.0 no matter how anonymous the signup is. Anonymity at the front door means little when the building has been broken into twice.


The score, broken down

How the 3.0 is built.

Privacy 3.9Trust 0.8Reliability 0.4 Headroom 4.9

Privacy

weight 50%

What identity, data and metadata the service can demand or collect.

78/100

78 × 50% = 3.9 of 10

Trust

weight 30%

Whether it can technically deliver what it claims — code, audits, age.

28/100

28 × 30% = 0.8 of 10

Reliability

weight 20%

Whether the no-KYC claim holds under real-world pressure.

20/100

20 × 20% = 0.4 of 10

Weighted score was 5.1 — a reliability rule capped it to 3.0. See the rubric →


Every point, sourced

What earned the score.

Privacy

  • +8No information required at signup; Tor-reachable - maximally no-KYC
  • +-6No default end-to-end encryption (Roundcube webmail; server can read mail)
  • +-3Hosting jurisdiction has shifted over time (server seized once)

Trust

  • +2Long-running; hands over data only under binding orders in its jurisdiction
  • +-52015 server disk seized after a bomb-hoax investigation
  • +-82025 SQL-injection breach exposed 1M+ user records

The fine print, read for you

The clause they bury.

Verbatim — the trapdoor
“A SQL-injection vulnerability in cock.li’s Roundcube webmail was exploited in 2025 to steal more than one million user records; the service has no default end-to-end encryption.”

What it meansThis is why maximally no-KYC does not mean safe. Because there is no default encryption, the mail cock.li holds is readable in principle - to a court order, or to a bad-enough breach. A no-questions-asked signup stops the provider from knowing who you are, but it does not secure your data: a single 2025 web vulnerability exposed over a million account records (email addresses, timestamps and settings; message contents, passwords and IPs were not in that dump), and a server disk was seized in 2015. Anonymity at signup and security of your data are different things.

Read the source →
KYC trigger threshold

None whatsoever - cock.li asks for no information at all and is reachable over Tor, making it the most no-KYC option we audit (KYC level 0). But the score is not about signup: with no default encryption, a 2015 disk seizure and a 2025 breach of 1M+ records, the mail itself is not safe. No-KYC here buys anonymity at signup, not security of your data.

Policy review — point by point

  • 2025 breach of 1M+ records

    A Roundcube SQL-injection flaw was exploited to steal more than a million user records.

  • No default encryption + a seizure

    No default end-to-end encryption; a server disk was seized in 2015 after a bomb-hoax investigation.

  • Maximally no-KYC

    Requires no information at all and is reachable over Tor - the most anonymous signup we audit.

Jurisdiction analysis

cock.li is a sole-operator project whose hosting has moved across jurisdictions, in part after the 2015 seizure. The operator states data is disclosed only under binding legal orders in the current jurisdiction. But the decisive facts are technical, not legal: no default encryption plus a 2025 breach mean the data is not safe regardless of jurisdiction. Sources are the operator’s site and breach/seizure reporting.


We keep watching

Incident & policy timeline.

  1. 2015

    Server disk seized after a bomb-hoax investigation

    After a cock.li address was used to send bomb hoaxes to schools, the host received a confiscation order and one disk of a RAID1 array was seized; the operator had also received subpoenas for user information beforehand.

    source ↗
  2. 2025

    SQL-injection breach exposes 1M+ records

    A SQL-injection vulnerability in cock.li’s Roundcube webmail was exploited to steal more than one million user records - email addresses, login timestamps, language and webmail settings, and some contact data. Passwords, message contents and IP addresses were reported as not included in the dump.

    source ↗

The verdict

Where it stands.

Strengths

  • Maximally no-KYC - no information at all, Tor-reachable
  • Free and long-running

Trade-offs

  • 2025 SQL-injection breach exposed 1M+ user records
  • No default end-to-end encryption - server can read your mail
  • 2015 server disk seizure
  • Sole-operator project; shifting hosting jurisdiction
Visit cock.li No affiliate relationship. We link to the official site directly.

Across the internet

What reviewers report.

Consistently praised

  • Unbeatable signup anonymity
  • Free, long-running, Tor-friendly

Recurring complaints

  • 2025 breach of over a million records
  • No encryption; prior server seizure

cock.li is known as the go-to throwaway/anonymous inbox, but the 2025 breach hardened the consensus that it is unsuitable for anything sensitive. Security researchers and press treat it as a cautionary example of no-KYC without security. Synthesized from breach reporting and community discussion.


Keep exploring

Related lists & categories.


Ask the bureau

cock.li, common questions.

Is cock.li no-KYC?

Completely - it asks for no information at all and works over Tor, which makes it the most no-KYC provider we audit (KYC level 0). But that is the only thing it does well; the mail itself is not secure.

Is cock.li safe?

No, not for anything sensitive. It has no default end-to-end encryption, had a server disk seized in 2015, and suffered a 2025 SQL-injection breach that exposed more than a million user records. Use it as a disposable, throwaway inbox for sign-ups you do not care about - never for private or important mail.

Why is it scored so low if it is the most no-KYC?

Because no-KYC is only one axis. Our score also weighs whether your data is actually safe, and cock.li fails that badly - a breach that exposes a million records is a serious, unreimbursed loss of user data, which caps the overall score regardless of how anonymous the signup is.

Your exact case not covered? The live Ask the bureau answers it and turns it into a public FAQ.