Case file · Email
cock.li
The most no-KYC mailbox there is - no information at all, Tor-reachable - and the clearest reason no-KYC is not the same as safe. It has no default encryption, had a server disk seized in 2015, and in 2025 a webmail SQL-injection breach exposed more than a million user records. A throwaway inbox, not a secure one.
The systematized overview
The bureau vs the internet.
3.0/10 · No information required
cock.li is as no-KYC as email gets: it asks for no information at all and is reachable over Tor. But it is the category’s sharpest lesson that no-KYC is not the same as secure. It runs Roundcube webmail with no default end-to-end encryption, had a server disk seized in 2015 after an address was used in bomb hoaxes, and in 2025 a SQL-injection breach exposed more than a million user records. Treat it as a disposable, secondary inbox - never for anything sensitive. The breach caps our score.
2 recurring praises · 2 recurring gripes
Most praised: unbeatable signup anonymity. Most cited downside: 2025 breach of over a million records.
We track our editorial score and community sentiment separately — neither moves the other. Read together, they're the systematized overview.
The facts
Jurisdiction, sign-up & encryption.
- Jurisdiction
- Sole operator (Vincent Canfield); hosting jurisdiction has shifted
- Sign-up needs
- No information at all; Tor-reachable
- KYC trigger
- None
- Encryption
- Roundcube webmail; no default end-to-end encryption
- Provider access
- Server can read mail; data proven exposable (2025 breach)
- Anon. payment
- Free; crypto donations
- Logging
- Operator states data disclosed only under binding legal orders
- Open source
- No
- Audited
- No
- Custom domain
- Multiple novelty domains offered
- Free tier
- Yes (free)
- Since
- 2013
The full read
Our analysis, in plain words.
cock.li occupies the far end of the no-KYC spectrum: it asks for absolutely no information, works over Tor, and has run for over a decade on donations. If the only thing you measured were signup anonymity, it would score at the top. But signup anonymity is not the same as security, and cock.li is the clearest illustration of the gap.
Its record is a catalogue of the risks that no-KYC does not address. In 2015, after one of its addresses was used to send bomb hoaxes to schools, a host received a confiscation order and a server disk was seized. In 2025, a SQL-injection vulnerability in its Roundcube webmail was exploited to steal more than a million account records - email addresses, timestamps and webmail settings, though message contents, passwords and IPs were reported as not included that time. There is no default end-to-end encryption, so the mail the service holds is readable in principle, whether to a court order or to a worse breach than 2025’s.
So we rate cock.li exactly as it should be used: a disposable, secondary inbox for throwaway signups where you would not care if the address leaked. The 2025 breach is an unreimbursed loss of user data on a large scale, which caps the overall score at 3.0 no matter how anonymous the signup is. Anonymity at the front door means little when the building has been broken into twice.
The score, broken down
How the 3.0 is built.
Privacy
weight 50%What identity, data and metadata the service can demand or collect.
78 × 50% = 3.9 of 10
Trust
weight 30%Whether it can technically deliver what it claims — code, audits, age.
28 × 30% = 0.8 of 10
Reliability
weight 20%Whether the no-KYC claim holds under real-world pressure.
20 × 20% = 0.4 of 10
Weighted score was 5.1 — a reliability rule capped it to 3.0. See the rubric →
Every point, sourced
What earned the score.
Privacy
The fine print, read for you
The clause they bury.
“A SQL-injection vulnerability in cock.li’s Roundcube webmail was exploited in 2025 to steal more than one million user records; the service has no default end-to-end encryption.”
What it meansThis is why maximally no-KYC does not mean safe. Because there is no default encryption, the mail cock.li holds is readable in principle - to a court order, or to a bad-enough breach. A no-questions-asked signup stops the provider from knowing who you are, but it does not secure your data: a single 2025 web vulnerability exposed over a million account records (email addresses, timestamps and settings; message contents, passwords and IPs were not in that dump), and a server disk was seized in 2015. Anonymity at signup and security of your data are different things.
Read the source →None whatsoever - cock.li asks for no information at all and is reachable over Tor, making it the most no-KYC option we audit (KYC level 0). But the score is not about signup: with no default encryption, a 2015 disk seizure and a 2025 breach of 1M+ records, the mail itself is not safe. No-KYC here buys anonymity at signup, not security of your data.
Policy review — point by point
-
2025 breach of 1M+ records
A Roundcube SQL-injection flaw was exploited to steal more than a million user records. ↗
-
No default encryption + a seizure
No default end-to-end encryption; a server disk was seized in 2015 after a bomb-hoax investigation. ↗
-
Maximally no-KYC
Requires no information at all and is reachable over Tor - the most anonymous signup we audit. ↗
cock.li is a sole-operator project whose hosting has moved across jurisdictions, in part after the 2015 seizure. The operator states data is disclosed only under binding legal orders in the current jurisdiction. But the decisive facts are technical, not legal: no default encryption plus a 2025 breach mean the data is not safe regardless of jurisdiction. Sources are the operator’s site and breach/seizure reporting.
We keep watching
Incident & policy timeline.
- 2015
Server disk seized after a bomb-hoax investigation
After a cock.li address was used to send bomb hoaxes to schools, the host received a confiscation order and one disk of a RAID1 array was seized; the operator had also received subpoenas for user information beforehand.
source ↗ - 2025
SQL-injection breach exposes 1M+ records
A SQL-injection vulnerability in cock.li’s Roundcube webmail was exploited to steal more than one million user records - email addresses, login timestamps, language and webmail settings, and some contact data. Passwords, message contents and IP addresses were reported as not included in the dump.
source ↗
The verdict
Where it stands.
Strengths
- Maximally no-KYC - no information at all, Tor-reachable
- Free and long-running
Trade-offs
- 2025 SQL-injection breach exposed 1M+ user records
- No default end-to-end encryption - server can read your mail
- 2015 server disk seizure
- Sole-operator project; shifting hosting jurisdiction
Across the internet
What reviewers report.
Consistently praised
- Unbeatable signup anonymity
- Free, long-running, Tor-friendly
Recurring complaints
- 2025 breach of over a million records
- No encryption; prior server seizure
cock.li is known as the go-to throwaway/anonymous inbox, but the 2025 breach hardened the consensus that it is unsuitable for anything sensitive. Security researchers and press treat it as a cautionary example of no-KYC without security. Synthesized from breach reporting and community discussion.
Keep exploring
Related lists & categories.
Ask the bureau
cock.li, common questions.
Is cock.li no-KYC?
Completely - it asks for no information at all and works over Tor, which makes it the most no-KYC provider we audit (KYC level 0). But that is the only thing it does well; the mail itself is not secure.
Is cock.li safe?
No, not for anything sensitive. It has no default end-to-end encryption, had a server disk seized in 2015, and suffered a 2025 SQL-injection breach that exposed more than a million user records. Use it as a disposable, throwaway inbox for sign-ups you do not care about - never for private or important mail.
Why is it scored so low if it is the most no-KYC?
Because no-KYC is only one axis. Our score also weighs whether your data is actually safe, and cock.li fails that badly - a breach that exposes a million records is a serious, unreimbursed loss of user data, which caps the overall score regardless of how anonymous the signup is.
Your exact case not covered? The live Ask the bureau answers it and turns it into a public FAQ.