Security

Security as architecture, not a feature.

The hard guarantees live in the design, not in a settings toggle. Here's exactly how your mail is protected — and what we deliberately never do.

Spam and phishing screening

Incoming mail is assessed for spam signals, sender authenticity, suspicious links and familiar phishing patterns before it reaches your main inbox.

Hidden trackers stay hidden

Known tracking pixels and remote message content are blocked from loading silently. You can read first and choose what to trust.

Two-factor, your way

Add TOTP via any authenticator app with single-use recovery codes. Sensitive admin actions require a fresh second factor — neither token nor code alone is enough.

Encrypted account sessions

Your IMAP password is sealed server-side with AES-256-GCM and only decrypted for the moment a mail operation runs. Rotating the master key invalidates stored sessions at once.

Short-lived, revocable tokens

Access tokens live 15 minutes; refresh tokens are single-use and rotate on every use. Logging out blacklists the token and deletes the session — a stolen token dies fast.

Hardened, locked-down backbone

Mail runs on a self-hosted Stalwart mail server whose management API is reachable only from localhost — never the public internet.

By omission

What we never do.

Good protection is also about removing avoidable risks.

  • No automatic loading of known tracking pixels
  • No hiding suspicious-link warnings behind jargon
  • No burying spam controls where you cannot find them
  • No selling or mining the contents of your correspondence
  • No long-lived session that cannot be revoked
  • No public exposure of the mail backend

Want the deep technical detail? Our security posture is documented and open to questions.

Ask us anything