# Can Discourse function without emails entirely?

**URL:** https://meta.discourse.org/t/can-discourse-function-without-emails-entirely/368701
**Category:** Support
**Created:** [June 3, 2025, 2:26pm UTC](https://meta.discourse.org/t/can-discourse-function-without-emails-entirely/368701 "2025-06-03T14:26:51Z")
**Posts on this page:** 11
**Page:** 1

<div class="post-metadata">

### Author: ![meglio](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/meglio/32/71444_2.png) [@meglio](https://meta.discourse.org/u/meglio)
#### Post date: [June 3, 2025, 2:26pm UTC](https://meta.discourse.org/t/can-discourse-function-without-emails-entirely/368701/1 "2025-06-03T14:26:51Z")

</div>

In a closed community with highly sensitive content, everyone wants guaranteed zero emails starting from registration. Is this possible in Discourse?

I guess we can turn emails off entirely system wide, but what about new user registrations? Now that you even support passkeys, could you make a fully functional no-emails Discourse possible?

---

<div class="post-metadata">

### Author: ![Bas](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/bas/32/294929_2.png) [@Bas](https://meta.discourse.org/u/Bas)
#### Post date: [June 3, 2025, 3:16pm UTC](https://meta.discourse.org/t/can-discourse-function-without-emails-entirely/368701/2 "2025-06-03T15:16:55Z")

</div>

> [@meglio](#):
>
> what about new user registrations?

I think you should be able to do this, _if_ you have SSO setup.

Emails are an absolutely requirement to verify email addresses. Otherwise you’ll get hit by spam. But you can bypass this if you delegate verification to your SSO set this:

> [@Oauth2 plugin sso, how to switch off email verification](https://meta.discourse.org/t/oauth2-plugin-sso-how-to-switch-off-email-verification/87542/2):
>
> There is a setting called “oauth2 email verified” that you can check. Here is the description for the setting: Check this if the OAuth2 site has verified the email

---

<div class="post-metadata">

### Author: ![JammyDodger](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/jammydodger/32/254611_2.png) [@JammyDodger](https://meta.discourse.org/u/JammyDodger)
#### Post date: [June 3, 2025, 3:28pm UTC](https://meta.discourse.org/t/can-discourse-function-without-emails-entirely/368701/3 "2025-06-03T15:28:25Z")

</div>

I’m on a site with email disabled, and I think that is only possible because of the SSO handling login and password resets, etc.

Without needing those, I think using onsite notifications and having no email notifications for anything works quite well. 👍

---

<div class="post-metadata">

### Author: ![satonotdead](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/satonotdead/32/447830_2.png) [@satonotdead](https://meta.discourse.org/u/satonotdead)
#### Post date: [June 4, 2025, 2:50am UTC](https://meta.discourse.org/t/can-discourse-function-without-emails-entirely/368701/4 "2025-06-04T02:50:28Z")

</div>

Hey, I’ll be the devil advocate for a while. It’s not my usual interaction around here because I truly respect all of you folks.

But I guess that being the crypto guy (people say _OG_) and after giving a decade learning to self-host my files, nodes, websites and blablah, motivates me to share my thoughs to you.

I have 7 years supporting Discourse and I manage a community that value privacy.

They trust on me ~~_(someone can say I’m not the guy but they know that I’m their guy)_~~ **and** they learn how to keep their own privacy at first.

Discourse is not built with stronger privacy on mind, it’s about mostly public communities.

Primarly tech support regardless the software itself is used for different markets, concepts, nations and so on 🙂

> [Depreceated encrypt PMs](https://meta.discourse.org/t/discourse-encrypt-deprecated/107918) shows the reality: **only 1% on the world takes care about their privacy**.

Meta on Discourse is not different and I bet your own community neither _(remember a lot of guys trusting on a random on internet like me, so we are all the same)_.

Apple, Amazon, Microsoft, Facebook, Google make money killing their users privacy. And almost everyone depends everyday on them.

Are you browsing on Chrome? You have no privacy.

