Private account migration tracker

Change your email across every account—without handing over passwords.

Import a credential-free account list, work from highest risk, follow source-linked instructions, and verify every new login before retiring your old address.

No account. No backend. Your encrypted workspace stays in this browser. Read the security model ↗

100source-linked provider playbooks ↗5,000recognized domains for safe imports ↗27automated tests in the public build ↗

Why forwarding is not enough

Mail migration moves messages. Account migration removes the old dependency.

01

Inventory

Find services where your old address is still a login, recovery path, or contact route.

02

Prioritize

Move identity, financial, government, health, and security accounts before subscriptions.

03

Verify

Test a fresh login and recovery path before removing the address you still control.

One queue for the entire move

Know what is safe, blocked, and still tied to the old inbox.

Mailshift separates changing an address from proving the new login and recovery path work. Nothing disappears from view because a confirmation email is delayed or support needs to intervene.

Open the working app →
Migration progress1 of 3 verified
33%

Faithful workflow preview · example data only

A migration you can audit

Local data. Human-controlled changes. Explicit proof.

  1. 1

    Create an encrypted workspace

    Choose a vault passphrase. Mailshift stores the encrypted workspace on this device; there is no recovery service.

  2. 2

    Import domains only

    Use a credential-free CSV. Password, username, email, OTP, secret, and recovery-code columns are rejected.

  3. 3

    Work from highest risk

    Identity and recovery roots rise above shopping, social, and entertainment accounts.

  4. 4

    Prove the handoff

    Track address change, recovery update, verification, fresh login, and old-address cleanup separately.

Designed to know less

A sensitive account map should not become someone else's database.

No mailbox connection

Mailshift does not scan email, automate logins, or ask for account passwords.

Encrypted local vault

Workspace data is protected with AES-256-GCM and stored in browser local storage.

Inspect or self-host

The complete MIT-licensed source, tests, playbooks, and threat model are public.

Migration field guide · 5 minute read

Moving email providers is easy. Moving your identity is the hard part.

Turn hundreds of inconsistent account changes into one risk-first migration queue—without automated login or mailbox scanning.

Read full guide
“Move identities, not only mail.”

Mailshift design principle

Before you import

Clear boundaries for a safer migration.

Why not use a spreadsheet?

A spreadsheet can list accounts. Mailshift adds risk ordering, provider guidance, separate verification gates, encrypted backup, and explicit handling for waiting or blocked changes.

Does Mailshift change my accounts automatically?

No. It organizes the work, links to provider settings, and records proof. You remain in control of every account change.

Does the hosted app send my account list anywhere?

No. There is no backend or analytics. The workspace is encrypted and stored in this browser. For maximum assurance, inspect the source and run it locally.

What if I forget my vault passphrase?

Mailshift cannot recover it. Resetting the vault deletes the local workspace. Keep the passphrase and an encrypted backup somewhere safe.

Free · Open source · MIT licensed

Retire the old address, not the accounts behind it.

Start in the browser, or inspect every line and run Mailshift locally.