Inventory
Find services where your old address is still a login, recovery path, or contact route.
Private account migration tracker
Import a credential-free account list, work from highest risk, follow source-linked instructions, and verify every new login before retiring your old address.
No account. No backend. Your encrypted workspace stays in this browser. Read the security model ↗
Why forwarding is not enough
Find services where your old address is still a login, recovery path, or contact route.
Move identity, financial, government, health, and security accounts before subscriptions.
Test a fresh login and recovery path before removing the address you still control.
One queue for the entire move
Mailshift separates changing an address from proving the new login and recovery path work. Nothing disappears from view because a confirmation email is delayed or support needs to intervene.
Open the working app →Faithful workflow preview · example data only
A migration you can audit
Choose a vault passphrase. Mailshift stores the encrypted workspace on this device; there is no recovery service.
Use a credential-free CSV. Password, username, email, OTP, secret, and recovery-code columns are rejected.
Identity and recovery roots rise above shopping, social, and entertainment accounts.
Track address change, recovery update, verification, fresh login, and old-address cleanup separately.
Designed to know less
Mailshift does not scan email, automate logins, or ask for account passwords.
Workspace data is protected with AES-256-GCM and stored in browser local storage.
The complete MIT-licensed source, tests, playbooks, and threat model are public.
Migration field guide · 5 minute read
Turn hundreds of inconsistent account changes into one risk-first migration queue—without automated login or mailbox scanning.
Read full guide“Move identities, not only mail.”
Mailshift design principle
Before you import
A spreadsheet can list accounts. Mailshift adds risk ordering, provider guidance, separate verification gates, encrypted backup, and explicit handling for waiting or blocked changes.
No. It organizes the work, links to provider settings, and records proof. You remain in control of every account change.
No. There is no backend or analytics. The workspace is encrypted and stored in this browser. For maximum assurance, inspect the source and run it locally.
Mailshift cannot recover it. Resetting the vault deletes the local workspace. Keep the passphrase and an encrypted backup somewhere safe.
Free · Open source · MIT licensed
Start in the browser, or inspect every line and run Mailshift locally.