> **It's real**
>
> ## Major Privacy Issues Google Faced with Chrome
> 
> **1. Extensive Data Collection and Profiling**
> 
> - Chrome collects significant amounts of user data, including location, search and browsing history, user identifiers, and product interaction data. This information is linked to individuals and devices, allowing Google to build detailed profiles for ad targeting and personalization[4](https://www.wired.com/story/google-chrome-browser-data/)[2](https://www.techradar.com/computing/browsers/is-google-chrome-violating-your-privacy-scary-new-notification-spooks-users-heres-what-you-can-do).
> - Critics argue that Chrome’s data collection practices are more invasive than those of competitors like Safari and Firefox, and that syncing with a Google account further expands the scope of data aggregation across Google services[4](https://www.wired.com/story/google-chrome-browser-data/)[7](https://www.vox.com/technology/387375/google-chrome-antitrust-privacy-android).
> 
> **2. Third-Party Cookies and Privacy Sandbox Controversy**
> 
> - Google’s long-promised plan to phase out third-party cookies in Chrome was repeatedly delayed and ultimately paused, drawing criticism from privacy advocates and regulators. The failure to eliminate these cookies leaves users exposed to cross-site tracking and surveillance[8](https://www.wired.com/story/google-chrome-third-party-cookies-privacy-rollback/)[5](https://www.forbes.com/sites/zakdoffman/2024/07/25/new-google-chrome-warning-microsoft-windows-10-windows-11-3-billion-users/).
> - Privacy advocates and digital rights groups, such as the Electronic Frontier Foundation, argue that abandoning the plan benefits Google’s business interests while failing to protect user privacy[8](https://www.wired.com/story/google-chrome-third-party-cookies-privacy-rollback/)[5](https://www.forbes.com/sites/zakdoffman/2024/07/25/new-google-chrome-warning-microsoft-windows-10-windows-11-3-billion-users/).
> 
> **3. Browsing History Leaks via :visited Links**
> 
> - For nearly 20 years, Chrome allowed websites to infer a user’s browsing history through the `:visited` CSS selector, which could be exploited for tracking, profiling, and phishing. This longstanding vulnerability was only addressed in Chrome version 136 with a new partitioning system to prevent cross-site history leaks[3](https://www.bleepingcomputer.com/news/security/chrome-136-fixes-20-year-browser-history-privacy-risk/).
> 
> **4. Personalized Ads Based on Browsing History**
> 
> - Chrome introduced features that use recent browsing history to profile users and display personalized ads. This raised concerns about transparency, informed consent, and the potential for manipulation or misuse of sensitive data[2](https://www.techradar.com/computing/browsers/is-google-chrome-violating-your-privacy-scary-new-notification-spooks-users-heres-what-you-can-do).
> - Many users and privacy experts view this as a significant privacy violation, as Chrome accesses and processes private browsing logs for advertising without clear user control[2](https://www.techradar.com/computing/browsers/is-google-chrome-violating-your-privacy-scary-new-notification-spooks-users-heres-what-you-can-do).
> 
> **5. Lawsuits and Regulatory Scrutiny**
> 
> - Google has faced lawsuits alleging unlawful data harvesting from Chrome users, including accusations that private browsing data was collected and retained without proper consent. Settlements have required Google to delete private browsing histories and review its data practices[7](https://www.vox.com/technology/387375/google-chrome-antitrust-privacy-android).
> 
> **6. Integration with Google’s Wider Ecosystem**
> 
> - Data collected via Chrome can be combined with information from other Google products (e.g., Gmail, Maps, Android), creating comprehensive user profiles that raise further privacy concerns[4](https://www.wired.com/story/google-chrome-browser-data/).
> 
> ## Summary Table
> 
> | Issue | Description | Source |
> | --- | --- | --- |
> | Data Collection & Profiling | Chrome collects and links vast amounts of personal data for profiling and ads | [4](https://www.wired.com/story/google-chrome-browser-data/)[2](https://www.techradar.com/computing/browsers/is-google-chrome-violating-your-privacy-scary-new-notification-spooks-users-heres-what-you-can-do)[7](https://www.vox.com/technology/387375/google-chrome-antitrust-privacy-android) |
> | Third-Party Cookie Phase-Out Failure | Google’s delays and reversal on cookie removal leaves users exposed to tracking | [8](https://www.wired.com/story/google-chrome-third-party-cookies-privacy-rollback/)[5](https://www.forbes.com/sites/zakdoffman/2024/07/25/new-google-chrome-warning-microsoft-windows-10-windows-11-3-billion-users/) |
> | Browsing History Leak via :visited Links | Exploitable CSS feature leaked browsing history for decades; only recently fixed | [3](https://www.bleepingcomputer.com/news/security/chrome-136-fixes-20-year-browser-history-privacy-risk/) |
> | Personalized Ads from Browsing History | Chrome uses recent browsing activity for ad targeting, raising transparency and consent issues | [2](https://www.techradar.com/computing/browsers/is-google-chrome-violating-your-privacy-scary-new-notification-spooks-users-heres-what-you-can-do) |
> | Lawsuits & Regulatory Action | Legal challenges over alleged unlawful data collection, including in private browsing modes | [7](https://www.vox.com/technology/387375/google-chrome-antitrust-privacy-android) |
> | Google Ecosystem Data Integration | Chrome data combined with other Google services for extensive profiling | [4](https://www.wired.com/story/google-chrome-browser-data/) |
> 
> These issues have contributed to ongoing debates about Chrome’s suitability for privacy-conscious users and have prompted some to recommend alternative browsers with stronger privacy protections[4](https://www.wired.com/story/google-chrome-browser-data/)[7](https://www.vox.com/technology/387375/google-chrome-antitrust-privacy-android).
> 
> 1. [Reddit - Please wait for verification](https://www.reddit.com/r/browsers/comments/146srua/is_chromes_lack_of_privacy_a_big_issue/)
> 2. [Is Google Chrome violating your privacy? Scary new notification spooks users - here’s what you can do | TechRadar](https://www.techradar.com/computing/browsers/is-google-chrome-violating-your-privacy-scary-new-notification-spooks-users-heres-what-you-can-do)
> 3. [Chrome 136 fixes 20-year browser history privacy risk](https://www.bleepingcomputer.com/news/security/chrome-136-fixes-20-year-browser-history-privacy-risk/)
> 4. [It’s time to ditch Chrome | WIRED](https://www.wired.com/story/google-chrome-browser-data/)
> 5. [Google Confirms Bad News For 3 Billion Chrome Users](https://www.forbes.com/sites/zakdoffman/2024/07/25/new-google-chrome-warning-microsoft-windows-10-windows-11-3-billion-users/)
> 6. [How Chrome Safe Browsing keeps your browsing data private - Computer - Google Chrome Help](https://support.google.com/chrome/answer/13844634)
> 7. [Google Chrome and antitrust: Will a new owner solve the browser’s privacy problems? | Vox](https://www.vox.com/technology/387375/google-chrome-antitrust-privacy-android)
> 8. [What Google's U-Turn on Third-Party Cookies Means for Chrome Privacy | WIRED](https://www.wired.com/story/google-chrome-third-party-cookies-privacy-rollback/)
> 9. [Understand privacy in Chrome - Google Chrome Help](https://support.google.com/chrome/answer/14225066)
> 10. [Privacy concerns with Google - Wikipedia](https://en.wikipedia.org/wiki/Privacy_concerns_with_Google)
> 11. [The Dark Side of Google Chrome: How Your Browser Betrays You](https://www.gen.uk/index.php?page=Home&option=Blog&article=20241003)

