Connect the site mirror

Once a main domain is verified (see Verify your main domain) and a burner has DNS set up (see Burner DNS setup), connect the two in Masking to start serving your site through the burner.

1
Connect a burner. On the Masking page, open the Connect a burner tab, select your verified main domain and pick a burner domain from your pool. The link defaults to a www.yourburner.com label. You may change the single DNS label, but tracking-like labels are rejected, and the bare root is intentionally not configured. Proxamail creates a secure custom hostname and serves your site through it, so your real domain never appears in the response. Paths and query strings are preserved. Existing mirrors live under the Your connections tab.
2
Keep must-work pages on your real site (optional). Some pages need your stable domain — payment, sign-up, login, OAuth. In the Send to real site field, list those paths exactly as they appear on your site (for example /checkout, /login); a visitor who opens one leaves the burner and lands on your real site. You can also add an Extra hosts to hide entry for something like a CDN subdomain — your apex domain and its subdomains are covered automatically.
3
Connect more burners (recommended). Add another burner per site with + Add burner (pick a different root domain; one root can hold one burner). Every ready burner can be used at the same time. If one gets blacklisted, only that burner is retired and the others remain available. Each site card shows how many burners are ready. Your sending automation can request a ready hostname from /api/masking/current — see API reference.
Your first email should carry no tracked link. The site mirror keeps your main domain out of what filters and blacklists scan — not out of view for a person who visits. A human who clicks a burner link still reaches your real site through the mirror.

"Needs a ready burner"

Every ready burner connected to a main domain can be used at the same time. When one is blacklisted, Proxamail retires only that burner and leaves the others available. This message means none of the connected burners is currently ready — retry setup or add another burner from the site card on the Masking page.

A burner was retired — do I need to update my links?

Only links that use the retired hostname need attention; links on your other ready burners keep working. Update the affected mailbox or campaign, or have your automation request a ready hostname from /api/masking/current instead of hard-coding one burner. Emails already delivered cannot have their links rewritten.

Next: Blacklist monitoring & rotation →