All systems operational 21 locations · null network Pay with crypto · ∅ KYC
Home / Blog / VPS opsec: email, DNS and PTR leaks
Blog

VPS opsec: email, DNS and PTR leaks

NulNet mail and Matrix abstract: envelope and chat glass

A no-ID checkout is one layer of many: personal inboxes, registered domains and misaligned PTR still correlate workloads. Hygiene that actually helps.

Short answer

A no-ID checkout covers the account object only: personal inboxes, registered domains and misaligned PTR still correlate workloads afterward. The hygiene that closes those gaps is operator work, and this page lists it.

What checkout does not erase

Anonymity at signup covers the account object — after that, correlation is your department. A personal inbox on the account links the VPS to your everyday identity; a domain registered under your name links every workload it hosts; DNS records publish history the moment they go live, and scraping archives keep copies. Settling in coins removes the card processor from the story — it does not retroactively edit DNS history or unsend an email address.

VPS from $3* (fund $50+), storage 1–5 TB NVMe from $24/mo annual-eff, dedicated with IPMI from $30.80/mo. Crypto invoice, no KYC.

Launch now

PTR and mail

If the box sends mail, alignment is the hygiene that matters: A/AAAA, PTR and HELO should tell the same story before the first message leaves. Editable PTR ships included, port 25 is open, and reputation warms on your sending habits alone — no host-side warmup service exists, so a cold IP that spams stays cold.

Panel tickets only

Support runs through the client panel: include the invoice code or IP, never a root password, and expect no chat or phone channel that would attach a voice to an account. Token-only signup goes one better — an account with no inbox on it cannot leak one.

Is a disposable email good enough?

Yes, if it actually receives the SSH credentials and invoice mail — the address has to work; it just does not have to be yours.

Does paying in crypto hide my DNS?

No. DNS is public infrastructure: current records, historical zones and certificate logs are all scraped. Registration privacy and record hygiene are separate work from settlement.

What is the single biggest leak?

Reuse — one inbox, one domain or one fingerprint across a private workload and your daily identity merges the two forever. Separate them at signup and keep them separate.

Primary sources

Ready to launch?

Build the box — VPS, storage or bare metal — create the password, pay the invoice that follows.