So, back in topic, going on SSO route for _real_ privacy means to self-host the service on local hardware or encrypted HD/SO.

I think [Authentik](https://meta.discourse.org/t/discourse-oauth2-basic/33879/302) -tested with Discourse- is our best bet for those who want open-source, community, respect and common sense.

> _I like to suggest e-mail alias services like [Duck](https://duck.com) or [Addy](https://addy.io) (better to self-host, from my perspective)._
> 
> _**And move to [LibreWolf](https://librewolf.net/) ASAP**._

Best wishes for your community and project. It’s good to see discussions about the major vortex on Internet.

---

<div class="post-metadata">

### Author: ![meglio](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/meglio/32/71444_2.png) [@meglio](https://meta.discourse.org/u/meglio)
#### Post date: [June 4, 2025, 2:57am UTC](https://meta.discourse.org/t/can-discourse-function-without-emails-entirely/368701/5 "2025-06-04T02:57:54Z")

</div>

> [@satonotdead](#):
>
> Discourse is not built with stronger privacy on mind, it’s about mostly public communities.

I was very disappointed when Discourse stopped supporting encrypted messaging. We were using it like a lot.

> [@satonotdead](#):
>
> I think [Authentik](https://meta.discourse.org/t/discourse-oauth2-basic/33879/302) -tested with Discourse- is our best bet for those who want open-source, community, respect and common sense.

Thanks for the hint.

> [@Bas](#):
>
> Emails are an absolutely requirement to verify email addresses. Otherwise you’ll get hit by spam.

When considering setting up an email-less Discourse instance, there is no way to get hit by spam.

When I say “email-less”, I really mean that in the absolute meaning. It’s not that difficult, most of it already exists in Discourse: you can just turn off sending out any emails completely. The only two missing bits are:

1. Initial setup for the first admin account, which weirdly requires an email.
2. New user signup.

I advocate for a single global switch such as “Email-less Discourse”, which will disable email and make it unnecessary throughout the application.

If the user installs the Discourse app, he’ll get all the updates through it, no need for an email.

If ther user uses a keypass, no need for an email either.

If no digest emails are sent, no need to verify emails.

Frantly, no need to have any email associated with an account at all.

I may sound a bit overwhelming, but in the same time, it is a) not that difficult to complete the remaining/missing 5% that hard-require email, and b) in my practice, it’s a legit case to have a email-less community, and it’s not very unique of an idea - in multiple web shops you can already “buy anonymously”, i.e. you can interact with the platform and even place an order without ever revealing your email. 4chat is yet another example that requires no user email but is huge.

