Skip to content

Security Best Practices — Protect Your Account & Aliases

CloakMetric is built with privacy and security at its core. Follow these best practices to keep your account and aliases safe.

Your password should be at least 8 characters. Use a mix of uppercase, lowercase, numbers, and symbols. Consider using a password manager.

Regularly review your active sessions in Settings > Account. If you see a session you don’t recognize, revoke it immediately and change your password.

Always keep your account email verified. This ensures you can recover your account and receive important security notifications.

Create a unique alias for each service you sign up for. If one service leaks your email, you’ll know exactly which one — and you can disable just that alias without affecting others.

When you’re done with an alias, deactivate it instead of deleting it. This way, if legitimate emails arrive later, you can re-enable it. Deleted aliases bounce all emails permanently.

Check the Analytics page regularly. A declining health score may indicate your alias is being used for spam or is on a blocklist.

When using a custom domain, ensure all five DNS records (Verification, MX, SPF, DKIM, DMARC) are properly configured. Missing records weaken your email authentication and increase the chance of spoofing.

A DMARC policy of p=quarantine or p=reject tells receiving servers to handle unauthorized emails strictly. This protects your domain from being impersonated.

Only grant the minimum permissions an API key needs. Use Read-only keys for monitoring and Standard keys for automation. Reserve Full Access for admin tools.

Set expiration dates on API keys and replace them before they expire. Never use keys without expiration for production integrations.

Store API keys in environment variables or secret management tools. Never commit them to version control.

Use the role system to give team members only the access they need. Viewers for stakeholders, Members for contributors, Admins for managers.

Regularly audit your team and remove members who no longer need access. Revoke access immediately when someone leaves your organization.