EuroSciCon Guides

EuroSciCon / Guides / Compare providers / Email without a phone number

Compare · Privacy

Email without a phone number

Four people ask this question for four different reasons, and they need four different answers. Start with what you are actually protecting against.

By the EuroSciCon Guides team✓ Checked against the live interfaceUpdated

Start with the threat, not the provider

“Which provider does not ask for a phone number” has four different correct answers, because people asking it are protecting against four different things. Identify yours first and the provider follows.

  • You have no number. A practical problem. Any never-asks provider solves it.
  • You do not want it in a marketing database. Solvable at most providers without changing provider.
  • You want the account unlinkable to you. The phone number is not your weak point, and choosing on that basis will mislead you.
  • You are protecting against SIM-swap. The opposite problem, and the fix is the reverse of what you would expect.
The four answers
  • No number available → Tuta or GMX. Fastest, no conditions.
  • Marketing concern → any provider. Add it, then delete it.
  • Anonymity → Proton or Tuta, and the number is the least of it.
  • SIM-swap risk → any provider, but remove SMS and use an authenticator app.

The four threat models

These look like one question and are four. Getting the wrong one produces advice that is technically correct and useless.

What you are protecting againstIs the phone number the issue?What actually solves it
You genuinely have no numberYes, entirelyA provider that never asks. Nothing else needed
Marketing and data brokersPartlyAny provider. Add the number, then remove it after setup
Being identified as youNoProvider choice plus network and device hygiene. The number is a minor input
SIM-swap account theftInvertedAny provider, but disable SMS recovery and use an authenticator app

The third row is where most advice goes wrong. Providers correlate accounts by IP address, device fingerprint, browser profile, recovery address and behaviour. A withheld phone number changes very little on its own, so choosing a provider purely for that reason buys less privacy than people expect while costing real recovery capability.

The fourth row is the one almost nobody raises, and it inverts the usual framing: a phone number on the account is itself an attack surface. If someone persuades your carrier to move your number to their SIM, every SMS code goes to them. For that threat, having no number registered is safer than having one.

What each provider actually requires

Accurate as of September 2026. Requirements change without announcement.

ProviderAsks for a number?Substitute demandedFriction
TutaNeverNone on the free tierUp to 48h manual approval
GMX / mail.comNeverOptional alternate emailNone. Heavily ad-supported
Proton MailNeverAn existing email, or a puzzleMethod chosen for you, varies by region
Outlook.comUsually notAlternate email addressLow. Microsoft is retiring SMS anyway
GmailConditionallyVaries per sign-upUnpredictable. No setting to disable
Yahoo, iCloud, ZohoYesNo documented route around it

Notice that the friction column, not the first column, is what usually decides. Tuta never asks but can hold a free account for two days. GMX never asks and lets you in immediately, at the cost of a busier interface. Both are correct answers to different questions.

If Gmail specifically is the requirement, its conditional behaviour is covered in Gmail without a phone number.

The recovery arithmetic

Whatever you decide, one calculation has to come out right, and it is the one people skip.

Every provider recovers an account by reaching you somewhere that is not the account. Take the number away and you must put something in its place, or the account has exactly one key and no spare.

Methods registeredWhat happens when you forget the password
NothingPermanent loss. Support cannot verify you, because verifying you is what the missing method was for
One methodFine until that method fails, then permanent loss
Two independent methodsResilient. Losing either still leaves a route in

Independent is the operative word. Two methods that fail together are one method. A recovery address at the same provider, backup codes screenshotted into the mailbox they unlock, and an authenticator app on the phone you just lost all look like redundancy and provide none.

Sign-up is not the only time you get asked

Choosing a provider on whether it asks for a number at sign-up answers half the question. The half that actually strands people is whether it can ask later, once the mailbox holds several years of mail and is the recovery address for everything else.

When it can happenWhat triggers itWhat it costs you
A sign-in that looks unusualNew country, new device, a long gapAccess, until you satisfy a check you may have nothing registered for
A password resetYou initiating itThe reset simply cannot complete
An abuse reviewSending volume, or a shared address rangeSending suspended first, then the account

The providers that never ask at sign-up mostly do not ask later either, because they are not using the number as an abuse control in the first place. The ones that make it optional at sign-up are the ones to watch: an optional field can become a required one at the exact moment you need access most, and consenting to it later is not possible if you are already locked out.

Which makes the test a different one. Do not ask "does this provider require a phone number." Ask "if I am locked out of this account in three years with no phone on file, what is the route back, and does it exist." If the honest answer is a support form and a hope, that is the account to keep secondary.

Setting it up so it survives

  1. Pick the provider from the threat table, not from the storage figures.
  2. Register an alternate address at a different company. This is the single highest-value step and it costs nothing.
  3. Add an authenticator app, and put its backup codes somewhere physical or in a password manager you can reach from another device.
  4. Add a passkey if the provider supports it and you have a device you will keep.
  5. Write down which methods you registered. The commonest failure is not losing a method, it is forgetting which ones exist.

What the failure looks like when none of this was done is set out in why recovery forms reject correct answers.

Sources

Frequently asked questions

Which email provider never asks for a phone number?
Tuta, GMX, mail.com and Proton Mail never ask on their free tiers. Outlook.com usually accepts an alternate email address instead and Microsoft is retiring SMS verification entirely. Which is right for you depends on friction: Tuta can hold a free account for up to 48 hours for manual approval, while GMX lets you in immediately.
Does avoiding a phone number make my account anonymous?
Not meaningfully. Providers correlate accounts by IP address, device fingerprint, browser profile, recovery address and behaviour. A withheld number changes very little on its own, so choosing a provider purely on that basis buys less privacy than expected while costing real recovery capability.
Can I add a phone number and then remove it?
Yes, at most providers, and for the marketing concern specifically that is often the simplest route. Complete sign-up with the number, register an alternate email and an authenticator app, then delete the number from the account.
Is having a phone number on my account actually a risk?
It can be. If someone persuades your carrier to transfer your number to their SIM, every SMS code goes to them. For that specific threat, having no number registered is safer than having one, and an authenticator app is safer than either.
What should I register instead of a phone number?
Two independent methods. An alternate email address at a different company, and an authenticator app with its backup codes stored outside the account. Independence is the point: two methods that fail together count as one.
What happens if I register nothing at all?
The account works perfectly until the day it does not. Forget the password or trigger an unusual sign-in check and there is no route back, because support cannot verify you when verification is precisely the thing that is missing.

Why you can trust this guide

  • Independently written. Not affiliated with, endorsed by, or sponsored by any email provider.
  • No credentials collected. Always sign in on any email provider's own pages, never through a third party.
  • Checked against the live interface before publishing, and re-checked when it changes.
  • Last reviewed: .