I guess all that’s missing is the will of the Discourse team to embrace the idea and complete a few tweaks to make Discourse truly email-less capable. It’s almost there already.

---

<div class="post-metadata">

### Author: ![Andrew\_Rowe](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/andrew_rowe/32/445877_2.png) [@Andrew\_Rowe](https://meta.discourse.org/u/Andrew_Rowe)
#### Post date: [June 4, 2025, 10:48am UTC](https://meta.discourse.org/t/can-discourse-function-without-emails-entirely/368701/6 "2025-06-04T10:48:51Z")

</div>

> [@meglio](#):
>
> Initial setup for the first admin account, which weirdly requires an email.

you can skip this as well with a command line during setup, I can’t remember off top of head

> [@Create an admin account from the console](https://meta.discourse.org/t/create-an-admin-account-from-the-console/17274):
>
> bookmark This guide provides instructions for creating an admin account or granting admin privileges using the console in a self-hosted Discourse installation. person_raising_hand Required user level: System Administrator warning Console access required So you want to create/grant Admin privileges or reset user password from console? Great, let’s get started! This guide will cover the following: Accessing the console Creating a new account with admin privileges Resetting an existin…

---

<div class="post-metadata">

### Author: ![Heliosurge](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/heliosurge/32/571810_2.png) [@Heliosurge](https://meta.discourse.org/u/Heliosurge)
#### Post date: [June 4, 2025, 7:02pm UTC](https://meta.discourse.org/t/can-discourse-function-without-emails-entirely/368701/7 "2025-06-04T19:02:21Z")

</div>

You email initially for setup However. We had a test site running with no email server after. Invite link may work for signup. We didn’t test invite link but manually activated accounts.

This pluginay help. But would verify in this post that it is still current. Looks like fork was released in March

> [@Disable Email Verification for Discourse Plugin](https://meta.discourse.org/t/disable-email-verification-for-discourse-plugin/280874/38):
>
> [GitHub - INSIinc/discourse\_skip\_email\_verification · GitHub](https://github.com/INSIinc/discourse_skip_email_verification) 我重写了这个插件，最新版本可用。I rewrote this plugin, the latest version is available(want star)

---

<div class="post-metadata">

### Author: ![meglio](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/meglio/32/71444_2.png) [@meglio](https://meta.discourse.org/u/meglio)
#### Post date: [June 6, 2025, 12:38am UTC](https://meta.discourse.org/t/can-discourse-function-without-emails-entirely/368701/8 "2025-06-06T00:38:26Z")

</div>

Here is another idea. For communities focused on privacy/anonimity, allow to use SimpleX instead of emails. So that a user can sign up by receiving a confirmation link via SimpleX from Discourse, and receive any transaction “emails” to their SimpleX chat.

---

<div class="post-metadata">

### Author: ![satonotdead](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/satonotdead/32/447830_2.png) [@satonotdead](https://meta.discourse.org/u/satonotdead)
#### Post date: [June 6, 2025, 3:13am UTC](https://meta.discourse.org/t/can-discourse-function-without-emails-entirely/368701/9 "2025-06-06T03:13:13Z")

</div>

So you need to host your own SMP server and take care about [their privacy issues](https://discuss.privacyguides.net/t/simplex-vs-cwtch-who-is-right/19256/112) and [IP leaks](https://github.com/simplex-chat/simplex-chat/issues/5122).

You probably want to [read this](https://news.ycombinator.com/item?id=41355781) and [this](https://old.reddit.com/r/privacy/comments/13u8e24/simplex_chat_private_and_secure_messenger_without/).

**If you want real privacy you need to keep away from clearnet.**

> [@satonotdead](#):
>
> I’ll be the devil advocate for a while

_The greatest enemy of knowledge is not ignorance, it’s illusion of knowledge._

---

<div class="post-metadata">

### Author: ![meglio](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/meglio/32/71444_2.png) [@meglio](https://meta.discourse.org/u/meglio)
#### Post date: [June 6, 2025, 4:01am UTC](https://meta.discourse.org/t/can-discourse-function-without-emails-entirely/368701/10 "2025-06-06T04:01:05Z")

</div>

Thanks for the links, I’ll go through them, although no need to sound like a smart alec.

---

<div class="post-metadata">

### Author: ![tobiaseigen](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/tobiaseigen/32/539204_2.png) [@tobiaseigen](https://meta.discourse.org/u/tobiaseigen)
#### Post date: [September 17, 2025, 8:35pm UTC](https://meta.discourse.org/t/can-discourse-function-without-emails-entirely/368701/11 "2025-09-17T20:35:16Z")

</div>


