EuroSciCon / Guides / Compare providers / Email without a phone number
Compare · PrivacyEmail without a phone number
Four people ask this question for four different reasons, and they need four different answers. Start with what you are actually protecting against.
“Which provider does not ask for a phone number” has four different correct answers, because people asking it are protecting against four different things. Identify yours first and the provider follows.
- You have no number. A practical problem. Any never-asks provider solves it.
- You do not want it in a marketing database. Solvable at most providers without changing provider.
- You want the account unlinkable to you. The phone number is not your weak point, and choosing on that basis will mislead you.
- You are protecting against SIM-swap. The opposite problem, and the fix is the reverse of what you would expect.
- No number available → Tuta or GMX. Fastest, no conditions.
- Marketing concern → any provider. Add it, then delete it.
- Anonymity → Proton or Tuta, and the number is the least of it.
- SIM-swap risk → any provider, but remove SMS and use an authenticator app.
The four threat models
These look like one question and are four. Getting the wrong one produces advice that is technically correct and useless.
| What you are protecting against | Is the phone number the issue? | What actually solves it |
|---|---|---|
| You genuinely have no number | Yes, entirely | A provider that never asks. Nothing else needed |
| Marketing and data brokers | Partly | Any provider. Add the number, then remove it after setup |
| Being identified as you | No | Provider choice plus network and device hygiene. The number is a minor input |
| SIM-swap account theft | Inverted | Any provider, but disable SMS recovery and use an authenticator app |
The third row is where most advice goes wrong. Providers correlate accounts by IP address, device fingerprint, browser profile, recovery address and behaviour. A withheld phone number changes very little on its own, so choosing a provider purely for that reason buys less privacy than people expect while costing real recovery capability.
The fourth row is the one almost nobody raises, and it inverts the usual framing: a phone number on the account is itself an attack surface. If someone persuades your carrier to move your number to their SIM, every SMS code goes to them. For that threat, having no number registered is safer than having one.
What each provider actually requires
Accurate as of September 2026. Requirements change without announcement.
| Provider | Asks for a number? | Substitute demanded | Friction |
|---|---|---|---|
| Tuta | Never | None on the free tier | Up to 48h manual approval |
| GMX / mail.com | Never | Optional alternate email | None. Heavily ad-supported |
| Proton Mail | Never | An existing email, or a puzzle | Method chosen for you, varies by region |
| Outlook.com | Usually not | Alternate email address | Low. Microsoft is retiring SMS anyway |
| Gmail | Conditionally | Varies per sign-up | Unpredictable. No setting to disable |
| Yahoo, iCloud, Zoho | Yes | — | No documented route around it |
Notice that the friction column, not the first column, is what usually decides. Tuta never asks but can hold a free account for two days. GMX never asks and lets you in immediately, at the cost of a busier interface. Both are correct answers to different questions.
If Gmail specifically is the requirement, its conditional behaviour is covered in Gmail without a phone number.
The recovery arithmetic
Whatever you decide, one calculation has to come out right, and it is the one people skip.
Every provider recovers an account by reaching you somewhere that is not the account. Take the number away and you must put something in its place, or the account has exactly one key and no spare.
| Methods registered | What happens when you forget the password |
|---|---|
| Nothing | Permanent loss. Support cannot verify you, because verifying you is what the missing method was for |
| One method | Fine until that method fails, then permanent loss |
| Two independent methods | Resilient. Losing either still leaves a route in |
Independent is the operative word. Two methods that fail together are one method. A recovery address at the same provider, backup codes screenshotted into the mailbox they unlock, and an authenticator app on the phone you just lost all look like redundancy and provide none.
Sign-up is not the only time you get asked
Choosing a provider on whether it asks for a number at sign-up answers half the question. The half that actually strands people is whether it can ask later, once the mailbox holds several years of mail and is the recovery address for everything else.
| When it can happen | What triggers it | What it costs you |
|---|---|---|
| A sign-in that looks unusual | New country, new device, a long gap | Access, until you satisfy a check you may have nothing registered for |
| A password reset | You initiating it | The reset simply cannot complete |
| An abuse review | Sending volume, or a shared address range | Sending suspended first, then the account |
The providers that never ask at sign-up mostly do not ask later either, because they are not using the number as an abuse control in the first place. The ones that make it optional at sign-up are the ones to watch: an optional field can become a required one at the exact moment you need access most, and consenting to it later is not possible if you are already locked out.
Which makes the test a different one. Do not ask "does this provider require a phone number." Ask "if I am locked out of this account in three years with no phone on file, what is the route back, and does it exist." If the honest answer is a support form and a hope, that is the account to keep secondary.
Setting it up so it survives
- Pick the provider from the threat table, not from the storage figures.
- Register an alternate address at a different company. This is the single highest-value step and it costs nothing.
- Add an authenticator app, and put its backup codes somewhere physical or in a password manager you can reach from another device.
- Add a passkey if the provider supports it and you have a device you will keep.
- Write down which methods you registered. The commonest failure is not losing a method, it is forgetting which ones exist.
What the failure looks like when none of this was done is set out in why recovery forms reject correct answers.
Sources
- Google: Verify your accountWhy verification is requested and when the prompt appears.
- Microsoft: How to create a new Microsoft accountThe alternate-email route for Outlook.com sign-ups.
- Tuta: Support and FAQFree-tier sign-up without a phone number, and the approval delay.
Frequently asked questions
Which email provider never asks for a phone number?
Does avoiding a phone number make my account anonymous?
Can I add a phone number and then remove it?
Is having a phone number on my account actually a risk?
What should I register instead of a phone number?
What happens if I register nothing at all?
Why you can trust this guide
- Independently written. Not affiliated with, endorsed by, or sponsored by any email provider.
- No credentials collected. Always sign in on any email provider's own pages, never through a third party.
- Checked against the live interface before publishing, and re-checked when it changes.
- Last reviewed: .